- sanitizer XSS serveur (markdown + page de partage) [BUG-021/022] - rate-limit/lockout MFA [BUG-023] - isolation vaults par segments [BUG-024] - caps regex ReDoS [BUG-025] - SSRF webhooks + secrets externalises [BUG-026] - rotation/revocation des jetons [BUG-027] - politique de mot de passe + invalidation sessions [BUG-028] - verrous users.json [BUG-029] - IP reelle dans les audits [BUG-030] - rate-limit par compte [BUG-031] - symlinks hors vault ignores [BUG-032] - recherche simple via inverted index [BUG-033] - token en memoire + cookie HttpOnly, CSP durcie [BUG-034] Tests: pytest 961 passed / 6 skipped, ruff 0, mypy 0, frontend vert.
70 lines
2.2 KiB
Bash
70 lines
2.2 KiB
Bash
# ObsiGate — Environment variables
|
|
# Copiez ce fichier en .env et modifiez les valeurs
|
|
# Le fichier .env n'est JAMAIS commité (présent dans .gitignore)
|
|
|
|
# Auth (décommenter pour activer)
|
|
OBSIGATE_AUTH_ENABLED=true
|
|
OBSIGATE_ADMIN_USER=admin
|
|
OBSIGATE_ADMIN_PASSWORD=chab30
|
|
|
|
# Sécurité des cookies (activer si derrière HTTPS)
|
|
# OBSIGATE_SECURE_COOKIES=false
|
|
|
|
# Tokens TTL en secondes
|
|
# OBSIGATE_ACCESS_TOKEN_TTL=900
|
|
# OBSIGATE_REFRESH_TOKEN_TTL=604800
|
|
|
|
# Rate limiting
|
|
# OBSIGATE_LOGIN_MAX_ATTEMPTS=10
|
|
# OBSIGATE_ACCOUNT_MAX_ATTEMPTS=10
|
|
# OBSIGATE_LOGIN_WINDOW_SECONDS=900
|
|
|
|
# IP client derrière un reverse proxy (fait confiance à X-Forwarded-For)
|
|
# OBSIGATE_TRUST_PROXY=false
|
|
|
|
# Webhooks : sécurité SSRF
|
|
# OBSIGATE_WEBHOOK_ALLOW_HTTP=false # autoriser http:// (défaut : HTTPS requis)
|
|
# OBSIGATE_WEBHOOK_ALLOW_PRIVATE=false # autoriser les IP privées/boucle
|
|
# Secret d'un webhook : OBSIGATE_WEBHOOK_SECRET_<ID_WEBHOOK_EN_MAJUSCULES>
|
|
|
|
# Watcher
|
|
# OBSIGATE_WATCHER_ENABLED=true
|
|
# OBSIGATE_WATCHER_USE_POLLING=false
|
|
# OBSIGATE_WATCHER_POLLING_INTERVAL=5.0
|
|
# OBSIGATE_WATCHER_DEBOUNCE=2.0
|
|
|
|
# Ignored directories (séparés par des virgules)
|
|
# OBSIGATE_IGNORED_DIRS=.obsidian,.trash,.git,__pycache__,node_modules,.obsigate-backup
|
|
|
|
# Audit
|
|
# OBSIGATE_AUDIT_MAX_SIZE=10485760
|
|
|
|
# Backup
|
|
# OBSIGATE_BACKUP_DIR=.obsigate-backup
|
|
|
|
# PDF (ROADMAP #74)
|
|
# OBSIGATE_PDF_MAX_SIZE_MB=50 # PDFs plus volumineux = texte non indexé
|
|
# OBSIGATE_PDF_EXTRACT_TIMEOUT=30 # secondes avant abandon de l'extraction
|
|
|
|
# WebAuthn / MFA (ROADMAP #64) — nécessaire hors localhost
|
|
# OBSIGATE_WEBAUTHN_RP_ID=obsigate.example.com
|
|
# OBSIGATE_WEBAUTHN_RP_NAME=ObsiGate
|
|
# OBSIGATE_WEBAUTHN_ORIGINS=https://obsigate.example.com
|
|
|
|
# ── AI Provider Configuration ──
|
|
# Définir au moins un provider pour activer les fonctionnalités AI dans l'éditeur
|
|
|
|
# AI_DEFAULT_PROVIDER=deepseek # deepseek | openrouter | gemini
|
|
|
|
# DeepSeek (recommandé, bon marché)
|
|
DEEPSEEK_API_KEY=sk-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
|
|
DEEPSEEK_MODEL=deepseek-chat
|
|
|
|
# OpenRouter (accès à plusieurs modèles)
|
|
# OPENROUTER_API_KEY=sk-or-v1-...
|
|
# OPENROUTER_MODEL=openai/gpt-4o-mini
|
|
|
|
# Google Gemini
|
|
# GEMINI_API_KEY=AIza...
|
|
# GEMINI_MODEL=gemini-2.0-flash
|