Files
gochat/backend/configs/config.yaml
T
Rogeeandrogee eb83d241fe HH-547: allow cross-origin widget requests (#126)
* HH-547: allow cross-origin widget requests

* fix(HH-547): align production preflight with wildcard CORS

---------

Co-authored-by: Rogee <rogee@ipao.vip>
2026-08-23 20:11:04 +08:00

83 lines
3.2 KiB
YAML

server:
host: "0.0.0.0"
port: 3000
mode: "debug" # debug, release, test
read_header_timeout_seconds: 5
read_timeout_seconds: 30
write_timeout_seconds: 30
idle_timeout_seconds: 120
shutdown_timeout_seconds: 30
max_header_bytes: 1048576
trusted_proxies: [] # add explicit reverse-proxy IPs/CIDRs; XFF is ignored otherwise
cors:
allowed_origins: [] # retained for config compatibility; GoChat allows all origins
allowed_methods: ["GET", "POST", "PUT", "DELETE", "PATCH", "OPTIONS"]
allowed_headers: ["Origin", "Content-Type", "Accept", "Authorization", "X-Account-ID", "X-Auth-Token", "X-Widget-Token", "X-Identifier-Hash", "access-token", "client", "uid", "token-type", "expiry"]
expose_headers: ["Content-Length", "access-token", "client", "uid", "token-type", "expiry"]
allow_credentials: false # retained for config compatibility; wildcard CORS does not use credentials
max_age: 86400 # preflight cache duration in seconds
database:
dsn: "postgres://postgres@localhost:5432/gochat_dev?sslmode=disable"
max_idle_conns: 10
max_open_conns: 100
conn_max_lifetime: 3600 # seconds
run_migrations: true # auto-run migrations on startup (dev convenience)
migrations_path: "migrations"
redis:
dsn: "redis://localhost:6379/0"
pool_size: 50
jwt:
secret: "gochat_dev_secret_change_in_production"
previous_secrets: []
allow_insecure_header_auth: false
access_expiry_minutes: 15
refresh_expiry_hours: 168
ws_ticket_ttl_seconds: 30
issuer: "gochat"
audience: "gochat-api"
encryption:
enabled: false
current_key_version: 1
aes_key: ""
previous_keys: {}
log:
level: "debug" # debug, info, warn, error
format: "json" # json, text
rate_limit:
enabled: true
login: { requests: 10, window_seconds: 60 }
password_reset: { requests: 5, window_seconds: 300 }
public_upload: { requests: 20, window_seconds: 60 }
webhook: { requests: 120, window_seconds: 60 }
search:
# Chatwoot parity target. Use "db" only for explicit local fallback.
engine: "meilisearch"
host: "http://localhost:7700"
api_key: ""
index_prefix: "gochat_"
timeout_seconds: 5
saml:
enabled: false # SAML 2.0 SSO — enable for enterprise IdP integration
# IdP metadata: provide URL or inline XML (URL preferred for auto-refresh)
idp_metadata_url: "" # e.g. "https://idp.example.com/metadata"
idp_metadata_xml: "" # fallback: paste IdP metadata XML here
sp_entity_id: "https://gochat.example.com/saml" # our SP entity ID
acs_url: "https://gochat.example.com/api/v1/saml/acs" # Assertion Consumer Service URL
# SP key/certificate: PEM format (required for signed AuthnRequest + response validation)
sp_private_key: "" # path or inline PEM — generate with: openssl genrsa -out sp.key 2048
sp_certificate: "" # path or inline PEM — generate with: openssl req -new -x509 -key sp.key -out sp.crt
clock_drift_tolerance: 180 # seconds of allowed clock drift for NotOnOrAfter validation
attribute_map:
email: "email" # SAML attribute → GoChat email field
display_name: "displayName" # SAML attribute → GoChat display name field
first_name: "firstName" # SAML attribute → first name component
last_name: "lastName" # SAML attribute → last name component