0cbae94842
Point the Tauri updater at the real self-hosted Gitea "latest release" path: https://git.infra.msai.al/mca/parking_solution/releases/latest/download/latest.json — redirects to the newest tag's latest.json published by release.yml. Verified against tauri-plugin-updater: it GETs the endpoint (200 + manifest / 204 = up to date) and reads platforms.linux-x86_64.{signature,url}. Document the desktop WS origin: the Tauri window loads from tauri://localhost (Linux may also send http://tauri.localhost), which is NOT same-origin with the backend, so WS_ALLOWED_ORIGINS must include both or the live feed won't connect. Added both to apps/server/.env.example. Updated the as-built in wiki/decisions/desktop-shell-tauri.md. Also carries an unrelated plans.namePlaceholder copy tweak already in the tree. turbo build lint 14/14 green. Claude-Session: https://claude.ai/code/session_01Xcm6ikLgGoCxxHrxtjkk5V
46 lines
2.4 KiB
Bash
46 lines
2.4 KiB
Bash
# Copy this file to `.env` (same folder: apps/server/.env) and fill it in.
|
|
# The dev/start scripts load it automatically via Node's --env-file-if-exists.
|
|
#
|
|
# cp apps/server/.env.example apps/server/.env
|
|
#
|
|
# Required ----------------------------------------------------------------
|
|
# The server refuses to start without a strong JWT_SECRET (>=32 chars).
|
|
# Generate one with: openssl rand -hex 32
|
|
JWT_SECRET=
|
|
|
|
# Dedicated HMAC key for signing the append-only event ledger (>=16 chars).
|
|
# Generate with: openssl rand -hex 32
|
|
# If unset, the server falls back to JWT_SECRET (logged as a warning) — fine for
|
|
# dev, but set a dedicated key before production. Events store the key that signed
|
|
# them (keyId), so verifyChain still validates a chain that spans a key change.
|
|
EVENT_SIGNING_KEY=
|
|
|
|
# Optional ----------------------------------------------------------------
|
|
# PORT=3000
|
|
# HOST=0.0.0.0 # interface to bind. 127.0.0.1 = loopback only.
|
|
# LOG_LEVEL=info
|
|
# DATABASE_URL=./parking.sqlite
|
|
# NODE_ENV=production # set in prod: makes auth cookies Secure (HTTPS-only)
|
|
|
|
# First admin (seed once): pnpm --filter @parking/server seed-admin
|
|
# ADMIN_USER=admin
|
|
# ADMIN_PASS=
|
|
|
|
# Comma-separated extra origins allowed to open the booth WebSocket (/api/ws).
|
|
# In dev, set the Vite SPA origin. Same-origin is always allowed without this.
|
|
# The Tauri DESKTOP shell loads from tauri://localhost (Linux may also send
|
|
# http://tauri.localhost), which is NOT same-origin with the backend — add both
|
|
# so the desktop app's live feed connects. See apps/desktop.
|
|
WS_ALLOWED_ORIGINS=http://localhost:5173,tauri://localhost,http://tauri.localhost
|
|
|
|
# Vision / ANPR (optional) -------------------------------------------------
|
|
# OFF by default. The Node SERVER's view of the vision microservice (apps/vision),
|
|
# which runs as a separate process with its OWN apps/vision/.env. Both sides share the
|
|
# VISION_ prefix but are different processes — keep the two .env files separate.
|
|
# See wiki/entities/opencv-anpr-service.md "Configuration".
|
|
# ANPR rides the entry/exit snapshot (button / QR / RFID triggers it) — no polling.
|
|
# VISION_ENABLED=1 # master switch — nothing runs without it
|
|
# VISION_URL=http://127.0.0.1:8089 # must match apps/vision VISION_HOST:VISION_PORT
|
|
# VISION_TIMEOUT_MS=1500 # per-request cap so a slow call can't hang the lane
|
|
# VISION_MIN_CONFIDENCE=0.5 # confidence floor; keep in sync with the service
|