Files
openteam/.env.example
T
SakurasanandClaude 9324a782d5 Passkey: 账户设置绑定 + 免密登录(WebAuthn)
- 引入 go-webauthn, Passkey 表存凭据, challenge 会话内存存储(带过期)
- API: /webauthn/register|login begin/complete, /webauthn/passkeys 列表/删除
- 配置 OT_WEBAUTHN_RP_ID/RP_ORIGIN/RP_NAME;登录成功发 JWT+refresh cookie
- 前端 lib/webauthn(编解码+凭据序列化+安全上下文检测), 账户设置绑定区, 登录页免密按钮
- 需 HTTPS 或 localhost(安全上下文)

Co-Authored-By: Claude <noreply@anthropic.com>
2026-08-16 02:00:08 +08:00

48 lines
1.5 KiB
Bash
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# openteam 服务配置示例 —— 复制为 .env 后修改
# 所有项均可用环境变量 OT_<KEY> 覆盖(点号转下划线,如 db.driver → OT_DB_DRIVER)
# 运行环境 development | production
OT_ENV=development
OT_PORT=8080
# 数据库(开发默认 SQLite;生产切 postgres)
OT_DB_DRIVER=sqlite
OT_DB_DSN=data/openteam.db
# OT_DB_DRIVER=postgres
# OT_DB_DSN=host=localhost user=openteam password=openteam dbname=openteam port=5432 sslmode=disable
# JWT(生产必须更换为随机长字符串)
OT_JWT_SECRET=change-me-to-a-long-random-string
OT_JWT_ACCESS_TTL=2h
OT_JWT_REFRESH_TTL=168h
OT_JWT_COOKIE_SECURE=false
# 注册策略:open(开放)| invite(邀请码)
OT_AUTH_REGISTRATION_MODE=open
# 渠道密钥加密主密钥(生产必须设置,32 字节以上)
OT_MASTER_KEY=change-me-master-key
# 默认上游渠道(首次启动自动创建 OpenAI 渠道)
OT_PROXY_UPSTREAM_KEY=
OT_PROXY_UPSTREAM_BASE_URL=https://api.openai.com
OT_PROXY_DEFAULT_MODEL=gpt-4o-mini
OT_PROXY_TIMEOUT=120s
# 渠道健康检查
OT_PROXY_HEALTH_INTERVAL=60s
OT_PROXY_HEALTH_FAIL_THRESHOLD=2
# 限流(内存计数,Redis 后置):用户级每秒请求数上限(0=不限制)
OT_RATELIMIT_USER_RPS=20
# Passkey(WebAuthn):RPID 为域名,RPOrigin 为前端来源(需 HTTPS 或 localhost)
OT_WEBAUTHN_RP_ID=localhost
OT_WEBAUTHN_RP_ORIGIN=http://localhost:5173
OT_WEBAUTHN_RP_NAME=openteam
# 初始管理员(仅首次创建生效)
OT_ADMIN_USERNAME=admin
OT_ADMIN_EMAIL=admin@localhost
OT_ADMIN_PASSWORD=admin123