name = "melody-auth" compatibility_date = "2025-01-01" keep_vars = true # Cloudflare account id, required if your cloudflare account is sharing access with other cloudflare accounts # account_id = "" # Enable this if you want to use workers with postgres database # compatibility_flags = [ "nodejs_compat" ] [vars] # Information COMPANY_LOGO_URL="https://valuemelody.com/logo.svg" COMPANY_EMAIL_LOGO_URL="https://valuemelody.com/logo.jpg" # be aware that svg format might not be supported in some email clients EMAIL_SENDER_NAME="Melody Auth" TERMS_LINK="" # Display a link to your terms on sign-up page PRIVACY_POLICY_LINK="" # Display a link to your privacy policy on sign-up page # System SUPPORTED_LOCALES=['en', 'fr'] # There is built-in support for zh as well ENABLE_LOCALE_SELECTOR=true # If there is only one SUPPORTED_LOCALE, the locale selector will be disabled regardless of this setting. # EMAIL_PROVIDER_NAME="" # The name of your email provider. Available options are 'smtp', 'sendgrid', 'mailgun', 'brevo', 'resend', 'postmark' # Suppression ENABLE_SIGN_UP=true ENABLE_PASSWORD_SIGN_IN=true ENABLE_PASSWORD_RESET=true # Please set up your mailer first https://auth.valuemelody.com/email-provider-setup.html ENABLE_NAMES=true NAMES_IS_REQUIRED=false ENABLE_USER_APP_CONSENT=true ENABLE_EMAIL_VERIFICATION=true # Please set up your mailer first https://auth.valuemelody.com/email-provider-setup.html. If true, on user sign-up, the email verification email will be sent. REPLACE_EMAIL_VERIFICATION_WITH_WELCOME_EMAIL=false # If both ENABLE_EMAIL_VERIFICATION and REPLACE_EMAIL_VERIFICATION_WITH_WELCOME_EMAIL are true, on user sign-up, the welcome email will be sent instead of the email verification email. ENABLE_ORG=false ALLOW_USER_SWITCH_ORG_ON_SIGN_IN=false ENABLE_USER_ATTRIBUTE=false BLOCKED_POLICIES=["change_org"] # A list of policy names that should be blocked (change_password, change_email, reset_mfa, manage_passkey, update_info, change_org), preventing end users from triggering them ENABLE_PASSWORDLESS_SIGN_IN=false # Please set up your mailer first https://auth.valuemelody.com/email-provider-setup.html. Setting this option to true will automatically override ENABLE_SIGN_UP, ENABLE_PASSWORD_SIGN_IN, ENABLE_PASSWORD_RESET, ALLOW_PASSKEY_ENROLLMENT, ENABLE_RECOVERY_CODE to false. Also, make sure to disable email MFA in order to use this feature. # USE_PASSWORDLESS_AS_MAGIC_LINK=false # If true and ENABLE_PASSWORDLESS_SIGN_IN is true, the passwordless sign-in email will contain a magic link. Clicking the link will automatically sign the user in without requiring them to manually enter the OTP code. EMBEDDED_AUTH_ORIGINS=[] # List of origins that are allowed to use embedded auth APIs. ENABLE_SAML_SSO_AS_SP=false # Experimental feature, only support in Node.js environment ENABLE_APP_BANNER=false # Enable the feature for displaying banners on the sign-in page of apps # Auth AUTHORIZATION_CODE_EXPIRES_IN=300 SPA_ACCESS_TOKEN_EXPIRES_IN=1800 SPA_REFRESH_TOKEN_EXPIRES_IN=604800 S2S_ACCESS_TOKEN_EXPIRES_IN=3600 ID_TOKEN_EXPIRES_IN=1800 SERVER_SESSION_EXPIRES_IN=1800 # Set to 0 to disable session # MFA OTP_MFA_IS_REQUIRED=false EMAIL_MFA_IS_REQUIRED=false # Please set up your mailer first https://auth.valuemelody.com/email-provider-setup.html SMS_MFA_IS_REQUIRED=false # Please set up your sms provider first https://auth.valuemelody.com/sms-provider-setup.html ENFORCE_ONE_MFA_ENROLLMENT=['otp', 'email'] # Enforce one MFA type from the list. Available options are ‘email’, ‘otp’, and ‘sms’. This setting is only effective if OTP_MFA_IS_REQUIRED, SMS_MFA_IS_REQUIRED, and EMAIL_MFA_IS_REQUIRED are all set to false. An empty list means no MFA type will be enforced. You must enable email functionality for the email MFA option to work. ALLOW_EMAIL_MFA_AS_BACKUP=true ALLOW_PASSKEY_ENROLLMENT=false ENABLE_RECOVERY_CODE=false ENABLE_MFA_REMEMBER_DEVICE=false # If true, the user can bypass MFA by remembering the device for 30 days. # Brute-force UNLOCK_ACCOUNT_VIA_PASSWORD_RESET=true PASSWORD_RESET_EMAIL_THRESHOLD=5 # Maximum number of password reset email requests allowed per day for a single email address based on ip address. 0 means no restriction. PASSWORD_RESET_CODE_THRESHOLD=5 # Number of failed password reset code verification attempts before further attempts are temporarily locked for the user/IP. 0 means no restriction. ACCOUNT_LOCKOUT_THRESHOLD=5 # Number of failed login attempts before the user account is locked. 