# Local development config. The REAL Cloudflare resource IDs for the deployed # instance live in the private projektor-workspace repo's wrangler.toml - never # commit real account/database/KV IDs here. Local dev (`wrangler dev` + `--local` # migrations) uses Miniflare and does not need real IDs, so placeholders are fine. name = "projektor-api" main = "src/index.ts" compatibility_date = "2024-09-23" compatibility_flags = [ "nodejs_compat", # PROJ-656: required by @cloudflare/workers-oauth-provider for Client ID Metadata # Documents. `global_fetch_strictly_public` stops the outbound CIMD fetch using # legacy same-zone origin routing (SSRF protection); `cache_option_enabled` allows # the `cache` option that fetch uses, which would otherwise need a compatibility # date of 2024-11-11 or later. Both must be present or the # `client_id_metadata_document_supported: true` we advertise in # /.well-known/oauth-authorization-server is a lie. "global_fetch_strictly_public", "cache_option_enabled", ] account_id = "REPLACE_WITH_YOUR_CLOUDFLARE_ACCOUNT_ID" [dev] port = 8787 # PROJ-496: daily sweep for the 30-day wiki trash purge (see `scheduled` in src/index.ts). # Cron expressions are UTC; 03:00 UTC is off-peak for all deployed regions so far. [triggers] crons = ["0 3 * * *"] [[d1_databases]] binding = "DB" database_name = "projektor" database_id = "REPLACE_WITH_YOUR_D1_DATABASE_ID" migrations_dir = "../../packages/db/migrations" [[kv_namespaces]] binding = "KV" id = "REPLACE_WITH_YOUR_KV_NAMESPACE_ID" [[kv_namespaces]] # PROJ-656/657: OAuth grants, authorization codes and access/refresh tokens. The # binding name is fixed by the library, which reads env.OAUTH_KV directly. Separate # from KV so a namespace wipe of one cache never silently signs everyone out. binding = "OAUTH_KV" id = "REPLACE_WITH_YOUR_OAUTH_KV_NAMESPACE_ID" [[r2_buckets]] binding = "R2" bucket_name = "projektor-files" # [[durable_objects.bindings]] # name = "WORKSPACE_HUB" # class_name = "WorkspaceHub" # # Always keep this migration, even with the binding above commented out: the class # ships in every build, and wrangler only applies migrations after the last deployed # tag, so adding "v1" later (after "v2") would never create WorkspaceHub. [[migrations]] tag = "v1" new_sqlite_classes = ["WorkspaceHub"] # PROJ-867 rate limiter (required): request rate-limit counters, one Durable Object # per key, kept in memory (no storage writes). SQLite-backed, so it works on the # Workers Free plan. Keep this migration AFTER the WorkspaceHub "v1" above: # wrangler applies migration tags in file order. Without this binding projektor falls # back to the deprecated D1 limiter (a D1 write on every request) and logs a warning; # that fallback is removed in a later release (PROJ-924). [[durable_objects.bindings]] name = "RATE_LIMITER" class_name = "RateLimiter" [[migrations]] tag = "v2" new_sqlite_classes = ["RateLimiter"] [vars] ENVIRONMENT = "development" CF_ACCESS_TEAM_DOMAIN = "" CF_ACCESS_AUDIENCE = "" # Login provisioning (services/provisioning.ts). ADMIN_EMAILS should include your # DEV_USER_EMAIL so the first local login auto-creates the default workspace as owner. ADMIN_EMAILS = "admin@projektor.dev" DEFAULT_WORKSPACE_SLUG = "projektor" DEFAULT_WORKSPACE_NAME = "Projektor" AUTO_JOIN_ROLE = "viewer" # Secrets (set via: wrangler secret put ): # JWT_SECRET # CF_ACCESS_TEAM_DOMAIN (override here or via secret) # CF_ACCESS_AUDIENCE (override here or via secret) # DEV_USER_EMAIL (local dev only) # BOOTSTRAP_SECRET (local dev only - required to use GET /bootstrap; if unset, the endpoint is disabled)