9d3d431416
- Added account types and privileged account types constants. - Created admin user controller for updating user security fields. - Developed role assignment controller for managing user roles. - Implemented validation middleware for request schemas. - Defined user role and auth session models for database interactions. - Created services for authentication, email notifications, and OTP handling. - Developed OAuth service for Google and Apple authentication. - Added JWT utility functions for token generation and verification. - Implemented comprehensive tests for authentication, session management, and password policies. - Created migration for updating user schema and adding new tables for auth sessions and user identities.
68 lines
1.4 KiB
Bash
68 lines
1.4 KiB
Bash
# Required for API and worker startup
|
|
APP_NAME=ZUMRI
|
|
NODE_ENV=development
|
|
PORT=3070
|
|
FRONTEND_URL=http://localhost:3000
|
|
TRUST_PROXY=0
|
|
|
|
DB_HOST=localhost
|
|
DB_PORT=3306
|
|
DB_NAME=zumri
|
|
DB_USER=zumri
|
|
DB_PASSWORD=replace_with_local_database_password
|
|
MYSQL_ROOT_PASSWORD=replace_with_local_root_password
|
|
|
|
REDIS_HOST=localhost
|
|
REDIS_PORT=6379
|
|
REDIS_PASSWORD=replace_with_local_redis_password
|
|
|
|
# Use separate randomly generated values of at least 32 characters.
|
|
JWT_SECRET=replace_with_a_random_value_at_least_32_chars
|
|
JWT_EXPIRES_IN=15m
|
|
JWT_ISSUER=zumri-api
|
|
JWT_AUDIENCE=zumri-clients
|
|
ACCESS_TOKEN_TTL=15m
|
|
REFRESH_TOKEN_TTL_DAYS=7
|
|
REMEMBER_ME_REFRESH_TOKEN_TTL_DAYS=30
|
|
LOGIN_OTP_TTL_SECONDS=900
|
|
LOGIN_OTP_MAX_ATTEMPTS=5
|
|
|
|
# Runtime controls
|
|
RUN_CRON=false
|
|
CACHE=true
|
|
JSON_BODY_LIMIT=1mb
|
|
API_RATE_LIMIT_WINDOW_MS=900000
|
|
API_RATE_LIMIT_MAX=300
|
|
SENSITIVE_RATE_LIMIT_WINDOW_MS=900000
|
|
SENSITIVE_RATE_LIMIT_MAX=20
|
|
SHUTDOWN_TIMEOUT_MS=10000
|
|
|
|
# Optional email feature
|
|
ENABLE_MAIL=false
|
|
MAIL_HOST=
|
|
MAIL_PORT=587
|
|
MAIL_USER=
|
|
MAIL_PASS=
|
|
MAIL_SECURE=false
|
|
MAIL_FROM=
|
|
|
|
# Optional S3 feature
|
|
ENABLE_S3=false
|
|
AWS_ACCESS_KEY_ID=
|
|
AWS_SECRET_ACCESS_KEY=
|
|
AWS_REGION=
|
|
AWS_S3_BUCKET_NAME=
|
|
|
|
# Optional documentation login
|
|
DOCS_USER=
|
|
DOCS_PASS=
|
|
|
|
# Optional application configuration
|
|
MANAGER_EMAIL=
|
|
DEFAULT_PASSWORD=
|
|
PASSWORD_RESET_TTL_SECONDS=900
|
|
EMAIL_VERIFICATION_TTL_SECONDS=86400
|
|
PUPPETEER_EXECUTABLE_PATH=
|
|
GOOGLE_CLIENT_ID=
|
|
APPLE_CLIENT_ID=
|