Files
dtf-system/deploy/portainer.env.example
Cauê Faleiros e3d5558198
All checks were successful
Build and deploy / Validate source (push) Successful in 9s
Build and deploy / Integration suite on a real stack (push) Successful in 2m49s
Build and deploy / Secret scan and release gate (push) Successful in 9s
Build and deploy / Publish images and notify Portainer (push) Has been skipped
feat: connect Tiny through its v3 API with OAuth
Tiny v3 replaces the v2 token adapter. An operator connects Tiny once from
the Kanban; the callback is authorised by a single-use state, because Tiny's
cross-site redirect does not carry the SameSite=Strict operator cookie.
Tokens are kept in provider_tokens, the refresh token rotates under a row
lock, and the worker keeps the connection alive while order creation is off.

Orders find or create the customer's contact by CNPJ, then POST /pedidos
with product ids from TINY_PRODUCT_TEXTIL_FOLHA, _TEXTIL_AVULSA, _UV_FOLHA
and _UV_AVULSA and numeroOrdemCompra DTF-<number>; a retry searches the
customer's recent orders for that number first. The product settings avoid a
_FILE suffix, which the secrets loader reads as a secret file path.

Production passes the application credentials through but keeps
TINY_ADAPTER fake: Tiny has no sandbox, so creating real orders waits for a
supervised test. compose.providers.yaml gives the local API and worker an
internet route for provider testing; the default local stack still has none.

Verified with the full CI integration sequence locally, including the new
tiny_oauth_test against the real database.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-24 12:46:09 -03:00

60 lines
1.7 KiB
Plaintext

# Non-secret Portainer stack variables. Never put credential values in this file.
PRODUCTION_DEPLOY_ENABLED=TBD
PRODUCTION_INPUTS_APPROVED=TBD
PRODUCTION_SECURITY_REVIEW_APPROVED=TBD
PRODUCTION_RESTORE_REHEARSED=TBD
API_IMAGE=gitea.blyzer.com.br/blyzer/dtf-api
WEB_IMAGE=gitea.blyzer.com.br/blyzer/dtf-web
IMAGE_TAG=latest
POSTGRES_IMAGE=postgres@sha256:0000000000000000000000000000000000000000000000000000000000000000
CLAMAV_IMAGE=clamav/clamav@sha256:0000000000000000000000000000000000000000000000000000000000000000
PUBLIC_ORIGIN=https://dtf.example.invalid
PUBLIC_HOST=dtf.example.invalid
KANBAN_HOST=kanban-dtf.example.invalid
SITE_PORT=8080
KANBAN_PORT=8081
R2_ENDPOINT=TBD
R2_PUBLIC_ENDPOINT=TBD
R2_BUCKET=TBD
POSTGRES_DB=dtf
POSTGRES_USER=dtf_admin
APP_DB_USER=dtf_app
POSTGRES_VOLUME=TBD
OPERATOR_EMAIL=TBD
PAYMENT_ADAPTER=TBD
FREIGHT_ADAPTER=TBD
TINY_ADAPTER=TBD
# Tiny API v3 application (Configurações > Geral > Aplicativos in Tiny). The
# redirect URL registered there must equal TINY_REDIRECT_URI.
TINY_CLIENT_ID=TBD
TINY_REDIRECT_URI=https://<KANBAN_DOMAIN>/api/operator/tiny/callback
TINY_PRODUCT_TEXTIL_FOLHA=TBD
TINY_PRODUCT_TEXTIL_AVULSA=TBD
TINY_PRODUCT_UV_FOLHA=TBD
TINY_PRODUCT_UV_AVULSA=TBD
WHATSAPP_ADAPTER=TBD
STORAGE_QUOTA_BYTES=TBD
OWNER_UPLOAD_QUOTA_BYTES=TBD
MAX_PENDING_UPLOADS=10
MAX_UPLOAD_BYTES=5368709120
UPLOAD_PART_BYTES=8388608
SCAN_MAX_BYTES=134217728
# Names of external Portainer/Docker Swarm secrets, never their values.
DATABASE_URL_SECRET=TBD
DATABASE_ADMIN_URL_SECRET=TBD
DB_ADMIN_PASSWORD_SECRET=TBD
APP_DB_PASSWORD_SECRET=TBD
R2_ACCESS_KEY_ID_SECRET=TBD
R2_SECRET_ACCESS_KEY_SECRET=TBD
OPERATOR_PASSWORD_SECRET=TBD
PAYMENT_TOKEN_SECRET=TBD
PAYMENT_WEBHOOK_SECRET=TBD
TINY_TOKEN_SECRET=TBD
WHATSAPP_TOKEN_SECRET=TBD