100b9f705c
Check Cross-Plugin Imports / check (push) Has been cancelled
- config.py: add auth_database_url, worker_database_url, migration_database_url - db/__init__.py: separate engines for auth/worker/migration + get_auth_db/get_worker_db - auth.py: all auth endpoints use get_auth_db (crm_auth role) - auth_service.py: remove login fallback, require active membership, check status - auth_service.py: switch_tenant checks active membership status - alembic/env.py: use migration_database_url for Alembic - docker-compose.yml: add AUTH_DATABASE_URL, WORKER_DATABASE_URL - .env.example: add all 4 DB URLs with separate roles - migration 0085: transfer ownership to crm_migration, fix BYPASSRLS, enable RLS+FORCE on all tenant tables, drop old policies, create new fail-closed policies scoped to crm_api+crm_worker, revoke excessive grants, grant minimal crm_auth access, drop crm_runtime, set default privileges - tests/test_rls_coverage.py: automated RLS coverage check (13 tests) - tests/test_cross_tenant_security_v2.py: RLS tests with unprivileged role
81 lines
2.2 KiB
Bash
81 lines
2.2 KiB
Bash
# LeoCRM v1.0 - Environment Variables Template
|
|
|
|
# === REQUIRED ===
|
|
DATABASE_URL=postgresql+asyncpg://crm_api:your_password@localhost:5432/crm_db
|
|
AUTH_DATABASE_URL=postgresql+asyncpg://crm_auth:your_password@localhost:5432/crm_db
|
|
WORKER_DATABASE_URL=postgresql+asyncpg://crm_worker:your_password@localhost:5432/crm_db
|
|
MIGRATION_DATABASE_URL=postgresql+asyncpg://crm_migration:your_password@localhost:5432/crm_db
|
|
REDIS_URL=redis://localhost:6379/0
|
|
|
|
# === REQUIRED for Docker/Production ===
|
|
# Redis password (required in Docker)
|
|
REDIS_PASSWORD=your_redis_password
|
|
|
|
# === OPTIONAL (with defaults) ===
|
|
|
|
# Environment: development | production | testing
|
|
ENVIRONMENT=development
|
|
|
|
# Log level: DEBUG | INFO | WARNING | ERROR
|
|
LOG_LEVEL=INFO
|
|
|
|
# Database pool
|
|
DB_POOL_SIZE=10
|
|
DB_MAX_OVERFLOW=20
|
|
DB_ECHO=false
|
|
|
|
# Session settings
|
|
SESSION_TTL_SECONDS=28800
|
|
SESSION_COOKIE_NAME=leocrm_session
|
|
SESSION_COOKIE_SECURE=false
|
|
SESSION_COOKIE_SAMESITE=strict
|
|
SESSION_COOKIE_HTTPONLY=true
|
|
|
|
# Password hashing
|
|
BCRYPT_ROUNDS=12
|
|
PASSWORD_RESET_EXPIRY_HOURS=1
|
|
|
|
# CORS allowed origins (comma-separated, NO wildcards)
|
|
CORS_ORIGINS=http://localhost:5173,http://localhost:3000
|
|
|
|
# Secret Key (for signing, sessions — use a secure random string ≥32 chars in prod)
|
|
SECRET_KEY=change-me-in-production-use-a-secure-random-string
|
|
|
|
# Storage (file uploads, DMS)
|
|
STORAGE_PATH=/tmp
|
|
# Storage backend: local (default) or s3
|
|
STORAGE_BACKEND=local
|
|
# S3-compatible storage (when STORAGE_BACKEND=s3)
|
|
S3_ENDPOINT=
|
|
S3_BUCKET=
|
|
S3_ACCESS_KEY=
|
|
S3_SECRET_KEY=
|
|
S3_REGION=us-east-1
|
|
S3_SECURE=true
|
|
|
|
# SMTP / Email
|
|
SMTP_HOST=localhost
|
|
SMTP_PORT=587
|
|
SMTP_USERNAME=
|
|
SMTP_PASSWORD=
|
|
SMTP_FROM_EMAIL=noreply@leocrm.local
|
|
SMTP_USE_TLS=true
|
|
|
|
# Rate limiting
|
|
RATE_LIMIT_LOGIN_MAX=5
|
|
RATE_LIMIT_LOGIN_WINDOW=900
|
|
RATE_LIMIT_RESET_MAX=3
|
|
RATE_LIMIT_RESET_WINDOW=3600
|
|
RATE_LIMIT_RESET_CONFIRM_MAX=5
|
|
RATE_LIMIT_RESET_CONFIRM_WINDOW=3600
|
|
RATE_LIMIT_GENERAL_MAX=60
|
|
RATE_LIMIT_GENERAL_WINDOW=60
|
|
|
|
# === AI / Search ===
|
|
# Ollama Cloud API Key (für LiteLLM)
|
|
API_KEY_OLLAMA_CLOUD=
|
|
# Embedding Modell (default: ollama/nomic-embed-text)
|
|
SEARCH_EMBEDDING_MODEL=ollama/nomic-embed-text
|
|
# LLM Modell für Query Understanding (default: ollama/deepseek-v4)
|
|
SEARCH_LLM_MODEL=ollama/deepseek-v4
|