fix: use process.env for runtime OAuth secrets
This commit is contained in:
@@ -3,6 +3,8 @@ services:
|
|||||||
build: .
|
build: .
|
||||||
ports:
|
ports:
|
||||||
- "4321:4321"
|
- "4321:4321"
|
||||||
|
env_file:
|
||||||
|
- .env
|
||||||
environment:
|
environment:
|
||||||
- NODE_ENV=production
|
- NODE_ENV=production
|
||||||
- HOST=0.0.0.0
|
- HOST=0.0.0.0
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
import { SignJWT, jwtVerify } from 'jose';
|
import { SignJWT, jwtVerify } from 'jose';
|
||||||
|
|
||||||
const JWT_SECRET = new TextEncoder().encode(import.meta.env.JWT_SECRET || '');
|
const JWT_SECRET = new TextEncoder().encode(process.env.JWT_SECRET || '');
|
||||||
|
|
||||||
export function generateCodeVerifier(): string {
|
export function generateCodeVerifier(): string {
|
||||||
const array = new Uint8Array(64);
|
const array = new Uint8Array(64);
|
||||||
@@ -30,16 +30,16 @@ export function generateState(): string {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export const vkOAuthConfig = {
|
export const vkOAuthConfig = {
|
||||||
clientId: import.meta.env.VK_CLIENT_ID || '',
|
clientId: process.env.VK_CLIENT_ID || '',
|
||||||
clientSecret: import.meta.env.VK_CLIENT_SECRET || '',
|
clientSecret: process.env.VK_CLIENT_SECRET || '',
|
||||||
authUrl: 'https://id.vk.com/oauth2/auth',
|
authUrl: 'https://id.vk.com/oauth2/auth',
|
||||||
tokenUrl: 'https://id.vk.ru/oauth2/auth',
|
tokenUrl: 'https://id.vk.ru/oauth2/auth',
|
||||||
scope: 'email phone',
|
scope: 'email phone',
|
||||||
};
|
};
|
||||||
|
|
||||||
export const yandexOAuthConfig = {
|
export const yandexOAuthConfig = {
|
||||||
clientId: import.meta.env.YANDEX_CLIENT_ID || '',
|
clientId: process.env.YANDEX_CLIENT_ID || '',
|
||||||
clientSecret: import.meta.env.YANDEX_CLIENT_SECRET || '',
|
clientSecret: process.env.YANDEX_CLIENT_SECRET || '',
|
||||||
authUrl: 'https://oauth.yandex.com/authorize',
|
authUrl: 'https://oauth.yandex.com/authorize',
|
||||||
tokenUrl: 'https://oauth.yandex.com/token',
|
tokenUrl: 'https://oauth.yandex.com/token',
|
||||||
scope: 'login:email login:info login:avatar',
|
scope: 'login:email login:info login:avatar',
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ export const GET: APIRoute = async ({ url }) => {
|
|||||||
const challenge = await generateCodeChallenge(verifier);
|
const challenge = await generateCodeChallenge(verifier);
|
||||||
const state = generateState();
|
const state = generateState();
|
||||||
|
|
||||||
const redirectUri = `${import.meta.env.PUBLIC_APP_URL || url.origin}/api/auth/callback/vk`;
|
const redirectUri = `${process.env.PUBLIC_APP_URL || url.origin}/api/auth/callback/vk`;
|
||||||
|
|
||||||
const params = new URLSearchParams({
|
const params = new URLSearchParams({
|
||||||
client_id: vkOAuthConfig.clientId,
|
client_id: vkOAuthConfig.clientId,
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ export const GET: APIRoute = async ({ url }) => {
|
|||||||
const challenge = await generateCodeChallenge(verifier);
|
const challenge = await generateCodeChallenge(verifier);
|
||||||
const state = generateState();
|
const state = generateState();
|
||||||
|
|
||||||
const redirectUri = `${import.meta.env.PUBLIC_APP_URL || url.origin}/api/auth/callback/yandex`;
|
const redirectUri = `${process.env.PUBLIC_APP_URL || url.origin}/api/auth/callback/yandex`;
|
||||||
|
|
||||||
const params = new URLSearchParams({
|
const params = new URLSearchParams({
|
||||||
client_id: yandexOAuthConfig.clientId,
|
client_id: yandexOAuthConfig.clientId,
|
||||||
|
|||||||
Reference in New Issue
Block a user