Build / build-and-push (push) Successful in 14s
An optional comma-separated list of glob patterns restricting which addresses may register, applied on top of APP_ALLOW_REGISTRATION. A non-matching new address is silently ignored exactly like registration being off; an address that already has an account can still sign in. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
68 lines
2.7 KiB
Bash
68 lines
2.7 KiB
Bash
# Copy to .env and adjust as needed. All values are optional and have sane
|
|
# development defaults (see src/Support/Config.php).
|
|
|
|
# Show full exception details in API error responses. Never enable in production.
|
|
APP_DEBUG=false
|
|
|
|
# Directory for generated files: the SQLite database and the JWT signing key.
|
|
# Defaults to <project>/storage. The Docker setup points this at a volume
|
|
# outside the bind-mounted source.
|
|
STORAGE_PATH=storage
|
|
|
|
# Path to the SQLite database file (absolute, or relative to the project root).
|
|
# Defaults to <STORAGE_PATH>/database.sqlite.
|
|
DATABASE_PATH=storage/database.sqlite
|
|
|
|
# Secret used to sign JWTs. Leave blank to auto-generate one into storage/secret.key.
|
|
JWT_SECRET=
|
|
|
|
# How long an issued token stays valid, in seconds (default: 86400 = 24h).
|
|
JWT_TTL=86400
|
|
|
|
# When false, POST /api/auth/magic-link only signs existing users in -- an
|
|
# unknown address is silently ignored (same response either way) rather than
|
|
# creating a new account. Closes sign-ups without touching existing users.
|
|
APP_ALLOW_REGISTRATION=true
|
|
|
|
# Optional allowlist restricting which addresses may create an account, applied
|
|
# on top of APP_ALLOW_REGISTRATION. Comma-separated glob patterns; leave blank
|
|
# to allow any address. Matching is case-insensitive. An address that already
|
|
# has an account can still sign in even if it no longer matches.
|
|
# APP_EMAIL_ALLOWLIST=*@example.com, *@*.example.org, someone@gmail.com
|
|
APP_EMAIL_ALLOWLIST=
|
|
|
|
# Minimum gap, in seconds, before a magic link can be resent to the same
|
|
# address (sign-in or email-change). The Docker Compose setup overrides this
|
|
# to 0 for local development, so links can be resent immediately.
|
|
MAGIC_LINK_RESEND_SECONDS=60
|
|
|
|
# Maximum number of projects a single user may create. 0 means unlimited.
|
|
MAX_PROJECTS_PER_OWNER=0
|
|
|
|
# Base URL the app is reached at. Verification magic links point here, e.g.
|
|
# <APP_URL>/verify-email?token=... The Docker image serves the SPA and the API
|
|
# together on http://localhost:8080; a host `npm run dev` serves it on :5173.
|
|
APP_URL=http://localhost:8080
|
|
|
|
# WebAuthn (passkeys). The relying party ID is the domain a passkey is bound
|
|
# to -- defaults to APP_URL's host. Browsers only allow `localhost` or a real
|
|
# domain served over HTTPS, so passkeys won't work when APP_URL is a LAN IP.
|
|
WEBAUTHN_RP_ID=
|
|
WEBAUTHN_RP_NAME=Projects
|
|
|
|
# Email delivery.
|
|
# mail — PHP's built-in mail() function (default)
|
|
# smtp — the SMTP server configured below
|
|
# log — append messages to MAIL_LOG_PATH instead of sending (dev/test)
|
|
MAIL_TRANSPORT=mail
|
|
MAIL_FROM=no-reply@todo.test
|
|
MAIL_FROM_NAME=Projects
|
|
MAIL_LOG_PATH=storage/mail.log
|
|
|
|
# Only used when MAIL_TRANSPORT=smtp.
|
|
MAIL_SMTP_HOST=
|
|
MAIL_SMTP_PORT=587
|
|
MAIL_SMTP_USERNAME=
|
|
MAIL_SMTP_PASSWORD=
|
|
MAIL_SMTP_ENCRYPTION=tls # tls | ssl | none
|