2026-01-07 16:20:49 +00:00
|
|
|
# SchoolCompare Environment Configuration
|
|
|
|
|
# Copy this file to .env and update the values
|
|
|
|
|
|
|
|
|
|
# =============================================================================
|
|
|
|
|
# DATABASE
|
|
|
|
|
# =============================================================================
|
|
|
|
|
# PostgreSQL connection string
|
|
|
|
|
DATABASE_URL=postgresql://schoolcompare:CHANGE_THIS_PASSWORD@localhost:5432/schoolcompare
|
|
|
|
|
|
|
|
|
|
# =============================================================================
|
|
|
|
|
# SERVER
|
|
|
|
|
# =============================================================================
|
|
|
|
|
# Set to False in production
|
|
|
|
|
DEBUG=False
|
|
|
|
|
|
|
|
|
|
# Server host and port
|
|
|
|
|
HOST=0.0.0.0
|
|
|
|
|
PORT=80
|
|
|
|
|
|
|
|
|
|
# =============================================================================
|
|
|
|
|
# CORS
|
|
|
|
|
# =============================================================================
|
2026-09-14 23:01:15 +01:00
|
|
|
# JSON array of allowed origins (pydantic-settings format)
|
2026-01-07 16:20:49 +00:00
|
|
|
# In production, only include your actual domain
|
|
|
|
|
ALLOWED_ORIGINS=["https://schoolcompare.co.uk"]
|
|
|
|
|
|
|
|
|
|
# =============================================================================
|
|
|
|
|
# SECURITY
|
|
|
|
|
# =============================================================================
|
|
|
|
|
# Admin API key for protected endpoints (e.g., /api/admin/reload)
|
|
|
|
|
# Generate a secure random key: python -c "import secrets; print(secrets.token_urlsafe(32))"
|
|
|
|
|
ADMIN_API_KEY=CHANGE_THIS_TO_A_SECURE_RANDOM_KEY
|
|
|
|
|
|
|
|
|
|
# Rate limiting (requests per minute per IP)
|
|
|
|
|
RATE_LIMIT_PER_MINUTE=60
|
2026-09-14 23:01:15 +01:00
|
|
|
GLOBAL_RATE_LIMIT_PER_MINUTE=3000
|
2026-01-07 16:20:49 +00:00
|
|
|
|
|
|
|
|
# Maximum request body size in bytes (default 1MB)
|
|
|
|
|
MAX_REQUEST_SIZE=1048576
|
|
|
|
|
|
|
|
|
|
# =============================================================================
|
2026-09-14 23:01:15 +01:00
|
|
|
# SEARCH AND OPTIONAL FEATURE FLAGS
|
2026-01-07 16:20:49 +00:00
|
|
|
# =============================================================================
|
2026-09-14 23:01:15 +01:00
|
|
|
TYPESENSE_URL=http://localhost:8108
|
|
|
|
|
TYPESENSE_API_KEY=CHANGE_THIS_TO_YOUR_TYPESENSE_KEY
|
|
|
|
|
|
|
|
|
|
# Empty URL disables Unleash-backed flags. Match the managed environment when used.
|
|
|
|
|
UNLEASH_URL=
|
|
|
|
|
UNLEASH_API_TOKEN=
|
|
|
|
|
|
|
|
|
|
# Page-size limits are currently declared by route Query parameters.
|
|
|
|
|
# DEFAULT_PAGE_SIZE, MAX_PAGE_SIZE and RATE_LIMIT_BURST are not reliable tuning
|
|
|
|
|
# controls in the current routes; see docs/LEGACY_CODE.md.
|