Auth SuperOAuth (JWT validation + httpOnly cookie), entités users/characters/level_thresholds, lazy calculation endurance, seed 100 niveaux, config prod-ready (trust proxy, helmet, CORS, rate limit). Validé : health 200, auth flow, character CRUD, endurance lazy, 401 sans cookie.
19 lines
392 B
Plaintext
19 lines
392 B
Plaintext
PORT=4000
|
|
NODE_ENV=development
|
|
|
|
# PostgreSQL
|
|
DATABASE_URL=postgresql://tetardpg:password@localhost:5432/tetardpg
|
|
|
|
# Redis
|
|
REDIS_URL=redis://localhost:6379
|
|
|
|
# Frontend CORS (virgule-séparé pour multi-origin)
|
|
FRONTEND_URL=http://localhost:5173
|
|
|
|
# SuperOAuth — service externe d'authentification
|
|
SUPER_OAUTH_URL=http://localhost:3000
|
|
SUPER_OAUTH_JWT_SECRET=
|
|
|
|
# Cookie signing
|
|
COOKIE_SECRET=
|