0 means no restriction. EMAIL_MFA_EMAIL_THRESHOLD=10 # Maximum number of Email MFA email requests allowed per 30 minutes for a single account based on ip address. 0 means no restriction. CHANGE_EMAIL_EMAIL_THRESHOLD=5 # Maximum number of change email verification code requests allowed per 30 minutes for a single account. 0 means no restriction. CHANGE_EMAIL_CODE_THRESHOLD=5 # Number of failed change email code verification attempts before further attempts are temporarily locked for the user/IP. 0 means no restriction. EMAIL_VERIFICATION_CODE_THRESHOLD=5 # Number of failed email verification code attempts before further attempts are temporarily locked for the user/IP for 30 minutes. 0 means no restriction. ACCOUNT_LOCKOUT_EXPIRES_IN=86400 # Set to 0 for indefinite lockout until manual intervention. SMS_MFA_MESSAGE_THRESHOLD=5 # Maximum number of SMS MFA message requests allowed per 30 minutes for a single account based on ip address. 0 means no restriction. MFA_CODE_VERIFY_THRESHOLD=10 # Number of failed MFA code verification attempts (email/sms/otp/passwordless combined) before further attempts are temporarily locked for the user/IP for 30 minutes. 0 means no restriction. # AUTH_CODE_VERIFIER_THRESHOLD=5 # Number of failed auth code exchange attempts with an invalid code_verifier before further attempts are temporarily locked for the user/IP for 30 minutes. 0 or unset means no restriction. Unknown auth codes are not counted. # Social Sign-in # GOOGLE_AUTH_CLIENT_ID="" # Google Sign-in will be suppressed if it is empty # FACEBOOK_AUTH_CLIENT_ID="" # Facebook Sign-in In will be suppressed if it is empty. When enable, you also need to set FACEBOOK_AUTH_CLIENT_SECRET in .dev.vars for Cloudflare development and Node environments, and in workers config for Cloudflare production environments. # GITHUB_AUTH_CLIENT_ID="" # GitHub Sign-in In will be suppressed if it is empty. When enable, you also need to set GITHUB_AUTH_CLIENT_SECRET in .dev.vars for Cloudflare development and Node environments, and in workers config for Cloudflare production environments. # GITHUB_AUTH_APP_NAME="" # GitHub Sign-in In will be suppressed if it is empty. When enable, you also need to set GITHUB_AUTH_CLIENT_SECRET in .dev.vars for Cloudflare development and Node environments, and in workers config for Cloudflare production environments. # DISCORD_AUTH_CLIENT_ID="" # Discord Sign-in In will be suppressed if it is empty. When enable, you also need to set DISCORD_AUTH_CLIENT_SECRET in .dev.vars for Cloudflare development and Node environments, and in workers config for Cloudflare production environments. # APPLE_AUTH_CLIENT_ID="" # Apple Sign-in In will be suppressed if it is empty. When enable, you also need to set APPLE_AUTH_CLIENT_SECRET in .dev.vars for Cloudflare development and Node environments, and in workers config for Cloudflare production environments. # OIDC_AUTH_PROVIDERS=[] # List of OIDC authentication providers for users to sign in with. Once a provider's name is set, it should remain unchanged. The provider must supports standard OAuth 2.0 IdToken exchange with PKCE and JWKS endpoint. Example: ['Auth0', 'Azure']. You must set the configurations for each of your OIDC_AUTH_PROVIDERS in src/configs/variable.ts file accordingly. # Log LOG_LEVEL="silent" # Set the log level to silent, info, warn, or error. If environment is set to dev, the log level always defaults to info, regardless of this value. ENABLE_EMAIL_LOG=false # Specify whether email should be logged. If enabled, ensure that you implement your own email log cleanup scheduler. ENABLE_SMS_LOG=false # Specify whether SMS should be logged. If enabled, ensure that you implement your own SMS log cleanup scheduler ENABLE_SIGN_IN_LOG=false # Specify whether the user’s sign-in IP (only applicable in production environments) and location details (only applicable in Cloudflare environments) should be logged. If enabled, ensure that you implement your own sign-in log cleanup scheduler, clearly disclose the collection of IP and location data in your privacy policy, and comply with all relevant legal requirements. [[kv_namespaces]] binding = "KV" id = "7d9be060a7bc48919251b37caa7e1fcd" # Replace with your own KV ID [[d1_databases]] binding = "DB" database_name = "melody-auth" database_id = "8dc67df2-771d-4e73-9c16-d04341b9740e" # Replace with your own D1 ID migrations_dir = "./migrations/sqlite" [assets] directory = "./dist/static" [observability] enabled = false # Set to true to enable Cloudflare workers logs. https://developers.cloudflare.com/workers/observability/logs/workers-logs/