first commit
This commit is contained in:
42
.env.example
Normal file
42
.env.example
Normal file
@@ -0,0 +1,42 @@
|
||||
# ---------------------------------------------------------------------------
|
||||
# Template for `.env.local` — your LOCAL overrides. Copy it:
|
||||
#
|
||||
# cp .env.example .env.local
|
||||
#
|
||||
# Do not copy it to `.env`. `.env` is committed and already holds the
|
||||
# production values; `.env.local` is loaded ahead of it and is gitignored.
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
# The one shared Loyaly platform API (Behavision). Server-side only and
|
||||
# deliberately NOT NEXT_PUBLIC: publishing the host would let a browser bypass
|
||||
# the BFF, which is what keeps the access token out of JavaScript.
|
||||
#
|
||||
# local dev http://127.0.0.1:8088 ← what belongs in .env.local
|
||||
# production https://mcp.loyaly.ai ← already set in the committed .env
|
||||
#
|
||||
# NOT platform.loyaly.ai — that host serves THIS console, not the API. Pointing
|
||||
# the variable there makes the BFF call its own origin, which fails in a way
|
||||
# that looks like a broken login form rather than a misconfiguration.
|
||||
#
|
||||
# Production no longer requires this: it accepts exactly one origin, so an unset
|
||||
# value can only have meant that one, and platformApi resolves it. Any OTHER
|
||||
# host set explicitly is still rejected. Locally it is worth setting, because a
|
||||
# dev machine legitimately means a different address.
|
||||
LOYALY_API_BASE=http://127.0.0.1:8088
|
||||
|
||||
# Signs the session cookie and encrypts the platform token bundle.
|
||||
#
|
||||
# The ONLY variable production requires, the only real secret, and the only one
|
||||
# taken solely from the environment — it is in no committed file, by design.
|
||||
# Set it as a Dokploy environment variable in the RUNTIME panel (a build
|
||||
# argument is not present at runtime), or mount it and set AUTH_SECRET_FILE to
|
||||
# its path. Locally, any string works; leave it blank and a development key is
|
||||
# used.
|
||||
#
|
||||
# Generate with: openssl rand -hex 32 (hex, not base64 — a trailing '=' can be
|
||||
# mangled by a dashboard env editor that splits on the first '=')
|
||||
AUTH_SECRET=
|
||||
|
||||
# Browser → this app's own BFF routes. Same origin, so leave it empty. Inlined
|
||||
# at BUILD time (NEXT_PUBLIC), so changing it at runtime does nothing.
|
||||
NEXT_PUBLIC_API_BASE=
|
||||
Reference in New Issue
Block a user