* HH-437 harden auth and account authorization * HH-437 reject revoked platform access --------- Co-authored-by: Rogee <rogee@ipao.vip>
37 lines
931 B
YAML
37 lines
931 B
YAML
# GoChat Production Environment Overrides
|
|
# Reference: Chatwoot config/environments/production.rb
|
|
|
|
server:
|
|
mode: "release"
|
|
cors:
|
|
# PRODUCTION: Must specify exact origins or wildcard patterns.
|
|
# NEVER leave empty in production — empty + non-debug = no CORS allowed.
|
|
allowed_origins:
|
|
- "https://app.yourdomain.com"
|
|
- "https://admin.yourdomain.com"
|
|
- "*.yourdomain.com" # matches any subdomain
|
|
allow_credentials: true # needed for JWT cookie-based auth
|
|
max_age: 86400
|
|
|
|
jwt:
|
|
allow_insecure_header_auth: false
|
|
|
|
database:
|
|
dsn: "postgres://gochat:CHANGE_ME@localhost:5432/gochat_production?sslmode=require"
|
|
pool_max: 20
|
|
log_level: "warn"
|
|
|
|
log:
|
|
level: "info"
|
|
format: "json"
|
|
|
|
worker:
|
|
concurrency: 10
|
|
redis_stream_prefix: "gochat:jobs"
|
|
redis_consumer_group: "gochat-workers"
|
|
redis_block_timeout_s: 5
|
|
redis_sweep_interval_s: 30
|
|
|
|
redis:
|
|
channel_prefix: "gochat_production"
|