Repository navigation
Expand file tree
/
Copy path.env.test.example
More file actions
86 lines (75 loc) · 4.8 KB
/
Copy path.env.test.example
File metadata and controls
86 lines (75 loc) · 4.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
# ── Test environment variables ─────────────────────────────────────────────
#
# Copy the vars you need into a local .env before running `npm test`
# locally (CI already sets these directly in .github/workflows/ci.yml).
#
# config/index.ts's test-mode fallback (loadConfig(), src/config/index.ts)
# no longer hardcodes real-looking credential values for the vars below —
# DATABASE_URL, JWT_SECRET, and STELLAR_PLATFORM_SECRET now throw a clear
# error if missing in test mode, rather than silently substituting a fake
# secret (#475). Every other var listed here has a safe, non-secret
# in-code default and only needs to be set if you want to override it.
#
# None of the values below are real credentials — they are placeholders/
# examples only.
NODE_ENV=test
# ── Database (REQUIRED — no fallback) ──────────────────────────────────────
# Point this at a disposable local/test Postgres instance.
DATABASE_URL=postgresql://chainlearn_test:test_password@localhost:5432/chainlearn_test
# ── Redis (optional — defaults to redis://localhost:6379) ─────────────────
REDIS_URL=redis://localhost:6379
# ── JWT (REQUIRED — no fallback) ───────────────────────────────────────────
# Must be at least 64 characters (256 bits) and not contain
# "change-in-production" or equal "your-secret-key" (see envSchema).
# This example string is exactly that shape and is safe to use verbatim
# for local test runs — it is not used anywhere outside test mode.
JWT_SECRET=test-secret-key-that-is-at-least-sixty-four-characters-long-for-tests
# ── Stellar ─────────────────────────────────────────────────────────────
STELLAR_NETWORK=testnet
# Optional — defaults to the public Stellar testnet endpoints below.
STELLAR_HORIZON_URL=https://horizon-testnet.stellar.org
STELLAR_SOROBAN_RPC_URL=https://soroban-testnet.stellar.org
# REQUIRED — no fallback. Must be a valid Stellar secret key
# (starts with "S", 56 chars, base32). Generate a throwaway testnet keypair,
# e.g. via `stellar keys generate` or the Stellar Laboratory — never reuse a
# mainnet or otherwise real secret here.
STELLAR_PLATFORM_SECRET=SAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
# Optional — any non-empty string works for tests that don't assert on the
# on-chain contract itself; defaults to "CHANGE_ME_IN_TEST_ENV" if unset.
STELLAR_QUIZ_CONTRACT_ID=CHANGE_ME_IN_TEST_ENV
STELLAR_REWARD_CONTRACT_ID=CHANGE_ME_IN_TEST_ENV
STELLAR_CREDENTIAL_CONTRACT_ID=CHANGE_ME_IN_TEST_ENV
# ── Request body limits (optional — see src/config/index.ts for defaults) ─
# REQUEST_BODY_LIMIT_BYTES=1048576
# MULTIPART_BODY_LIMIT_BYTES=5242880
# AVATAR_UPLOAD_MAX_BYTES=2097152
# AVATAR_UPLOAD_DIR=uploads/avatars
# PUBLIC_BASE_URL=http://localhost:3000
# Test-only environment variables (#475).
#
# Copy this to .env.test and it's picked up automatically when
# NODE_ENV=test (vitest sets this). Everything here is a fake value that
# only needs to satisfy envSchema's validation, not point at anything real —
# tests mock the database/Redis/Stellar clients they actually exercise.
#
# CI should set these as real environment variables instead of committing a
# .env.test file; config/index.ts's own TEST_FALLBACKS (used when neither
# process.env nor .env.test supplies a value) exist so `npm test` still
# works out of the box with zero setup, but a checked-in .env.test isn't
# required and must never contain anything other than fake test values.
DATABASE_URL=postgresql://chainlearn_test:test_password@localhost:5432/chainlearn_test
REDIS_URL=redis://localhost:6379
# OWASP: 256-bit secret = at least 64 characters, must not be a placeholder
# string the schema explicitly rejects (see JWT_SECRET's .refine in
# config/index.ts) — this one is long enough and isn't "your-secret-key" or
# "change-in-production", so it passes validation while being obviously fake.
JWT_SECRET=test-secret-key-that-is-at-least-sixty-four-characters-long-for-tests
STELLAR_HORIZON_URL=https://horizon-testnet.stellar.org
STELLAR_SOROBAN_RPC_URL=https://soroban-testnet.stellar.org
# Must match /^S[A-Z2-7]{55}$/ (a syntactically valid Stellar secret key
# shape) even though it isn't a real funded account — the old hardcoded
# fallback of "test" failed this regex outright.
STELLAR_PLATFORM_SECRET=SAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
STELLAR_QUIZ_CONTRACT_ID=test-quiz-contract
STELLAR_REWARD_CONTRACT_ID=test-reward-contract
STELLAR_CREDENTIAL_CONTRACT_ID=test-credential-contract