# Copy to .env and fill in. Values below are development-friendly defaults. # Required. Generate one, e.g. `python -c "import secrets; print(secrets.token_urlsafe(50))"`. DJANGO_SECRET_KEY=change-me # Development toggles. DJANGO_DEBUG=True # Hosts Django will serve. `.localhost` matches localhost and any *.localhost # subdomain, which the tenant middleware needs for per-club subdomains. DJANGO_ALLOWED_HOSTS=.localhost,127.0.0.1,[::1] # Multi-tenancy: subdomains of this base domain resolve to a club by slug, # e.g. http://ajax-united.localhost:8000/ -> club with slug "ajax-united". # In production set this to your real base domain (e.g. rosterchief.app). ROSTERCHIEF_BASE_DOMAIN=localhost # Two-factor auth. ROSTERCHIEF_BASE_DOMAIN doubles as the WebAuthn Relying Party # ID, so ONE passkey works across every club subdomain. Change it and existing # passkeys stop validating -- they are cryptographically bound to that domain. # ROSTERCHIEF_RP_NAME is what the browser shows during a passkey prompt. # ROSTERCHIEF_RP_NAME=RosterChief # Sessions are shared across club subdomains (log in once, all clubs). Derived # from ROSTERCHIEF_BASE_DOMAIN in production; left host-only on localhost # because browsers reject a Domain attribute there. Override if needed. # DJANGO_SESSION_COOKIE_DOMAIN=.rosterchief.app # DJANGO_CSRF_COOKIE_DOMAIN=.rosterchief.app # Optional. Defaults to sqlite:///db.sqlite3 for dev; point at Postgres in prod. # DJANGO_DATABASE_URL=postgres://user:pass@localhost:5432/rosterchief # Optional. CSRF trusted origins (needed for subdomains in prod), comma-separated. # DJANGO_CSRF_TRUSTED_ORIGINS=https://*.rosterchief.app # Optional. # DJANGO_TIME_ZONE=Europe/Brussels