From be8103c1d27ea38ca789b7b44be637f95ef66bd2 Mon Sep 17 00:00:00 2001 From: Suriyakumarvijayanayagam Date: Tue, 22 Sep 2026 15:52:06 +0530 Subject: [PATCH] security: remove hardcoded credentials, untrack .env - config/system_config.py: defaults are localhost with empty credentials; real hosts/secrets must come from env (.env or docker-compose) - main.py: help text lists env var names instead of real NATS host/user - doormile_test.py: reads infra config from env instead of literals - untrack .env, ignore .env/.env.*, add .env.example with keys only - pytest.ini: testpaths=tests so doormile_test.py isn't collected Credentials remain in git history and must be rotated. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_012AJLYcbTHCe45fyFnMfEin --- .env.example | 16 ++++++++++++++++ .gitignore | 5 +++++ config/system_config.py | 31 ++++++++++++++++--------------- doormile_test.py | 20 ++++++++++++-------- main.py | 9 +++++---- pytest.ini | 3 +++ 6 files changed, 57 insertions(+), 27 deletions(-) create mode 100644 .env.example create mode 100644 pytest.ini diff --git a/.env.example b/.env.example new file mode 100644 index 0000000..36eb587 --- /dev/null +++ b/.env.example @@ -0,0 +1,16 @@ +GO_API_BASE_URL= +NATS_URL= +REDIS_HOST= +REDIS_PORT= +REDIS_PASSWORD= +INTERNAL_API_KEY= +DB_HOST= +DB_PORT= +DB_NAME= +DB_USER= +DB_PASSWORD= +NATS_USER= +NATS_PASSWORD= +ANTHROPIC_API_KEY= +LLM_MODEL=claude-opus-4-8 +LOG_LEVEL=INFO diff --git a/.gitignore b/.gitignore index 4ebcdd6..e78aae2 100644 --- a/.gitignore +++ b/.gitignore @@ -7,3 +7,8 @@ venv/ .idea/ .vscode/ + +# secrets +.env +.env.* +!.env.example diff --git a/config/system_config.py b/config/system_config.py index 96f25c4..ea049d6 100644 --- a/config/system_config.py +++ b/config/system_config.py @@ -1,27 +1,28 @@ """System configuration for LogiFlow AI.""" import os -# Infrastructure Connections — values come from environment / .env file. -# Hardcoded strings are last-resort defaults; set the matching env var in production. -NATS_URL = os.getenv("NATS_URL", "nats://doormile:Package@321#@66.116.226.161:4223") -NATS_HOST = os.getenv("NATS_HOST", "66.116.226.161") -NATS_PORT = int(os.getenv("NATS_PORT", "4223")) -NATS_USER = os.getenv("NATS_USER", "doormile") -NATS_PASSWORD = os.getenv("NATS_PASSWORD", "Package@321#") +# Infrastructure Connections — values come from environment / .env file +# (see .env.example). Defaults point at localhost with no credentials so the +# system runs in local-fallback mode; real hosts and secrets are never in code. +NATS_URL = os.getenv("NATS_URL", "nats://localhost:4222") +NATS_HOST = os.getenv("NATS_HOST", "localhost") +NATS_PORT = int(os.getenv("NATS_PORT", "4222")) +NATS_USER = os.getenv("NATS_USER", "") +NATS_PASSWORD = os.getenv("NATS_PASSWORD", "") -REDIS_HOST = os.getenv("REDIS_HOST", "66.116.226.255") -REDIS_PORT = int(os.getenv("REDIS_PORT", "6380")) -REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "Package@321#") +REDIS_HOST = os.getenv("REDIS_HOST", "localhost") +REDIS_PORT = int(os.getenv("REDIS_PORT", "6379")) +REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "") # Postgres — individual params to avoid @ in password breaking DSN parsing -DB_HOST = os.getenv("DB_HOST", "31.97.228.132") -DB_PORT = int(os.getenv("DB_PORT", "5433")) +DB_HOST = os.getenv("DB_HOST", "localhost") +DB_PORT = int(os.getenv("DB_PORT", "5432")) DB_NAME = os.getenv("DB_NAME", "logistics") -DB_USER = os.getenv("DB_USER", "admin") -DB_PASSWORD = os.getenv("DB_PASSWORD", "Package@321#") +DB_USER = os.getenv("DB_USER", "postgres") +DB_PASSWORD = os.getenv("DB_PASSWORD", "") GO_API_BASE_URL = os.getenv("GO_API_BASE_URL", "http://localhost:8080") -INTERNAL_API_KEY = os.getenv("INTERNAL_API_KEY", "doormile-internal-2024") +INTERNAL_API_KEY = os.getenv("INTERNAL_API_KEY", "") # Route Optimization API (Valhalla-backed road routing). The ExpressDispatchAgent # calls its Doormile endpoint (/api/v1/optimization/doormile/sequence) to order a diff --git a/doormile_test.py b/doormile_test.py index e100f02..48acdce 100644 --- a/doormile_test.py +++ b/doormile_test.py @@ -3,6 +3,7 @@ Doormile Full System Test Suite v2 Fixed: correct routes, 2-step login, pricing payload, health endpoint """ +import os import asyncio import aiohttp import json @@ -13,14 +14,17 @@ import redis.asyncio as aioredis from datetime import datetime # ── Config ──────────────────────────────────────────────────────────────────── -API_BASE = "https://api.doormile.com" -NATS_URL = "nats://66.116.226.161:4223" -NATS_USER = "doormile" -NATS_PASSWORD = "Package@321#" -REDIS_HOST = "66.116.226.255" -REDIS_PORT = 6380 -REDIS_PASSWORD = "Package@321#" -INTERNAL_KEY = "doormile-internal-2024" +from dotenv import load_dotenv +load_dotenv() + +API_BASE = os.getenv("GO_API_BASE_URL", "https://api.doormile.com") +NATS_URL = os.environ["NATS_URL"] +NATS_USER = os.getenv("NATS_USER", "") +NATS_PASSWORD = os.getenv("NATS_PASSWORD", "") +REDIS_HOST = os.environ["REDIS_HOST"] +REDIS_PORT = int(os.getenv("REDIS_PORT", "6379")) +REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "") +INTERNAL_KEY = os.environ["INTERNAL_API_KEY"] # Test customer — uses the one created by Window 1 test TEST_PHONE = "9900000001" diff --git a/main.py b/main.py index e959aff..b8873c2 100644 --- a/main.py +++ b/main.py @@ -204,11 +204,12 @@ Usage: python main.py --portal Launch Streamlit customer portal python main.py --help Show this help -Infrastructure (set in .env): - NATS nats://doormile@66.116.226.161:4223 - Redis 66.116.226.255:6380 +Infrastructure (set in .env — see .env.example): + NATS NATS_URL / NATS_USER / NATS_PASSWORD + Redis REDIS_HOST / REDIS_PORT / REDIS_PASSWORD PG DB_HOST / DB_PORT / DB_NAME / DB_USER / DB_PASSWORD - API GO_API_BASE_URL + API GO_API_BASE_URL / INTERNAL_API_KEY + LLM ANTHROPIC_API_KEY / LLM_MODEL """) diff --git a/pytest.ini b/pytest.ini new file mode 100644 index 0000000..6f94355 --- /dev/null +++ b/pytest.ini @@ -0,0 +1,3 @@ +[pytest] +testpaths = tests +asyncio_mode = auto