bambuddy/.env.example
maziggy 70857af393 feat(auth): SSO autologin + disable local username/password login (#1589)
Adds a global local_login_enabled setting plus a per-provider
  is_autologin flag on OIDCProvider so operators who run their own SSO
  enabled, or if the calling admin has no UserOIDCLink — either would
  lock everyone out. App-layer invariant: at most one provider can carry
  is_autologin; setting it on one clears it on every other.

  /auth/advanced-auth/status surfaces both new fields so the LoginPage
  decides UI in one query. The env-var bypass flips the reported
  local_login_enabled back to true so the SPA matches what the route
  will accept.
2026-06-25 14:54:27 +02:00

68 lines
3.2 KiB
Text

# BambuTrack Environment Configuration
# Copy this file to .env and adjust values as needed
# Debug mode (true = DEBUG logging, false = production with INFO logging)
DEBUG=true
# Log level (only used when DEBUG=false)
# Options: DEBUG, INFO, WARNING, ERROR
LOG_LEVEL=INFO
# Enable file logging (logs written to logs/bambutrack.log)
LOG_TO_FILE=true
# Home Assistant Integration (for HA Add-on deployments)
# When both HA_URL and HA_TOKEN are set, Home Assistant integration is automatically enabled
# and these values override any database settings (read-only in UI)
# HA_URL=http://supervisor/core
# HA_TOKEN=your-long-lived-access-token
# Trusted iframe origins (#1191) — comma-separated list of scheme://host[:port]
# origins permitted to embed Bambuddy via <iframe>. Defaults to empty (strict:
# only same-origin embedding allowed). Set this to your Home Assistant origin
# when using the HA Webpage dashboard panel, since HA on port 8123 and Bambuddy
# on port 8000 are different origins to the browser. Wildcards, paths, and
# non-http(s) schemes are rejected at startup with a warning.
# TRUSTED_FRAME_ORIGINS=http://homeassistant.local:8123
# MFA at-rest encryption key (#1219) — Fernet, base64-encoded 32 bytes.
# Auto-generated and stored in DATA_DIR/.mfa_encryption_key on first startup
# if unset. Set explicitly to manage the key out-of-band (e.g. via a secret
# manager).
# Generate with: python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
#
# NOTE: Local backups (.zip) include the auto-generated key file, so a backup
# is self-contained. If you set this variable explicitly, ensure your backups
# also store the value separately (otherwise an encrypted backup cannot be
# restored after key loss).
# MFA_ENCRYPTION_KEY=
# External library folders (GHSA-r2qv follow-up) — colon-separated list of
# host paths that users are permitted to register as external library
# folders via Settings → Library → "Add external folder".
#
# Empty (the default) means the external-folder feature is DISABLED:
# attempts to register one return HTTP 400. Set this to one or more
# absolute paths to opt in. Paths that fall inside Bambuddy's own
# DATA_DIR / LOG_DIR / static dir are always rejected regardless of
# this value.
#
# Example for a single NAS mount:
# BAMBUDDY_EXTERNAL_ROOTS=/mnt/nas/3d-prints
# Example for two roots:
# BAMBUDDY_EXTERNAL_ROOTS=/mnt/nas/3d-prints:/srv/library
#
# In Docker, also bind-mount the host path into the container at the same
# location (see docker-compose.yml for the matching volume snippet).
# BAMBUDDY_EXTERNAL_ROOTS=
# Local-login recovery bypass (#1589) — set to "true" / "1" / "yes" to
# accept username + password credentials on /auth/login (and to allow the
# /auth/forgot-password flow) even when the in-app setting "Disable local
# login" is turned on. This is the documented "SSO is broken, let me back
# in" path for an operator whose only normal sign-in route is via OIDC.
# /auth/advanced-auth/status also reports local_login_enabled=true while
# this is set, so the login page shows the credentials form to match.
# LDAP is governed by its own ldap_enabled toggle and is not affected.
# Leave unset for normal operation.
# BAMBUDDY_LOCAL_LOGIN=true