The README still opened on "Primary School Compass", a KS2 tool for Wandsworth and Merton served by FastAPI and vanilla JavaScript with Chart.js. Every layer of that sentence is now wrong: coverage is England-wide across KS2, KS4, all-through and post-16, Next.js owns the public UI, and school data comes from dbt-built `marts.*` rather than CSVs loaded at startup. The setup instructions walked a reader into a virtualenv and a CSV import that cannot build the current schema, so following the docs produced an empty database and a wrong mental model at the same time. Replace the narrative docs with two reference documents that were checked against the code: docs/ARCHITECTURE.md for request flow, data ownership, the backend/frontend module boundaries and the real publication sequence, and docs/DEVELOPMENT.md for the checks that actually run, including the container and CI version skew that makes "just run pytest" misleading. The env examples drifted the same way. ALLOWED_ORIGINS is a JSON array, not a comma-separated list; the frontend needs FASTAPI_URL, DATABASE_URL and PAYLOAD_SECRET, none of which were documented; and RATE_LIMIT_BURST, DEFAULT_PAGE_SIZE and MAX_PAGE_SIZE were presented as tuning controls the routes do not consult. Each is now stated as it behaves. MIGRATION_SUMMARY.md keeps its content but gains a banner, because it reads like setup instructions and is not. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016y2J6bs8gbuSJbH18w7Tan
54 lines
2.1 KiB
Bash
54 lines
2.1 KiB
Bash
# SchoolCompare Environment Configuration
|
|
# Copy this file to .env and update the values
|
|
|
|
# =============================================================================
|
|
# DATABASE
|
|
# =============================================================================
|
|
# PostgreSQL connection string
|
|
DATABASE_URL=postgresql://schoolcompare:CHANGE_THIS_PASSWORD@localhost:5432/schoolcompare
|
|
|
|
# =============================================================================
|
|
# SERVER
|
|
# =============================================================================
|
|
# Set to False in production
|
|
DEBUG=False
|
|
|
|
# Server host and port
|
|
HOST=0.0.0.0
|
|
PORT=80
|
|
|
|
# =============================================================================
|
|
# CORS
|
|
# =============================================================================
|
|
# JSON array of allowed origins (pydantic-settings format)
|
|
# In production, only include your actual domain
|
|
ALLOWED_ORIGINS=["https://schoolcompare.co.uk"]
|
|
|
|
# =============================================================================
|
|
# SECURITY
|
|
# =============================================================================
|
|
# Admin API key for protected endpoints (e.g., /api/admin/reload)
|
|
# Generate a secure random key: python -c "import secrets; print(secrets.token_urlsafe(32))"
|
|
ADMIN_API_KEY=CHANGE_THIS_TO_A_SECURE_RANDOM_KEY
|
|
|
|
# Rate limiting (requests per minute per IP)
|
|
RATE_LIMIT_PER_MINUTE=60
|
|
GLOBAL_RATE_LIMIT_PER_MINUTE=3000
|
|
|
|
# Maximum request body size in bytes (default 1MB)
|
|
MAX_REQUEST_SIZE=1048576
|
|
|
|
# =============================================================================
|
|
# SEARCH AND OPTIONAL FEATURE FLAGS
|
|
# =============================================================================
|
|
TYPESENSE_URL=http://localhost:8108
|
|
TYPESENSE_API_KEY=CHANGE_THIS_TO_YOUR_TYPESENSE_KEY
|
|
|
|
# Empty URL disables Unleash-backed flags. Match the managed environment when used.
|
|
UNLEASH_URL=
|
|
UNLEASH_API_TOKEN=
|
|
|
|
# Page-size limits are currently declared by route Query parameters.
|
|
# DEFAULT_PAGE_SIZE, MAX_PAGE_SIZE and RATE_LIMIT_BURST are not reliable tuning
|
|
# controls in the current routes; see docs/LEGACY_CODE.md.
|