Security fixes: - Remove hardcoded MongoDB credentials from server.js (fail fast in production) - Add OAuth state parameter validation for CSRF protection - Add input validation for unitCode parameter to prevent NoSQL injection - Add isValidUnitCode helper function Deployment: - Update docker-compose.yml to use env_file and environment variables - Create .env.example with all required configuration variables
21 lines
679 B
Plaintext
21 lines
679 B
Plaintext
# MongoDB Connection
|
|
MONGO_URI=mongodb://username:password@host:27017
|
|
|
|
# Google OAuth Credentials (from Google Cloud Console)
|
|
GOOGLE_CLIENT_ID=your-client-id.apps.googleusercontent.com
|
|
GOOGLE_CLIENT_SECRET=your-client-secret
|
|
GOOGLE_CALLBACK_URL=https://apartments.maverickapplications.com/api/auth/google/callback
|
|
|
|
# JWT Configuration
|
|
# Generate with: node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
|
|
JWT_SECRET=generate-a-secure-random-string-minimum-32-characters
|
|
|
|
# Application URLs
|
|
FRONTEND_URL=https://apartments.maverickapplications.com
|
|
|
|
# Activity Logging Level: all, navigation, none
|
|
ACTIVITY_LOG_LEVEL=all
|
|
|
|
# Node Environment
|
|
NODE_ENV=production
|