updates on the otp updates on the customer app

This commit is contained in:
2026-09-15 11:50:12 +05:30
parent e8f4c0a593
commit 89321c9e06
17 changed files with 1072 additions and 69 deletions

View File

@@ -1,7 +1,7 @@
# App Config
APP_PORT=8081
ENV=development
JWT_SECRET_KEY=DoormileSuperSecretJWTKey2026!
JWT_SECRET_KEY=change-me-locally
INTERNAL_API_KEY=doormile-internal-2024
# Reverse proxy — comma-separated IPs/CIDRs allowed to set X-Forwarded-For.
@@ -16,13 +16,13 @@ DB_HOST=31.97.228.132
DB_PORT=5433
DB_NAME=logistics
DB_USER=admin
DB_PASSWORD=Package@321#
DB_PASSWORD=
# Redis Configuration
REDIS_HOST=31.97.228.132
REDIS_PORT=6379
REDIS_USER=admin
REDIS_PASSWORD=Package@321#
REDIS_PASSWORD=
# SMTP Configuration (email OTP verification)
SMTP_HOST=smtp.gmail.com
@@ -38,4 +38,26 @@ $env:PATH += ";C:\Program Files\Docker\Docker\resources\bin"
>> docker push doormile/doormile-backend:latest
>>
# ── Required / changed 2026-09-11 ───────────────────────────────────────────
# JWT_SECRET_KEY no longer has a default. It used to fall back to a literal in
# config/config.go, which meant anyone holding this repository could mint a
# valid token for any user id and any role against a deployment that had not
# overridden it.
# ENV=production + unset -> the service REFUSES TO START (cfg.Validate).
# anything else + unset -> an ephemeral per-process key is generated and a
# warning logged; tokens will not survive a restart.
# Set it for a stable local session, and make sure it is set in production
# before deploying (the JWT_SECRET_KEY line above).
#
# NATS_URL and the AI/optimiser hosts also lost their defaults, which pointed at
# the real production cluster — an unconfigured local run silently joined the
# live stream and competed with the production workers. Unset now means
# "disabled": no NATS connection, no route sequencing, legacy assignment
# scoring. Set them explicitly where you actually want them.
# NATS_URL=nats://localhost:4222
# NATS_USER=
# NATS_PASSWORD=
# AI_LAYER_BASE_URL=
# ROUTE_OPTIMIZER_URL=
#
# DB_PASSWORD has no default either — set it for your own database.