-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
31 lines (26 loc) · 1.6 KB
/
Copy path.env.example
File metadata and controls
31 lines (26 loc) · 1.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
# Winnow environment. Copy to .env and fill in.
# --- Runtime mode ------------------------------------------------------------
# 'real' = my self-hosted install against my Gmail.
# 'demo' = public demo backend (Fly.io), synthetic data, no live LLM.
# The API refuses to boot if this is inconsistent with DB state:
# - 'demo' with real rows in `users` → refuse
# - 'real' with no row in `users` → refuse
WINNOW_MODE=real
# --- Database ---------------------------------------------------------------
WINNOW_DATABASE_URL=postgresql+psycopg://winnow:winnow@localhost:5432/winnow
# Separate DB for the integration test suite. Tests are skipped if unset.
WINNOW_TEST_DATABASE_URL=postgresql+psycopg://winnow:winnow@localhost:5432/winnow_test
# --- Encryption -------------------------------------------------------------
# Fernet key for encrypting users.gmail_refresh_token.
# Generate once with: python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
# Rotating this key invalidates any already-stored refresh token.
WINNOW_ENCRYPTION_KEY=
# --- LLM (real app only; demo mode ignores this) ---------------------------
# Read at process startup; not stored in the DB.
WINNOW_LLM_API_KEY=
# --- Demo-only --------------------------------------------------------------
# HMAC-SHA256 salt for hashing visitor IPs in demo_sessions.ip_hash.
# Plain SHA256 of an IPv4 address is trivially reversible; the salt fixes that.
# Any random 32+ byte string. Rotating it invalidates existing session records
# for rate-limiting purposes only (session cookies themselves still resolve).
WINNOW_IP_HASH_SALT=