Files
CompanySite/.env.example
T
platform-mcp e4b962bb1b
Ping Search Engines / Notify Search Engines (push) Successful in 5s
E2E Test Suite / Form Interaction Tests (push) Failing after 10m11s
E2E Test Suite / Mobile Device Tests (push) Failing after 10m49s
E2E Test Suite / Cross-Browser Regression (webkit) (push) Failing after 11m42s
E2E Test Suite / Cross-Browser Regression (firefox) (push) Failing after 12m34s
E2E Test Suite / Cross-Browser Regression (chromium) (push) Failing after 13m26s
E2E Test Suite / Destructive & Chaos Tests (push) Failing after 14m19s
E2E Test Suite / Security Header Tests (push) Failing after 14m55s
E2E Test Suite / Smoke Tests (P0) (push) Failing after 20m54s
E2E Test Suite / Critical User Journeys (push) Has been skipped
E2E Test Suite / API Integration Tests (push) Has been skipped
E2E Test Suite / Test Report Summary (push) Has been cancelled
Deploy to Production / Build & Verify (push) Waiting to run
Deploy to Production / Pre-Deploy Tests (push) Blocked by required conditions
Deploy to Production / Deploy to Railway (push) Has been cancelled
Deploy to Production / Deploy to Render (push) Has been cancelled
Deploy to Production / Deploy to VPS (PM2) (push) Has been cancelled
Deploy to Production / Deploy to Fly.io (push) Has been cancelled
Deploy to Production / Post-Deploy Verification (push) Has been cancelled
Deploy to Production / Notify on Failure (push) Has been cancelled
feat(api/contact): wire env-driven SMTP for contact + project inquiry forms
Both the contact form (/contact) and the homepage "Tell us about your project"
inline lead form post to /api/contact. Updated that single handler to build
the nodemailer transport from a clean set of SMTP_* env vars per spec:

  SMTP_HOST / SMTP_PORT / SMTP_USER / SMTP_PASS
  SMTP_FROM + SMTP_FROM_NAME  -> "From: Ajay Ghanwat <ghanwat.ajay@workroot.in>"
  MAIL_ADMIN_TO               -> admin notification recipient
                                  (falls back to SMTP_FROM, then legacy
                                   CONTACT_EMAIL_TO / CONTACT_EMAIL / SMTP_USER)
  SMTP_REQUIRE_TLS            -> force STARTTLS upgrade on port 587
  SMTP_CONNECTION_TIMEOUT_MS  -> defaults to 10000
  SMTP_GREETING_TIMEOUT_MS    -> defaults to 10000
  SMTP_SOCKET_TIMEOUT_MS      -> defaults to 10000

Behaviour preserved:
- Existing user-facing auto-reply (the block previously at L270) kept.
  Subject + body now adapt for project-inquiry sources (homepage-inline,
  homepage-hero, homepage-final-cta, mobile-sticky) so the admin inbox
  can triage [Project Inquiry] vs [Contact Form] at a glance.
- Graceful degradation per FORM_INTEGRATION.md: missing env vars or a
  failed nodemailer import logs a structured warning and returns 200 —
  the site never 500s on email config.
- Rate limiting, honeypot, CORS, validation, and fire-and-forget
  background dispatch are untouched.

Observability:
- Structured console logs at: transport created, admin accepted (with
  messageId), user auto-reply accepted (with messageId), and send-failure
  (with smtp code/command/response). SMTP_PASS is never logged.

