feat: add production environment variables documentation to TODO.md
This commit is contained in:
54
TODO.md
Normal file
54
TODO.md
Normal file
@@ -0,0 +1,54 @@
|
||||
# TODO
|
||||
|
||||
## Production Environment Variables
|
||||
|
||||
Cloudflare `vars` currently covers the non-secret values in `wrangler.jsonc`.
|
||||
Cloudflare Secrets are currently empty, so production still needs the following
|
||||
runtime values configured before deploy.
|
||||
|
||||
### Required For Current Production Path
|
||||
|
||||
| Variable | How to get it | Configure as |
|
||||
| --- | --- | --- |
|
||||
| `BETTER_AUTH_SECRET` | Generate a high-entropy production secret, for example `openssl rand -base64 32`. | Cloudflare Secret |
|
||||
| `RESEND_API_KEY` | Create or retrieve an API key from the Resend dashboard. The current mail adapter only supports `MAIL_PROVIDER=resend`. | Cloudflare Secret |
|
||||
| `CAPTCHA_SECRET_KEY` | Use the Cloudflare Turnstile Secret Key. The provided `TURNSTILE_SECRET_KEY` value should be stored under this variable name. | Cloudflare Secret |
|
||||
| `GOOGLE_CLIENT_SECRET` | Open Google Auth Platform / OAuth client settings and copy the client secret for the configured `GOOGLE_CLIENT_ID`. | Cloudflare Secret |
|
||||
|
||||
Set with:
|
||||
|
||||
```bash
|
||||
pnpm exec wrangler secret put BETTER_AUTH_SECRET
|
||||
pnpm exec wrangler secret put RESEND_API_KEY
|
||||
pnpm exec wrangler secret put CAPTCHA_SECRET_KEY
|
||||
pnpm exec wrangler secret put GOOGLE_CLIENT_SECRET
|
||||
```
|
||||
|
||||
### Configure Only If Enabling The Feature
|
||||
|
||||
| Variable | When needed | How to get it |
|
||||
| --- | --- | --- |
|
||||
| `GITHUB_CLIENT_ID` | Enable GitHub OAuth. | Create a GitHub OAuth App. |
|
||||
| `GITHUB_CLIENT_SECRET` | Enable GitHub OAuth. | Generate it in the GitHub OAuth App settings. |
|
||||
| `GENERIC_OAUTH_PROVIDER_ID` | Enable generic OIDC/OAuth. | Choose a provider id such as `auth0`, `zitadel`, or another stable name. |
|
||||
| `GENERIC_OAUTH_DISCOVERY_URL` | Enable generic OIDC/OAuth. | Get the provider's `.well-known/openid-configuration` URL. |
|
||||
| `GENERIC_OAUTH_CLIENT_ID` | Enable generic OIDC/OAuth. | Get it from the provider application settings. |
|
||||
| `GENERIC_OAUTH_CLIENT_SECRET` | Enable generic OIDC/OAuth. | Get it from the provider application settings. |
|
||||
| `PASSKEY_RP_ID` | Enable passkeys. | Use the relying-party domain, for example `cfw-auth.bowong.cc` or `bowong.cc`. |
|
||||
| `PASSKEY_RP_NAME` | Enable passkeys. | Pick the user-facing product name, for example `MixVideo`. |
|
||||
| `PASSKEY_ORIGIN` | Enable passkeys. | Use the full origin, for example `https://cfw-auth.bowong.cc`. |
|
||||
| `ENABLE_JWT` | Enable Better Auth JWT plugin. | Set to `true`. Leave unset to disable. |
|
||||
| `ENABLE_BEARER` | Enable Better Auth bearer plugin. | Set to `true`. Leave unset to disable. |
|
||||
| `EXPO_SCHEME` | Accept Expo app origins. | Read the `scheme` from the Expo app config. |
|
||||
| `SMS_PROVIDER` | Enable SMS. | Current code supports `webhook` or `twilio`. |
|
||||
| `SMS_WEBHOOK_URL` | Use `SMS_PROVIDER=webhook`. | Use the SMS provider webhook endpoint. |
|
||||
| `TWILIO_ACCOUNT_SID` | Use `SMS_PROVIDER=twilio`. | Get it from the Twilio Console. |
|
||||
| `TWILIO_AUTH_TOKEN` | Use `SMS_PROVIDER=twilio`. | Get it from the Twilio Console. |
|
||||
| `TWILIO_FROM` | Use `SMS_PROVIDER=twilio`. | Use a Twilio verified or purchased sending number. |
|
||||
|
||||
### Needs Cleanup
|
||||
|
||||
| Variable | Action |
|
||||
| --- | --- |
|
||||
| `OAUTH_PROVIDERS` | Current source code does not read this variable. Either define its semantics and implement usage, or remove it from `Env`. |
|
||||
|
||||
Reference in New Issue
Block a user