Files
LogiFlow/.env.example
Claude 0a816fa881 fix(securite): lock down the two unauthenticated emergency endpoints
- POST /api/emergency-admin-reset accepted a fallback secret hardcoded in
  the repository, letting anyone who read the source reset the production
  admin account to admin/admin (EMERGENCY_SECRET is not set in the shipped
  docker-compose, so the fallback was live). The route now returns 404
  unless EMERGENCY_SECRET is explicitly configured, and invalid attempts
  are logged.
- POST /api/admin/emergency-migration ran database migrations with no
  authentication at all; it now requires an authenticated admin.

A sweep of the remaining API surface found no other unauthenticated
mutation or read routes beyond /api/health. .env.example documents
EMERGENCY_SECRET and ENCRYPTION_KEY.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
2026-08-14 16:21:40 +00:00

33 lines
1.0 KiB
Bash

# Environment Variables for LogiFlow Production
# Database Configuration (préconfigurés pour Docker)
DATABASE_URL=postgresql://logiflow_admin:LogiFlow2025!@postgres:5432/logiflow_db
# Session Configuration
SESSION_SECRET=LogiFlow_Super_Secret_Session_Key_2025_Production
# Application Configuration
NODE_ENV=production
PORT=5000
# Authentication Configuration
USE_LOCAL_AUTH=true
# Configuration de la base de données
POSTGRES_DB=logiflow_db
POSTGRES_USER=logiflow_admin
POSTGRES_PASSWORD=LogiFlow2025!
POSTGRES_PORT=5434
# Note de sécurité:
# Les identifiants sont préconfigurés pour simplifier le déploiement.
# En production, vous pouvez les modifier si nécessaire.
# Chiffrement des secrets en base (mots de passe SMTP, jetons NocoDB).
# Repli sur SESSION_SECRET si absent. ATTENTION : changer cette clé rend
# les secrets déjà chiffrés illisibles.
ENCRYPTION_KEY=
# Route de secours POST /api/emergency-admin-reset : désactivée si vide.
# Ne définir qu'en cas de besoin, puis retirer.
EMERGENCY_SECRET=