WhatsApp demo path (relay #748): - WHATSAPP_DEMO_TO config under the WhatsApp section (env-based, .env-only; .env.example keeps an empty placeholder; real numbers never enter source). - build_demo_webhook_payload() in app/routers/whatsapp.py builds the Meta demo payload from it (fails closed when unset), so the webhook round trip logs from_number = demo number (surfaces in GET /api/whatsapp/mock-log) and the auto-reply targets the same number. - tests/test_whatsapp_demo_number.py: default empty + never committed in tracked files, payload builder from/to, 200/403/401 gates unchanged. Branding (logo-assets-v1, sha256-verified, same-origin app/static/branding): - Login header uses h96 full lockup; logged-in topbar (base.html) uses h48 on a light chip (logo ink is ~2:1 vs the dark nav); favicons 32x32 + 16x16 in <head>. img-src 'self' data: blob: already allows /static/branding/*. - tests/test_branding_assets.py: page placement + same-origin serving + CSP. - AGENTS.md synced.
78 lines
3.8 KiB
Python
78 lines
3.8 KiB
Python
"""Application configuration via Pydantic-settings environment variables."""
|
|
|
|
from __future__ import annotations
|
|
|
|
from pathlib import Path
|
|
|
|
from pydantic_settings import BaseSettings, SettingsConfigDict
|
|
|
|
|
|
class Settings(BaseSettings):
|
|
model_config = SettingsConfigDict(
|
|
env_file=".env",
|
|
env_file_encoding="utf-8",
|
|
case_sensitive=False,
|
|
extra="ignore",
|
|
)
|
|
|
|
# ── App ──────────────────────────────────────────────────────────
|
|
APP_NAME: str = "Denya OneCare"
|
|
DEBUG: bool = False
|
|
|
|
# ── Database ─────────────────────────────────────────────────────
|
|
DATABASE_URL: str = "sqlite+aiosqlite:///./denya_onecare.db"
|
|
|
|
# ── Auth ─────────────────────────────────────────────────────────
|
|
SECRET_KEY: str = ""
|
|
ALGORITHM: str = "HS256"
|
|
ACCESS_TOKEN_EXPIRE_MINUTES: int = 60 # Phase 1: raised 30 -> 60 for fewer re-logins
|
|
REFRESH_TOKEN_EXPIRE_MINUTES: int = 60 * 24 * 7 # 7 days
|
|
|
|
# ── CORS ─────────────────────────────────────────────────────────
|
|
CORS_ORIGINS: str = "*"
|
|
|
|
# ── WhatsApp ─────────────────────────────────────────────────────
|
|
WHATSAPP_PHONE_NUMBER_ID: str = ""
|
|
WHATSAPP_ACCESS_TOKEN: str = ""
|
|
WHATSAPP_VERIFY_TOKEN: str = ""
|
|
META_GRAPH_BASE: str = "https://graph.facebook.com/v18.0"
|
|
# Shared secret for inbound webhook POSTs (header ``X-Webhook-Secret``).
|
|
# Fail-closed: when unset/empty the webhook rejects every message.
|
|
WHATSAPP_WEBHOOK_SECRET: str = ""
|
|
# Expected sender/recipient number (E.164) for the WhatsApp demo round
|
|
# trip (webhook -> ticket -> mock-log). Set per deployment in .env only —
|
|
# never commit a real number. When set, the demo payload builder
|
|
# (``app/routers/whatsapp.py::build_demo_webhook_payload``) originates
|
|
# messages from it, the auto-reply targets it, and ``/api/whatsapp/mock-log``
|
|
# surfaces it. Empty (default) means the demo payload cannot be built:
|
|
# the helper fails closed rather than fabricating a sender.
|
|
WHATSAPP_DEMO_TO: str = ""
|
|
|
|
# ── Login rate limiting ──────────────────────────────────────────
|
|
LOGIN_RATE_LIMIT_MAX_ATTEMPTS: int = 5
|
|
LOGIN_RATE_LIMIT_WINDOW_SECONDS: int = 15 * 60
|
|
|
|
# ── Paths ────────────────────────────────────────────────────────
|
|
BASE_DIR: Path = Path(__file__).resolve().parent.parent.parent
|
|
|
|
|
|
settings = Settings()
|
|
|
|
# ── Fail-closed secret validation (HARDENING.md P0.1) ─────────────────
|
|
# Refuse to boot without a real SECRET_KEY. Devs must create a local .env
|
|
# (see .env.example); production injects it via docker-compose env_file.
|
|
_KNOWN_PLACEHOLDER_SECRETS = {
|
|
"",
|
|
"change-me-in-production",
|
|
"change-me-in-production-use-a-real-secret",
|
|
"changeme",
|
|
"secret",
|
|
}
|
|
|
|
if settings.SECRET_KEY in _KNOWN_PLACEHOLDER_SECRETS or len(settings.SECRET_KEY) < 32:
|
|
raise RuntimeError(
|
|
"SECRET_KEY is missing, a known placeholder, or shorter than 32 chars. "
|
|
"Generate one with: openssl rand -hex 32 — and set it in .env "
|
|
"(dev) or the runtime environment (prod). Refusing to start."
|
|
)
|