Replace the additive LINKEDIN_EXTRA_SCOPES approach with a single
full-override env var per flow, exploded into an array at the config
layer (config/trypost.php -> platforms.linkedin{,-page}.scopes). This
keeps env values as plain comma-separated strings, lets self-hosters
override the entire set in one place, and removes the controller-side
scope-merge logic.
- config/trypost.php: explode LINKEDIN_SCOPES / LINKEDIN_PAGE_SCOPES
into the scopes arrays (deprecated r_basicprofile stays out of the
personal default)
- LinkedInController: drop resolveScopes(), read config scopes directly
- LinkedInPageController: drop the hardcoded $scopes property, read
config scopes at both call sites
- tests: drive the connect scope assertions from config overrides
- .env.example, docker/.env.docker.example: document LINKEDIN_SCOPES
and LINKEDIN_PAGE_SCOPES
224 lines
5.8 KiB
Text
224 lines
5.8 KiB
Text
APP_NAME="TryPost"
|
||
APP_ENV=local
|
||
APP_KEY=
|
||
APP_DEBUG=true
|
||
APP_URL=http://localhost
|
||
|
||
# Self-hosted mode (skips payment requirements)
|
||
SELF_HOSTED=true
|
||
|
||
TELESCOPE_ENABLED=false
|
||
|
||
APP_LOCALE=en
|
||
APP_FALLBACK_LOCALE=en
|
||
APP_FAKER_LOCALE=en_US
|
||
|
||
APP_MAINTENANCE_DRIVER=file
|
||
|
||
BCRYPT_ROUNDS=12
|
||
|
||
LOG_CHANNEL=stack
|
||
LOG_STACK=single
|
||
LOG_DEPRECATIONS_CHANNEL=null
|
||
LOG_LEVEL=debug
|
||
|
||
# Database (PostgreSQL or MySQL)
|
||
# PostgreSQL: DB_CONNECTION=pgsql, DB_PORT=5432, DB_USERNAME=postgres
|
||
# MySQL: DB_CONNECTION=mysql, DB_PORT=3306, DB_USERNAME=root
|
||
DB_CONNECTION=pgsql
|
||
DB_HOST=127.0.0.1
|
||
DB_PORT=5432
|
||
DB_DATABASE=trypost
|
||
DB_USERNAME=postgres
|
||
DB_PASSWORD=
|
||
|
||
# Session
|
||
SESSION_DRIVER=database
|
||
SESSION_LIFETIME=1440
|
||
SESSION_ENCRYPT=false
|
||
SESSION_PATH=/
|
||
SESSION_DOMAIN=null
|
||
|
||
# Broadcasting, Queue, Cache
|
||
BROADCAST_CONNECTION=reverb
|
||
QUEUE_CONNECTION=redis
|
||
CACHE_STORE=redis
|
||
|
||
# File Storage
|
||
# Options: local, s3, r2 (or any S3-compatible: MinIO, DigitalOcean Spaces, etc.)
|
||
FILESYSTEM_DISK=local
|
||
|
||
# Redis
|
||
REDIS_HOST=127.0.0.1
|
||
REDIS_PASSWORD=null
|
||
REDIS_PORT=6379
|
||
|
||
# Mail
|
||
MAIL_MAILER=smtp
|
||
MAIL_HOST=127.0.0.1
|
||
MAIL_PORT=2525
|
||
MAIL_USERNAME=null
|
||
MAIL_PASSWORD=null
|
||
MAIL_ENCRYPTION=null
|
||
MAIL_FROM_ADDRESS="hello@example.com"
|
||
MAIL_FROM_NAME="${APP_NAME}"
|
||
|
||
# Reverb (WebSockets)
|
||
REVERB_APP_ID=1001
|
||
REVERB_APP_KEY=your-reverb-key
|
||
REVERB_APP_SECRET=your-reverb-secret
|
||
REVERB_HOST="localhost"
|
||
REVERB_PORT=8080
|
||
REVERB_SCHEME=http
|
||
|
||
# AWS S3 (set FILESYSTEM_DISK=s3)
|
||
AWS_ACCESS_KEY_ID=
|
||
AWS_SECRET_ACCESS_KEY=
|
||
AWS_DEFAULT_REGION=us-east-1
|
||
AWS_BUCKET=
|
||
AWS_URL=
|
||
|
||
# Cloudflare R2 (set FILESYSTEM_DISK=r2)
|
||
R2_ACCESS_KEY_ID=
|
