Unleash holds flag state; it does not hold the list of flags. REGISTRY is that list, because the SDK evaluates an unknown flag to False and without a registry that is an undeclared False — indistinguishable from a typo in a flag name. Fail-closed throughout, and never raises: an unset UNLEASH_URL, an unreachable server, a client that throws, an undeclared name — all False. A flag layer that can 500 a request path or stop the API booting is worse than one that is switched off. Every flag defaults to False, with no per-flag override, because a flag that defaults on is a kill switch and this is deliberately not one. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015mWQnpye9F299NVRCCSRvj
67 lines
2.0 KiB
Python
67 lines
2.0 KiB
Python
"""
|
|
Application configuration using pydantic-settings.
|
|
Loads from environment variables and .env file.
|
|
"""
|
|
|
|
import secrets
|
|
from pathlib import Path
|
|
from typing import List, Optional
|
|
from pydantic_settings import BaseSettings
|
|
from pydantic import Field
|
|
|
|
|
|
class Settings(BaseSettings):
|
|
"""Application settings loaded from environment."""
|
|
|
|
# Paths
|
|
data_dir: Path = Path(__file__).parent.parent / "data"
|
|
frontend_dir: Path = Path(__file__).parent.parent / "frontend"
|
|
|
|
# Server
|
|
host: str = "0.0.0.0"
|
|
port: int = 80
|
|
debug: bool = False # Set to False in production
|
|
|
|
# Database
|
|
database_url: str = "postgresql://schoolcompare:schoolcompare@localhost:5432/schoolcompare"
|
|
|
|
# CORS - Production should only allow the actual domain
|
|
allowed_origins: List[str] = ["https://schoolcompare.co.uk"]
|
|
|
|
# API
|
|
default_page_size: int = 50
|
|
max_page_size: int = 100
|
|
|
|
# Security
|
|
admin_api_key: str = Field(default_factory=lambda: secrets.token_urlsafe(32))
|
|
rate_limit_per_minute: int = 60 # Requests per minute per IP
|
|
rate_limit_burst: int = 10 # Allow burst of requests
|
|
max_request_size: int = 1024 * 1024 # 1MB max request size
|
|
|
|
# Typesense
|
|
typesense_url: str = "http://localhost:8108"
|
|
typesense_api_key: str = ""
|
|
|
|
# Feature flags (Unleash). An empty unleash_url disables flags entirely and
|
|
# every flag evaluates False — the correct behaviour for local development
|
|
# and CI, and the reason no test needs a running Unleash.
|
|
unleash_url: str = ""
|
|
unleash_api_token: str = ""
|
|
unleash_app_name: str = "schoolcompare-backend"
|
|
# On a named volume, so a restart during an Unleash outage keeps
|
|
# last-known state instead of reverting a released feature to dark.
|
|
unleash_cache_directory: str = "/app/.unleash"
|
|
|
|
# Analytics
|
|
ga_measurement_id: Optional[str] = "G-J0PCVT14NY" # Google Analytics 4 Measurement ID
|
|
|
|
class Config:
|
|
env_file = ".env"
|
|
env_file_encoding = "utf-8"
|
|
extra = "ignore"
|
|
|
|
|
|
# Singleton instance
|
|
settings = Settings()
|
|
|