Files
SBC/.env.example
T
Claude 942bc70865 Conformité RGPD : registre des traitements, droit à l'image, HTTPS
Registre des traitements (art. 30 RGPD) et formulaires d'autorisation de
droit à l'image (majeur / mineur) générés depuis un nouvel onglet « RGPD »
de l'administration (admins uniquement) : documents A4 imprimables et
téléchargeables, pré-remplis à partir des Paramètres de l'association. Le
registre recense les 7 traitements réels de l'application (adhésions,
annuaire, inscriptions, facturation, espace membre, photos, e-mails) avec
finalité, base légale, personnes, données, destinataires et durées ; la
facturation est conservée 10 ans (obligation comptable, art. L123-22).

Politique de confidentialité complétée du traitement de facturation
(adresse, factures, paiements), de la conservation comptable de 10 ans et
des destinataires (trésoriers, expert-comptable, administration fiscale).

HTTPS en production : en-tête HSTS (1 an, includeSubDomains) et redirection
HTTP→HTTPS (308) des requêtes reçues via le reverse proxy (X-Forwarded-Proto),
sans impacter les appels directs (healthcheck). Nouveau drapeau FORCE_HTTPS
dans docker-compose et .env.example, aux côtés de COOKIE_SECURE et
TRUST_PROXY documentés pour la production.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o
2026-07-16 20:30:48 +00:00

44 lines
1.8 KiB
Bash

# OPTIONAL: the stack starts without any .env thanks to preconfigured
# defaults in docker-compose.yml. For production, copy this file to .env
# (or set the variables in Portainer) and override everything below.
# openssl rand -hex 32 # use for JWT_SECRET
# openssl rand -hex 24 # use for each DB password
# PostgreSQL superuser password (used only inside the db container)
POSTGRES_PASSWORD=change-me-postgres-superuser
# Password of the restricted application role (sbc_app) the API connects with
APP_DB_PASSWORD=change-me-app-db-password
# Secret used to sign session tokens (JWT), at least 32 characters.
# If unset, the app generates a random one at startup (sessions are then
# invalidated whenever the container restarts).
JWT_SECRET=change-me-64-hex-chars-min
# Initial password of the admin account (admin@sluc-businessclub.fr).
# Applied/updated at API startup. Change it after first login.
ADMIN_INITIAL_PASSWORD=ChangeMe-Admin-2026!
# Initial password given to every seeded member account (demo data only)
MEMBER_INITIAL_PASSWORD=ChangeMe-Membre-2026!
# --- HTTPS (production) -----------------------------------------------
# In production, serve the site over HTTPS through your reverse proxy and
# set the three flags below to "true". The proxy must forward the headers
# X-Forwarded-Proto and X-Forwarded-Host to the app.
# Adds the Secure flag on the session cookie (cookie sent over HTTPS only)
COOKIE_SECURE=false
# Lets the app trust X-Forwarded-* headers from the reverse proxy
TRUST_PROXY=false
# Redirects any plain-HTTP request (through the proxy) to HTTPS
FORCE_HTTPS=false
# Uncommon ports to avoid collisions with other services
# Application (public web port)
APP_PORT=8321
# PostgreSQL, bound to 127.0.0.1 only (local admin access)
DB_PORT=58412