The bot runs on a Linux host where macOS Keychain isn't available, so .env is the default supported storage for the personal PAT. Both paths land in the same process.env slot, but the previous README framing implied Keychain was mandatory. - .env.example: promote ASSETS_SYNC_TOKEN from a comment to a real REPLACE_ME field; note chmod 600 and rotation guidance - README: split the setup section into "Setup A - production/Linux (.env)" and "Setup B - local dev on macOS (Keychain)"; clarify that the wrapper is a no-op if ASSETS_SYNC_TOKEN is already exported - bin/load-assets-sync-secret.sh: soften the header comment to match Co-authored-by: Cursor <cursoragent@cursor.com>
79 lines
3.2 KiB
Text
79 lines
3.2 KiB
Text
# =============================================
|
|
# .env.example
|
|
# Copy to .env and fill in real values. DO NOT commit .env.
|
|
# =============================================
|
|
|
|
# --- Server ---
|
|
PORT=1866
|
|
NODE_ENV=development
|
|
|
|
# --- Jira ---
|
|
# Preferred: use the JIRA_CLOUD_ID gateway form. When set, requests go to
|
|
# https://api.atlassian.com/ex/jira/{cloudId}. If unset, JIRA_BASE_URL is used
|
|
# directly (e.g. https://your-site.atlassian.net).
|
|
JIRA_CLOUD_ID=
|
|
JIRA_BASE_URL=https://your-site.atlassian.net
|
|
|
|
# Auth. 'basic' = email + API token (Atlassian API tokens).
|
|
# 'bearer' = OAuth bearer token in Authorization header.
|
|
JIRA_AUTH_TYPE=basic
|
|
JIRA_EMAIL=service-account@example.com
|
|
JIRA_API_TOKEN=REPLACE_ME
|
|
|
|
# JSM Service Desk (Store Support). Numeric service desk id.
|
|
JIRA_SERVICE_DESK_ID=170
|
|
|
|
# Role name used to restrict visibility on comments posted by this service.
|
|
# Common values: "Administrators", "Service Desk Team".
|
|
JIRA_COMMENT_VISIBILITY_ROLE=Service Desk Team
|
|
|
|
# --- Jira Assets (Store Number -> Assets object resolution) ---
|
|
# Workspace id for Jira Assets. If unset, the app tries to auto-discover via
|
|
# /rest/servicedeskapi/assets/workspace, but setting it explicitly is safer
|
|
# on tenants with more than one Assets workspace.
|
|
JIRA_ASSETS_WORKSPACE_ID=
|
|
|
|
# Numeric object schema and object type id for the Stores schema in Assets.
|
|
JIRA_ASSETS_STORE_SCHEMA_ID=68
|
|
JIRA_ASSETS_STORE_OBJECT_TYPE_ID=109
|
|
|
|
# The attribute name (as shown in the Assets UI) holding the store number.
|
|
JIRA_ASSETS_STORE_NUMBER_ATTRIBUTE=Store Number
|
|
# Optional. If set, the app will also try attribute[<id>]=... form in AQL.
|
|
JIRA_ASSETS_STORE_NUMBER_ATTRIBUTE_ID=
|
|
|
|
# The custom field on the JSM request that holds the Store Assets reference.
|
|
JIRA_STORE_CUSTOM_FIELD_ID=customfield_10261
|
|
|
|
# --- Assets Stores cache (personal-PAT sync workaround) ---
|
|
# The service account is silently filtered out of Object Type 109 (see
|
|
# Forgejo issue #1). Until that's fixed, the app populates a local store-number
|
|
# -> objectId cache using a *personal* Atlassian PAT that has the right role.
|
|
# This PAT is used ONLY for reading the Stores schema; nothing that mutates
|
|
# Jira state uses it.
|
|
#
|
|
# The .env file is the primary supported storage for the PAT (the bot runs on
|
|
# a Linux host; macOS Keychain isn't available there). Because .env stays out
|
|
# of source control (.gitignore) and app.log no longer echoes auth headers,
|
|
# the cleartext token here is scoped to whoever has filesystem access on the
|
|
# deploy host — lock the file down with `chmod 600 .env` and rotate the token
|
|
# if that trust changes.
|
|
#
|
|
# For local dev on macOS you can instead source the token from Keychain via
|
|
# bin/load-assets-sync-secret.sh (see README) and leave ASSETS_SYNC_TOKEN out
|
|
# of .env entirely.
|
|
ASSETS_SYNC_EMAIL=you@ae.com
|
|
ASSETS_SYNC_TOKEN=REPLACE_ME
|
|
|
|
# Where the local cache lives on disk (JSON). Gitignored. Regenerable via
|
|
# POST /api/wxccai/admin/storesCache/refresh.
|
|
STORES_CACHE_PATH=./data/stores.json
|
|
# How often to run a full resync (hours). 0 disables the scheduler.
|
|
STORES_CACHE_REFRESH_HOURS=24
|
|
# Cache is considered "stale" after this many hours; boot-time refresh fires
|
|
# if the on-disk snapshot is older than this.
|
|
STORES_CACHE_STALE_AFTER_HOURS=48
|
|
|
|
# --- xAI (Grok) ---
|
|
XAI_API_KEY=REPLACE_ME
|
|
XAI_BASE_URL=https://api.x.ai/v1
|