||
R2_SECRET_ACCESS_KEY=
|
||
R2_ENDPOINT=
|
||
R2_REGION=auto
|
||
R2_BUCKET=
|
||
R2_URL=
|
||
|
||
# DigitalOcean Spaces (set FILESYSTEM_DISK=spaces)
|
||
SPACES_ACCESS_KEY_ID=
|
||
SPACES_SECRET_ACCESS_KEY=
|
||
SPACES_ENDPOINT=
|
||
SPACES_REGION=
|
||
SPACES_BUCKET=
|
||
|
||
# ============================================
|
||
# Social Platform Credentials
|
||
# ============================================
|
||
# Get your API keys from each platform's developer portal
|
||
|
||
# LinkedIn (https://developer.linkedin.com)
|
||
LINKEDIN_CLIENT_ID=
|
||
LINKEDIN_CLIENT_SECRET=
|
||
LINKEDIN_CLIENT_REDIRECT="${APP_URL}/accounts/linkedin/callback"
|
||
LINKEDIN_PAGE_CLIENT_REDIRECT="${APP_URL}/accounts/linkedin-page/callback"
|
||
# Optional: comma-separated OAuth scopes for each LinkedIn connect flow.
|
||
# Override these only if your LinkedIn dev app has legacy/enterprise products
|
||
# approved — e.g. add `r_basicprofile` to the personal set to re-enable the
|
||
# vanityName lookup via /v2/me. Leave unset to use the safe defaults.
|
||
# LINKEDIN_SCOPES="openid,profile,email,w_member_social"
|
||
# LINKEDIN_PAGE_SCOPES="openid,profile,email,w_organization_social,r_organization_social,rw_organization_admin,w_member_social"
|
||
|
||
# X / Twitter (https://developer.twitter.com)
|
||
X_CLIENT_ID=
|
||
X_CLIENT_SECRET=
|
||
X_CLIENT_REDIRECT="${APP_URL}/accounts/x/callback"
|
||
|
||
# TikTok (https://developers.tiktok.com)
|
||
TIKTOK_CLIENT_ID=
|
||
TIKTOK_CLIENT_SECRET=
|
||
TIKTOK_CLIENT_REDIRECT="${APP_URL}/accounts/tiktok/callback"
|
||
|
||
# Facebook (https://developers.facebook.com)
|
||
FACEBOOK_CLIENT_ID=
|
||
FACEBOOK_CLIENT_SECRET=
|
||
FACEBOOK_CLIENT_REDIRECT="${APP_URL}/accounts/facebook/callback"
|
||
|
||
# Instagram (https://developers.facebook.com)
|
||
INSTAGRAM_CLIENT_ID=
|
||
INSTAGRAM_CLIENT_SECRET=
|
||
INSTAGRAM_CLIENT_REDIRECT="${APP_URL}/accounts/instagram/callback"
|
||
|
||
# Threads (https://developers.facebook.com)
|
||
THREADS_CLIENT_ID=
|
||
THREADS_CLIENT_SECRET=
|
||
THREADS_CLIENT_REDIRECT="${APP_URL}/accounts/threads/callback"
|
||
|
||
# Google (https://console.cloud.google.com)
|
||
# Used for YouTube social account connection AND Google login/signup
|
||
GOOGLE_AUTH_ENABLED=false
|
||
GOOGLE_CLIENT_ID=
|
||
GOOGLE_CLIENT_SECRET=
|
||
GOOGLE_CLIENT_REDIRECT="${APP_URL}/accounts/youtube/callback"
|
||
GOOGLE_AUTH_CALLBACK="${APP_URL}/auth/google/callback"
|
||
|
||
# GitHub (https://github.com/settings/developers)
|
||
# Used for GitHub login/signup
|
||
GITHUB_AUTH_ENABLED=false
|
||
GITHUB_CLIENT_ID=
|
||
GITHUB_CLIENT_SECRET=
|
||
GITHUB_AUTH_CALLBACK="${APP_URL}/auth/github/callback"
|
||
|
||
# Pinterest (https://developers.pinterest.com)
|
||
PINTEREST_CLIENT_ID=
|
||
PINTEREST_CLIENT_SECRET=
|
||
PINTEREST_CLIENT_REDIRECT="${APP_URL}/accounts/pinterest/callback"
