Beyond parity — the web-feasible versions of the "host-only" items plus extras AtomCMS doesn't have: - App-level abuse/DDoS guard (src/lib/services/abuse-guard.ts): counts requests per IP and auto-adds flooders to website_ip_blacklist (enforced by the access guard) + fires ddosDetected(). OFF by default, tunable via settings. The iptables layer stays host-only; this is the real app-tier mitigation. Access guard now also enforces the IP blacklist (cached). - PWA: a themeable web manifest (src/app/manifest.ts) + a service worker (public/sw.js, cache-first assets / network-first pages) registered after hydration — the hotel is now installable. - /api/health: DB + emulator(RCON) + runtime status probe. - /developers: a public API documentation page covering every REST endpoint with its method, path and auth requirement. - jobs-worker: daily emulator JAR backup (runs host-side in the worker, like AtomCMS's backup command) — copies + prunes; no-ops unless EMULATOR_JAR_PATH + EMULATOR_BACKUP_DIR are set. Verified live (prod, amx_test): /api/health ok, manifest + sw served, docs page renders, normal pages unaffected by the guard. tsc 0, vitest 49/49, next build 0.
66 lines
2.0 KiB
Bash
66 lines
2.0 KiB
Bash
# Connection to the LIVE/COPY emulator MySQL/MariaDB database.
|
|
# The schema is owned by the Arcturus emulator — this app reads/writes data,
|
|
# it does NOT own or migrate the emulator tables. Format:
|
|
DATABASE_URL=mysql://user:[email protected]:3306/atomcms
|
|
|
|
# Optional pool tuning (defaults shown)
|
|
DATABASE_POOL_SIZE=40
|
|
DATABASE_IDLE_TIMEOUT_MS=300000
|
|
DATABASE_CONNECT_TIMEOUT_MS=10000
|
|
|
|
# Used by SSO ticket generation ({HOTEL_NAME}-{uuid})
|
|
HOTEL_NAME=Atom
|
|
APP_URL=http://localhost:3000
|
|
|
|
# NextAuth (>=32 chars) + Laravel APP_KEY (base64:...) for existing 2FA secrets
|
|
AUTH_SECRET=
|
|
APP_KEY=
|
|
CONVERT_PASSWORDS=false
|
|
|
|
# Password hashing for NEW/upgraded passwords: "bcrypt" (default; 60-char $2y$,
|
|
# fits a varchar(64) users.password) or "argon2id" (~97 chars, needs a wider
|
|
# column). Existing accounts in either format still verify on login.
|
|
PASSWORD_HASH=bcrypt
|
|
|
|
# Filesystem directory the badge uploader (/admin/badges) writes <code>.gif into
|
|
# — the emulator's badge image folder (e.g. .../assets/c_images/album1584).
|
|
# Leave unset to disable badge uploads.
|
|
BADGE_UPLOAD_DIR=
|
|
|
|
# Emulator JAR backup job (jobs-worker, runs host-side). When both are set, the
|
|
# worker copies the JAR daily into the backup dir, keeping the newest N.
|
|
EMULATOR_JAR_PATH=
|
|
EMULATOR_BACKUP_DIR=
|
|
EMULATOR_BACKUP_KEEP=7
|
|
|
|
# RCON link to the Arcturus emulator
|
|
RCON_HOST=127.0.0.1
|
|
RCON_PORT=3001
|
|
|
|
# Optional OAuth (enabled when both id+secret are set)
|
|
DISCORD_CLIENT_ID=
|
|
DISCORD_CLIENT_SECRET=
|
|
GOOGLE_CLIENT_ID=
|
|
GOOGLE_CLIENT_SECRET=
|
|
|
|
# Optional SMTP (password reset / alert emails)
|
|
SMTP_HOST=
|
|
SMTP_PORT=587
|
|
SMTP_USER=
|
|
SMTP_PASSWORD=
|
|
SMTP_FROM=
|
|
|
|
# Optional alerting (jobs worker / alert service)
|
|
DISCORD_WEBHOOK_URL=
|
|
ALERT_EMAIL=
|
|
|
|
# Optional AI content moderation (user comments / guestbook).
|
|
# When set, posts are checked against the OpenAI Moderations endpoint in
|
|
# addition to the website_wordfilter blocklist. Fail-open if unset/erroring.
|
|
OPENAI_API_KEY=
|
|
|
|
# Optional PayPal top-up (sandbox by default)
|
|
PAYPAL_CLIENT_ID=
|
|
PAYPAL_SECRET=
|
|
PAYPAL_API=https://api-m.sandbox.paypal.com
|