sum-guy-429 commited on
Commit
10dec07
·
verified ·
1 Parent(s): 8a41708

docs: document Space Secrets / env vars for operators

Browse files

Document required env var names for operators. No secret values included.

Files changed (1) hide show
  1. README.md +25 -0
README.md CHANGED
@@ -43,3 +43,28 @@ npm run build
43
  ## Deployment
44
 
45
  This repository is configured as a **Docker Space** and serves the Next.js app on port `7860`.
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
43
  ## Deployment
44
 
45
  This repository is configured as a **Docker Space** and serves the Next.js app on port `7860`.
46
+
47
+
48
+ ## Environment variables (Space Secrets)
49
+
50
+ Set these in **Settings → Variables and secrets** on the Space. Do **not** commit values to git.
51
+
52
+ | Name | Required | Purpose |
53
+ |------|----------|---------|
54
+ | `SESSION_SECRET` | Yes | Signs session cookies (`src/lib/session.ts`). Use a long random string; rotate if leaked. |
55
+ | `HF_OAUTH_CLIENT_ID` | Yes* | Hugging Face OAuth app client id (`src/lib/huggingface.ts`). |
56
+ | `HF_OAUTH_CLIENT_SECRET` | Yes* | OAuth app client secret — Space **Secret** only. |
57
+ | `HF_DATASET_REPO` | Yes* | Target dataset repo for signup writes (e.g. `org/name`). |
58
+ | `HF_DATASET_WRITE_TOKEN` | Yes* | Write-scoped Hub token for that dataset — Space **Secret** only; least privilege. |
59
+ | `APP_URL` | Recommended | Public Space URL used for OAuth redirects (e.g. `https://humanitys-last-hackathon-signup.hf.space`). |
60
+ | `HF_HUB_URL` | Optional | Hub base URL; defaults to `https://huggingface.co`. |
61
+ | `NODE_ENV` | Set by Docker | `production` in the Space image. |
62
+
63
+ \*Required when using the full HF OAuth + dataset write path. If the live page only deep-links to HF registration, some OAuth vars may be unused — verify against current `page.tsx` / API routes before rotating.
64
+
65
+ ### Operator checks
66
+
67
+ 1. Secrets exist in the Space UI (not in the repo).
68
+ 2. `SESSION_SECRET` is unique to this Space and not reused elsewhere.
69
+ 3. `HF_DATASET_WRITE_TOKEN` is scoped to the signup dataset only; rotate after staff changes.
70
+ 4. OAuth redirect URI in the HF OAuth app matches `APP_URL` + the callback route under `/api/auth/huggingface/callback`.