CI / build-and-test (push) Successful in 14m57s
P0 - Aucun secret servi au navigateur : /assets/config.local.js est généré par le serveur AVANT les montages statiques (il l'emporte sur le fichier local) et ne contient plus YOUTUBE_API_KEY(S) ; le fichier local n'est plus copié dans l'image Docker ni embarqué dans dist (angular ignore config.local.js) ; youtube-api.service n'appelle plus googleapis directement (fetchYouTube = /api/yt -> /proxy/api/yt), gardes « pas de clé => écran vide », rotation et carte de bans côté client supprimées ; readiness YouTube via /healthz (youtube.keys.count) ; messages d'erreur orientés configuration serveur. - CORS : origines pilotées par API_ALLOWED_ORIGINS (CSV), méthode PATCH ajoutée (requis par /user/preferences), header X-API-Key accepté. - Clés d'API longue durée : table api_keys (empreinte SHA-256 + préfixe affichable), routes GET/POST /api/keys et DELETE /api/keys/:id, jeton ntk_… affiché une seule fois, last_used_at à chaque usage ; X-API-Key accepté par authMiddleware ET authMiddlewareCookieAware. P1 - X-Request-Id renvoyé sur chaque réponse + journal JSON structuré en prod (ts, reqId, method, route, status, ms). - GET /metrics : exposition Prometheus sans dépendance (http_requests_total par route/code, somme+nombre de durées, uptime/mémoire ; METRICS_TOKEN verrouille l'accès si défini). - Rate-limit sur /api/details (DETAILS_RATE_LIMIT, 60/min, réponse JSON) — /transcript avait déjà le sien. - Version unique package.json : menu du compte, info.version de l'OpenAPI (+ schéma apiKeyAuth et chemins /keys / /metrics documentés). Tests : api_coverage +7 cas « production-ready » (sentinel de fuite de clé, X-Request-Id, /metrics, CORS PATCH, contrat/version, cycle complet des clés d'API), suggest, transcript, flags, filters, kind — verts. Build OK. Vérifs instance locale : config servie sans secret, /api/yt 200 avec la clé serveur, /metrics alimenté, menu 1.0.59 et 40 cartes rendues sans clé côté client.
32 lines
1.7 KiB
JavaScript
32 lines
1.7 KiB
JavaScript
// Local (non-versioned) config for BROWSER-SAFE values only.
|
|
// Copy this file to `assets/config.local.js` to override a browser-safe value.
|
|
// Optional: the server already generates its own /assets/config.local.js from
|
|
// its environment and serves it BEFORE any static file.
|
|
//
|
|
// SECURITY NOTE: everything set here is shipped to the browser. NEVER put a
|
|
// secret in this file. Server-only keys — YOUTUBE_API_KEY(S), TWITCH_CLIENT_SECRET,
|
|
// GEMINI_API_KEY, RUMBLE_API_KEY, VIMEO_ACCESS_TOKEN, JWT_SECRET — belong in the
|
|
// server environment (docker-compose/.env); the app consumes them through
|
|
// /api/yt/*, /api/twitch-token and /api/ai/* endpoints.
|
|
//
|
|
// The image build skips this file entirely (not copied into the image, not
|
|
// bundled into dist/browser/assets), so it can never leak into production.
|
|
|
|
// Dailymotion Player ID (required since Feb 2026: embeds without a Player ID
|
|
// return HTTP 403 "Forbidden"). Create a Player in Dailymotion Studio
|
|
// (https://www.dailymotion.com/partner/embed/players) — ideally a vertical
|
|
// player (aspect_ratio 9:16) for Shorts — and set its ID here.
|
|
// If unset, the app falls back to a public demo player ID (x8lr5).
|
|
// window.DAILYMOTION_PLAYER_ID = 'x8lr5';
|
|
|
|
// YouTube: the key lives on the server only (YOUTUBE_API_KEY / YOUTUBE_API_KEYS
|
|
// in docker-compose/.env) — requests go through /api/yt, never through here.
|
|
|
|
// Odysee: no API key is required when using the built-in proxy.
|
|
// Rumble: server-side scraping, no key required.
|
|
|
|
// Twitch: TWITCH_CLIENT_ID (public) may be mirrored here, the secret stays on
|
|
// the server. Gemini: server env GEMINI_API_KEY only.
|
|
|
|
// You can add other browser-safe provider keys/tokens here if needed in the future.
|