Backend: - OAuth service with pluggable provider architecture (Google + Authentik) - Generic authorize/callback endpoints for any provider - Authentik OIDC integration (configurable base URL) - hashed_password made nullable for OAuth-only users - Migration 009: nullable password column - /auth/switch endpoint returns full AuthResponse for account switching - OAuth-only users get clear error on password login attempt - UserResponse includes oauth_provider + avatar_url Frontend: - OAuth buttons on login form (Google + Authentik) - OAuth callback handler (/auth/callback route) - Multi-account auth store (accounts array, addAccount, switchTo, removeAccount) - Account switcher dropdown in header (hover to see other accounts) - "Add another account" option - English + Russian translations Config: - GOOGLE_CLIENT_ID/SECRET/REDIRECT_URI - AUTHENTIK_CLIENT_ID/SECRET/BASE_URL/REDIRECT_URI Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
43 lines
1.4 KiB
Python
43 lines
1.4 KiB
Python
from pydantic_settings import BaseSettings
|
|
|
|
|
|
class Settings(BaseSettings):
|
|
DATABASE_URL: str = "postgresql+asyncpg://ai_assistant:changeme@postgres:5432/ai_assistant"
|
|
SECRET_KEY: str = "changeme_secret_key_at_least_32_chars_long"
|
|
ENVIRONMENT: str = "development"
|
|
|
|
ACCESS_TOKEN_EXPIRE_MINUTES: int = 15
|
|
REFRESH_TOKEN_EXPIRE_DAYS: int = 30
|
|
REFRESH_TOKEN_EXPIRE_HOURS: int = 24
|
|
|
|
BACKEND_CORS_ORIGINS: list[str] = ["http://localhost", "http://localhost:3000"]
|
|
|
|
ANTHROPIC_API_KEY: str = ""
|
|
CLAUDE_MODEL: str = "claude-sonnet-4-20250514"
|
|
|
|
UPLOAD_DIR: str = "/data/uploads"
|
|
MAX_UPLOAD_SIZE_MB: int = 20
|
|
|
|
LOG_LEVEL: str = "INFO"
|
|
DOCS_ENABLED: bool = True
|
|
RATE_LIMIT_REQUESTS: int = 20
|
|
RATE_LIMIT_WINDOW_SECONDS: int = 60
|
|
|
|
GOOGLE_CLIENT_ID: str = ""
|
|
GOOGLE_CLIENT_SECRET: str = ""
|
|
GOOGLE_REDIRECT_URI: str = "http://localhost/api/v1/auth/oauth/google/callback"
|
|
|
|
AUTHENTIK_CLIENT_ID: str = ""
|
|
AUTHENTIK_CLIENT_SECRET: str = ""
|
|
AUTHENTIK_BASE_URL: str = "" # e.g. https://auth.example.com
|
|
AUTHENTIK_REDIRECT_URI: str = "http://localhost/api/v1/auth/oauth/authentik/callback"
|
|
|
|
FIRST_ADMIN_EMAIL: str = "admin@example.com"
|
|
FIRST_ADMIN_USERNAME: str = "admin"
|
|
FIRST_ADMIN_PASSWORD: str = "changeme_admin_password"
|
|
|
|
model_config = {"env_file": ".env", "extra": "ignore"}
|
|
|
|
|
|
settings = Settings()
|