Files
url_shortening_service/.env.example
T
westfarn 630b770c12
Deploy Beta / unit-tests (push) Successful in 4s
Deploy Beta / docker (push) Successful in 13s
Deploy Beta / deploy-beta (push) Successful in 2m38s
Implement v1 URL shortener (Bearer API, public 302, landing, CI) (#2)
## Summary

- Standalone Django 6 shortener: Bearer `/api/links/` (create/list/detail/disable) and public `GET /<code>` 302
- Host split, target-host allowlist, named rotatable tokens; `short_url` from `PUBLIC_SHORT_URL`
- Landing page, DEBUG-only `/debug/` mint form, Django admin
- Docker/compose (host **8005**), Gitea CI like monica_site (PR tests, beta on merge, prod button)
- Caller contract in `API.md`

Closes #1. Infra follow-up: [server-infra#22](ai_ml_operations/server-infra#22).

## Test plan
- [ ] `cd site && uv run python manage.py test`
- [ ] `docker compose up --build` → http://127.0.0.1:8005/
- [ ] `POST /api/links/` with `Bearer monica:dev-only-token` → 201
- [ ] `GET /<code>` → 302 to allowlisted https URL
- [ ] No Bearer → 401; non-allowlisted host → 400
- [ ] `/debug/` only when `DEBUG=true`

Reviewed-on: #2
2026-08-30 04:55:33 -07:00

37 lines
1.6 KiB
Bash

# Local development defaults. Copy to `.env` (gitignored) — never commit secrets.
# docker compose auto-loads `.env` for ${VAR} substitution into the web container.
DJANGO_ENV=dev
DJANGO_DEBUG=true
DJANGO_SECRET_KEY=dev-only-change-me
DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,0.0.0.0,web,url-shortener
# Leave empty for SQLite when running manage.py on the host.
# Compose ignores this and uses the bundled Postgres via COMPOSE_DATABASE_URL.
# DATABASE_URL=
SITE_NAME=URL Shortening Service
CREDIT_NAME=AI ML Operations
CREDIT_URL=https://aimloperations.com
SHORT_DOMAIN=localhost:8005
# Origin printed in minted short_url (phones hit this). Local: this machine.
PUBLIC_SHORT_URL=http://127.0.0.1:8005
# Host values that only serve GET /<code> (no /api/).
SHORT_PUBLIC_HOSTS=go.mkdrealtor.com
# Host values that serve /api/ (Bearer required). May include a public DNS name.
SHORT_API_HOSTS=localhost,127.0.0.1,0.0.0.0,web,url-shortener
# Django admin — keep local. Do not add the public API hostname.
SHORT_ADMIN_HOSTS=localhost,127.0.0.1
# Named, rotatable tokens. This is what keeps /api/ closed on a public hostname.
# Generate: python -c "import secrets; print(secrets.token_urlsafe(32))"
# Format: name:secret,name:secret — never reuse DJANGO_SECRET_KEY.
SHORTENER_API_TOKENS=monica:dev-only-token
# target_url hostname allowlist (exact or suffix).
SHORT_ALLOWED_HOSTS=mkdrealtor.com,aimloperations.com,*.aimloperations.com
SHORT_CODE_LENGTH=6
# HMAC pepper for click IP hashes. Distinct from DJANGO_SECRET_KEY.
CLICK_IP_PEPPER=dev-click-pepper-change-me
GUNICORN_WORKERS=2