mirror of
https://github.com/suitenumerique/drive.git
synced 2026-09-12 12:47:59 +02:00
Running the POC locally needs the two apps to trust each other: a dev placeholder token shared by both directions of the server-to-server API, the Docs URLs resolvable from the compose network, and an impress client in the Keycloak realm so Docs signs in on Drive's identity provider (single session across both apps).
120 lines
5.3 KiB
Plaintext
120 lines
5.3 KiB
Plaintext
# Django
|
|
DJANGO_ALLOWED_HOSTS=*
|
|
DJANGO_SECRET_KEY=ThisIsAnExampleKeyForDevPurposeOnly
|
|
DJANGO_SETTINGS_MODULE=drive.settings
|
|
DJANGO_SUPERUSER_PASSWORD=admin
|
|
|
|
# Logging
|
|
# Set to DEBUG level for dev only
|
|
LOGGING_LEVEL_HANDLERS_CONSOLE=INFO
|
|
LOGGING_LEVEL_LOGGERS_ROOT=INFO
|
|
LOGGING_LEVEL_LOGGERS_APP=INFO
|
|
|
|
# Python
|
|
PYTHONPATH=/app
|
|
|
|
# Drive settings
|
|
|
|
# Mail
|
|
DJANGO_EMAIL_BRAND_NAME="La Suite Numérique"
|
|
DJANGO_EMAIL_HOST="mailcatcher"
|
|
DJANGO_EMAIL_LOGO_IMG="http://localhost:3000/assets/logo-suite-numerique.png"
|
|
DJANGO_EMAIL_PORT=1025
|
|
DJANGO_EMAIL_URL_APP="http://localhost:3000"
|
|
|
|
# User reconciliation
|
|
USER_RECONCILIATION_FORM_URL="http://localhost:3000"
|
|
|
|
# Media
|
|
STORAGES_STATICFILES_BACKEND=django.contrib.staticfiles.storage.StaticFilesStorage
|
|
AWS_S3_ACCESS_KEY_ID=drive
|
|
AWS_S3_SECRET_ACCESS_KEY=password
|
|
AWS_S3_REGION_NAME=eu-east-1
|
|
AWS_S3_SIGNATURE_VERSION=s3v4
|
|
AWS_S3_DOMAIN_REPLACE=http://localhost:9000
|
|
AWS_S3_ENDPOINT_URL=http://minio:9000
|
|
# To use with ds-proxy
|
|
# AWS_S3_DOMAIN_REPLACE=http://localhost:4444/upstream
|
|
# AWS_S3_ENDPOINT_URL=http://ds-proxy:4444/upstream
|
|
MEDIA_BASE_URL=http://localhost:8083
|
|
|
|
# OIDC
|
|
OIDC_OP_JWKS_ENDPOINT=http://nginx:8083/realms/drive/protocol/openid-connect/certs
|
|
OIDC_OP_AUTHORIZATION_ENDPOINT=http://localhost:8083/realms/drive/protocol/openid-connect/auth
|
|
OIDC_OP_TOKEN_ENDPOINT=http://nginx:8083/realms/drive/protocol/openid-connect/token
|
|
OIDC_OP_USER_ENDPOINT=http://nginx:8083/realms/drive/protocol/openid-connect/userinfo
|
|
|
|
OIDC_RP_CLIENT_ID=drive
|
|
OIDC_RP_CLIENT_SECRET=ThisIsAnExampleKeyForDevPurposeOnly
|
|
OIDC_RP_SIGN_ALGO=RS256
|
|
OIDC_RP_SCOPES="openid email"
|
|
|
|
LOGIN_REDIRECT_URL=http://localhost:3000
|
|
LOGIN_REDIRECT_URL_FAILURE=http://localhost:3000
|
|
LOGOUT_REDIRECT_URL=http://localhost:3000
|
|
|
|
OIDC_REDIRECT_ALLOWED_HOSTS="localhost:8083,localhost:3000"
|
|
OIDC_AUTH_REQUEST_EXTRA_PARAMS={"acr_values": "eidas1"}
|
|
|
|
# Resource Server Backend
|
|
OIDC_OP_URL=http://localhost:8083/realms/drive
|
|
OIDC_OP_INTROSPECTION_ENDPOINT = http://nginx:8083/realms/drive/protocol/openid-connect/token/introspect
|
|
OIDC_RESOURCE_SERVER_ENABLED=False
|
|
OIDC_RS_CLIENT_ID=drive
|
|
OIDC_RS_CLIENT_SECRET=ThisIsAnExampleKeyForDevPurposeOnly
|
|
OIDC_RS_AUDIENCE_CLAIM="client_id" # The claim used to identify the audience
|
|
OIDC_RS_ALLOWED_AUDIENCES=""
|
|
|
|
# Frontend
|
|
FRONTEND_THEME=dsfr-light
|
|
FRONTEND_MORE_LINK=https://docs.numerique.gouv.fr/docs/fa0aba15-e119-4185-b466-a4b37ad95950/
|
|
FRONTEND_FEEDBACK_BUTTON_SHOW=True
|
|
