43 lines
2.1 KiB
Plaintext
43 lines
2.1 KiB
Plaintext
# ---------------------------------------------------------------------------
|
|
# Template for `.env.local` — your LOCAL overrides. Copy it:
|
|
#
|
|
# cp .env.example .env.local
|
|
#
|
|
# Do not copy it to `.env`. `.env` is committed and already holds the
|
|
# production values; `.env.local` is loaded ahead of it and is gitignored.
|
|
# ---------------------------------------------------------------------------
|
|
|
|
# The one shared Loyaly platform API (Behavision). Server-side only and
|
|
# deliberately NOT NEXT_PUBLIC: publishing the host would let a browser bypass
|
|
# the BFF, which is what keeps the access token out of JavaScript.
|
|
#
|
|
# local dev http://127.0.0.1:8088 ← what belongs in .env.local
|
|
# production https://mcp.loyaly.ai ← already set in the committed .env
|
|
#
|
|
# NOT platform.loyaly.ai — that host serves THIS console, not the API. Pointing
|
|
# the variable there makes the BFF call its own origin, which fails in a way
|
|
# that looks like a broken login form rather than a misconfiguration.
|
|
#
|
|
# Production no longer requires this: it accepts exactly one origin, so an unset
|
|
# value can only have meant that one, and platformApi resolves it. Any OTHER
|
|
# host set explicitly is still rejected. Locally it is worth setting, because a
|
|
# dev machine legitimately means a different address.
|
|
LOYALY_API_BASE=http://127.0.0.1:8088
|
|
|
|
# Signs the session cookie and encrypts the platform token bundle.
|
|
#
|
|
# The ONLY variable production requires, the only real secret, and the only one
|
|
# taken solely from the environment — it is in no committed file, by design.
|
|
# Set it as a Dokploy environment variable in the RUNTIME panel (a build
|
|
# argument is not present at runtime), or mount it and set AUTH_SECRET_FILE to
|
|
# its path. Locally, any string works; leave it blank and a development key is
|
|
# used.
|
|
#
|
|
# Generate with: openssl rand -hex 32 (hex, not base64 — a trailing '=' can be
|
|
# mangled by a dashboard env editor that splits on the first '=')
|
|
AUTH_SECRET=
|
|
|
|
# Browser → this app's own BFF routes. Same origin, so leave it empty. Inlined
|
|
# at BUILD time (NEXT_PUBLIC), so changing it at runtime does nothing.
|
|
NEXT_PUBLIC_API_BASE=
|