// Local (non-versioned) config for BROWSER-SAFE values only. // Copy this file to `assets/config.local.js` to override a browser-safe value. // Optional: the server already generates its own /assets/config.local.js from // its environment and serves it BEFORE any static file. // // SECURITY NOTE: everything set here is shipped to the browser. NEVER put a // secret in this file. Server-only keys — YOUTUBE_API_KEY(S), TWITCH_CLIENT_SECRET, // GEMINI_API_KEY, RUMBLE_API_KEY, VIMEO_ACCESS_TOKEN, JWT_SECRET — belong in the // server environment (docker-compose/.env); the app consumes them through // /api/yt/*, /api/twitch-token and /api/ai/* endpoints. // // The image build skips this file entirely (not copied into the image, not // bundled into dist/browser/assets), so it can never leak into production. // Dailymotion Player ID (required since Feb 2026: embeds without a Player ID // return HTTP 403 "Forbidden"). Create a Player in Dailymotion Studio // (https://www.dailymotion.com/partner/embed/players) — ideally a vertical // player (aspect_ratio 9:16) for Shorts — and set its ID here. // If unset, the app falls back to a public demo player ID (x8lr5). // window.DAILYMOTION_PLAYER_ID = 'x8lr5'; // YouTube: the key lives on the server only (YOUTUBE_API_KEY / YOUTUBE_API_KEYS // in docker-compose/.env) — requests go through /api/yt, never through here. // Odysee: no API key is required when using the built-in proxy. // Rumble: server-side scraping, no key required. // Twitch: TWITCH_CLIENT_ID (public) may be mirrored here, the secret stays on // the server. Gemini: server env GEMINI_API_KEY only. // You can add other browser-safe provider keys/tokens here if needed in the future.