Adds three new environment variables that give instance operators control
over Apprise notification services, addressing GDPR and compliance concerns
around third-party data transfers.
## New environment variables
- APPRISE_ENABLED (default: true)
Set to "false" to globally prevent users from creating Apprise notification
services and to silently skip sending any Apprise notifications. Existing
services in the database are preserved but not used while disabled.
- APPRISE_ALLOWED_SCHEMAS (default: empty — no restriction)
Comma-separated allowlist of Apprise URL schemas (e.g. "slack,tgram").
When set, only services whose URL schema appears in this list can be
created or will be sent. Takes priority over APPRISE_BLOCKED_SCHEMAS.
Uses Apprise's internal schema names (e.g. "tgram" for Telegram).
- APPRISE_BLOCKED_SCHEMAS (default: empty — built-in list applies)
Comma-separated blocklist of Apprise URL schemas (e.g. "discord,slack").
When set, replaces the built-in blocked list entirely. When empty, the
built-in list (syslog, dbus, kde, qt, glib, gnome, macosx, windows)
continues to apply as a fallback.
## Enforcement
Validation happens at two layers:
1. API layer (create endpoints for user and board notification services)
Returns HTTP 403 when Apprise is disabled, HTTP 422 when the URL schema
is not permitted. This gives users immediate feedback in the UI.
2. Python send layer (send_notifications.py)
The schema config is passed as a JSON argument so the same allow/block
rules apply at send time, guarding against services that were created
before the config was tightened.
## Files changed
- server/config/custom.js — parse new env vars via existing envToArray helper
- server/utils/send_notifications.py — accept schemaConfig as argv[4]; replace
hard-coded BLOCKED_SCHEMAS_SET with dynamic allowed/blocked resolution
- server/api/helpers/utils/send-notifications.js — short-circuit when disabled;
