- auth.py/auth_routes.py: Login Flow v2 (verified against real NC source/docs) - no OAuth2 client registration needed, backend polls server-side so no CORS issues. Sessions are hashed-token cookies; NC app passwords encrypted at rest (Fernet). Every /api/* route guarded by a blueprint-wide before_request, not per-route decorators, so future routes are protected by default. - receipts/groups scoped per owner_nc_user_id; cross-user access 404s. - nc_client/cospend_client take (username, app_password) per call instead of one shared global credential - each user's uploads/shares/ bills now happen as themselves. - Frontend: LoginGate component drives the login flow (open NC login in a new tab, poll our backend, done). - Merged the old separate review step into the split screen, redesigned with Tailwind (was unstyled/broken), default-excluded-per-item splitting with one-click "include everyone" fixed, DD.MM.YYYY date field, receipt-icon branding. - Dropped LLM bounding-box highlighting - unreliable on real receipts, plain photo upload instead. - Only mention who a bill is split with in its title when there's more than one bill off the same receipt to disambiguate.
45 lines
1.7 KiB
Bash
45 lines
1.7 KiB
Bash
# Copy to .env and fill in. Never commit .env.
|
|
|
|
# --- Nextcloud ---
|
|
# Server address only - each user logs in themselves via Nextcloud Login
|
|
# Flow v2 (see /auth/login/start); there's no shared NC_USERNAME/APP_PASSWORD
|
|
# any more.
|
|
NC_BASE_URL=https://cloud.dominik-roth.eu
|
|
# Folder (relative to each user's own files root) receipt images get
|
|
# uploaded to. Created automatically on first upload if missing (each path
|
|
# segment).
|
|
NC_UPLOAD_FOLDER=Documents/Cospend/Assets
|
|
|
|
# --- Cospend ---
|
|
# Optional: pre-selects a project in the UI. The app lists all your Cospend
|
|
# projects via the API (GET /ocs/v2.php/apps/cospend/api/v1/projects), so
|
|
# this is just a convenience default, not required.
|
|
COSPEND_PROJECT_ID=
|
|
|
|
# --- Vision LLM (OpenAI-compatible chat completions API) ---
|
|
# OpenAI example:
|
|
# LLM_BASE_URL=https://api.openai.com/v1
|
|
# LLM_MODEL=gpt-4o-mini
|
|
# Gemini (OpenAI-compat layer) example:
|
|
# LLM_BASE_URL=https://generativelanguage.googleapis.com/v1beta/openai/
|
|
# LLM_MODEL=gemini-2.0-flash
|
|
LLM_BASE_URL=
|
|
LLM_API_KEY=
|
|
LLM_MODEL=
|
|
|
|
# --- Flask ---
|
|
FLASK_SECRET_KEY=dev-change-me
|
|
DATABASE_PATH=instance/wgbill.sqlite3
|
|
|
|
# --- Auth ---
|
|
# Generate with: python3 -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
|
|
# Encrypts stored Nextcloud app passwords at rest. Required - the app
|
|
# refuses to store/read a token without it. Keep this secret; losing it
|
|
# means every logged-in user has to log in again.
|
|
TOKEN_ENCRYPTION_KEY=
|
|
# Idle session lifetime in days (sliding - refreshed on each use).
|
|
SESSION_TTL_DAYS=30
|
|
# Cookies need Secure (HTTPS-only) for any real deployment. Only set to
|
|
# false for plain-http localhost dev.
|
|
SESSION_COOKIE_SECURE=true
|