Config via env, abuse/resource limits, and production serving so the app is safe to expose publicly: - Fail-fast on missing SECRET_KEY when MULTI_USER=true - quickjs per-execution time/memory limits (while(true) can't hang server) - Per-user/per-IP rate limiting on turn/script/auth endpoints - Request body size limit + per-user row caps - Security headers (CSP, X-Frame-Options, nosniff, referrer-policy) incl. SSE - Debug router 403 and /docs disabled in multi-user mode - DATABASE_URL support (defaults to Neon Postgres) alongside SQLite - Documented all env vars in backend/.env.example Verified locally via uvicorn (MULTI_USER=1, SQLite); see plan/09-phase-hardening.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017e6tQuojBLYPetUfmhit4X
10 lines
147 B
Plaintext
10 lines
147 B
Plaintext
fastapi>=0.115
|
|
uvicorn[standard]>=0.30
|
|
sqlalchemy>=2.0
|
|
pydantic>=2.7
|
|
httpx>=0.27
|
|
tiktoken>=0.7
|
|
quickjs>=1.19
|
|
cryptography>=42
|
|
psycopg[binary]>=3.2
|