Files
Epicure/.env.example
T
Arnaud f871f4f588 feat: real Stripe billing -- Checkout, Customer Portal, admin billing dashboard (v0.73.0)
Implements plans/STRIPE_PLAN.md sections 1-9 for solo Pro/Family
billing (family multi-user sharing, section 1a, deliberately deferred
-- flagged in that plan as the most novel/error-prone piece).

Decisions locked in: cancel/downgrade at period end (Stripe Portal
default), no trial period.

- lib/stripe.ts: single client factory reading STRIPE_SECRET_KEY via
  site-settings (DB overrides env, same pattern as every other
  provider key in this codebase).
- Webhook route rewritten on the real `stripe` SDK
  (stripe.webhooks.constructEvent replaces the hand-rolled HMAC
  verifier) and now handles the full event set: checkout.session.completed,
  customer.subscription.{updated,deleted}, invoice.{payment_failed,paid}.
  past_due deliberately never downgrades tier on its own -- Stripe
  retries the card first, recovering via invoice.paid or eventually
  giving up via subscription.deleted. Every handler audit-logs under
  billing.<event>. Dedup via the existing processed_stripe_events
  table, unchanged.
- Schema: tierDefinitions gained stripe{ProductId,PriceIdMonthly,
  PriceIdYearly} (the lookup table mapping a Price back to a tier on
  checkout); users gained stripeSubscriptionId/subscriptionStatus/
  currentPeriodEnd.
- New POST /api/v1/billing/checkout (creates a subscription Checkout
  Session, allow_promotion_codes: true), POST /api/v1/billing/portal
  (Stripe's hosted self-serve cancel/upgrade/card-update), GET
  /api/v1/billing/status.
- /settings/billing: current plan + renewal date, past_due warning,
  usage-vs-limits (reuses the existing UsageQuotaSection), plan
  comparison cards with per-tier Checkout buttons, manage-billing
  button once a Stripe customer exists.
- /admin/billing: connection status (test/live mode detection),
  subscriber counts, past-due list, recent billing audit events, link
  to Stripe Dashboard. Tier Limits page extended with the three Stripe
  price fields per tier (own render branch, not the numeric+Unlimited-
  switch machinery the existing fields use).

Before going live: an admin needs to create real Products/Prices in
Stripe, enter the IDs on Tier Limits, and configure the Stripe-side
webhook endpoint -- all operational steps the plan always called for,
none of it code.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 13:37:14 +02:00

93 lines
3.0 KiB
Bash

# Database
DATABASE_URL=postgresql://epicure:epicure@localhost:5432/epicure
# Redis
REDIS_URL=redis://localhost:6379
# Storage (MinIO / S3-compatible)
STORAGE_ENDPOINT=http://localhost:9000
STORAGE_ACCESS_KEY=minioadmin
STORAGE_SECRET_KEY=minioadmin
STORAGE_BUCKET=epicure-uploads
STORAGE_REGION=us-east-1
# Auth (generate with: openssl rand -base64 32)
BETTER_AUTH_SECRET=
BETTER_AUTH_URL=http://localhost:3000
# Encryption key for BYOK AI keys stored in DB (generate with: openssl rand -base64 32)
# Separate from BETTER_AUTH_SECRET for key separation. Falls back to BETTER_AUTH_SECRET if unset.
ENCRYPTION_SECRET=
# OAuth — Google (always available)
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
# OAuth — GitHub (optional; set NEXT_PUBLIC_GITHUB_ENABLED=true to show button in UI)
GITHUB_CLIENT_ID=
GITHUB_CLIENT_SECRET=
NEXT_PUBLIC_GITHUB_ENABLED=
# OAuth — Discord (optional; set NEXT_PUBLIC_DISCORD_ENABLED=true to show button in UI)
DISCORD_CLIENT_ID=
DISCORD_CLIENT_SECRET=
NEXT_PUBLIC_DISCORD_ENABLED=
# OIDC — Authentik (or any OIDC provider)
# AUTHENTIK_BASE_URL: base URL including application slug, e.g.
# https://auth.example.com/application/o/epicure
# The discovery document is fetched from $AUTHENTIK_BASE_URL/.well-known/openid-configuration
# In authentik: create an OAuth2/OpenID provider, set redirect URI to
# $BETTER_AUTH_URL/api/auth/callback/authentik
AUTHENTIK_CLIENT_ID=
AUTHENTIK_CLIENT_SECRET=
AUTHENTIK_BASE_URL=
# Set to true to show Authentik login button in UI
NEXT_PUBLIC_AUTHENTIK_ENABLED=
# SMTP (leave blank to log emails to console in dev)
SMTP_HOST=
SMTP_PORT=587
SMTP_SECURE=false
SMTP_USER=
SMTP_PASS=
SMTP_FROM=Epicure <noreply@epicure.app>
# Web push (generate with: npx web-push generate-vapid-keys)
NEXT_PUBLIC_VAPID_PUBLIC_KEY=
VAPID_PRIVATE_KEY=
# Gitea (optional — in-app support tickets open an issue here if all three are set)
GITEA_URL=
GITEA_TOKEN=
GITEA_REPO=owner/repo
# Set as the webhook secret on the Gitea repo's webhook config (issues + issue_comment
# events) to sync issue close/reopen/comments back into Epicure support tickets.
GITEA_WEBHOOK_SECRET=
# USDA FoodData Central (optional, free — get a key at https://fdc.nal.usda.gov/api-key-signup)
# Improves recipe nutrition estimates with real per-ingredient data instead of AI-only guesses.
USDA_API_KEY=
# Stripe (optional — billing for Pro/Family tiers). Only needed as a
# bootstrap fallback for self-hosters without the admin settings UI set up
# yet — a value stored via Admin > Settings takes precedence.
STRIPE_SECRET_KEY=
STRIPE_PUBLISHABLE_KEY=
STRIPE_WEBHOOK_SECRET=
# Shared secret for internal cron-triggered endpoints (e.g. weekly digest email).
# Generate with: openssl rand -base64 32
CRON_SECRET=
# AI Providers (configure at least one)
OPENROUTER_API_KEY=
OPENROUTER_DEFAULT_MODEL=google/gemini-flash-1.5
OPENAI_API_KEY=
ANTHROPIC_API_KEY=
OLLAMA_BASE_URL=http://localhost:11434
# Grocery delivery handoff (optional — without these, shopping lists only offer "copy as text")
NEXT_PUBLIC_GROCERY_PROVIDER=
INSTACART_API_KEY=