Files
screenclipper/.env.example
T
ayrisdevandClaude Sonnet 5 fb8485d638 feat: panele auth sistemi ekle (kullanıcı/şifre + oturum + middleware)
Panel şu ana kadar herkese açıktı — URL'yi bilen herkes kanal
ekleyip/silebilir, cookie güncelleyebilir, kayıt indirebilirdi.

- users tablosu (bcrypt şifre hash'i)
- /login: hiç kullanıcı yoksa "ilk admin hesabı oluştur" formu, varsa
  normal giriş formu
- jose ile imzalanmış, httpOnly çerezde tutulan 30 günlük oturum
- middleware.ts: /login hariç tüm rotaları korur (video stream route'u
  dahil — aynı origin istekleri çerezi otomatik taşır)
- layout: oturum yoksa nav hiç gösterilmiyor, varsa kullanıcı adı +
  çıkış butonu ekleniyor

SESSION_SECRET production'da zorunlu (docker-compose derleme zamanında
kontrol ediyor); Coolify'a rastgele bir değer eklendi.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-01 11:26:42 +03:00

48 lines
2.1 KiB
Bash
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Local dev (running services directly on the host) uses localhost.
# docker-compose overrides DATABASE_URL/REDIS_URL/SHARED_MEDIA_ROOT to
# internal container hostnames — see infra/docker-compose.yml.
DATABASE_URL=postgresql://streamclipper:streamclipper@localhost:5432/streamclipper
REDIS_URL=redis://localhost:6379
SHARED_MEDIA_ROOT=./shared-media
# Canlı yayın tespiti yt-dlp ile yapılıyor (bkz. youtubePolling.ts) —
# YouTube Data API key gerekmiyor.
OPENAI_API_KEY=
TELEGRAM_BOT_TOKEN=
TELEGRAM_CHAT_ID=
POLL_INTERVAL_MS=60000
SEGMENT_TIME_SEC=900
API_DAEMON_PORT=4001
# Signs the panel's login session cookies (frontend). Generate with:
# openssl rand -base64 32
# Required in production (docker-compose fails to start without it) — a
# fixed insecure default is only used for local dev when unset.
SESSION_SECRET=
# Set to a live YouTube URL to bypass the 60s polling loop and start
# capturing immediately — useful for testing the pipeline without waiting
# for a real scheduled stream.
FORCE_LIVE_URL=
# YouTube cookies (Netscape cookies.txt content) are configured from the
# panel's /settings page, not here — they rotate every few hours and are
# stored in the app_settings table so they can be updated without a
# redeploy. Use a throwaway/secondary Google account, not your main one —
# it's a live session credential.
# URL of a bgutil-ytdlp-pot-provider HTTP server (see docker-compose.yml
# sc_pot_provider). Needed alongside cookies to avoid YouTube's "The page
# needs to be reloaded" proof-of-origin token check. In docker-compose this
# is auto-set to http://sc_pot_provider:4416; leave blank for local dev
# unless you're running the provider yourself.
YTDLP_POT_PROVIDER_URL=
# Residential/ISP proxy (http://user:pass@host:port) for yt-dlp calls.
# Datacenter server IPs get progressively more flagged the more they're
# used for yt-dlp requests — a clean residential/ISP IP avoids that. Use an
# ISP proxy product specifically (e.g. Oxylabs "ISP Proxies"), not a plain
# datacenter proxy — the latter has the same problem as the server itself.
PROXY_URL=