dorfteich/deploy/compose/.env.example
Claude Opus 4.8 d4ebcfcfbe
All checks were successful
CD / Build and push images (push) Successful in 2m45s
CI / Lint, typecheck, test (push) Successful in 1m56s
CI / Auth e2e pack (push) Successful in 2m1s
CI / Build container images (push) Has been skipped
CD / Deploy to Test (push) Successful in 9s
CD / Smoke tests against Test (push) Successful in 1m9s
CD / Promote to Int (push) Successful in 12s
Add collaboration token issuance and connection authentication (#34)
The api mints a short-lived (60 s) HS256 JWT per page open after an interim
permission check; the collab server authenticates every connection with it
(ADR 0003/0007 — the only JWTs in the system).

- packages/shared: browser-safe token schema/types in `collab-token`, and the
  Node `crypto` sign/verify in `token-crypto` behind its own subpath export
  (`@dorfteich/shared/token-crypto`) so the web bundle never pulls in
  `node:crypto`. Only HS256 is produced/accepted; the signature is checked in
  constant time before any untrusted field is read.
- api: `GET /pages/:id/collab-token` (auth-required) returns
  {token, mode, expiresInSeconds}; `mode` is rw/ro via the interim access
  service; issuance is logged at debug level without the token value.
- collab: `onAuthenticate` verifies the token, checks the pageId matches the
  document name, stores {userId, mode} context, and enforces `ro` via
  Hocuspocus' read-only connection flag. Hocuspocus' own signal handling is
  disabled so index.ts remains the single shutdown owner.
- Shared COLLAB_TOKEN_SECRET env for api + collab (compose, dev overlay,
  .env.example, stage docs); a dev default keeps native dev/test/CI running.

Tests: shared token round-trip/rejection; api endpoint e2e (auth required,
claims, 404 for non-members/unknown ids); collab integration via
HocuspocusProvider (valid token connects; expired/tampered/mismatched-page/
wrong-secret rejected; read-only writes dropped, verified with two clients).

Closes #34

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 15:52:19 +02:00

48 lines
2.0 KiB
Plaintext

# Dorfteich stage configuration. Copy to `.env` (mode 600, never in git)
# next to docker-compose.yml and adjust the values.
# --- required ---------------------------------------------------------------
# PostgreSQL password for the `dorfteich` database user.
POSTGRES_PASSWORD=change-me
# Secret that signs/verifies the short-lived collaboration tokens (issue #34).
# The api and collab services share this one value; use a long random string
# (e.g. `openssl rand -base64 32`). Min length 16.
COLLAB_TOKEN_SECRET=change-me-to-a-long-random-string
# --- images -----------------------------------------------------------------
# Image name prefix. Stages pull from the Gitea registry, e.g.
# gitea.101010.cloud/stwaidele/dorfteich — local builds use the default.
IMAGE_PREFIX=dorfteich
# Image tag to run: a git SHA, `test`, `int`, or a release tag like v1.2.0.
TAG=latest
# --- ports (localhost only; the host reverse proxy routes to these) ---------
# Suggested per stage on the shared VPS: test 8100/8101/8102,
# int 8110/8111/8112, prod 8120/8121/8122 (web/api/collab).
WEB_PORT=8100
API_PORT=8101
# collab (Hocuspocus) WebSocket server; the proxy routes /collab here.
COLLAB_PORT=8102
# --- behavior ----------------------------------------------------------------
# pino log level: fatal|error|warn|info|debug|trace
LOG_LEVEL=info
# Compose project name; set per stage (dorfteich-test, dorfteich-int, …).
COMPOSE_PROJECT_NAME=dorfteich
# --- public URL + mail --------------------------------------------------------
# Public base URL of the stage (scheme + host). E-mail links and the CSRF
# origin check are derived from it — it must match what browsers use.
APP_BASE_URL=https://test.dorfteich.cloud
# SMTP relay for outgoing mail (verification, password reset). Leave unset
# to keep the Mailpit dev defaults; real stages need a real relay.
SMTP_HOST=mail.example.com
SMTP_PORT=465
SMTP_SECURE=true
SMTP_USER=wiki@example.com
SMTP_PASS=change-me
SMTP_FROM=Dorfteich <wiki@example.com>