# ─── UOMysticmoon server — local dev environment ─── # Copy to server/.env for running `npm run dev` outside Docker. # (In Docker, the root .env / docker-compose provides these instead.) NODE_ENV=development PORT=3000 # Logging — written to BOTH the console and a log file (default /logs/app.log). LOG_LEVEL=debug # console verbosity: error | warn | info | debug FILE_LOG_LEVEL=debug # file verbosity LOG_TO_FILE=true # set false for console-only # LOG_DIR= # defaults to server/logs # LOG_FILE=app.log # Point at a local or Dockerized MariaDB DB_HOST=127.0.0.1 DB_PORT=3306 DB_NAME=uomysticmoon DB_USER=uomm DB_PASSWORD=change-me-db-password JWT_SECRET=dev-only-change-me JWT_EXPIRES_IN=1d COOKIE_SECURE=auto COOKIE_NAME=uomm_token # Reverse-proxy trust. Request path: client -> Pangolin -> newt agent "ptero" # (separate VM) -> this app. ptero is the hop that connects to us, so pin # TRUST_PROXY to ptero's LAN IP: Express then honours X-Forwarded-For ONLY on # connections from ptero, and req.ip / req.secure reflect the real client (used # by rate limiting, backoff, bot-ban, activity log). # -> e.g. 10.0.0.42 (RECOMMENDED in prod; requires a static # DHCP reservation for ptero in Omada — a lease change would # silently break IP trust) # an integer -> that many hops (fallback if you can't pin an IP) # false -> no proxy (direct connections) # NOTE: a blanket "true" is intentionally rejected (coerced to 1) — it would let # clients spoof their IP via a forged X-Forwarded-For and dodge rate limits/bans. TRUST_PROXY=1 # Set to 1 to log each request's raw peer address + X-Forwarded-For + resolved # req.ip, so you can verify/refresh ptero's IP without redeploying. Noisy — # leave off in normal operation. DEBUG_TRUST_PROXY=0 # Optional TOTP two-factor (opt-in per user). TOTP_ISSUER=UOMysticmoon # How long the "password verified, awaiting code" step stays valid. TOTP_CHALLENGE_TTL=5m # Created on first boot if the users table is empty ADMIN_USERNAME=admin ADMIN_PASSWORD=change-me-admin-password SMTP_HOST= SMTP_PORT=587 SMTP_USER= SMTP_PASS= CONTACT_TO=UOMysticmoon@gmail.com CLIENT_ORIGIN=http://localhost:5173