seahaven-ap/.env.example
Adam Moussa bbfa6e4a3c
feat(api): switch live auth to host cookie BFF
Replace Bearer as the documented session path with Cognito hosted UI plus __Host-ap_* cookies so the SPA can call /api with credentials include.
2026-09-22 12:39:00 -04:00

37 lines
1.1 KiB
Text

# Default data path until the API is wired (AP later tickets).
VITE_USE_MOCKS=true
# AP-22 visual parity uses Stampli wordmark when false/unset.
# AP-38 Sea Haven branding cutover: set true.
VITE_SEA_HAVEN_BRAND=false
# --- @seahaven-ap/api (AP-14) ---
API_PORT=8787
DATABASE_DRIVER=postgres
DATABASE_URL=postgresql://seahaven:seahaven@127.0.0.1:5432/seahaven_ap
# Local-only auth bypass. Allowed only when NODE_ENV is development or test.
DEV_AUTH_BYPASS=true
DEV_AUTH_SUB=seed-sub-admin
DEV_AUTH_EMAIL=admin@seahavenind.com
DEV_AUTH_NAME=Dev Admin
DEV_AUTH_ROLE=admin
# Cognito (required when DEV_AUTH_BYPASS=false)
# COGNITO_ISSUER=https://cognito-idp.us-east-1.amazonaws.com/<pool-id>
# COGNITO_AUDIENCE=<app-client-id>
# COGNITO_DOMAIN=<hosted-ui-domain>
# APP_ORIGIN=http://127.0.0.1:3000
# ORIGIN_VERIFY_SECRET=
# Aurora Data API driver (DATABASE_DRIVER=data-api)
# AWS_REGION=us-east-1
# RDS_CLUSTER_ARN=
# RDS_SECRET_ARN=
# RDS_DATABASE=seahaven_ap
# MinIO (docker compose) — used by AP-15 document uploads
MINIO_ENDPOINT=http://127.0.0.1:9000
MINIO_ACCESS_KEY=seahaven
MINIO_SECRET_KEY=seahavensecret
MINIO_BUCKET=seahaven-ap-documents