-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
63 lines (53 loc) · 2.76 KB
/
Copy path.env.example
File metadata and controls
63 lines (53 loc) · 2.76 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
# ---------------------------------------------------------------------------
# MAC central auth service — environment template.
# Copy to `.env` and fill in. NEVER commit the real .env.
# Secrets live in the committee password manager under projects@monashcoding.com.
# ---------------------------------------------------------------------------
# Public base URL of this service (used as JWT issuer and OAuth redirect base).
# Locally you can use http://localhost:3000
BETTER_AUTH_URL=https://auth.monashcoding.com
# Long random secret for Better Auth (sessions, state signing).
# Generate: openssl rand -base64 32
BETTER_AUTH_SECRET=replace-me-with-openssl-rand-base64-32
# --- Postgres (self-hosted) ---
# IMPORTANT: keep the password URL/shell-safe — letters and digits only. Characters
# like $ @ : / # break Docker/Dokploy env interpolation and the assembled DATABASE_URL.
# Generate a safe one: openssl rand -hex 24
POSTGRES_USER=mac_auth
POSTGRES_PASSWORD=replace-me-hex-only-no-special-chars
POSTGRES_DB=mac_auth
# --- Google OAuth ---
# Redirect URI to register: https://auth.monashcoding.com/api/auth/callback/google
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
# --- Microsoft OAuth (tenant "common" — personal + work/school accounts) ---
# Redirect URI to register: https://auth.monashcoding.com/api/auth/callback/microsoft
MICROSOFT_CLIENT_ID=
MICROSOFT_CLIENT_SECRET=
# Extra origins allowed to initiate auth flows (comma-separated).
# NOTE: every https *.monashcoding.com subdomain is trusted automatically — you do NOT
# need to list MAC apps here. Use this only for off-domain origins, e.g. local dev:
# TRUSTED_ORIGINS=http://localhost:3000,http://localhost:3001
# Origins are exact: 127.0.0.1 and other ports must be listed separately if actually used.
TRUSTED_ORIGINS=
# JWT audience claim MAC apps verify against.
JWT_AUDIENCE=mac-suite
# --- Committee roster (Notion) ---
# Membership, team, and exec status are DERIVED from the Notion committee roster and
# synced into Postgres hourly; the token then carries roles + team. A Notion outage never
# affects logins — tokens are minted from the last-synced roster in Postgres.
#
# Notion integration token (owned by projects@monashcoding.com; shared with notioncal-to-gcal).
NOTION_TOKEN=
# Notion committee-roster database id.
NOTION_ROSTER_DB_ID=
# Notion API version — match notioncal-to-gcal for consistency.
NOTION_VERSION=2022-06-28
# Optional: per-request Notion fetch timeout in ms (default 15000).
# NOTION_TIMEOUT_MS=15000
# Infra superusers granted the "admin" role — comma-separated emails. NOT from Notion.
# Also gates POST /api/admin/sync-roster.
ADMIN_EMAILS=
# Set to 1 for ONE sync to bypass the >50%-removal guard (genuine recruitment churn),
# then unset. Leave unset in normal operation.
# FORCE_ROSTER_SYNC=