pass schemaConfig JSON to the Python script
- server/api/helpers/notification-services/create-one-in-{user,board}.js — add
appriseDisabled and schemaNotAllowed exits with schema validation logic
- server/api/controllers/notification-services/create-in-{user,board}.js — wire
new exits to forbidden (403) and unprocessableEntity (422) responses
- server/.env.sample — document all three new variables with comments
102 lines
3.2 KiB
Bash
102 lines
3.2 KiB
Bash
## Required
|
|
|
|
BASE_URL=http://localhost:1337
|
|
DATABASE_URL=postgresql://postgres@localhost/planka
|
|
SECRET_KEY=notsecretkey
|
|
|
|
## Optional
|
|
|
|
# LOG_LEVEL=warn
|
|
# LOG_FILE=
|
|
|
|
# TRUST_PROXY=true
|
|
# MAX_UPLOAD_FILE_SIZE=
|
|
# TOKEN_EXPIRES_IN=365 # In days
|
|
|
|
# STORAGE_LIMIT=
|
|
# ACTIVE_USERS_LIMIT=
|
|
|
|
# related: https://github.com/knex/knex/issues/2354
|
|
# As knex does not pass query parameters from the connection string,
|
|
# we have to use environment variables in order to pass the desired values, e.g.
|
|
# PGSSLMODE=<value>
|
|
|
|
# Configure knex to accept SSL certificates
|
|
# KNEX_REJECT_UNAUTHORIZED_SSL_CERTIFICATE=false
|
|
|
|
# The default application language used as a fallback when a user's language is not set.
|
|
# This language is also used for per-board notifications.
|
|
# DEFAULT_LANGUAGE=en-US
|
|
|
|
# Do not comment out DEFAULT_ADMIN_EMAIL if you want to prevent this user from being edited/deleted
|
|
# DEFAULT_ADMIN_EMAIL=demo@demo.demo
|
|
# DEFAULT_ADMIN_PASSWORD=demo
|
|
# DEFAULT_ADMIN_NAME=Demo Demo
|
|
# DEFAULT_ADMIN_USERNAME=demo
|
|
|
|
# Set to true to show more detailed authentication error messages.
|
|
# It should not be enabled without a rate limiter for security reasons.
|
|
# SHOW_DETAILED_AUTH_ERRORS=false
|
|
|
|
# All outgoing HTTP requests (SMTP, webhooks, Apprise notifications, favicon fetching, etc.)
|
|
# will be sent through this proxy if set.
|
|
# OUTGOING_PROXY=http://proxy:3128
|
|
|
|
# Apprise notifications configuration.
|
|
# Set to false to prevent users from configuring and sending Apprise notifications.
|
|
# APPRISE_ENABLED=false
|
|
# Comma-separated allowlist of Apprise schemas users may use (e.g. slack,telegram).
|
|
# When set, only schemas in this list are accepted; APPRISE_BLOCKED_SCHEMAS is ignored.
|
|
# APPRISE_ALLOWED_SCHEMAS=
|
|
# Comma-separated blocklist of Apprise schemas. Replaces the built-in blocked list.
|
|
# APPRISE_BLOCKED_SCHEMAS=syslog,dbus,kde,qt,glib,gnome,macosx,windows
|
|
|
|
# Set to true to expose the Swagger specification at /swagger.json
|
|
# SWAGGER_EXPOSED=false
|
|
|
|
# S3_ENDPOINT=
|
|
# S3_REGION=
|
|
# S3_ACCESS_KEY_ID=
|
|
# S3_SECRET_ACCESS_KEY=
|
|
# S3_BUCKET=
|
|
# S3_FORCE_PATH_STYLE=true
|
|
# S3_REQUEST_CHECKSUM_CALCULATION=
|
|
|
|
# OIDC_ISSUER=
|
|
# OIDC_CLIENT_ID=
|
|
# OIDC_CLIENT_SECRET=
|
|
# OIDC_USE_OAUTH_CALLBACK=true
|
|
# OIDC_ID_TOKEN_SIGNED_RESPONSE_ALG=
|
|
# OIDC_USERINFO_SIGNED_RESPONSE_ALG=
|
|
# OIDC_SCOPES=openid email profile
|
|
# OIDC_RESPONSE_MODE=fragment
|
|
# OIDC_USE_DEFAULT_RESPONSE_MODE=true
|
|
# OIDC_ADMIN_ROLES=admin
|
|
# OIDC_PROJECT_OWNER_ROLES=project_owner
|
|
# OIDC_BOARD_USER_ROLES=board_user
|
|
# OIDC_CLAIMS_SOURCE=userinfo
|
|
# OIDC_EMAIL_ATTRIBUTE=email
|
|
# OIDC_NAME_ATTRIBUTE=name
|
|
# OIDC_USERNAME_ATTRIBUTE=preferred_username
|
|
# OIDC_ROLES_ATTRIBUTE=groups
|
|
# OIDC_IGNORE_USERNAME=true
|
|
# OIDC_IGNORE_ROLES=true
|
|
# OIDC_ENFORCED=true
|
|
# OIDC_TIMEOUT=3500
|
|
# OIDC_DEBUG=true
|
|
|
|
# Email Notifications (https://nodemailer.com/smtp/)
|
|
# These values override and disable configuration in the UI if set.
|
|
# SMTP_HOST=
|
|
# SMTP_PORT=587
|
|
# SMTP_NAME=
|
|
# SMTP_SECURE=true
|
|
# SMTP_TLS_REJECT_UNAUTHORIZED=false
|
|
# SMTP_USER=
|
|
# SMTP_PASSWORD=
|
|
# SMTP_FROM="Demo Demo" <demo@demo.demo>
|
|
|
|
# Using Gravatar directly exposes user IPs and hashed emails to a third party (GDPR risk).
|
|
# Use a proxy you control for privacy, or leave commented out or empty to disable.
|
|
# GRAVATAR_BASE_URL=https://www.gravatar.com/avatar/
|