Skip to main content

Overview

The Password Generator application uses environment variables to manage configuration across different environments. This guide covers all required and optional environment variables for both frontend and backend.

Backend Environment Variables

Required Variables

These variables must be set for the Django backend to function properly:
string
required
Django secret key for cryptographic signing. Generate a secure random string.
boolean
required
Enable or disable debug mode. Must be False in production.
string
required
PostgreSQL database connection URL (production only).
In development with DEBUG=True, SQLite is used automatically and DATABASE_URL is not required.

Deployment Configuration

list
required
Comma-separated list of allowed hostnames for production.
list
default:"localhost,127.0.0.1"
Comma-separated list of allowed hostnames for development.

CORS Configuration

Cross-Origin Resource Sharing (CORS) settings allow the frontend to communicate with the backend API:
list
required
Comma-separated list of allowed origins for production.
list
Comma-separated list of allowed origins for development.
list
required
Comma-separated list of trusted origins for CSRF protection in production.
list
Comma-separated list of trusted origins for CSRF protection in development.

Database Configuration

The application uses different database configurations based on the DEBUG setting:

Development (DEBUG=True)

settings.py

Production (DEBUG=False)

settings.py
The production configuration uses dj-database-url to parse the DATABASE_URL and enables SSL connections.

JWT Authentication Configuration

The application uses JWT tokens for authentication with the following settings:
settings.py
duration
default:"1 day"
How long access tokens remain valid.
duration
default:"1 day"
How long refresh tokens remain valid.
boolean
default:"True"
Generate a new refresh token when refreshing.
boolean
default:"True"
Blacklist old refresh tokens after rotation.

Fly.io Specific

string
Automatically set by Fly.io. The app name is added to ALLOWED_HOSTS.
settings.py

Frontend Environment Variables

API Configuration

string
required
Backend API URL. Must be prefixed with NEXT_PUBLIC_ to be exposed to the browser.
.env.local
The current implementation in src/app/utils/Request.api.js uses a hardcoded URL. Update it to use this environment variable:

Environment File Examples

Backend .env (Development)

.env

Backend .env (Production)

.env

Frontend .env.local

.env.local

Django Settings Configuration

The application uses django-environ to read environment variables:
settings.py

REST Framework Configuration

The Django REST Framework is configured with JWT authentication:
settings.py

Static Files Configuration (Production)

settings.py

Localization Settings

The application is configured for Colombian Spanish:
settings.py

Security Best Practices

1

Generate a strong SECRET_KEY

Use a cryptographically secure random string:
2

Never commit .env files

Add to .gitignore:
.gitignore
3

Use different keys per environment

Never reuse the same SECRET_KEY across development, staging, and production.
4

Restrict CORS origins

Only allow your frontend domain(s):
5

Enable database SSL in production

The configuration already includes ssl_require=True for PostgreSQL connections.

Environment Variable Checklist

Backend Production
  • SECRET_KEY is set to a strong random value
  • DEBUG=False
  • DATABASE_URL points to PostgreSQL
  • ALLOWED_HOSTS_DEPLOY includes your domain
  • CORS_ALLOWED_ORIGINS_DEPLOY includes your frontend domain
  • CSRF_TRUSTED_ORIGINS_DEPLOY includes your frontend domain
Backend Development
  • SECRET_KEY is set (can be simple for dev)
  • DEBUG=True
  • ALLOWED_HOSTS_DEV includes localhost
  • CORS_ALLOWED_ORIGINS_DEV includes localhost:3000
Frontend
  • NEXT_PUBLIC_API_URL points to backend API
  • Updated Request.api.js to use environment variable

Troubleshooting

”SECRET_KEY” KeyError

If you see this error, the SECRET_KEY environment variable is not set:

CORS Errors

If you see CORS errors in the browser console:
  1. Verify CORS_ALLOWED_ORIGINS_DEPLOY includes your frontend URL (with protocol)
  2. Ensure there are no trailing slashes
  3. Check the backend logs for CORS rejection messages

Database Connection Failed

If the database connection fails:

Next Steps

Frontend Deployment

Deploy the Next.js frontend

Backend Deployment

Deploy the Django backend