Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
104 lines (87 loc) · 5.08 KB
/
Copy path.env.example
File metadata and controls
104 lines (87 loc) · 5.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
### OBP API Configuration ###
VITE_OBP_API_HOST=http://127.0.0.1:8080
VITE_OBP_API_VERSION=v5.1.0
### OBP gRPC endpoint (used by the gRPC services browser) ###
### Defaults to grpc.<VITE_OBP_API_HOST hostname> if not set — port 443 with TLS for an https
### base URL, port 50051 without TLS for http (no grpc. prefix for localhost/IPs).
### VITE_OBP_GRPC_TLS=true|false overrides the port-based TLS default.
# VITE_OBP_GRPC_HOST=localhost:50051
### API Explorer Host ###
VITE_OBP_API_EXPLORER_HOST=http://localhost:5173
### Session Configuration ###
VITE_OBP_SERVER_SESSION_PASSWORD=change-me-to-a-secure-random-string
### OAuth2 Redirect URL (shared by all providers) ###
VITE_OAUTH2_REDIRECT_URL=http://localhost:5173/api/oauth2/callback
### Logout behaviour ###
### Controls what happens when a user logs out:
### public (default) - Full SSO logout: also ends the Keycloak/OIDC session
### (via end_session_endpoint), so the next login requires
### credentials. Use for public-facing / shared machines.
### internal - Local-only logout: clears the app session but keeps the
### provider SSO session, so re-login is silent. Use for
### deployments within a single trusted organisation.
### Unset or unrecognised values fall back to "public".
VITE_OBP_LOGOUT_MODE=public
### Redis Configuration (Optional - uses localhost:6379 if not set) ###
# VITE_OBP_REDIS_URL=redis://127.0.0.1:6379
# VITE_OBP_REDIS_PASSWORD=
# VITE_OBP_REDIS_USERNAME=
### Multi-Provider OAuth2/OIDC Configuration ###
### If VITE_OBP_OAUTH2_WELL_KNOWN_URL is set, it will be used
### Otherwise, the system fetches available providers from: VITE_OBP_API_HOST/obp/v5.1.0/well-known
### Configure credentials below for each provider you want to support
### (Optional) ###
# VITE_OBP_OAUTH2_WELL_KNOWN_URL=http://127.0.0.1:9000/obp-oidc/.well-known/openid-configuration
### OBP-OIDC Provider ###
VITE_OBP_OIDC_CLIENT_ID=your-obp-oidc-client-id
VITE_OBP_OIDC_CLIENT_SECRET=your-obp-oidc-client-secret
### Keycloak Provider (Optional) ###
# VITE_KEYCLOAK_CLIENT_ID=your-keycloak-client-id
# VITE_KEYCLOAK_CLIENT_SECRET=your-keycloak-client-secret
### Google Provider (Optional) ###
### 1. Create an OAuth client in Google Cloud Console (APIs & Services -> Credentials
### -> Create Credentials -> OAuth client ID, type "Web application").
### 2. Add VITE_OAUTH2_REDIRECT_URL (see above, default
### http://localhost:5173/api/oauth2/callback) as an Authorized redirect URI.
### 3. On the OBP-API side: include "google" in oauth2.oidc_provider and add
### https://www.googleapis.com/oauth2/v3/certs to oauth2.jwk_set.url,
### otherwise the provider is not advertised by /well-known and Google
### id_tokens are rejected. See README "Login with Google" for details.
# VITE_GOOGLE_CLIENT_ID=your-google-client-id.apps.googleusercontent.com
# VITE_GOOGLE_CLIENT_SECRET=your-google-client-secret
### GitHub Provider (Optional) ###
# VITE_GITHUB_CLIENT_ID=your-github-client-id
# VITE_GITHUB_CLIENT_SECRET=your-github-client-secret
### Custom OIDC Provider (Optional) ###
# VITE_CUSTOM_OIDC_PROVIDER_NAME=my-custom-provider
# VITE_CUSTOM_OIDC_CLIENT_ID=your-custom-client-id
# VITE_CUSTOM_OIDC_CLIENT_SECRET=your-custom-client-secret
### Berlin Group TPP Signature Certificate Configuration (Optional) ###
# VITE_BG_PRIVATE_KEY_PATH=./certs/private_key.pem
# VITE_BG_CERTIFICATE_PATH=./certs/certificate.pem
# VITE_BG_KEY_ID=SN=1082, CA=CN=Your Name, O=YourOrg
# VITE_BG_API_VERSION=v1.3
# VITE_BG_PSU_DEVICE_ID=device-1234567890
# VITE_BG_PSU_DEVICE_NAME=API-Explorer-II
# VITE_BG_PSU_IP_ADDRESS=127.0.0.1
# VITE_BG_TPP_REDIRECT_URI=https://your-app.com/berlin-group/redirect
# VITE_BG_TPP_NOK_REDIRECT_URI=https://your-app.com/berlin-group/error
### Resource Docs Version ###
VITE_OBP_API_DEFAULT_RESOURCE_DOC_VERSION=OBPv7.0.0
### /status page: when set, the consumer_id shown under each OAuth2 provider links to the
### consumer's page on the API Manager, e.g. VITE_API_MANAGER_URL=http://localhost:3003
# VITE_API_MANAGER_URL=
### End user addresses ###
### API Explorer II calls OBP-API from its own server. So that OBP-API sees each end
### user's address (for per-IP rate limits, IP penalties and the busiest-callers view) rather
### than this server's, API Explorer II passes on the X-Forwarded-For chain it received and
### appends the address of the machine that sent it the request (NGINX, or the browser). There
### is nothing to configure for that here. OBP-API reads the chain from the right and needs:
### trust.proxy.enabled=true
### trust.proxy.header=X-Forwarded-For
### trust.proxy.peers=<NGINX>, <API Explorer II>, <Opey>, <OBP-MCP> (addresses or CIDR ranges)
### Which proxies in front of API Explorer II Express believes about the browser's address and
### protocol (secure cookies, and the Berlin Group PSU-IP-Address header). A number trusts that
### many proxies (1 = one NGINX); a comma-separated list of addresses or CIDR ranges trusts only
### those; true / false trusts all / none. Unset: 1 when NODE_ENV=production, otherwise false.
# VITE_OBP_TRUST_PROXY=1