|
||
|
||
# AI Services
|
||
OPENAI_API_KEY=
|
||
ANTHROPIC_API_KEY=
|
||
GEMINI_API_KEY=
|
||
ELEVENLABS_API_KEY=
|
||
|
||
# AI Provider Selection
|
||
# text: openai | anthropic | gemini | xai | groq | mistral | deepseek | ...
|
||
# image: openai | gemini | xai
|
||
# audio: openai | elevenlabs
|
||
AI_TEXT_PROVIDER=openai
|
||
AI_TEXT_MODEL=gpt-5.4
|
||
AI_IMAGE_PROVIDER=openai
|
||
AI_AUDIO_PROVIDER=elevenlabs
|
||
|
||
# ============================================
|
||
# Stripe (Cashier — billing)
|
||
# ============================================
|
||
# Required when SELF_HOSTED=false. Get keys at https://dashboard.stripe.com/apikeys
|
||
STRIPE_KEY=
|
||
STRIPE_SECRET=
|
||
STRIPE_WEBHOOK_SECRET=
|
||
# Set to false to allow generic signup trial without requiring a card.
|
||
REQUIRE_CARD_FOR_TRIAL=true
|
||
|
||
# Stripe Plan Price IDs (one per plan × interval). Used by PlanSeeder.
|
||
STRIPE_STARTER_MONTHLY=
|
||
STRIPE_STARTER_YEARLY=
|
||
STRIPE_PLUS_MONTHLY=
|
||
STRIPE_PLUS_YEARLY=
|
||
STRIPE_PRO_MONTHLY=
|
||
STRIPE_PRO_YEARLY=
|
||
STRIPE_MAX_MONTHLY=
|
||
STRIPE_MAX_YEARLY=
|
||
|
||
# Laravel Nightwatch (production telemetry — disabled by default in dev)
|
||
NIGHTWATCH_ENABLED=false
|
||
NIGHTWATCH_TOKEN=
|
||
|
||
# Platform feature flags (all default to true; set to false to hide a platform)
|
||
# TIKTOK_ENABLED=true
|
||
# PINTEREST_ENABLED=true
|
||
# MASTODON_ENABLED=true
|
||
# BLUESKY_ENABLED=true
|
||
|
||
# Media Services
|
||
UNSPLASH_ACCESS_KEY=
|
||
UNSPLASH_SECRET_KEY=
|
||
GIPHY_API_KEY=
|
||
|
||
# Google Tag Manager (optional - analytics)
|
||
GTM_ID=
|
||
|
||
# PostHog (optional - analytics; off by default, self-hosted installs can ignore)
|
||
POSTHOG_ENABLED=false
|
||
POSTHOG_API_KEY=
|
||
POSTHOG_HOST=https://us.i.posthog.com
|
||
|
||
# Vite
|
||
VITE_APP_NAME="${APP_NAME}"
|
||
VITE_REVERB_APP_KEY="${REVERB_APP_KEY}"
|
||
VITE_REVERB_HOST="${REVERB_HOST}"
|
||
VITE_REVERB_PORT="${REVERB_PORT}"
|
||
VITE_REVERB_SCHEME="${REVERB_SCHEME}"
|
||
VITE_POSTHOG_ENABLED="${POSTHOG_ENABLED}"
|
||
VITE_POSTHOG_API_KEY="${POSTHOG_API_KEY}"
|
||
VITE_POSTHOG_HOST="${POSTHOG_HOST}"
|