Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
106 lines (75 loc) · 3.32 KB
/
Copy path.env.example
File metadata and controls
106 lines (75 loc) · 3.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
# diffwatch — Environment Configuration (Secure Production Setup)
# Copia questo file in .env e personalizza i valori
# --- Server Configuration ---
# Porta del server (default: 3333)
DIFFWATCH_PORT=3333
# Token di autenticazione (generato automaticamente all'avvio, non modificare manualmente)
# Il token viene salvato in ~/.diffwatch-token e letto dagli hooks
# DIFFWATCH_TOKEN=<generato-automaticamente>
# --- Security Settings ---
# Directory root permessa (default: process.cwd())
# Solo file dentro questa directory possono essere acceduti
# DIFFWATCH_ALLOWED_ROOT=/home/user/projects
# Rate limit — richieste massime per minuto per IP (default: 60)
DIFFWATCH_RATE_LIMIT_MAX=60
# Rate limit — finestra temporale in millisecondi (default: 60000 = 1 minuto)
DIFFWATCH_RATE_LIMIT_WINDOW_MS=60000
# JSON body size limit (default: 1mb)
# Valore massimo per prevenire memory exhaustion
DIFFWATCH_JSON_BODY_LIMIT=1mb
# --- WebSocket Configuration ---
# WebSocket heartbeat interval in millisecondi (default: 30000 = 30s)
DIFFWATCH_WS_HEARTBEAT_INTERVAL_MS=30000
# --- Snapshot Store Settings ---
# TTL snapshot in millisecondi (default: 3600000 = 1 ora)
# Dopo questo tempo, snapshot accepted/rejected vengono eliminati
DIFFWATCH_SNAPSHOT_TTL_MS=3600000
# Cleanup interval in millisecondi (default: 300000 = 5 minuti)
DIFFWATCH_CLEANUP_INTERVAL_MS=300000
# --- Logging Configuration ---
# Log level: error, warn, info, debug (default: info)
LOG_LEVEL=info
# Audit log file path (default: ~/.diffwatch-audit.log)
DIFFWATCH_AUDIT_LOG_PATH=/home/user/.diffwatch-audit.log
# Enable audit logging (default: true)
DIFFWATCH_AUDIT_ENABLED=true
# --- CORS Configuration ---
# Allowed origins per CORS (comma-separated, default: localhost only)
# IMPORTANTE: NON usare * in produzione!
DIFFWATCH_ALLOWED_ORIGINS=http://127.0.0.1:3333,http://localhost:3333
# --- Development/Debug ---
# Enable debug mode (default: false)
# In debug mode, log più verbosi e security check meno stringenti (SOLO per dev!)
DEBUG=false
# Disable security checks (default: false)
# PERICOLOSO: Disabilita path validation e auth — SOLO per testing!
DIFFWATCH_DISABLE_SECURITY=false
# --- Production Hardening ---
# Require HTTPS per WebSocket (default: false, diventa true se NODE_ENV=production)
# Nota: Richiede setup reverse proxy (nginx, Caddy)
DIFFWATCH_REQUIRE_HTTPS=false
# Enable CSP (Content Security Policy) strict mode (default: false)
DIFFWATCH_STRICT_CSP=false
# --- Node.js Environment ---
# Node environment (development, production, test)
NODE_ENV=development
# --- Example Production Configuration ---
# Copia questa sezione per produzione (se diffwatch viene deployato su server remoto):
#
# NODE_ENV=production
# DIFFWATCH_PORT=3333
# DIFFWATCH_RATE_LIMIT_MAX=30
# DIFFWATCH_JSON_BODY_LIMIT=512kb
# DIFFWATCH_REQUIRE_HTTPS=true
# DIFFWATCH_STRICT_CSP=true
# LOG_LEVEL=warn
# DIFFWATCH_AUDIT_ENABLED=true
# DIFFWATCH_ALLOWED_ORIGINS=https://your-domain.com
# --- Security Notes ---
# 1. NON committare .env in Git (già in .gitignore)
# 2. Generare nuovo token per ogni ambiente (auto-generato)
# 3. Usare HTTPS in produzione (reverse proxy)
# 4. Non esporre porta 3333 pubblicamente (firewall)
# 5. Eseguire diffwatch come utente non-root
# 6. Limitare DIFFWATCH_ALLOWED_ROOT alla directory minima necessaria
# 7. Monitorare DIFFWATCH_AUDIT_LOG_PATH per attività sospette