security: remove hardcoded credentials, untrack .env

- config/system_config.py: defaults are localhost with empty credentials;
  real hosts/secrets must come from env (.env or docker-compose)
- main.py: help text lists env var names instead of real NATS host/user
- doormile_test.py: reads infra config from env instead of literals
- untrack .env, ignore .env/.env.*, add .env.example with keys only
- pytest.ini: testpaths=tests so doormile_test.py isn't collected

Credentials remain in git history and must be rotated.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012AJLYcbTHCe45fyFnMfEin
This commit is contained in:
2026-09-22 15:52:06 +05:30
parent 7227d2d2bd
commit be8103c1d2
6 changed files with 57 additions and 27 deletions

16
.env.example Normal file
View File

@@ -0,0 +1,16 @@
GO_API_BASE_URL=
NATS_URL=
REDIS_HOST=
REDIS_PORT=
REDIS_PASSWORD=
INTERNAL_API_KEY=
DB_HOST=
DB_PORT=
DB_NAME=
DB_USER=
DB_PASSWORD=
NATS_USER=
NATS_PASSWORD=
ANTHROPIC_API_KEY=
LLM_MODEL=claude-opus-4-8
LOG_LEVEL=INFO

5
.gitignore vendored
View File

@@ -7,3 +7,8 @@ venv/
.idea/
.vscode/
# secrets
.env
.env.*
!.env.example

View File

@@ -1,27 +1,28 @@
"""System configuration for LogiFlow AI."""
import os
# Infrastructure Connections — values come from environment / .env file.
# Hardcoded strings are last-resort defaults; set the matching env var in production.
NATS_URL = os.getenv("NATS_URL", "nats://doormile:Package@321#@66.116.226.161:4223")
NATS_HOST = os.getenv("NATS_HOST", "66.116.226.161")
NATS_PORT = int(os.getenv("NATS_PORT", "4223"))
NATS_USER = os.getenv("NATS_USER", "doormile")
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "Package@321#")
# Infrastructure Connections — values come from environment / .env file
# (see .env.example). Defaults point at localhost with no credentials so the
# system runs in local-fallback mode; real hosts and secrets are never in code.
NATS_URL = os.getenv("NATS_URL", "nats://localhost:4222")
NATS_HOST = os.getenv("NATS_HOST", "localhost")
NATS_PORT = int(os.getenv("NATS_PORT", "4222"))
NATS_USER = os.getenv("NATS_USER", "")
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "")
REDIS_HOST = os.getenv("REDIS_HOST", "66.116.226.255")
REDIS_PORT = int(os.getenv("REDIS_PORT", "6380"))
REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "Package@321#")
REDIS_HOST = os.getenv("REDIS_HOST", "localhost")
REDIS_PORT = int(os.getenv("REDIS_PORT", "6379"))
REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "")
# Postgres — individual params to avoid @ in password breaking DSN parsing
DB_HOST = os.getenv("DB_HOST", "31.97.228.132")
DB_PORT = int(os.getenv("DB_PORT", "5433"))
DB_HOST = os.getenv("DB_HOST", "localhost")
DB_PORT = int(os.getenv("DB_PORT", "5432"))
DB_NAME = os.getenv("DB_NAME", "logistics")
DB_USER = os.getenv("DB_USER", "admin")
DB_PASSWORD = os.getenv("DB_PASSWORD", "Package@321#")
DB_USER = os.getenv("DB_USER", "postgres")
DB_PASSWORD = os.getenv("DB_PASSWORD", "")
GO_API_BASE_URL = os.getenv("GO_API_BASE_URL", "http://localhost:8080")
INTERNAL_API_KEY = os.getenv("INTERNAL_API_KEY", "doormile-internal-2024")
INTERNAL_API_KEY = os.getenv("INTERNAL_API_KEY", "")
# Route Optimization API (Valhalla-backed road routing). The ExpressDispatchAgent
# calls its Doormile endpoint (/api/v1/optimization/doormile/sequence) to order a

View File

@@ -3,6 +3,7 @@
Doormile Full System Test Suite v2
Fixed: correct routes, 2-step login, pricing payload, health endpoint
"""
import os
import asyncio
import aiohttp
import json
@@ -13,14 +14,17 @@ import redis.asyncio as aioredis
from datetime import datetime
# ── Config ────────────────────────────────────────────────────────────────────
API_BASE = "https://api.doormile.com"
NATS_URL = "nats://66.116.226.161:4223"
NATS_USER = "doormile"
NATS_PASSWORD = "Package@321#"
REDIS_HOST = "66.116.226.255"
REDIS_PORT = 6380
REDIS_PASSWORD = "Package@321#"
INTERNAL_KEY = "doormile-internal-2024"
from dotenv import load_dotenv
load_dotenv()
API_BASE = os.getenv("GO_API_BASE_URL", "https://api.doormile.com")
NATS_URL = os.environ["NATS_URL"]
NATS_USER = os.getenv("NATS_USER", "")
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "")
REDIS_HOST = os.environ["REDIS_HOST"]
REDIS_PORT = int(os.getenv("REDIS_PORT", "6379"))
REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "")
INTERNAL_KEY = os.environ["INTERNAL_API_KEY"]
# Test customer — uses the one created by Window 1 test
TEST_PHONE = "9900000001"

View File

@@ -204,11 +204,12 @@ Usage:
python main.py --portal Launch Streamlit customer portal
python main.py --help Show this help
Infrastructure (set in .env):
NATS nats://doormile@66.116.226.161:4223
Redis 66.116.226.255:6380
Infrastructure (set in .env — see .env.example):
NATS NATS_URL / NATS_USER / NATS_PASSWORD
Redis REDIS_HOST / REDIS_PORT / REDIS_PASSWORD
PG DB_HOST / DB_PORT / DB_NAME / DB_USER / DB_PASSWORD
API GO_API_BASE_URL
API GO_API_BASE_URL / INTERNAL_API_KEY
LLM ANTHROPIC_API_KEY / LLM_MODEL
""")

3
pytest.ini Normal file
View File

@@ -0,0 +1,3 @@
[pytest]
testpaths = tests
asyncio_mode = auto