Full NestJS backend for the KC-App platform: - auth: Authentik OIDC resource-server strategy + guest invite-code JWT login, plus TokenVerificationService for the WS handshake path - kc: Leitungsteam-only KC (event) creation/listing - wahl: Wahl/Workshop admin, Force-Zuteilung overrides, ZuteilungService (port of the WP plugin's kc_run_zuteilung), CSV export - files: LT-only upload with visibility tiers; list/download filtered by caller tier; StorageProvider abstraction (WebDAV/Nextcloud default, S3) - chat: Gemeinde group / DM / LT-wide / broadcast channels; REST + raw ws gateway sharing ChatService access rules - sync: append-only SyncLogEntry replication log + local<->cloud push/pull scheduler, shared-secret guarded - common: Role enum, @Roles decorator, KC-scoped RolesGuard (LT global) - serves client/web/ interim static web client under / (API under /api) Typecheck, nest build and boot test pass; needs real Postgres/Authentik/ Nextcloud to run end to end. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
37 lines
1.3 KiB
Bash
37 lines
1.3 KiB
Bash
# Postgres connection used by Prisma
|
|
DATABASE_URL="postgresql://postgres:postgres@localhost:5432/kcapp?schema=public"
|
|
|
|
# Authentik OIDC issuer, e.g. https://auth.example.org/application/o/kc-app/
|
|
AUTHENTIK_ISSUER_URL="https://authentik.example.org/application/o/kc-app"
|
|
|
|
# Secret used to sign guest/Konfi session tokens (local accounts only)
|
|
GUEST_JWT_SECRET="change-me"
|
|
|
|
PORT=3000
|
|
|
|
# File storage: defaults to Nextcloud via WebDAV; set STORAGE_PROVIDER=s3 to
|
|
# use an S3-compatible bucket instead (see S3_* vars below).
|
|
STORAGE_PROVIDER="webdav"
|
|
WEBDAV_URL="https://nextcloud.example.org/remote.php/dav/files/kc-app"
|
|
WEBDAV_USERNAME="kc-app"
|
|
WEBDAV_PASSWORD="change-me"
|
|
|
|
# Only used when STORAGE_PROVIDER=s3
|
|
S3_BUCKET="kc-app"
|
|
S3_REGION="auto"
|
|
S3_ENDPOINT=""
|
|
S3_FORCE_PATH_STYLE="false"
|
|
S3_ACCESS_KEY_ID=""
|
|
S3_SECRET_ACCESS_KEY=""
|
|
|
|
# Unique id for THIS server instance (local on-site vs. cloud); used to tag
|
|
# replication log entries and avoid echoing changes back to their origin.
|
|
SERVER_ID="change-me-uuid"
|
|
|
|
# Local/cloud sync: set on the LOCAL (on-site) server to periodically push/
|
|
# pull against the cloud instance's API base URL. Leave SYNC_ENABLED=false
|
|
# on the cloud server (it only needs to expose /sync/ingest + /sync/export).
|
|
SYNC_ENABLED="false"
|
|
SYNC_PEER_URL="https://kc-app-cloud.example.org/api"
|
|
SYNC_SHARED_SECRET="change-me"
|