-
-
Notifications
You must be signed in to change notification settings - Fork 407
Expand file tree
/
Copy pathexample.env
More file actions
61 lines (52 loc) · 2.52 KB
/
Copy pathexample.env
File metadata and controls
61 lines (52 loc) · 2.52 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
BITBUCKET_CLIENT_ID=01234567890123456789
BITBUCKET_CLIENT_SECRET=0123456789abcdef0123456789abcdef0123456
BITBUCKET_SCOPE=repository:write
BITBUCKET_WORKSPACE=workspace_name
ENCRYPTION_KEYS='[{"isPrimary": true, "id": 0, "value": "11223344556677889900aabbccddeeff"}]'
ENCRYPTION_JWT_SIGNING_KEY=asdfasdfasdf
ENCRYPTION_JWT_REFRESH_SIGNING_KEY=fljasdlfkjadf
GITHUB_CLIENT_ID=01234567890123456789
GITHUB_CLIENT_SECRET=0123456789abcdef0123456789abcdef0123456
GITHUB_ENTERPRISE_HOSTNAME=optional_if_using_enterprise
GITHUB_ENTERPRISE_PORT=optional_if_enterprise_and_non_standard
GITHUB_ENTERPRISE_PROTOCOL=optional_if_enterprise_and_non_standard
GITHUB_SCOPE=public_repo
GITLAB_CLIENT_ID=01234567890123456789
GITLAB_CLIENT_SECRET=0123456789abcdef0123456789abcdef0123456
GITLAB_SCOPE=read_user read_repository write_repository profile read_api api
GITLAB_REDIRECT_URI=http://localhost:3000/api/oauth/return
GITLAB_HOST=https://gitlab.myawesomesite.com
GOOGLE_CLIENT_ID=01234567890123456789
GOOGLE_CLIENT_SECRET=0123456789abcdef0123456789abcdef0123456
GOOGLE_SCOPE=openid email profile
GOOGLE_REDIRECT_URI=http://localhost:3000/api/oauth/return
NODE_ENV=development
SERVER_API_PROTOCOL=http
# FQDN hostname needed to run if using domain
APP_HOSTNAME=example.com
# variables needed for tls configurations
APP_PORT=443
APP_USE_TLS=true
APP_TLS_CERT_PATH=/path/to/certificate.pem
APP_TLS_KEY_PATH=/path/to/privatekey.pem
# LOCALES_ALLOWED is a JSON array of allowed locale codes, when empty no restrictions are applied
LOCALES_ALLOWED='[]'
LOCALE_DEFAULT=en
# Optional Plausible Analytics. Disabled unless explicitly enabled.
# PLAUSIBLE_ENABLED=false
# PLAUSIBLE_EVENT_URL=https://analytics.example.com/api/event
# PLAUSIBLE_DOMAIN=threatdragon.example.com
# PLAUSIBLE_DASHBOARD_URL=https://analytics.example.com/share/replace-with-public-dashboard
# PLAUSIBLE_ALLOW_INSECURE=false
# RFC 9116 security.txt implementation (optional)
# If enabled, contact and expires are required
SECURITY_TXT_ENABLED=true
# You can have multiple contacts by providing a comma separated list
# These should be in order of preference
SECURITY_TXT_CONTACT=mailto:someone@somewhere.com, https://example.com/security-contact-form, tel:+1-555-555-5555
SECURITY_TXT_POLICY=https://github.com/OWASP/threat-dragon/security/policy
SECURITY_TXT_CANONICAL=https://threat-dragon.example.com/.well-known/security.txt
SECURITY_TXT_PREFERRED_LANGUAGES=en
# Expires must be a valid RFC3339 ISO.8601-2 date
# It's RECOMMENDED to not have the expiration > 1 year in the future
SECURITY_TXT_EXPIRES=2028-01-01T00:00:00Z