Misc:
- .env.example updated to document the new variables and the legacy
  aliases that are still honored.
2026-06-17 12:25:08 +05:30

110 lines
3.8 KiB
Bash

# ==================================
# Server Configuration
# ==================================
# Host address for the server to bind to
# - Use 0.0.0.0 to accept connections from any network interface (REQUIRED for deployment platforms)
# - Use 127.0.0.1 or localhost for local development only
HOST=0.0.0.0
# Port number for the application server
# - Default: 10000 (configured for deployment platforms like Render, Railway, Fly.io)
# - Many platforms override this with their own PORT environment variable
PORT=10000
# ==================================
# Environment Settings
# ==================================
# Node environment mode
# - production: Optimized for deployment with minification and performance settings
# - development: Enhanced debugging and hot-reload capabilities
# - test: For running automated tests
NODE_ENV=production
# ==================================
# Optional Configuration
# ==================================
# Uncomment and configure as needed for your application
# Database connection string
# DATABASE_URL=postgresql://user:password@localhost:5432/dbname
# API Keys and Secrets
# API_KEY=your_api_key_here
# SESSION_SECRET=your_session_secret_here
# ==================================
# Contact Form & Email (SMTP)
# ==================================
# Used by /api/contact (powers both the contact page form AND the
# homepage "Tell us about your project" inline lead form).
# If unset, submissions are logged to console (dev/staging mode).
#
# --- Required for live email delivery ---
# SMTP_HOST=smtp.hostinger.com
# SMTP_PORT=587 # 587 = STARTTLS (recommended)
# SMTP_USER=ghanwat.ajay@workroot.in
# SMTP_PASS=your_app_password_here # MARK AS SECRET in platform UI
#
# --- From header (RFC 5322) ---
# SMTP_FROM=ghanwat.ajay@workroot.in
# SMTP_FROM_NAME=Ajay Ghanwat
#
# --- Admin recipient for inbound submissions ---
# Falls back to SMTP_FROM, then legacy CONTACT_EMAIL_TO/CONTACT_EMAIL.
# MAIL_ADMIN_TO=ghanwat.ajay@workroot.in
#
# --- TLS & timeouts (optional, sensible defaults applied) ---
# SMTP_REQUIRE_TLS=true # set to "false" to disable STARTTLS upgrade
# SMTP_CONNECTION_TIMEOUT_MS=10000
# SMTP_GREETING_TIMEOUT_MS=10000
# SMTP_SOCKET_TIMEOUT_MS=10000
#
# --- Legacy aliases (still honored for backwards compatibility) ---
# CONTACT_EMAIL_TO=hello@workroot.in
# CONTACT_EMAIL=hello@workroot.in
# ==================================
# Newsletter Integration
# ==================================
# Choose ONE provider. Leave others blank.
# Option A: Mailchimp
# MAILCHIMP_API_KEY=your_mailchimp_api_key
# MAILCHIMP_LIST_ID=your_audience_list_id
# MAILCHIMP_DC=us1
# Option B: ConvertKit
# CONVERTKIT_API_KEY=your_convertkit_api_key
# CONVERTKIT_FORM_ID=your_form_id
# If no newsletter provider is configured, new subscribers are logged to console
# and optionally emailed to CONTACT_EMAIL via SMTP (if SMTP is configured)
# ==================================
# Analytics and Monitoring
# ==================================
# Option A: Google Analytics 4 (GA4)
# Format: G-XXXXXXXXXX (NOT the old UA-XXXXXXXXX-X format)
# Get your Measurement ID at: Google Analytics → Admin → Data Streams → Web Stream
# GOOGLE_ANALYTICS_ID=G-XXXXXXXXXX
# Option B: Plausible Analytics (privacy-focused, GDPR compliant)
# Set to your site's domain (no https://)
# PLAUSIBLE_DOMAIN=workroot.in
# Both can be enabled simultaneously if desired.
# If neither is set, no analytics scripts are injected.
# Sentry error tracking (optional)
# Get your DSN at https://sentry.io → Project → Settings → Client Keys (DSN)
# SENTRY_DSN=https://xxx@oXXXXXX.ingest.sentry.io/XXXXXXX
# Structured logging level: debug | info | warn | error (default: info in prod, debug in dev)
# LOG_LEVEL=info
# Application release version — used for Sentry release tracking
# RELEASE_VERSION=1.0.0