Files
nsrbandCursor 770ed8121a feat(watcher): gate receipt watch with WATCHER_MAILBOXES
Limit Pub/Sub INBOX watch and receipt processing to an allowlisted mailbox set; leave the agent CLI usable for all connected accounts.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 10:09:25 +07:00

42 lines
1.5 KiB
Bash

# Google OAuth Web client (gmail.modify)
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
# Must match an Authorized redirect URI in Google Cloud Console.
# Local (Vite proxies /callback to Fastify):
GOOGLE_REDIRECT_URI=http://localhost:5173/callback
# Production:
# GOOGLE_REDIRECT_URI=https://oauth.0dev.web.id/callback
# 32+ random characters. Used to derive the session cookie key.
SESSION_SECRET=change-me-to-a-long-random-string
PORT=3000
NODE_ENV=development
# Optional default mailbox when CLI omits --user (else users.is_default / sole account)
# GMAIL_DEFAULT_USER=you@gmail.com
# Watcher (apps/watcher) — Gmail Pub/Sub push
WATCHER_PORT=3001
# Only these mailboxes get INBOX watch + receipt parsing (comma-separated).
# Empty / unset = all connected accounts. CLI (npm run gmail) is unaffected.
WATCHER_MAILBOXES=eleven16th@gmail.com
# Full topic name, e.g. projects/my-gcp-project/topics/gmail-push
# A short name like gmail-push is expanded if GOOGLE_CLOUD_PROJECT is set.
GOOGLE_PUBSUB_TOPIC=
# GOOGLE_CLOUD_PROJECT=
# Shared secret. Push URL: https://host/pubsub/gmail?token=...
PUBSUB_VERIFICATION_TOKEN=
# Defaults to apps/api/data/app.db (same OAuth tokens as the web app)
# SQLITE_PATH=
# PocketBase (watcher writes parsed receipts to collection `spendings`)
# Use a _superusers account (admin), not a users-collection login.
POCKETBASE_URL=
POCKETBASE_USER=
POCKETBASE_PASSWORD=
# ntfy alerts for parse failures / non-duplicate skips (default: system topic)
# NTFY_URL=https://n.0dev.web.id/system