security: remove hardcoded credentials, untrack .env

- config/system_config.py: defaults are localhost with empty credentials;
  real hosts/secrets must come from env (.env or docker-compose)
- main.py: help text lists env var names instead of real NATS host/user
- doormile_test.py: reads infra config from env instead of literals
- untrack .env, ignore .env/.env.*, add .env.example with keys only
- pytest.ini: testpaths=tests so doormile_test.py isn't collected

Credentials remain in git history and must be rotated.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012AJLYcbTHCe45fyFnMfEin
This commit is contained in:
2026-09-22 15:52:06 +05:30
parent 7227d2d2bd
commit be8103c1d2
6 changed files with 57 additions and 27 deletions

View File

@@ -3,6 +3,7 @@
Doormile Full System Test Suite v2
Fixed: correct routes, 2-step login, pricing payload, health endpoint
"""
import os
import asyncio
import aiohttp
import json
@@ -13,14 +14,17 @@ import redis.asyncio as aioredis
from datetime import datetime
# ── Config ────────────────────────────────────────────────────────────────────
API_BASE = "https://api.doormile.com"
NATS_URL = "nats://66.116.226.161:4223"
NATS_USER = "doormile"
NATS_PASSWORD = "Package@321#"
REDIS_HOST = "66.116.226.255"
REDIS_PORT = 6380
REDIS_PASSWORD = "Package@321#"
INTERNAL_KEY = "doormile-internal-2024"
from dotenv import load_dotenv
load_dotenv()
API_BASE = os.getenv("GO_API_BASE_URL", "https://api.doormile.com")
NATS_URL = os.environ["NATS_URL"]
NATS_USER = os.getenv("NATS_USER", "")
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "")
REDIS_HOST = os.environ["REDIS_HOST"]
REDIS_PORT = int(os.getenv("REDIS_PORT", "6379"))
REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "")
INTERNAL_KEY = os.environ["INTERNAL_API_KEY"]
# Test customer — uses the one created by Window 1 test
TEST_PHONE = "9900000001"