-
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
138 lines (124 loc) · 7.09 KB
/
Copy path.env.example
File metadata and controls
138 lines (124 loc) · 7.09 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
# Deployment identity - leave unset if you're self-hosting. Only the
# official pacifinance.com deployment sets this to "hosted" (in its own
# Vercel/Doppler config, never committed here); it tells the frontend
# whether to show hosted-community copy or self-hosted-instance copy, e.g.
# on the Comparison page's benchmark opt-in card (GET /api/config).
DEPLOYMENT_MODE=
# Supabase (Project Settings -> API)
SUPABASE_URL=
SUPABASE_SERVICE_ROLE_KEY=
# Optional safety timeout for server-side Supabase fetches (milliseconds).
SUPABASE_FETCH_TIMEOUT_MS=10000
# Upstash Redis (REST API, used for cache + registration anti-replay guard -
# not optional, e.g. registration hard-fails without a reachable one).
# Docker self-hosting: leave both unset. docker-compose.yml runs a local
# redis + redis-http (Upstash's own REST shim) and defaults these to point
# at it, so no cloud Upstash account is needed. Set both here only to use a
# real Upstash instance instead (required for `npm run dev:server` outside
# Docker, which has no local Redis of its own).
UPSTASH_REDIS_REST_URL=
UPSTASH_REDIS_REST_TOKEN=
# Cloudflare Turnstile (registration captcha). Required against the real
# backend (this includes Docker self-hosting) - there is no server-side dev
# bypass by design, since one would only be as safe as never forgetting to
# set NODE_ENV=production. VITE_DEV_MODE's Turnstile bypass only helps the
# mock/demo frontend (npm start with no backend); it does nothing here, the
# real backend still calls Cloudflare's siteverify and rejects the fake
# token it sends. Without registering a real Turnstile site, use Cloudflare's
# own official test keys instead (always pass, real verification, no bypass
# code involved):
# TURNSTILE_SECRET_KEY=1x0000000000000000000000000000000AA
# VITE_TURNSTILE_SITE_KEY=1x00000000000000000000AA
# These are fine to keep indefinitely if this instance stays local/private
# (e.g. self-hosted just for yourself, never reachable from the public
# internet) - there's no bot-abuse surface to protect in that case. Only
# create your own site, at https://dash.cloudflare.com/?to=/:account/turnstile
# for your own domain, if you're going to expose registration publicly - you
# cannot reuse pacifinance.com's keys either way, Cloudflare validates the
# widget against the domain it was registered for.
TURNSTILE_SECRET_KEY=
# Public Turnstile widget site key (not TURNSTILE_SECRET_KEY); paste the raw value without quotes.
VITE_TURNSTILE_SITE_KEY=
# Optional safety timeout for Turnstile verification and registration steps (milliseconds).
TURNSTILE_VERIFY_TIMEOUT_MS=10000
REGISTRATION_STEP_TIMEOUT_MS=10000
DEPENDENCY_HEALTH_TIMEOUT_MS=3000
# Comma-separated list of hostnames the Turnstile token's verified hostname must
# match in production (falls back to pacifinance.com,www.pacifinance.com if unset).
# Must match the hostname(s) configured on the Turnstile widget in Cloudflare.
TURNSTILE_ALLOWED_HOSTNAMES=
# CoinGecko API key (demo tier)
CG_KEY=
CG_TIMEOUT_MS=6000
# OpenFIGI API key (optional — raises the instrument search rate limit from
# 5/min to 25 per 6 seconds). The search feature works without it, just more
# rate-limited. Sign up for free at https://www.openfigi.com/api
OPENFIGI_KEY=
OPENFIGI_TIMEOUT_MS=6000
# Finnhub API key (free tier — 60 req/min, first stop for free-text stock/ETF/
# bond/fund symbol & name search since OpenFIGI's unauthenticated search is far
# more rate-limited). Sign up for free at https://finnhub.io/register
FINNHUB_KEY=
