Add trustHost: true to NextAuth config so Auth.js accepts requests when running behind Traefik/reverse proxy. Without this, Auth.js rejects the credential callback because the forwarded host doesn't match its expectations. Made-with: Cursor
44 lines
1.3 KiB
Text
44 lines
1.3 KiB
Text
# Database (shared PostgreSQL on CT 102)
|
|
DATABASE_URL="postgresql://echos_ocr:YOUR_PASSWORD@192.168.68.102:5432/echos_ocr"
|
|
|
|
# Vercel AI Gateway (routes to OpenAI, Google, Anthropic, etc.)
|
|
AI_GATEWAY_API_KEY=""
|
|
|
|
# Ollama (only needed if using Ollama as the AI provider)
|
|
OLLAMA_BASE_URL="http://192.168.68.108:11434"
|
|
|
|
# MinIO S3 Storage (CT 105)
|
|
MINIO_ENDPOINT="192.168.68.105"
|
|
MINIO_PORT="9000"
|
|
MINIO_ACCESS_KEY="minioadmin"
|
|
MINIO_SECRET_KEY="YOUR_MINIO_SECRET"
|
|
MINIO_BUCKET="echos-ocr"
|
|
|
|
# Folder Watch (optional, mount a host path into the container)
|
|
WATCH_DIR=""
|
|
|
|
# Auth.js (required — generate with: npx auth secret)
|
|
AUTH_SECRET=""
|
|
# Set AUTH_URL to your external URL when behind a reverse proxy
|
|
AUTH_URL="https://staging.echoocr.stillwell.cloud"
|
|
|
|
# Authentik OIDC SSO (optional — enables "Sign in with SSO" button)
|
|
# Create an OAuth2/OIDC provider in Authentik and set these values.
|
|
AUTHENTIK_ISSUER=""
|
|
AUTHENTIK_CLIENT_ID=""
|
|
AUTHENTIK_CLIENT_SECRET=""
|
|
|
|
# Legacy Authentik forward-auth (deprecated — will be removed)
|
|
AUTHENTIK_URL="https://auth.stillwell.cloud"
|
|
AUTHENTIK_API_TOKEN=""
|
|
|
|
# SMTP for outbound email (verification, invitations)
|
|
# Falls back to EMAIL_IMAP_* values if not set
|
|
SMTP_HOST=""
|
|
SMTP_PORT="587"
|
|
SMTP_USER=""
|
|
SMTP_PASS=""
|
|
SMTP_FROM=""
|
|
|
|
# Environment indicator (set to "staging" for staging deployments)
|
|
NEXT_PUBLIC_ENV=""
|