Files
Zumri-Backend/.env.sample
T
Sathira Sri Sathara 9d3d431416 feat: implement identity and security features
- Added account types and privileged account types constants.
- Created admin user controller for updating user security fields.
- Developed role assignment controller for managing user roles.
- Implemented validation middleware for request schemas.
- Defined user role and auth session models for database interactions.
- Created services for authentication, email notifications, and OTP handling.
- Developed OAuth service for Google and Apple authentication.
- Added JWT utility functions for token generation and verification.
- Implemented comprehensive tests for authentication, session management, and password policies.
- Created migration for updating user schema and adding new tables for auth sessions and user identities.
2026-09-03 13:56:18 +05:30

68 lines
1.4 KiB
Bash

# Required for API and worker startup
APP_NAME=ZUMRI
NODE_ENV=development
PORT=3070
FRONTEND_URL=http://localhost:3000
TRUST_PROXY=0
DB_HOST=localhost
DB_PORT=3306
DB_NAME=zumri
DB_USER=zumri
DB_PASSWORD=replace_with_local_database_password
MYSQL_ROOT_PASSWORD=replace_with_local_root_password
REDIS_HOST=localhost
REDIS_PORT=6379
REDIS_PASSWORD=replace_with_local_redis_password
# Use separate randomly generated values of at least 32 characters.
JWT_SECRET=replace_with_a_random_value_at_least_32_chars
JWT_EXPIRES_IN=15m
JWT_ISSUER=zumri-api
JWT_AUDIENCE=zumri-clients
ACCESS_TOKEN_TTL=15m
REFRESH_TOKEN_TTL_DAYS=7
REMEMBER_ME_REFRESH_TOKEN_TTL_DAYS=30
LOGIN_OTP_TTL_SECONDS=900
LOGIN_OTP_MAX_ATTEMPTS=5
# Runtime controls
RUN_CRON=false
CACHE=true
JSON_BODY_LIMIT=1mb
API_RATE_LIMIT_WINDOW_MS=900000
API_RATE_LIMIT_MAX=300
SENSITIVE_RATE_LIMIT_WINDOW_MS=900000
SENSITIVE_RATE_LIMIT_MAX=20
SHUTDOWN_TIMEOUT_MS=10000
# Optional email feature
ENABLE_MAIL=false
MAIL_HOST=
MAIL_PORT=587
MAIL_USER=
MAIL_PASS=
MAIL_SECURE=false
MAIL_FROM=
# Optional S3 feature
ENABLE_S3=false
AWS_ACCESS_KEY_ID=
AWS_SECRET_ACCESS_KEY=
AWS_REGION=
AWS_S3_BUCKET_NAME=
# Optional documentation login
DOCS_USER=
DOCS_PASS=
# Optional application configuration
MANAGER_EMAIL=
DEFAULT_PASSWORD=
PASSWORD_RESET_TTL_SECONDS=900
EMAIL_VERIFICATION_TTL_SECONDS=86400
PUPPETEER_EXECUTABLE_PATH=
GOOGLE_CLIENT_ID=
APPLE_CLIENT_ID=