Files
gochat/backend/configs/config.prod.yaml
T
Rogeeandrogee cf263d10b4 HH-437: harden production auth and tenant authorization (#84)
* HH-437 harden auth and account authorization

* HH-437 reject revoked platform access

---------

Co-authored-by: Rogee <rogee@ipao.vip>
2026-08-21 19:13:10 +08:00

37 lines
931 B
YAML

# GoChat Production Environment Overrides
# Reference: Chatwoot config/environments/production.rb
server:
mode: "release"
cors:
# PRODUCTION: Must specify exact origins or wildcard patterns.
# NEVER leave empty in production — empty + non-debug = no CORS allowed.
allowed_origins:
- "https://app.yourdomain.com"
- "https://admin.yourdomain.com"
- "*.yourdomain.com" # matches any subdomain
allow_credentials: true # needed for JWT cookie-based auth
max_age: 86400
jwt:
allow_insecure_header_auth: false
database:
dsn: "postgres://gochat:CHANGE_ME@localhost:5432/gochat_production?sslmode=require"
pool_max: 20
log_level: "warn"
log:
level: "info"
format: "json"
worker:
concurrency: 10
redis_stream_prefix: "gochat:jobs"
redis_consumer_group: "gochat-workers"
redis_block_timeout_s: 5
redis_sweep_interval_s: 30
redis:
channel_prefix: "gochat_production"