docs(self-hosting): own-credentials section, stale connector lines, complete .env.example (#2146)
* docs(self-hosting): own-credentials section, stale connector lines, complete .env.example (#2131) SELF-HOSTING.md said the Skatteverket client wiring "ships in a following release"; PR #2103 merged it, so both bank sync and Skatteverket now carry traffic through the hosted proxy with a key. The two stale sentences are replaced and SOVEREIGN.md line 48 says the same thing. New "Own credentials (no connector key)" subsection documents the path an operator takes without a key: Enable Banking app in restricted production mode with the callback URL, the Skatteverket developer-portal application with the redirect URI, every variable the code reads, the five production base URLs (all defaults point at the test environment), the kill switch, and the rule that any own credential switches that upstream out of connector mode. .env.example gains the Skatteverket block, the optional Enable Banking variables, and RESEND_INBOUND_DOMAIN / RESEND_INBOUND_WEBHOOK_SECRET, which the invoice-inbox manifest requires but the example never listed. DOCKER.md no longer claims Enable Banking is excluded from the self-host preset (docker/extensions.self-hosted.json ships it). ENABLE_BANKING_SANDBOX is removed from the enable-banking manifest and the index.ts header: declared as optional, never read anywhere; the sandbox is selected by ENABLE_BANKING_API_URL. Logged in DECISIONS.md. Closes #2131 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012C6M2ZoZc6QDRxU3m9WzgE Signed-off-by: Emil <emilmattsson14@gmail.com> * docs(self-hosting): correct key format, AISP scope caveat, SKV scopes and rotation note (#2131) Skeptic findings on PR #2146, one pass: - ENABLE_BANKING_PRIVATE_KEY: the decoder base64-decodes first and wraps anything else as DER, so a raw PEM fails at JWT signing. The docs and .env.example no longer claim it is accepted. - Enable Banking restricted mode covers the operator's own accounts only; an instance hosting client companies is doing licensed AIS and needs the connector key or its own AISP registration. Said so. - Listed the OAuth scopes the app requests (both AGI scopes), noted that the kill switch gates API calls, not the BankID login, and that the token encryption key has no dual-key rotation. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012C6M2ZoZc6QDRxU3m9WzgE Signed-off-by: Emil <emilmattsson14@gmail.com> --------- Signed-off-by: Emil <emilmattsson14@gmail.com> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5.1
parent
97107398c0
commit
d8cf78330e
+28
-2
@@ -116,6 +116,8 @@ RECEIPT_HUNT_COMPANY_IDS=
|
||||
# EMAIL_PROVIDER=resend|smtp # optional; RESEND_API_KEY wins, else SMTP_HOST
|
||||
# RESEND_API_KEY=
|
||||
# RESEND_FROM_EMAIL=
|
||||
# RESEND_INBOUND_DOMAIN= # invoice-inbox extension: per-company inbox addresses are {local-part}@{this domain}
|
||||
# RESEND_INBOUND_WEBHOOK_SECRET= # invoice-inbox extension: verifies the Resend inbound webhook signature
|
||||
# SMTP_HOST=
|
||||
# SMTP_PORT=587
|
||||
# SMTP_SECURE=false # true = implicit TLS on 465, false = STARTTLS required (set SMTP_REQUIRE_TLS=false only for a plaintext LAN relay)
|
||||
@@ -124,9 +126,33 @@ RECEIPT_HUNT_COMPANY_IDS=
|
||||
# SMTP_FROM_EMAIL=
|
||||
# SMTP_REQUIRE_TLS=true # false only for a plaintext relay on a trusted LAN
|
||||
# SMTP_TLS_REJECT_UNAUTHORIZED=true
|
||||
# Bank connections (Enable Banking)
|
||||
# Bank connections (Enable Banking), own credentials. Set APP_ID and PRIVATE_KEY
|
||||
# as a pair: any one of them (or a _PRODUCTION variant) switches the bank
|
||||
# upstream out of connector mode. Leave all unset to route bank sync through
|
||||
# GNUBOK_CONNECTOR_KEY. See docs/SELF-HOSTING.md, "Own credentials".
|
||||
# ENABLE_BANKING_APP_ID=
|
||||
# ENABLE_BANKING_PRIVATE_KEY=
|
||||
# ENABLE_BANKING_PRIVATE_KEY= # base64-encoded PEM (bare base64 DER also works; raw PEM does not)
|
||||
# ENABLE_BANKING_API_URL=https://api.enablebanking.com # default; api.tilisy.com = sandbox
|
||||
# ENABLE_BANKING_PSU_TYPE=business
|
||||
# Skatteverket API (VAT/AGI submission, skattekonto), own credentials. Setting
|
||||
# either client id switches the upstream out of connector mode. Every base URL
|
||||
# defaults to Skatteverket's TEST environment (test BankID only): set all five
|
||||
# for production. SKATTEVERKET_ENABLED and the encryption key are needed in
|
||||
# connector mode too. SKATTEVERKET_SYSTEM_* and SKATTEVERKET_OMBUD_ORG_NUMBER
|
||||
# are hosted-only. See docs/SELF-HOSTING.md, "Own credentials".
|
||||
# SKATTEVERKET_ENABLED=true
|
||||
# SKATTEVERKET_OAUTH2_CLIENT_ID=
|
||||
# SKATTEVERKET_OAUTH2_CLIENT_SECRET=
|
||||
# SKATTEVERKET_APIGW_CLIENT_ID=
|
||||
# SKATTEVERKET_APIGW_CLIENT_SECRET=
|
||||
# SKATTEVERKET_TOKEN_ENCRYPTION_KEY= # openssl rand -base64 32; rotating it forces every user to reconnect
|
||||
# SKATTEVERKET_ENV=production # test | production; defaults to test
|
||||
# SKATTEVERKET_OAUTH_BASE_URL=https://peroauth2.skatteverket.se/oauth2/v1/per
|
||||
# SKATTEVERKET_API_BASE_URL=https://api.skatteverket.se/momsdeklaration/v1
|
||||
# SKATTEVERKET_AGD_INLAMNING_API_BASE_URL=https://api.skatteverket.se/arbetsgivardeklaration/inlamning/v1
|
||||
# SKATTEVERKET_AGD_PERIOD_API_BASE_URL=https://api.skatteverket.se/arbetsgivardeklaration/hanteraredovisningsperiod/v1
|
||||
# SKATTEVERKET_SKATTEKONTO_API_BASE_URL=https://api.skatteverket.se/beskattning/skattekonto/v2
|
||||
# SKATTEVERKET_DISABLED=true # emergency kill switch
|
||||
# Peppol e-invoicing via Qvalia (certified Access Point + SMP, partner model).
|
||||
# The adapter registers itself when QVALIA_API_KEY, QVALIA_PARTNER_REG_NO and
|
||||
# QVALIA_BASE_URL are all set; PEPPOL_TRANSPORT_PROVIDER=qvalia switches it on
|
||||
|
||||
Reference in New Issue
Block a user