# .env is committed deliberately, at the repo owner's instruction, so the
# deployment does not depend on re-entering config in the Dokploy UI.
#
# The two database secrets are NOT in it - they are set as Dokploy environment
# variables, which override the file (settings.py calls load_dotenv() without
# override=True, so the process environment wins).
#
# The auth secrets ARE in it. AUTH_SECRET_KEY signs every access token, so
# anyone with read access to this repository can mint an admin token, and git
# history keeps it after any rotation. Regenerate with
# `python scripts/make_auth_secrets.py` if that stops being acceptable.
!.env

# Local overrides and the generated sign-in passwords stay out of git.
.env.local
SIGNIN_PASSWORDS.txt

# Python
__pycache__/
*.pyc
*.pyo
.venv/
venv/
*.egg-info/
.pytest_cache/

# Logs
*.log

# OS
.DS_Store
Thumbs.db
