# Copy to .env.local and fill in real values. See FRONTEND_GUIDE.md for what # each of these means; .env.local itself is gitignored, never commit real # secrets here. # Winofy backend (this Django/DRF app) WINOFY_API_BASE_URL=https://winofy-staging.winsoo.ir/api # Gooyal accounts (OAuth2 resource owner password/OTP grant). # The browser calls Gooyal directly (its CORS is open), so these are also # exposed client-side via the NEXT_PUBLIC_ copies below — the client_secret # is intentionally public here, see .env.local's original comment for why. GOOYAL_ACCOUNTS_BASE_URL=https://accounts-staging.gooyal.ir GOOYAL_CLIENT_ID= GOOYAL_CLIENT_SECRET= GOOYAL_OAUTH_SCOPE="accounts.account:change_password accounts.account:update accounts.account:retrieve wallet.wallet:get_balance wallet.user:transaction_list data_crud.data:retrieve data_crud.data:update data_crud.data:delete notifications.push:get_client_token accounts.profile:list" NEXT_PUBLIC_GOOYAL_ACCOUNTS_BASE_URL=https://accounts-staging.gooyal.ir NEXT_PUBLIC_GOOYAL_CLIENT_ID= NEXT_PUBLIC_GOOYAL_CLIENT_SECRET= NEXT_PUBLIC_GOOYAL_OAUTH_SCOPE="accounts.account:change_password accounts.account:update accounts.account:retrieve wallet.wallet:get_balance wallet.user:transaction_list data_crud.data:retrieve data_crud.data:update data_crud.data:delete notifications.push:get_client_token accounts.profile:list" # Session cookie encryption — generate with: openssl rand -base64 32 SESSION_SECRET=