FRONTEND_FEEDBACK_BUTTON_IDLE=False
|
|
FRONTEND_FEEDBACK_ITEMS={"form":{"url": "https://tally.so/r/w2YaWL"}, "tchap":{"url": "https://tchap.gouv.fr/#/room/#fichiers:agent.dinum.tchap.gouv.fr"}, "visio":{"url": "https://cal.com/robin-lecomte-eyul9w/fichiers"}}
|
|
FRONTEND_FEEDBACK_MESSAGES_WIDGET_ENABLED=False
|
|
FRONTEND_FEEDBACK_MESSAGES_WIDGET_API_URL=
|
|
FRONTEND_FEEDBACK_MESSAGES_WIDGET_CHANNEL=
|
|
FRONTEND_FEEDBACK_MESSAGES_WIDGET_PATH=
|
|
FRONTEND_HELP_MENU_CONFIG={"documentationUrl": "https://docs.numerique.gouv.fr/docs/87938a46-6f85-4a08-9043-62d1d7d43176/", "legal": {"personalDataUrl": "https://docs.numerique.gouv.fr/docs/1b2c0c97-5141-4a4a-a98d-2a57802f5e72/", "termsOfUseUrl": "https://docs.numerique.gouv.fr/docs/637b1d6a-3b22-4195-b3a2-d88c42e48133/", "accessibilityUrl": "https://docs.numerique.gouv.fr/docs/96653d0c-c9e0-49e3-b98d-d19d5613506a/", "legalNoticeUrl": "https://docs.numerique.gouv.fr/docs/96653d0c-c9e0-49e3-b98d-d19d5613506a/"},"supportEmail": "mailto:support@numerique.gouv.fr"}
|
|
|
|
# WOPI
|
|
WOPI_CLIENTS="collabora,onlyoffice"
|
|
WOPI_COLLABORA_DISCOVERY_URL="http://collabora:9980/hosting/discovery"
|
|
WOPI_ONLYOFFICE_DISCOVERY_URL=http://onlyoffice/hosting/discovery
|
|
WOPI_SRC_BASE_URL=http://app-dev:8000
|
|
# Disable rename for Collabora by default because it does not post messages when renaming a file.
|
|
# So the frontend cannot reflect renaming operations.
|
|
WOPI_COLLABORA_OPTIONS={"SupportsRename": False}
|
|
# Background conversion of legacy Office files (.doc, .xls, .ppt) is forced
|
|
# server-side via the OnlyOffice /converter endpoint.
|
|
WOPI_ONLYOFFICE_OPTIONS={"ForceConvertExtensions": ["doc", "xls", "ppt"], "ConvertServiceUrl": "http://onlyoffice/converter"}
|
|
WOPI_ONLYOFFICE_CONVERT_JWT_SECRET=ThisIsNotASecretKeyDev
|
|
|
|
# Indexer
|
|
# SEARCH_INDEXER_CLASS="core.services.search_indexers.SearchIndexer"
|
|
SEARCH_INDEXER_SECRET=find-api-key-for-driv-with-exactly-50-chars-length # Key generated by create_demo in Find app.
|
|
SEARCH_INDEXER_URL="http://find:8000/api/v1.0/documents/index/"
|
|
SEARCH_INDEXER_QUERY_URL="http://find:8000/api/v1.0/documents/search/"
|
|
|
|
# Enables the search of indexed files through the API
|
|
FEATURES_INDEXED_SEARCH=True
|
|
|
|
# Malware detection
|
|
# Delay the "safe" result so the frontend can observe the "analyzing" upload
|
|
# state (polling + badge). Tune the delay with MALWARE_DETECTION_DUMMY_SLEEP.
|
|
MALWARE_DETECTION_BACKEND=core.malware_detection.SleepyDummyBackend
|
|
MALWARE_DETECTION_DUMMY_SLEEP=10
|
|
|
|
# Store OIDC tokens in the session
|
|
# OIDC_STORE_ACCESS_TOKEN = True
|
|
# OIDC_STORE_REFRESH_TOKEN = True # Store the encrypted refresh token in the session.
|
|
# Must be a valid Fernet key (32 url-safe base64-encoded bytes)
|
|
# To create one, use the bin/fernetkey command.
|
|
# OIDC_STORE_REFRESH_TOKEN_KEY="your-32-byte-encryption-key=="
|
|
|
|
# Docs <-> Drive POC integration
|
|
SERVER_TO_SERVER_API_TOKENS=docs-drive-poc-secret
|
|
FRONTEND_DOCS_URL=http://localhost:3001
|
|
DOCS_API_BASE_URL=http://docs-app-dev-1:8000/api/v1.0
|
|
DOCS_SERVER_TO_SERVER_TOKEN=docs-drive-poc-secret
|