towerops/config/dev.exs
Graham McIntire ca7bb75472 fix: 11 critical security/correctness bugs from code audit
- C1: Replace innerHTML template literals with DOM textContent in sites_map.ts
- C2: Derive user_id from current_scope instead of client params in policy consent
- C3: Fix broken halt() in GDPR data export (orphaned _ = ... halt())
- C4: Add owner/admin authorization check to MembersController update/delete
- C5: Require HMAC signature on agent release webhook (was optional)
- C6: Fix Repo.all_by/2 (not a real Ecto function) → Repo.all with query
- C7: Move auth exemption to before_send callback in BruteForceProtection
- C8: Block </style>/<script injection in status page custom_css validation
- C9: Create secrets.example.yaml with placeholders; secrets.yaml already gitignored
- C10: Load Stripe key from STRIPE_SECRET_KEY env var instead of hardcoded value
- C13: Remove credentials from PubSub backup broadcast; channel resolves them

C11 (no force_ssl): by design — Cloudflared terminates TLS
C12 (device quota race): false positive — FOR UPDATE serializes correctly
2026-05-12 10:20:52 -05:00

245 lines
8.7 KiB
Elixir

import Config
# Console backend configuration
config :logger, :console,
format: "[$level] $message\n",
metadata: []
# File backend configuration (writes to log/dev.log)
# Backend is registered in application.ex via LoggerBackends.add/1
config :logger, :file_log,
path: "log/dev.log",
level: :info,
format: "[$level] $message\n",
metadata: []
# Logger configuration
config :logger,
level: :info
# Configure file system watcher to ignore directories that don't need watching
# This prevents "too many open files" errors in development
config :phoenix, :code_reloader,
ignore: [
~r"deps/",
~r"_build/",
~r"node_modules/",
~r"assets/node_modules/",
~r"\.git/",
~r"priv/static/",
~r"priv/mibs/",
~r"e2e/",
~r"test/",
~r"cover/",
~r"doc/"
]
# Initialize plugs at runtime for faster development compilation
config :phoenix, :plug_init_mode, :runtime
# Set a higher stacktrace during development. Avoid configuring such
# in production as building large stacktraces may be expensive.
config :phoenix, :stacktrace_depth, 20
config :phoenix_live_view,
# Include debug annotations and locations in rendered markup.
# Changing this configuration will require mix clean and a full recompile.
debug_heex_annotations: true,
debug_attributes: true,
# Enable helpful, but potentially expensive runtime checks
enable_expensive_runtime_checks: true
# Disable swoosh api client as it is only required for production adapters.
config :swoosh, :api_client, false
# Configure Oban for background jobs
config :towerops, Oban,
repo: Towerops.Repo,
queues: [
default: 10,
discovery: 10,
# SNMP polling jobs - one per device
pollers: 50,
# Device monitoring jobs - health checks
monitors: 50,
# Alert notifications (PagerDuty, email, etc.)
notifications: 10,
maintenance: 5,
weather: 2,
# RF coverage prediction (CPU + GDAL/HTTP-range I/O heavy, slow)
coverage: 2
],
plugins: [
# Cron jobs for periodic maintenance tasks
{Oban.Plugins.Cron,
crontab: [
# Run neighbor cleanup every hour
{"0 * * * *", Towerops.Snmp.NeighborCleanupWorker},
# Check for stale agents every minute
{"* * * * *", Towerops.Workers.StaleAgentWorker},
# Cloud latency probes every 8 hours (00:00, 08:00, 16:00)
{"0 */8 * * *", Towerops.Workers.CloudLatencyProbeWorker},
# Evaluate latency-based agent reassignment 30 min after each probe batch
{"30 0,8,16 * * *", Towerops.Workers.AgentLatencyEvaluator},
# Health check for missing jobs every 10 minutes
{"*/10 * * * *", Towerops.Workers.JobHealthCheckWorker},
# Fetch latest firmware versions daily at 2 AM
{"0 2 * * *", Towerops.Workers.FirmwareVersionFetcherWorker},
# MikroTik configuration backups daily at 7 AM UTC
{"0 7 * * *", Towerops.Workers.MikrotikBackupWorker},
# Mark stale backup requests as timeout every 10 minutes
{"*/10 * * * *", Towerops.Workers.BackupTimeoutWorker},
# Send backup summary email daily at 8 AM
{"0 8 * * *", Towerops.Workers.BackupSummaryWorker},
# Delete expired IP bans every hour
{"0 * * * *", Towerops.Workers.ExpiredBanCleanupWorker},
# Delete stale violation records daily at 2 AM
{"0 2 * * *", Towerops.Workers.StaleViolationCleanupWorker},
# Sync Preseem data every 10 minutes
{"*/10 * * * *", Towerops.Workers.PreseemSyncWorker},
# Compute Preseem baselines and fleet profiles nightly at 2:30 AM
{"30 2 * * *", Towerops.Workers.PreseemBaselineWorker},
# Sync Gaiia data every 15 minutes
{"*/15 * * * *", Towerops.Workers.GaiiaSyncWorker},
# Device health insights nightly at 3:30 AM
{"30 3 * * *", Towerops.Workers.DeviceHealthInsightWorker},
