# ─── UOMysticmoon server — local dev environment ─── # Copy to server/.env for running `npm run dev` outside Docker. # (In Docker, the root .env / docker-compose provides these instead.) NODE_ENV=development PORT=3000 # Logging — written to BOTH the console and a log file (default /logs/app.log). LOG_LEVEL=debug # console verbosity: error | warn | info | debug FILE_LOG_LEVEL=debug # file verbosity LOG_TO_FILE=true # set false for console-only # LOG_DIR= # defaults to server/logs # LOG_FILE=app.log # Point at a local or Dockerized MariaDB DB_HOST=127.0.0.1 DB_PORT=3306 DB_NAME=uomysticmoon DB_USER=uomm DB_PASSWORD=change-me-db-password JWT_SECRET=dev-only-change-me JWT_EXPIRES_IN=1d COOKIE_SECURE=auto COOKIE_NAME=uomm_token # Encryption key for secrets stored at rest (OAuth client secrets in auth_providers). # Any string — hashed to a 256-bit AES-GCM key. REQUIRED in production; in dev an # insecure key is derived from JWT_SECRET if unset (with a warning). SECRET_ENC_KEY=dev-only-change-me-too # Public base URL of this app, used to build the OAuth redirect_uri # (${APP_BASE_URL}/api/v1/auth/sso/:provider/callback). Set this in production so # the callback URL matches what you register with Google/Discord. If unset, it is # derived from the incoming request (fine for local dev). APP_BASE_URL=http://localhost:5173 # Short-lived mobile access token lifetime + refresh token lifetime (Part 2). MOBILE_ACCESS_TTL=15m MOBILE_REFRESH_TTL_DAYS=30 # Reverse-proxy trust. Request path: client -> Pangolin -> newt agent "ptero" # (separate VM) -> this app. ptero is the hop that connects to us, so pin # TRUST_PROXY to ptero's LAN IP: Express then honours X-Forwarded-For ONLY on # connections from ptero, and req.ip / req.secure reflect the real client (used # by rate limiting, backoff, bot-ban, activity log). # -> e.g. 10.0.0.42 (RECOMMENDED in prod; requires a static # DHCP reservation for ptero in Omada — a lease change would # silently break IP trust) # an integer -> that many hops (fallback if you can't pin an IP) # false -> no proxy (direct connections) # NOTE: a blanket "true" is intentionally rejected (coerced to 1) — it would let # clients spoof their IP via a forged X-Forwarded-For and dodge rate limits/bans. TRUST_PROXY=1 # Set to 1 to log each request's raw peer address + X-Forwarded-For + resolved # req.ip, so you can verify/refresh ptero's IP without redeploying. Noisy — # leave off in normal operation. DEBUG_TRUST_PROXY=0 # Optional TOTP two-factor (opt-in per user). TOTP_ISSUER=UOMysticmoon # How long the "password verified, awaiting code" step stays valid. TOTP_CHALLENGE_TTL=5m # Created on first boot if the users table is empty ADMIN_USERNAME=admin ADMIN_PASSWORD=change-me-admin-password SMTP_HOST= SMTP_PORT=587 SMTP_USER= SMTP_PASS= CONTACT_TO=UOMysticmoon@gmail.com CLIENT_ORIGIN=http://localhost:5173