# Copy to .env and fill in before running with docker-compose, # or export these yourself before `node server.js`. # Required: a long random string used to sign session cookies. # Generate one with: node -e "console.log(require('node:crypto').randomBytes(32).toString('hex'))" SESSION_SECRET= # Set to true once this is served over HTTPS (e.g. behind a reverse proxy). # Leave false for plain-HTTP LAN use, otherwise cookies won't be sent. COOKIE_SECURE=false # Set to true after your household(s) are created to stop accepting new signups. DISABLE_PUBLIC_SIGNUP=false # Only needed outside Docker if you want the SQLite file somewhere specific. # DATA_DIR=./data # PORT=3007 # Web Push (optional) — notifies parents when a kid checks off a task. # Requires real HTTPS with a browser-trusted certificate — self-signed does # NOT work on iOS, and plain HTTP doesn't work at all (see README's # "Push notifications" section). Leave unset to skip this feature; the # app degrades gracefully with no broken UI when it's not configured. # Generate with: npx web-push generate-vapid-keys # VAPID_PUBLIC_KEY= # VAPID_PRIVATE_KEY= # VAPID_SUBJECT=mailto:you@example.com