CI / Frozen lockfile install (pull_request) Successful in 53s
CI / Secrets not embedded (E00-S02-T08) (pull_request) Successful in 25s
CI / Database-postgres import isolation (E00-S03-T02) (pull_request) Successful in 24s
CI / Migration ledger (E00-S03-T03) (pull_request) Successful in 52s
CI / Migration advisory lock (E00-S03-T04) (pull_request) Successful in 49s
CI / Migration failure diagnostic (E00-S03-T05) (pull_request) Successful in 47s
CI / App readiness after migrations (E00-S03-T06) (pull_request) Successful in 1m8s
CI / Field-specific startup errors (E00-S04-T02) (pull_request) Successful in 1m2s
CI / Secret redaction from logs (E00-S04-T03) (pull_request) Successful in 1m5s
CI / Env adapter owns process.env (E00-S04-T04) (pull_request) Successful in 1m2s
CI / TypeBox/Ajv config schema (E00-S04-T01) (pull_request) Successful in 58s
CI / .env.example placeholders only (E00-S04-T05) (pull_request) Successful in 24s
CI / Compose config (E00-S03-T01) (pull_request) Successful in 25s
Addresses PR #404 review findings F2/F3/F4 on issue #186: - F3 (fail-closed): ship EPPP_SESSION_SECRET placeholder as `change-me` (9 chars), shorter than the schema's 32-character minimum, so an unedited `cp .env.example .env` is rejected at startup instead of booting with a publicly known secret. - F2 (gitleaks-clean): build the secret-shaped mutation-probe literal at runtime from short non-secret fragments; the branch no longer embeds a secret-shaped literal in the test source. - F4 (masked messages): assertion messages mask/truncate values that come from the template instead of echoing the raw string. - test: add a fail-closed length test for the EPPP_SESSION_SECRET placeholder (< 32 chars); keep mutation probes non-vacuous.
48 lines
1.9 KiB
Bash
48 lines
1.9 KiB
Bash
# EPPP configuration template — [E00-S04-T05]
|
|
#
|
|
# Copy this file to `.env` and fill in real values:
|
|
#
|
|
# cp .env.example .env
|
|
#
|
|
# Every value in this file is a PLACEHOLDER — the template intentionally ships
|
|
# no real secrets. Real `.env` files stay git-ignored (`.env`, `.env.*` in
|
|
# `.gitignore`), so a committed example can never leak a local secret. Never
|
|
# commit a real `.env`.
|
|
|
|
# --- Server configuration (read by @personal-blog/config, E00-S04-T04) -------
|
|
|
|
# Interface the HTTP server binds — a hostname or IPv4/IPv6 address.
|
|
# Default: 0.0.0.0 (all interfaces — the container default).
|
|
HOST=0.0.0.0
|
|
|
|
# Port the HTTP server listens on — an integer in the valid TCP range
|
|
# (1-65535). Default: 3000.
|
|
PORT=3000
|
|
|
|
# PostgreSQL connection string (optional). When unset, the app reports ready
|
|
# immediately and skips the startup migration run (the local non-container
|
|
# developer path). When set, the shape is:
|
|
# postgres://<user>:<password>@<host>:5432/<database>
|
|
# (add your own credentials; a local no-credential default is shown below)
|
|
DATABASE_URL=postgres://localhost:5432/eppp
|
|
|
|
# Admin-session secret — REQUIRED and at least 32 characters (the config
|
|
# schema's required field; Security-and-Operations §32/§26). Generate a fresh
|
|
# one with `openssl rand -hex 32` and replace the placeholder below. The
|
|
# placeholder is intentionally SHORTER than the 32-character minimum, so an
|
|
# unedited `cp .env.example .env` is rejected at startup (fails closed)
|
|
# instead of booting with a publicly known secret.
|
|
EPPP_SESSION_SECRET=change-me
|
|
|
|
# --- Docker Compose overrides (optional — compose.yaml has dev defaults) ------
|
|
|
|
# PostgreSQL database name / user / password and host port for the `db`
|
|
# service (compose.yaml interpolates these with dev defaults).
|
|
POSTGRES_DB=eppp
|
|
POSTGRES_USER=eppp
|
|
POSTGRES_PASSWORD=change-me-db-password
|
|
POSTGRES_PORT=5432
|
|
|
|
# Host port for the `app` service. Default: 3000.
|
|
APP_PORT=3000
|