mirror of
https://github.com/suitenumerique/docs.git
synced 2026-09-13 13:17:53 +02:00
Add to the dev realm:
- `docs-mcp-client`, the public PKCE client MCP clients authenticate
with, with optional scopes `docs:documents:{search,read,create}` and
`docs-mcp`.
- `docs-api`, the confidential client Django uses as introspection
credentials (`OIDC_RS_CLIENT_ID/SECRET`).
- the `docs:documents:*` consent scopes and a `docs-mcp` audience-mapper
scope that stamps the `docs-mcp` audience only when requested.
Point the resource-server env at the `impress` realm and the new
clients, allow the `docs-mcp-client` audience, and grant users
`offline_access` for refresh tokens.
107 lines
4.1 KiB
Plaintext
107 lines
4.1 KiB
Plaintext
# Django
|
|
DJANGO_ALLOWED_HOSTS=*
|
|
DJANGO_SECRET_KEY=ThisIsAnExampleKeyForDevPurposeOnly
|
|
DJANGO_SETTINGS_MODULE=impress.settings
|
|
DJANGO_SUPERUSER_PASSWORD=admin
|
|
|
|
# Logging
|
|
# Set to DEBUG level for dev only
|
|
LOGGING_LEVEL_HANDLERS_CONSOLE=INFO
|
|
LOGGING_LEVEL_LOGGERS_ROOT=INFO
|
|
LOGGING_LEVEL_LOGGERS_APP=INFO
|
|
|
|
# Python
|
|
PYTHONPATH=/app
|
|
|
|
# impress settings
|
|
|
|
# Mail
|
|
DJANGO_EMAIL_BRAND_NAME="La Suite Numérique"
|
|
DJANGO_EMAIL_HOST="mailcatcher"
|
|
DJANGO_EMAIL_LOGO_IMG="http://localhost:3000/assets/logo-suite-numerique.png"
|
|
DJANGO_EMAIL_PORT=1025
|
|
DJANGO_EMAIL_URL_APP="http://localhost:3000"
|
|
|
|
# Backend url
|
|
IMPRESS_BASE_URL="http://localhost:8072"
|
|
|
|
# Media
|
|
STORAGES_STATICFILES_BACKEND=django.contrib.staticfiles.storage.StaticFilesStorage
|
|
AWS_S3_ENDPOINT_URL=http://minio:9000
|
|
AWS_S3_ACCESS_KEY_ID=impress
|
|
AWS_S3_SECRET_ACCESS_KEY=password
|
|
MEDIA_BASE_URL=http://localhost:8083
|
|
|
|
# OIDC
|
|
OIDC_OP_JWKS_ENDPOINT=http://nginx:8083/realms/impress/protocol/openid-connect/certs
|
|
OIDC_OP_AUTHORIZATION_ENDPOINT=http://localhost:8083/realms/impress/protocol/openid-connect/auth
|
|
OIDC_OP_TOKEN_ENDPOINT=http://nginx:8083/realms/impress/protocol/openid-connect/token
|
|
OIDC_OP_USER_ENDPOINT=http://nginx:8083/realms/impress/protocol/openid-connect/userinfo
|
|
OIDC_OP_INTROSPECTION_ENDPOINT=http://nginx:8083/realms/impress/protocol/openid-connect/token/introspect
|
|
|
|
OIDC_RP_CLIENT_ID=impress
|
|
OIDC_RP_CLIENT_SECRET=ThisIsAnExampleKeyForDevPurposeOnly
|
|
OIDC_RP_SIGN_ALGO=RS256
|
|
OIDC_RP_SCOPES="openid email"
|
|
|
|
LOGIN_REDIRECT_URL=http://localhost:3000
|
|
LOGIN_REDIRECT_URL_FAILURE=http://localhost:3000
|
|
LOGOUT_REDIRECT_URL=http://localhost:3000
|
|
|
|
OIDC_REDIRECT_ALLOWED_HOSTS="localhost:8083,localhost:3000"
