[READ-ONLY] Mirror of https://github.com/thoda-dev/shhh. Self-hostable zero-knowledge pastebin for secrets that expire on their own
docker end-to-end-encryption nuxt nuxtjs pastebin secrets selft-hosted zero-knowledge
Something went wrong. Try again.
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778# Copy to .env and fill in. Only secrets and infrastructure live here — everything else# (retention, sizes, quotas, rate limits, registration, forced 2FA) is configured from the admin# dashboard and stored in the database.# --- Required ---# Connection string for Postgres. The bundled docker-compose service provides this default; point it# at your own server to use an existing database.DATABASE_URL=postgres://shhh:shhh@db:5432/shhh# Signs session cookies. Generate one with: openssl rand -base64 32# Changing it later logs everybody out.BETTER_AUTH_SECRET=# The public URL of your instance, no trailing slash. Also used to build the links sent by email,# so it must be the address your users actually reach — not localhost, in production.BETTER_AUTH_URL=https://shhh.example.com# --- Bundled database (ignored if DATABASE_URL points elsewhere) ---POSTGRES_USER=shhhPOSTGRES_PASSWORD=shhhPOSTGRES_DB=shhh# Host port the app is published on.PORT=3000# --- Reverse proxy ---# How many proxies you control sit in front of this app. 0 (the default) ignores X-Forwarded-For and# uses the connection's own address — correct when nothing is in front, and safe when something is.# Set it to 1 behind a single nginx/Caddy/Traefik, 2 behind Cloudflare plus your own proxy, and so on.# Rate limits, the IP allow/blocklist and automatic bans all key on the address this resolves, so a# value larger than your real chain would let a caller choose their own address.TRUSTED_PROXY_DEPTH=0# How long an automatic ban lasts (probe paths, untrusted bots). 0 bans permanently.# Bans an admin places by hand from the dashboard are always permanent and are never shortened here.AUTO_BAN_DURATION_HOURS=72# Optional. GET /api/health always reports whether the instance and its database are up, which is# all a monitor needs. Set a token to also expose the mail provider and storage usage, readable with# `Authorization: Bearer <token>` — without it those two fields are simply absent.HEALTH_TOKEN=# --- Cloudflare Turnstile (anti-bot on paste creation) ---# Required in production: paste creation rejects requests without a valid token.# Get a pair at https://dash.cloudflare.com/?to=/:account/turnstile and add your domain to the# widget's allowed hostnames, otherwise the widget errors out in the browser.NUXT_PUBLIC_TURNSTILE_SITE_KEY=NUXT_TURNSTILE_SECRET_KEY=# --- Mail ---# 'none' is a valid, supported configuration: the instance works without mail, but email# verification, password reset links, invitations and paste sharing by email are all unavailable# (resetting a password becomes a manual admin action).# Switching provider requires editing this file and restarting — it is deliberately not a runtime# setting, so no credential ever reaches the database.MAIL_PROVIDER=none# Sender address, required unless MAIL_PROVIDER=none. e.g. "shhh <no-reply@example.com>"MAIL_FROM=# MAIL_PROVIDER=resendRESEND_API_KEY=# MAIL_PROVIDER=smtpMAIL_SMTP_HOST=MAIL_SMTP_PORT=587# 'true' for implicit TLS (usually port 465); leave false for STARTTLS on 587.MAIL_SMTP_SECURE=false# Leave both empty for a relay that takes no credentials.MAIL_SMTP_USER=MAIL_SMTP_PASS=