Verified catalogue of mobiles and laptops sold in India, collected from real retail listings (FastAPI backend, React frontend, Postgres/pgvector). - REST API under /api/elec (read-only catalogue; admin endpoints need login) - MCP server (FastMCP) at /mcp/ with list_categories, search_products, get_product and price_history tools - Real ratings and reviews read from product pages and search results - Production Dockerfile (requirements-api.txt, no PyTorch) and .env.production.example; remote database only via an explicit ELEC_ALLOW_REMOTE_DB host/name allowlist - docs/API.md: endpoint and MCP reference with live examples Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
44 lines
1.9 KiB
Plaintext
44 lines
1.9 KiB
Plaintext
# Production environment for the Electronics Catalog API container.
|
|
# Copy to .env.production (never committed, never baked into the image) or paste
|
|
# each line into the deployment platform's Environment settings.
|
|
|
|
# --- Database: the production copy in loyalycatalogue (schema elec) ---
|
|
DB_HOST=31.97.228.132
|
|
DB_PORT=6054
|
|
DB_NAME=loyalycatalogue
|
|
DB_USER=admin
|
|
# The server is remote: allow more than the 5 s local default to connect.
|
|
DB_CONNECT_TIMEOUT_SECONDS=15
|
|
# The single quotes ARE part of this password. Container env values are taken
|
|
# literally (docker --env-file and platform Environment tabs do not strip
|
|
# quotes), so write it exactly as the password, quotes included:
|
|
DB_PASSWORD='<production password>'
|
|
# Explicit opt-in past the local-only guard in settings.py. Exact host and
|
|
# database only; any other remote target is still refused.
|
|
ELEC_ALLOW_REMOTE_DB=true
|
|
ELEC_REMOTE_DB_HOSTS=31.97.228.132
|
|
ELEC_REMOTE_DB_NAMES=loyalycatalogue
|
|
|
|
# --- Features not available in the container ---
|
|
USE_OLLAMA=false
|
|
ELEC_USE_LLM=false
|
|
USE_EMBEDDINGS=false
|
|
|
|
# --- Web search (only used by admin collection runs) ---
|
|
USE_DDG_SEARCH=true
|
|
USE_GOOGLE_CSE=false
|
|
ELEC_CONTACT=<contact email for robots-polite fetching>
|
|
|
|
# --- Browser access: every first-party web app that calls this API, exact
|
|
# origins only (no "*"). Pinned by tests/test_cors_origins.py; add a new app
|
|
# there and here together. Non-browser callers (curl, MCP clients) ignore CORS. ---
|
|
API_CORS_ORIGINS=https://app.nearledaily.com,http://localhost:3100,https://catalogue.nearle.ai.in
|
|
|
|
# --- Auth: guards the admin endpoints. Never deploy with AUTH_ENABLED=false
|
|
# or AUTH_ALLOW_ANY_LOGIN=true. ---
|
|
AUTH_ENABLED=true
|
|
AUTH_ALLOW_ANY_LOGIN=false
|
|
AUTH_SECRET_KEY=<new random value: python -c "import secrets; print(secrets.token_urlsafe(48))">
|
|
AUTH_ADMIN_USERNAME=admin
|
|
AUTH_ADMIN_PASSWORD_HASH=<same PBKDF2 hash as the local backend/.env>
|