mirror of
https://github.com/AletheiaVox/signal_bridge_remote.git
synced 2026-10-07 03:18:17 +08:00
- Remove the authless "sole connected phone" fallback and SB_REQUIRE_MCP_AUTH: an unauthenticated request no longer reaches whichever phone is online alone. - Mcp-Session-Id is no longer a credential; the Bearer token is checked on every request (MCP auth spec). - Refresh tokens live 90 days (was 30, equal to the access token, so they were always dead when first needed). - A rejected refresh no longer counts toward the IP ban: a client with an expired token was retrying into a self-renewing ban on its own IP. - 401s carry the RFC 9728 WWW-Authenticate discovery header.
57 lines
2.8 KiB
Plaintext
57 lines
2.8 KiB
Plaintext
# Signal Bridge Remote — Environment Configuration
|
||
# Copy this to .env and fill in your values.
|
||
|
||
# ═══ REQUIRED ═══════════════════════════════════════════════════════════
|
||
# Generate with: python -c "import secrets; print(secrets.token_hex(32))"
|
||
SB_SECRET_KEY=your-secret-key-here
|
||
|
||
# ═══ Server ═════════════════════════════════════════════════════════════
|
||
SB_HOST=0.0.0.0
|
||
SB_PORT=8420
|
||
|
||
# ═══ Auth ═══════════════════════════════════════════════════════════════
|
||
# Set to "false" to lock out new registrations after your users are set up
|
||
SB_REGISTRATION_OPEN=true
|
||
# How long login tokens last (hours)
|
||
SB_TOKEN_EXPIRY_HOURS=168
|
||
|
||
# ═══ Rate Limiting (anti-harassment) ════════════════════════════════════
|
||
# Auth endpoint: strict to prevent credential stuffing
|
||
SB_RATE_LIMIT_AUTH=5/minute
|
||
# Command endpoint: generous for normal use, blocks floods
|
||
SB_RATE_LIMIT_COMMANDS=120/minute
|
||
# Global per-IP limit
|
||
SB_RATE_LIMIT_GLOBAL=300/minute
|
||
# Max WebSocket connections per IP
|
||
SB_MAX_WS_PER_IP=3
|
||
# Auto-ban after N failed auth attempts (per IP, 1-hour window)
|
||
SB_BAN_THRESHOLD=20
|
||
# How long bans last (minutes)
|
||
SB_BAN_DURATION_MINUTES=30
|
||
|
||
# ═══ Safety ═════════════════════════════════════════════════════════════
|
||
# How often to ping phones (seconds)
|
||
SB_HEARTBEAT_INTERVAL=2.0
|
||
# How long before declaring a phone dead (seconds)
|
||
SB_HEARTBEAT_TIMEOUT=6.0
|
||
|
||
# ═══ Governor (session intensity limiter) ═══════════════════════════════
|
||
# Heat accumulates from intensity × time and dissipates when idle; when it
|
||
# hits the threshold the governor forces a cooldown. Server-wide defaults —
|
||
# each user can override via GET/POST /safety/config.
|
||
SB_GOVERNOR_ENABLED=true
|
||
# Heat units/second at intensity 1.0
|
||
SB_GOVERNOR_HEAT_RATE=3.0
|
||
# Heat units/second dissipated when idle
|
||
SB_GOVERNOR_COOL_RATE=2.0
|
||
# Heat % that triggers cooldown
|
||
SB_GOVERNOR_COOLDOWN_ENTER=90.0
|
||
# Heat % at which cooldown may end
|
||
SB_GOVERNOR_COOLDOWN_EXIT=30.0
|
||
# Minimum seconds a cooldown lasts
|
||
SB_GOVERNOR_COOLDOWN_DURATION=30.0
|
||
|
||
# ═══ Database ═══════════════════════════════════════════════════════════
|
||
# SQLite file path (auto-created)
|
||
SB_DB_PATH=./signal_bridge.db
|