Initial commit: Kalendartool (Next.js, Prisma, Docker)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
60
lib/config.ts
Normal file
60
lib/config.ts
Normal file
@@ -0,0 +1,60 @@
|
||||
/**
|
||||
* Zentrale, typsichere Konfiguration aus Umgebungsvariablen.
|
||||
*
|
||||
* Alle Werte werden beim ersten Zugriff validiert, damit Fehlkonfigurationen
|
||||
* sofort (und nicht erst zur Laufzeit an versteckter Stelle) auffallen.
|
||||
* Keine Magic Strings in der restlichen Anwendung.
|
||||
*/
|
||||
|
||||
function requireEnv(name: string): string {
|
||||
const value = process.env[name];
|
||||
if (!value || value.trim().length === 0) {
|
||||
throw new Error(
|
||||
`Umgebungsvariable ${name} ist nicht gesetzt. Bitte .env anlegen (Vorlage: .env.example).`,
|
||||
);
|
||||
}
|
||||
return value.trim();
|
||||
}
|
||||
|
||||
/** Session-Secret: mindestens 32 Zeichen, sonst ist es nicht sicher. */
|
||||
function requireSessionSecret(): string {
|
||||
const secret = requireEnv('SESSION_SECRET');
|
||||
if (secret.length < 32) {
|
||||
throw new Error(
|
||||
'SESSION_SECRET muss mindestens 32 Zeichen lang sein (z. B. crypto.randomBytes(48).toString("base64url")).',
|
||||
);
|
||||
}
|
||||
return secret;
|
||||
}
|
||||
|
||||
/** Liest die Konfiguration einmalig und cached das Ergebnis. */
|
||||
let cachedConfig: AppConfig | undefined;
|
||||
|
||||
export interface AppConfig {
|
||||
sessionSecret: string;
|
||||
appUrl: string;
|
||||
/** Wenn false, ist die Registrierung nur ueber Invite-Links moeglich. */
|
||||
allowOpenRegistration: boolean;
|
||||
/** MultiToolApp-Plattform: Basis-URL (JWKS-Abruf). null = SSO deaktiviert. */
|
||||
hubUrl: string | null;
|
||||
/** Tool-Slug in der Hub-Registry (Token-`aud`). */
|
||||
hubToolSlug: string | null;
|
||||
/** Erwarteter Token-`iss` (Hub-Basis-URL). */
|
||||
hubIssuer: string | null;
|
||||
}
|
||||
|
||||
export function getConfig(): AppConfig {
|
||||
if (cachedConfig) {
|
||||
return cachedConfig;
|
||||
}
|
||||
cachedConfig = {
|
||||
sessionSecret: requireSessionSecret(),
|
||||
appUrl: process.env.APP_URL?.trim() || 'http://localhost:3000',
|
||||
allowOpenRegistration:
|
||||
(process.env.ALLOW_OPEN_REGISTRATION ?? 'true').toLowerCase() === 'true',
|
||||
hubUrl: process.env.HUB_URL?.trim() || null,
|
||||
hubToolSlug: process.env.HUB_TOOL_SLUG?.trim() || null,
|
||||
hubIssuer: process.env.HUB_ISSUER?.trim() || null,
|
||||
};
|
||||
return cachedConfig;
|
||||
}
|
||||
Reference in New Issue
Block a user