Files
EpicNext-Cms/.env.example
T
Simo 4eccd146ba Default password hashing to bcrypt (fits varchar(64) users.password)
Verified against the live AtomCMS DB: users.password is varchar(64), so
argon2id (~97 chars) overflows the column and registration/upgrade fail
with 'value too long'. bcrypt (60-char $2y$) fits and matches the
existing accounts. hashPassword() now emits bcrypt by default; set
PASSWORD_HASH=argon2id to opt back in (needs a widened column).
verifyPassword() still accepts both, so existing logins keep working.

Verified end-to-end against the live DB: bcrypt $2y$ login round-trips
(correct=true, wrong=false). tsc 0, vitest 8/8 (password suite).
2026-06-28 16:26:33 +02:00

55 lines
1.6 KiB
Bash

# Connection to the LIVE/COPY emulator MySQL/MariaDB database.
# The schema is owned by the Arcturus emulator — this app reads/writes data,
# it does NOT own or migrate the emulator tables. Format:
DATABASE_URL=mysql://user:[email protected]:3306/atomcms
# Optional pool tuning (defaults shown)
DATABASE_POOL_SIZE=40
DATABASE_IDLE_TIMEOUT_MS=300000
DATABASE_CONNECT_TIMEOUT_MS=10000
# Used by SSO ticket generation ({HOTEL_NAME}-{uuid})
HOTEL_NAME=Atom
APP_URL=http://localhost:3000
# NextAuth (>=32 chars) + Laravel APP_KEY (base64:...) for existing 2FA secrets
AUTH_SECRET=
APP_KEY=
CONVERT_PASSWORDS=false
# Password hashing for NEW/upgraded passwords: "bcrypt" (default; 60-char $2y$,
# fits a varchar(64) users.password) or "argon2id" (~97 chars, needs a wider
# column). Existing accounts in either format still verify on login.
PASSWORD_HASH=bcrypt
# RCON link to the Arcturus emulator
RCON_HOST=127.0.0.1
RCON_PORT=3001
# Optional OAuth (enabled when both id+secret are set)
DISCORD_CLIENT_ID=
DISCORD_CLIENT_SECRET=
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
# Optional SMTP (password reset / alert emails)
SMTP_HOST=
SMTP_PORT=587
SMTP_USER=
SMTP_PASSWORD=
SMTP_FROM=
# Optional alerting (jobs worker / alert service)
DISCORD_WEBHOOK_URL=
ALERT_EMAIL=
# Optional AI content moderation (user comments / guestbook).
# When set, posts are checked against the OpenAI Moderations endpoint in
# addition to the website_wordfilter blocklist. Fail-open if unset/erroring.
OPENAI_API_KEY=
# Optional PayPal top-up (sandbox by default)
PAYPAL_CLIENT_ID=
PAYPAL_SECRET=
PAYPAL_API=https://api-m.sandbox.paypal.com