Files
skrift-backend/src/config/index.js
s4luorth c73109b8ca
All checks were successful
Build & Deploy / deploy (push) Successful in 9s
FTP: Passwort base64-sicher via SKRIFT_FTP_PASSWORD_B64
Passwoerter mit Sonderzeichen ($ # @) werden in .env-Dateien verstuemmelt
(bestaetigt durch falsche pw_len -> 530 Login incorrect). Neue Variable
SKRIFT_FTP_PASSWORD_B64 nimmt den base64-kodierten Wert (env-sicher) und
wird dekodiert; hat Vorrang vor SKRIFT_FTP_PASSWORD.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 11:33:33 +02:00

84 lines
3.3 KiB
JavaScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
require('dotenv').config();
const path = require('path');
const isProduction = process.env.NODE_ENV === 'production';
module.exports = {
env: process.env.NODE_ENV || 'development',
port: parseInt(process.env.PORT, 10) || 4000,
scriptalizer: {
licenseKey: process.env.SCRIPTALIZER_LICENSE_KEY,
errFrequency: parseInt(process.env.SCRIPTALIZER_ERR_FREQUENCY, 10) || 0,
endpoint: 'https://www.scriptalizer.co.uk/QuantumScriptalize.asmx/Scriptalize',
fontMap: {
tilda: 'PremiumUltra79',
alva: 'PremiumUltra23',
ellie: 'PremiumUltra39'
},
separator: '|||', // Triple pipe separator (tested and working)
maxInputSize: 48000 // 48KB limit
},
preview: {
// No batch size limit - frontend can send any number of letters
// Backend splits into 25-letter batches for Scriptalizer API internally
scriptalizerBatchSize: 25
// No cache lifetime - files are kept until manually cleaned
// No rate limiting
},
paths: {
cache: isProduction ? '/app/cache' : path.join(__dirname, '../../cache'),
previews: isProduction ? '/app/cache/previews' : path.join(__dirname, '../../cache/previews'),
output: isProduction ? '/app/output' : path.join(__dirname, '../../output'),
fonts: isProduction ? '/app/fonts' : path.join(__dirname, '../../fonts')
},
cors: {
origin: process.env.CORS_ORIGIN || '*',
credentials: true
},
auth: {
apiToken: process.env.API_TOKEN || null
},
// Directus ist die Datenquelle für Aufträge (Rolle "Service"-Token).
directus: {
url: process.env.DIRECTUS_URL || '',
token: process.env.DIRECTUS_TOKEN || ''
},
paypal: {
clientId: process.env.PAYPAL_CLIENT_ID || '',
clientSecret: process.env.PAYPAL_CLIENT_SECRET || '',
// 'sandbox' oder 'live'
environment: process.env.PAYPAL_ENVIRONMENT || 'sandbox'
},
// Alternativer Übermittlungsweg (batch_submissions): Ziel-FTP für die täglichen
// Bündel (xlsx + Sammel-Druck-PDF). Passwort NUR über ENV.
// envClean entfernt versehentliche umschließende Anführungszeichen und CR/LF
// (häufige .env-Fallen unter Windows/docker env_file), die sonst zu „530
// Login incorrect" führen, obwohl die Daten korrekt sind.
ftp: (() => {
const envClean = (v) => String(v || '').replace(/[\r\n]+/g, '').replace(/^(['"])([\s\S]*)\1$/, '$2');
// Passwoerter mit Sonderzeichen ($ # @ …) werden in .env-Dateien oft
// verstuemmelt ($ = Variable, # = Kommentar). Deshalb bevorzugt base64:
// SKRIFT_FTP_PASSWORD_B64 wird dekodiert und ist damit env-sicher.
const pwB64 = envClean(process.env.SKRIFT_FTP_PASSWORD_B64);
const password = pwB64 ? Buffer.from(pwB64, 'base64').toString('utf8') : envClean(process.env.SKRIFT_FTP_PASSWORD);
return {
host: envClean(process.env.SKRIFT_FTP_HOST),
port: parseInt(process.env.SKRIFT_FTP_PORT, 10) || 21,
user: envClean(process.env.SKRIFT_FTP_USER),
password,
// explizites FTP über TLS (wie im FTP-Client eingestellt). 'false' schaltet ab.
secure: String(process.env.SKRIFT_FTP_SECURE || 'true').toLowerCase() !== 'false',
// Selbstsigniertes Zertifikat zulassen (viele FTP-Server) – auf 'false' setzen für strikte Prüfung.
rejectUnauthorized: String(process.env.SKRIFT_FTP_REJECT_UNAUTHORIZED || 'false').toLowerCase() === 'true',
};
})(),
};