C1: reset_user_pin wrote to a non-existent column (pin_failed_attempts);
the real column is failed_pin_attempts, so every PIN reset 500'd. Fixed
the column name; new e2e (pin-reset.spec.ts) proves a reset returns a
usable PIN and the target can recover with it.
C2: config.rs::validate_secrets now rejects placeholder-ish secrets
(change_me/dev_secret/placeholder), enforces len>=32 in prod, and
requires a real ADMIN_PASSWORD_HASH. docker-compose.yml sets
APP_ENV=production so the guard actually runs. Corrected the false
"fixed" claim in SECURITY-BACKLOG.md. .env.example documents the rule.
Riders in these files (documented here since git can't split hunks):
- host.rs also carries the event-scoped ban_user fix and the
close_event/open_event no-op broadcast guard (medium).
- docker-compose.yml also adds ORIGIN (H6), app/frontend healthchecks with
Caddy waiting on health, and per-service memory limits (medium).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
52 lines
3.4 KiB
Plaintext
52 lines
3.4 KiB
Plaintext
# ── Domain ────────────────────────────────────────────────────────────────────
|
||
# Public domain Caddy will serve and obtain a TLS certificate for.
|
||
DOMAIN=my-event.example.com
|
||
|
||
# ── App server ────────────────────────────────────────────────────────────────
|
||
APP_PORT=3000
|
||
# Set to `production` in real deployments. This activates the secret guard that
|
||
# refuses to boot with placeholder JWT_SECRET / ADMIN_PASSWORD_HASH values.
|
||
# (docker-compose.yml already sets APP_ENV=production for the app service.)
|
||
APP_ENV=production
|
||
|
||
# ── Database ──────────────────────────────────────────────────────────────────
|
||
# Set a strong password and keep it in sync between DATABASE_URL and
|
||
# POSTGRES_PASSWORD. Generate one with: openssl rand -hex 24
|
||
DATABASE_URL=postgres://eventsnap:CHANGE_ME_use_a_strong_password@db:5432/eventsnap
|
||
POSTGRES_USER=eventsnap
|
||
POSTGRES_PASSWORD=CHANGE_ME_use_a_strong_password
|
||
POSTGRES_DB=eventsnap
|
||
|
||
# ── Authentication ────────────────────────────────────────────────────────────
|
||
# Generate with: openssl rand -hex 64
|
||
JWT_SECRET=change_me_to_a_random_64_byte_hex_string
|
||
SESSION_EXPIRY_DAYS=30
|
||
|
||
# Admin dashboard password (bcrypt hash).
|
||
# Generate with: htpasswd -bnBC 12 "" yourpassword | tr -d ':\n'
|
||
ADMIN_PASSWORD_HASH=$2y$12$placeholder_replace_me
|
||
|
||
# ── Event ─────────────────────────────────────────────────────────────────────
|
||
EVENT_NAME=Max & Maria's Wedding
|
||
EVENT_SLUG=max-maria-2026
|
||
|
||
# ── Storage ───────────────────────────────────────────────────────────────────
|
||
MEDIA_PATH=/media
|
||
|
||
# ── Upload limits ─────────────────────────────────────────────────────────────
|
||
DEFAULT_MAX_IMAGE_SIZE_MB=20
|
||
DEFAULT_MAX_VIDEO_SIZE_MB=500
|
||
|
||
# ── Rate limiting ─────────────────────────────────────────────────────────────
|
||
DEFAULT_UPLOAD_RATE_PER_HOUR=10
|
||
DEFAULT_FEED_RATE_PER_MIN=60
|
||
DEFAULT_EXPORT_RATE_PER_DAY=3
|
||
|
||
# ── Capacity ──────────────────────────────────────────────────────────────────
|
||
DEFAULT_ESTIMATED_GUEST_COUNT=100
|
||
# Fraction of total storage that triggers the "low storage" warning (0.0–1.0)
|
||
DEFAULT_QUOTA_TOLERANCE=0.75
|
||
|
||
# ── Workers ───────────────────────────────────────────────────────────────────
|
||
COMPRESSION_WORKER_CONCURRENCY=2
|