The Gotify and ntfy tokens, the SMTP password and the webhook secret were stored as plain text in the settings table. They are now encrypted with the same key as integration credentials (CREDENTIALS_ENCRYPTION_KEY), marked with an "enc:v1:" prefix. Settings are decrypted when read and encrypted when written, so nothing else changes; values saved before this are converted at startup. An edit that doesn't touch a credential keeps its stored ciphertext, so a wrong or missing key (which reads as empty) can't be made permanent by an unrelated edit. Without a key new credentials fall back to plain storage, and the startup warning, .env.example and the Privacy page say so. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
33 lines
1.5 KiB
Bash
33 lines
1.5 KiB
Bash
# Public URL the app is reachable at (used for OIDC redirect_uri and cookie behavior).
|
|
APP_BASE_URL=https://homelab.example.lan
|
|
|
|
# Random long string used to sign session cookies. Generate with:
|
|
# node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
|
|
SESSION_SECRET=change-me-to-a-random-64-char-hex-string
|
|
|
|
# 32-byte (64 hex char) key used to encrypt stored integration API tokens, and the
|
|
# notification channels' credentials (Gotify/ntfy tokens, SMTP password, webhook
|
|
# secret), at rest (AES-256-GCM). Generate the same way as SESSION_SECRET.
|
|
# Losing/changing this key makes those stored credentials unreadable.
|
|
CREDENTIALS_ENCRYPTION_KEY=change-me-to-a-random-64-char-hex-string
|
|
|
|
# Port docker-compose publishes on the host (container always listens on 3000).
|
|
HOST_PORT=3000
|
|
|
|
# Optional, for the arm64 compose files (docker-compose.arm64*.yml): registry image and tag.
|
|
#IMAGE_REPO=gitea.labsconnect.se/bobban/homelabmanager-homelab-manager
|
|
#ARM64_TAG=arm64
|
|
|
|
# --- Authentik OIDC application/provider ---
|
|
# Create an OAuth2/OIDC "Provider" in Authentik with:
|
|
# Redirect URI: <APP_BASE_URL>/auth/callback
|
|
# Scopes: openid, email, profile
|
|
# then create an "Application" using that provider, and assign the users/groups
|
|
# who should be able to sign in. Copy the provider's values below.
|
|
AUTHENTIK_ISSUER_URL=https://authentik.example.lan/application/o/homelab-manager/
|
|
AUTHENTIK_CLIENT_ID=
|
|
AUTHENTIK_CLIENT_SECRET=
|
|
|
|
# Notification channels (Gotify, ntfy, SMTP, webhook) are configured in-app
|
|
# under Settings, not here.
|