Guest-first multi-user mode behind AIDND_MULTI_USER (local installs unchanged): signed-cookie guest sessions bootstrapped by /api/auth/me, register upgrades the guest in place, login/logout, per-IP rate limits. Every router scoped by user_id; Settings become per-user with the API key Fernet-encrypted at rest and write-only through the API. Users without a key get a server-funded demo key (OpenRouter free models, 20 turns/day, memory bank disabled on demo turns). Public read-only demo scenarios (seed_demo.py); debug log restricted to local mode. Frontend: auth modal + guest nudge, 401 re-establish/retry, demo banner and key management in Settings. Migrations 13-23 adopt existing data under a local user and encrypt stored keys. Verified: migration on a copy of real data.db, two-session isolation + register/login via curl and Chrome, demo cap 429, live OpenRouter turn through the encrypted-key path, vite build + oxlint. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KFsGHju9szibJJa2YJcdbg
45 lines
2.1 KiB
Bash
45 lines
2.1 KiB
Bash
# Environment variables read by the backend.
|
|
#
|
|
# NOTE: the app reads real environment variables — it does NOT auto-load this
|
|
# file. Set them in your shell, in docker-compose.yml, or in your host's
|
|
# dashboard. This file is documentation (and a template for deploy configs).
|
|
|
|
# Absolute path for the SQLite database file. Parent directory is created if
|
|
# missing. Default when unset: backend/data.db
|
|
# Docker compose sets this to /data/data.db (a named volume).
|
|
AIDND_DB_PATH=
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Phase 8 — optional accounts & multi-user (all optional; defaults keep the
|
|
# app in frictionless single-user "local mode")
|
|
# ---------------------------------------------------------------------------
|
|
|
|
# "1"/"true" turns on multi-user mode: guest sessions via signed cookies,
|
|
# register/login UI, per-user data. Leave unset for local installs.
|
|
AIDND_MULTI_USER=
|
|
|
|
# Secret for signing session cookies and encrypting stored API keys at rest.
|
|
# If unset, one is auto-generated into `secret.key` next to the database
|
|
# (fine for local/docker-volume runs). Set it explicitly on hosted deploys so
|
|
# sessions survive redeploys when the disk is ephemeral or replaced.
|
|
AIDND_SECRET_KEY=
|
|
|
|
# "1" marks session cookies Secure (HTTPS-only). Turn on in production.
|
|
AIDND_COOKIE_SECURE=
|
|
|
|
# --- Shared demo key (BYOK fallback; only active when AIDND_MULTI_USER=1) ---
|
|
# Users with no API key of their own get this server-funded endpoint with a
|
|
# model whitelist and a per-day turn cap. Unset = no demo, users must bring
|
|
# their own key. Memory bank/auto-summarization are disabled on demo turns.
|
|
AIDND_DEMO_API_KEY=
|
|
# Default endpoint if unset: https://openrouter.ai/api/v1
|
|
AIDND_DEMO_ENDPOINT_URL=
|
|
# Comma-separated model whitelist. Default: google/gemma-4-26b-a4b-it:free
|
|
AIDND_DEMO_MODELS=
|
|
# Successful AI turns per user per day on the demo key. Default: 20
|
|
AIDND_DEMO_TURNS_PER_DAY=
|
|
|
|
# The AI endpoint/API key/model are NOT env vars — they are configured at
|
|
# runtime in the app's Settings page and stored (encrypted) in the database.
|
|
# Phase 9 will add: rate limiting and CORS_ORIGINS.
|