# System insights (agent offline detection) every 5 minutes
{"*/5 * * * *", Towerops.Workers.SystemInsightWorker},
# Gaiia reconciliation insights nightly at 4:30 AM
{"30 4 * * *", Towerops.Workers.GaiiaInsightWorker},
# Backhaul capacity utilization insights every 15 minutes
{"*/15 * * * *", Towerops.Workers.CapacityInsightWorker},
# Sync device usage to Stripe daily at 3 AM UTC
{"0 3 * * *", Towerops.Workers.BillingSyncWorker}
]},
# Automatically delete completed jobs after 60 seconds
{Oban.Plugins.Pruner, max_age: 60},
# Rescue orphaned jobs (when node crashes)
{Oban.Plugins.Reindexer, schedule: "0 2 * * *"},
# Rescue jobs stuck in executing state (mark as cancelled after 10 minutes)
{Oban.Plugins.Lifeline, rescue_after: to_timeout(minute: 10)}
]
# Configure your database
# Configure your database
# In CI, DATABASE_URL is set and will be used automatically by Ecto.
# Locally, fall back to individual connection parameters.
if database_url = System.get_env("DATABASE_URL") do
config :towerops, Towerops.Repo,
url: database_url,
stacktrace: true,
show_sensitive_data_on_connection_error: true,
pool_size: 10
else
config :towerops, Towerops.Repo,
username: "postgres",
password: "postgres",
hostname: "localhost",
database: "towerops_dev",
stacktrace: true,
show_sensitive_data_on_connection_error: true,
pool_size: 10
end
# Configure Cloak encryption for development
# Use a fixed key for development (DO NOT use in production!)
config :towerops, Towerops.Vault,
ciphers: [
default: {
Cloak.Ciphers.AES.GCM,
# Development-only key - replace with env var in production
tag: "AES.GCM.V1", key: Base.decode64!("nQWmgQYhoCNXA3PAxwriKxLyPHAOWH9VgpLkBOXrowM=")
}
]
# For development, we disable any cache and enable
# debugging and code reloading.
#
# The watchers configuration can be used to run external
# watchers to your application. For example, we can use it
# to bundle .js and .css sources.
config :towerops, ToweropsWeb.Endpoint,
# Binding to loopback ipv4 address prevents access from other machines.
# Change to `ip: {0, 0, 0, 0}` to allow access from other machines.
http: [ip: {127, 0, 0, 1}],
check_origin: false,
code_reloader: true,
debug_errors: true,
secret_key_base: "ZA80pnF0GDr5/cb3jn/mtGjJPjg+0J68+MkglRQMlZNbxWYLPOAMCcYo2/rajclz",
watchers: [
esbuild: {Esbuild, :install_and_run, [:towerops, ~w(--sourcemap=inline --watch)]},
tailwind: {Tailwind, :install_and_run, [:towerops, ~w(--watch)]}
]
# ## SSL Support
#
# In order to use HTTPS in development, a self-signed
# certificate can be generated by running the following
# Mix task:
#
# mix phx.gen.cert
#
# Run `mix help phx.gen.cert` for more information.
#
# The `http:` config above can be replaced with:
#
# https: [
# port: 4001,
# cipher_suite: :strong,
# keyfile: "priv/cert/selfsigned_key.pem",
# certfile: "priv/cert/selfsigned.pem"
# ],
#
# If desired, both `http:` and `https:` keys can be
# configured to run both http and https servers on
# different ports.
# Reload browser tabs when matching files change.
config :towerops, ToweropsWeb.Endpoint,
live_reload: [
web_console_logger: true,
patterns: [
# Static assets, except user uploads
~r"priv/static/(?!uploads/).*\.(js|css|png|jpeg|jpg|gif|svg)$",
# Gettext translations
~r"priv/gettext/.*\.po$",
# Router, Controllers, LiveViews and LiveComponents
~r"lib/towerops_web/router\.ex$",
~r"lib/towerops_web/(controllers|live|components)/.*\.(ex|heex)$"
]
]
# Webhook secret for CI-triggered agent updates
config :towerops, :agent_webhook_secret, "dev-webhook-secret"
# Set environment identifier for runtime checks
config :towerops, :env, :dev
# Configure SNMP MIB directories for development
# Point to local priv/mibs subdirectories where MIB files are stored
# Note: The root mibs/ directory only contains symlinks to LibreNMS repo
# SNMP MIB directories for development
# MibTranslator automatically expands these to include subdirectories
config :towerops, :mib_dirs, [
Path.join([File.cwd!(), "priv", "mibs"]),
"/usr/share/snmp/mibs"
]
# Disable rate limiting in development
config :towerops, :rate_limiting_enabled, false
# Redis is not configured in development - application will use stub Agent
# If you need Redis for local development, set REDIS_HOST env var
# Configure SNMP polling interval for development (60 seconds)
config :towerops, :snmp_min_poll_interval, 60
# Enable dev routes for dashboard and mailbox
config :towerops, dev_routes: true
# Stripe configuration for development
config :towerops,
stripe_secret_key: System.get_env("STRIPE_SECRET_KEY", "sk_test_use_your_own_key"),
stripe_webhook_secret: "whsec_dev_fake_secret",
stripe_price_id: "price_1T81XBS77kvnTfgyPlw1jF8N",
stripe_meter_id: "mtr_test_61UHPU067veEZ7bhl41S77kvnTfgyODY"