# Copy this file to .env and adjust values as needed
# Only variables prefixed with TL_ are exposed to the renderer via window.env
TL_API_URL="http://localhost:8338/"

# Frontend URL (used for generating invitation links and auth redirects)
FRONTEND_URL="http://localhost:1212"

# Create S3/GCS/Azure buckets/containers and use workspace per team when set.
# Requires TFL_STORAGE_PROVIDER=aws, gcp, or azure.
TFL_REMOTE_STORAGE_ENABLED=true
MULTIUSER=true # Set to true to enable multi-user features
# Disable all local providers globally:
# - When set to "true" (case-insensitive), no local providers can be created
#   (automatic or manual) for any team, and the default admin seeding path
#   will not create a default local provider.
# - Any other value (or unset) means local providers are enabled.
DISABLE_LOCAL_PROVIDERS=""
# Max parallel threads for local provider launches (default: 2).
# Increase if you frequently launch multiple local jobs concurrently.
# TFL_LAUNCH_MAX_WORKERS="2"
# Storage backend: aws (S3) | gcp (GCS) | azure (Blob/ADLS via abfs) | localfs.
# Use aws/gcp/azure with TFL_REMOTE_STORAGE_ENABLED; use localfs + TFL_STORAGE_URI for a local directory.
TFL_STORAGE_PROVIDER="aws"
# TFL_STORAGE_URI="/path/to/workspace"  # Required for localfs; optional override root for aws/gcp/azure

# Azure storage configuration (for TFL_STORAGE_PROVIDER=azure)
# Either provide a single connection string:
# AZURE_STORAGE_CONNECTION_STRING="DefaultEndpointsProtocol=...;AccountName=...;AccountKey=...;EndpointSuffix=core.windows.net"
# Or provide account-based configuration:
# AZURE_STORAGE_ACCOUNT="your_account_name"
# AZURE_STORAGE_KEY="your_account_key"
# AZURE_STORAGE_SAS_TOKEN="your_sas_token"  # optional alternative to key

TRANSFORMERLAB_JWT_SECRET="APPLE"
TRANSFORMERLAB_REFRESH_SECRET="APPLE123"

# SMTP configuration for email invites
SMTP_SERVER="smtp.example.com"
SMTP_PORT="587"
SMTP_USERNAME="your_email@example.com"
SMTP_PASSWORD="your_email_password"
EMAIL_FROM="your_email@example.com"

## Authentication Providers:
# Default admin user seeded on first startup (password is always admin123 initially)
# TLAB_DEFAULT_ADMIN_EMAIL="admin@example.com"
EMAIL_AUTH_ENABLED="true"
EMAIL_METHOD="dev"

# Google Auth can be setup using Google Auth Platform
GOOGLE_OAUTH_ENABLED="false"
#GOOGLE_OAUTH_CLIENT_ID="your-google-oauth-client-id.apps.googleusercontent.com"
#GOOGLE_OAUTH_CLIENT_SECRET="your-google-oauth-client-secret"

# To get Github client id and secret:
# Go to Github profile -> settings -> developer settings -> oauth app
GITHUB_OAUTH_ENABLED="false"
GITHUB_OAUTH_CLIENT_ID="your_github_client_id"
GITHUB_OAUTH_CLIENT_SECRET="your_github_client_secret"

# Generic OIDC (OpenID Connect) - any compliant IdP (Okta, Keycloak, Auth0, etc.)
# Add one or more providers using index 0, 1, 2... Discovery URL is the IdP's .well-known/openid-configuration
# In your IdP, set redirect/callback URI to: <API_BASE_URL>/auth/oidc-0/callback (use oidc-1 for second provider, etc.)
#OIDC_0_DISCOVERY_URL="https://your-idp.example.com/.well-known/openid-configuration"
#OIDC_0_CLIENT_ID="your-client-id"
#OIDC_0_CLIENT_SECRET="your-client-secret"
#OIDC_0_NAME="Company SSO"
#OIDC_1_DISCOVERY_URL="https://other-idp.example.com/.well-known/openid-configuration"
#OIDC_1_CLIENT_ID="..."
#OIDC_1_CLIENT_SECRET="..."
#OIDC_1_NAME="Other IdP"

# Sentry error tracking (optional - works for both frontend and backend)
# SENTRY_DSN="https://your-sentry-dsn@sentry.io/project-id"
# SENTRY_ENABLE_TRACING="true"  # Enable distributed tracing between frontend and backend

# Disable the "new version available" banner in the web frontend.
# The CLI update check is unaffected.
# TL_DISABLE_UPDATE_CHECK="true"

# Don't fetch galleries from the internet, this helps
# with development
# TLAB_USE_LOCAL_GALLERIES=1