|
|
OIDC_AUTH_REQUEST_EXTRA_PARAMS={"acr_values": "eidas1"}
|
|
|
|
# Resource Server Backend
|
|
# Also validates tokens the MCP server forwards from its callers (see core/mcp_api and
|
|
# documentation/mcp_server.md): the user's Keycloak token is introspected here with
|
|
# OIDC_RS_CLIENT_ID/SECRET (the `docs-api` confidential client) as credentials.
|
|
# OIDC_RS_AUDIENCE_CLAIM stays at its "client_id" default: it's process-wide (shared with
|
|
# the disabled external_api feature), and new resource-server callers just get added to
|
|
# OIDC_RS_ALLOWED_AUDIENCES. For a forwarded token that client_id is the public client the
|
|
# user authenticated as (docs-mcp-client).
|
|
OIDC_OP_URL=http://localhost:8083/realms/impress
|
|
OIDC_OP_INTROSPECTION_ENDPOINT=http://nginx:8083/realms/impress/protocol/openid-connect/token/introspect
|
|
OIDC_RESOURCE_SERVER_ENABLED=False
|
|
OIDC_RS_CLIENT_ID=docs-api
|
|
OIDC_RS_CLIENT_SECRET=ThisIsAnExampleKeyForDevPurposeOnly
|
|
OIDC_RS_ALLOWED_AUDIENCES=docs-mcp-client
|
|
OIDC_RS_SCOPES=docs:documents:search,docs:documents:read,docs:documents:create
|
|
|
|
# Store OIDC tokens in the session. Needed by search/ endpoint.
|
|
# OIDC_STORE_ACCESS_TOKEN=True
|
|
# OIDC_STORE_REFRESH_TOKEN=True # Store the encrypted refresh token in the session.
|
|
|
|
# Must be a valid Fernet key (32 url-safe base64-encoded bytes)
|
|
# To create one, use the bin/fernetkey command.
|
|
# OIDC_STORE_REFRESH_TOKEN_KEY="your-32-byte-encryption-key=="
|
|
|
|
# User reconciliation
|
|
USER_RECONCILIATION_FORM_URL=http://localhost:3000
|
|
|
|
# Collaboration
|
|
COLLABORATION_API_URL=http://y-provider-development:4444/collaboration/api/
|
|
COLLABORATION_BACKEND_BASE_URL=http://app-dev:8000
|
|
COLLABORATION_SERVER_ORIGIN=http://localhost:3000
|
|
COLLABORATION_SERVER_SECRET=my-secret
|
|
COLLABORATION_WS_NOT_CONNECTED_READ_ONLY=true
|
|
COLLABORATION_WS_URL=ws://localhost:4444/collaboration/ws/
|
|
COLLABORATION_WS_INACTIVITY_TIMEOUT=15 # Seconds
|
|
|
|
DJANGO_SERVER_TO_SERVER_API_TOKENS=server-api-token
|
|
Y_PROVIDER_API_BASE_URL=http://y-provider-development-converter:4444/api/
|
|
Y_PROVIDER_API_KEY=yprovider-api-key
|
|
|
|
DOCSPEC_API_URL=http://docspec:4000/conversion
|
|
|
|
# Theme customization
|
|
THEME_CUSTOMIZATION_CACHE_TIMEOUT=15
|
|
|
|
# Indexer (disabled by default)
|
|
# SEARCH_INDEXER_CLASS=core.services.search_indexers.FindDocumentIndexer
|
|
SEARCH_INDEXER_SECRET=find-api-key-for-docs-with-exactly-50-chars-length # Key generated by create_demo in Find app.
|
|
INDEXING_URL=http://find:8000/api/v1.0/documents/index/
|
|
SEARCH_URL=http://find:8000/api/v1.0/documents/search/
|
|
SEARCH_INDEXER_QUERY_LIMIT=50
|
|
|
|
CONVERSION_UPLOAD_ENABLED=true
|