59c35ce39f
Flask-session login scoped to one client_id (never a request param), self-service + operator-triggered password reset via single-use tokens, and an Owner accounts tab on the CRM dashboard. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
19 lines
879 B
Bash
19 lines
879 B
Bash
# Copy to .env on the host and fill in. .env and secrets/ are gitignored.
|
|
DB_PASSWORD=change-me-strong
|
|
CRM_API_TOKEN=change-me-long-random
|
|
BOOKING_TOKEN_SECRET=change-me-long-random-too
|
|
# Owner-login session cookie signing key (#19). Dedicated secret -- rotating
|
|
# it just logs owners out, without touching CRM_API_TOKEN/BOOKING_TOKEN_SECRET.
|
|
SESSION_SECRET_KEY=change-me-long-random-session-too
|
|
SHEET_ID=1raMSWRZw_JfHlWqOb3LbhaQ6LWx0VGblxIV4Z2pSzp8
|
|
# Booking confirmation email (#18). Left blank, sending is skipped (logged,
|
|
# not fatal) -- mail relay setup is a separate infra/triage item.
|
|
SMTP_HOST=
|
|
SMTP_PORT=587
|
|
SMTP_USERNAME=
|
|
SMTP_PASSWORD=
|
|
# Used as the From address when a client has no domain configured.
|
|
MAIL_FALLBACK_FROM=noreply@mivanchenko.de
|
|
# Base URL the manage-booking link in the confirmation email is built from.
|
|
PUBLIC_BASE_URL=https://onboard.mivanchenko.de
|