FINNHUB_TIMEOUT_MS=6000
# App-level encryption key for sensitive free-text fields (currently expenses.notes).
# 32 random bytes, base64: generate with `openssl rand -base64 32`. Lives only in
# Doppler/Vercel env vars, never in the DB or the repo. Losing/rotating it makes
# previously-encrypted notes unreadable unless the old key is kept for decryption.
DB_ENCRYPTION_KEY=
# Shared secret checked against the Authorization header on /api/cron/* endpoints.
# Set the same value here and as a Vercel env var: Vercel automatically sends it
# as "Authorization: Bearer $CRON_SECRET" when invoking Vercel Cron Jobs. The
# reminder-sending endpoint (/api/cron/send-reminders) is on the same router, but
# it's called by a Supabase pg_cron + pg_net job instead of Vercel Cron (see
# supabase/migrations/schedule-send-reminders.sql) — set the identical value in
# the Supabase Vault secret that migration references.
CRON_SECRET=
# VAPID keypair for Web Push (RFC 8292). Generate once with:
# npx web-push generate-vapid-keys
# VAPID_PUBLIC_KEY/VAPID_PRIVATE_KEY are server-only (never in the repo).
# VITE_WEB_PUSH_PUBLIC_KEY is the SAME public key, exposed to the frontend so the
# browser can create a push subscription — it's not a secret, but keep it in sync
# with VAPID_PUBLIC_KEY or subscriptions will fail to verify.
VAPID_PUBLIC_KEY=
VAPID_PRIVATE_KEY=
VITE_WEB_PUSH_PUBLIC_KEY=
# Contact URL Web Push services may use to reach you about a misbehaving
# subscription (required by the protocol as a "mailto:" or "https://" subject).
VAPID_CONTACT=mailto:support@pacifinance.com
# Umami analytics (self-hosters: leave both unset to run with analytics fully
# disabled - there is no default website ID, on purpose, so a self-hosted
# instance never reports its traffic into pacifinance.com's own dashboard).
# Create your own site at https://umami.is (or a self-hosted Umami) to get a
# website ID, and only override the script URL if you're not proxying /stats/
# through your own reverse proxy the way vercel.json does for the hosted app.
VITE_UMAMI_WEBSITE_ID=
VITE_UMAMI_SCRIPT_URL=
# GitHub integration (optional, all three unset just disables these features):
# - GITHUB_TOKEN raises the rate limit on the public GitHub stats widget
# (server/src/cache/items/githubStats.ts) from 60 to 5000 req/hour. A
# plain personal access token with no scopes is enough.
# - GITHUB_APP_ID / GITHUB_APP_INSTALLATION_ID / GITHUB_APP_PRIVATE_KEY let
# the feedback form (src/components/FeedbackForm.tsx) file submissions as
# GitHub issues (server/src/libs/githubApp.ts). Requires a GitHub App with
# "Issues: write" permission installed on the target repo.
GITHUB_TOKEN=
GITHUB_APP_ID=
GITHUB_APP_INSTALLATION_ID=
GITHUB_APP_PRIVATE_KEY=
# Local dev only (ignored on Vercel, which sets VERCEL=1 and PORT automatically)
PORT=3000
NODE_ENV=development
# Docker self-hosting only: the HOST-side port the `api` container's port
# 3000 gets published on (docker-compose.yml). Only matters for reaching the
# API directly from the host (curl, Postman, ...) - the `web` container
# always reaches `api` over the internal Docker network regardless of this.
# Defaults to 3001; override here if that's also already taken on your
# machine instead of editing docker-compose.yml.
API_HOST_PORT=3001
# Set to "true" only for local development. Combined with an unset
# VITE_TURNSTILE_SITE_KEY, it lets sign-up/recovery skip Turnstile in the
# frontend-only mock/demo mode (npm start, no backend). It does NOT bypass
# Turnstile against the real backend (Docker self-hosting included) - see the
# Cloudflare Turnstile section above for testing that path instead. Never set
# this in a production deployment — leave unset.
VITE_DEV_MODE=