# Denya OneCare — runtime environment template (HARDENING.md P0.1/P1.1) # Copy to .env and fill in real values. NEVER commit .env. # Generate the secret with: openssl rand -hex 32 # ── Required ───────────────────────────────────────────── SECRET_KEY= DATABASE_URL=sqlite+aiosqlite:///./data/denya_onecare.db # Explicit origin allow-list — "*" is rejected at startup (P0.2) CORS_ORIGINS=http://localhost:8000 # ── Optional (WhatsApp; needed before wiring Meta) ─────── WHATSAPP_PHONE_NUMBER_ID= WHATSAPP_ACCESS_TOKEN= WHATSAPP_VERIFY_TOKEN= META_GRAPH_BASE=https://graph.facebook.com/v18.0 # ── Webhook auth (P0) ────────────────────────────────── # Shared secret for inbound WhatsApp webhook POSTs (X-Webhook-Secret header). # FAIL-CLOSED: when unset/empty, every webhook message is rejected (403). # Generate with: openssl rand -hex 32 WHATSAPP_WEBHOOK_SECRET= # ── WhatsApp demo path (optional) ─────────────────────── # Expected sender/recipient number (E.164) for the WhatsApp demo round trip # (webhook -> ticket -> mock-log). Set the real number ONLY on the deploy # host's .env — keep this template an empty placeholder, never a live number. # Empty (default): the demo payload builder fails closed (no fabricated sender). WHATSAPP_DEMO_TO= # ── Login rate limiting (P0) ──────────────────────────── # ~5 failed login attempts per 15 minutes per IP+email → HTTP 429 LOGIN_RATE_LIMIT_MAX_ATTEMPTS=5 LOGIN_RATE_LIMIT_WINDOW_SECONDS=900