- Added support for multiple captcha providers including Google reCAPTCHA (v2 and v3), hCaptcha, and Cloudflare Turnstile. - Introduced new fields in the verification configuration for selecting captcha providers and enabling alt-account detection. - Implemented logic to handle verification attempts and flag potential alt accounts based on IP and invite code analysis. - Updated environment configuration to include necessary keys for captcha providers. - Enhanced the user interface to allow selection of captcha providers in the verification setup. - Improved backend handling of verification records to store additional data related to captcha provider usage.
63 lines
2.5 KiB
Plaintext
63 lines
2.5 KiB
Plaintext
NODE_ENV=production
|
||
# Shared by apps/bot (gateway connection) and apps/webui (narrow REST calls +
|
||
# BullMQ job enqueueing for guild backups, giveaways and the scheduler).
|
||
BOT_TOKEN=
|
||
BOT_CLIENT_ID=
|
||
BOT_CLIENT_SECRET=
|
||
# Optional: register slash commands only on this guild (instant sync for dev).
|
||
# Leave empty in production so commands are global. When set, global commands
|
||
# are cleared; when empty, leftover guild-scoped commands are cleared on startup
|
||
# so Discord does not show every command twice.
|
||
BOT_GUILD_ID=
|
||
DATABASE_URL=postgresql://nexumi:nexumi@postgres:5432/nexumi
|
||
REDIS_URL=redis://redis:6379
|
||
LOG_LEVEL=info
|
||
DEFAULT_LOCALE=de
|
||
METRICS_TOKEN=
|
||
SENTRY_DSN=
|
||
BACKUP_RETENTION_DAYS=14
|
||
BACKUP_CRON=0 3 * * *
|
||
BACKUP_DIR=/backups
|
||
HEALTH_PORT=8080
|
||
# Internal bot health/metrics base (Docker healthcheck). Captcha links use WEBUI_URL.
|
||
PUBLIC_BASE_URL=http://localhost:8080
|
||
TWITCH_CLIENT_ID=
|
||
TWITCH_CLIENT_SECRET=
|
||
|
||
# WebUI (apps/webui) – public URL behind Traefik (also used for captcha verification links)
|
||
WEBUI_URL=https://dashboard.nexumi.de
|
||
# Discord Developer Portal OAuth2 redirect:
|
||
# https://dashboard.nexumi.de/api/auth/callback
|
||
# Must be at least 32 characters long. Generate e.g. with `openssl rand -hex 32`.
|
||
SESSION_SECRET=
|
||
# Comma-separated Discord user IDs treated as global bot owners (owner panel, Phase 7 Batch C).
|
||
OWNER_USER_IDS=
|
||
|
||
# Public site / bot links (Phase 8)
|
||
SUPPORT_SERVER_URL=
|
||
LEGAL_OPERATOR_NAME=HexaHost Inh. Samuel Müller
|
||
LEGAL_OPERATOR_ADDRESS=Richard-Miller-Straße 1, 94051 Hauzenberg, Deutschland
|
||
LEGAL_OPERATOR_EMAIL=info@hexahost.de
|
||
LEGAL_OPERATOR_PHONE=+49 15566 175855
|
||
|
||
# ---------------------------------------------------------------------------
|
||
# Verification captcha providers (WebUI). Leave empty to disable a provider.
|
||
# MATH always works without keys. Per-guild provider is chosen in the dashboard.
|
||
# ---------------------------------------------------------------------------
|
||
# Google reCAPTCHA v2 (checkbox) – https://www.google.com/recaptcha/admin
|
||
RECAPTCHA_SITE_KEY=
|
||
RECAPTCHA_SECRET_KEY=
|
||
# Google reCAPTCHA v3 (score-based). Falls back to RECAPTCHA_* if unset.
|
||
RECAPTCHA_V3_SITE_KEY=
|
||
RECAPTCHA_V3_SECRET_KEY=
|
||
RECAPTCHA_V3_MIN_SCORE=0.5
|
||
# hCaptcha – https://dashboard.hcaptcha.com
|
||
HCAPTCHA_SITE_KEY=
|
||
HCAPTCHA_SECRET_KEY=
|
||
# Cloudflare Turnstile – https://dash.cloudflare.com → Turnstile
|
||
TURNSTILE_SITE_KEY=
|
||
TURNSTILE_SECRET_KEY=
|
||
# Salt for hashing client IPs used in alt-account detection (min 16 chars).
|
||
# Generate e.g. with: openssl rand -hex 16
|
||
CAPTCHA_IP_HASH_SALT=
|