Electronics Catalog: API, MCP server, frontend and deployment
Verified catalogue of mobiles and laptops sold in India, collected from real retail listings (FastAPI backend, React frontend, Postgres/pgvector). - REST API under /api/elec (read-only catalogue; admin endpoints need login) - MCP server (FastMCP) at /mcp/ with list_categories, search_products, get_product and price_history tools - Real ratings and reviews read from product pages and search results - Production Dockerfile (requirements-api.txt, no PyTorch) and .env.production.example; remote database only via an explicit ELEC_ALLOW_REMOTE_DB host/name allowlist - docs/API.md: endpoint and MCP reference with live examples Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
43
backend/.env.production.example
Normal file
43
backend/.env.production.example
Normal file
@@ -0,0 +1,43 @@
|
||||
# Production environment for the Electronics Catalog API container.
|
||||
# Copy to .env.production (never committed, never baked into the image) or paste
|
||||
# each line into the deployment platform's Environment settings.
|
||||
|
||||
# --- Database: the production copy in loyalycatalogue (schema elec) ---
|
||||
DB_HOST=31.97.228.132
|
||||
DB_PORT=6054
|
||||
DB_NAME=loyalycatalogue
|
||||
DB_USER=admin
|
||||
# The server is remote: allow more than the 5 s local default to connect.
|
||||
DB_CONNECT_TIMEOUT_SECONDS=15
|
||||
# The single quotes ARE part of this password. Container env values are taken
|
||||
# literally (docker --env-file and platform Environment tabs do not strip
|
||||
# quotes), so write it exactly as the password, quotes included:
|
||||
DB_PASSWORD='<production password>'
|
||||
# Explicit opt-in past the local-only guard in settings.py. Exact host and
|
||||
# database only; any other remote target is still refused.
|
||||
ELEC_ALLOW_REMOTE_DB=true
|
||||
ELEC_REMOTE_DB_HOSTS=31.97.228.132
|
||||
ELEC_REMOTE_DB_NAMES=loyalycatalogue
|
||||
|
||||
# --- Features not available in the container ---
|
||||
USE_OLLAMA=false
|
||||
ELEC_USE_LLM=false
|
||||
USE_EMBEDDINGS=false
|
||||
|
||||
# --- Web search (only used by admin collection runs) ---
|
||||
USE_DDG_SEARCH=true
|
||||
USE_GOOGLE_CSE=false
|
||||
ELEC_CONTACT=<contact email for robots-polite fetching>
|
||||
|
||||
# --- Browser access: every first-party web app that calls this API, exact
|
||||
# origins only (no "*"). Pinned by tests/test_cors_origins.py; add a new app
|
||||
# there and here together. Non-browser callers (curl, MCP clients) ignore CORS. ---
|
||||
API_CORS_ORIGINS=https://app.nearledaily.com,http://localhost:3100,https://catalogue.nearle.ai.in
|
||||
|
||||
# --- Auth: guards the admin endpoints. Never deploy with AUTH_ENABLED=false
|
||||
# or AUTH_ALLOW_ANY_LOGIN=true. ---
|
||||
AUTH_ENABLED=true
|
||||
AUTH_ALLOW_ANY_LOGIN=false
|
||||
AUTH_SECRET_KEY=<new random value: python -c "import secrets; print(secrets.token_urlsafe(48))">
|
||||
AUTH_ADMIN_USERNAME=admin
|
||||
AUTH_ADMIN_PASSWORD_HASH=<same PBKDF2 hash as the local backend/.env>
|
||||
Reference in New Issue
Block a user