Changeset f574435 in Klonkt


Ignore:
Timestamp:
07/21/2026 03:45:36 AM (7 weeks ago)
Author:
Robin <roboburr@…>
Branches:
main
Children:
e2ea5c4
Parents:
4590e66
git-author:
Robin <roboburr@…> (07/21/2026 03:45:33 AM)
git-committer:
Robin <roboburr@…> (07/21/2026 03:45:36 AM)
Message:

Docs: README + .env.example for paid posts and auto-generated keys

Tell users how the paid-posts key works: no env editing needed, it's
generated on first use like SESSION_SECRET already is. Plus a general pass
for missing features.

Changed files:
README.md

  • "What it does": Paid posts (own Patreon, passkey unlock, no visitor account/cookie, patron identity never stored)
  • Configuration table: PAID_SECRET (auto) + KLONKT_PREMIUM_ENABLED; SESSION_SECRET marked auto (matches .env.example, not "required")
  • new "Auto-generated secrets & backups" section: where the keys live, why PAID_SECRET is outside the DB, and to back up storage/ as a whole
  • Stack: link to FEDERATION.md

.env.example

  • PAID_SECRET block (auto-generate, or openssl rand -base64 32)
  • paid posts added to the premium-extras list

-robo
Co-Authored-By: Claude Opus 4.8 <noreply@…>

Files:
2 edited

Legend:

Unmodified
Added
Removed
  • .env.example

    r4590e66 rf574435  
    1111# restarts/updates). Or set your own: openssl rand -hex 32
    1212SESSION_SECRET=
     13# Encrypts the stored Patreon secrets for paid posts. Same deal: leave EMPTY to
     14# auto-generate on first use (saved to storage/.paid-secret, kept outside the DB
     15# so a database dump alone stays useless). Or set your own: openssl rand -base64 32
     16PAID_SECRET=
    1317DATABASE_PATH=./storage/database.sqlite
    1418MEDIA_PATH=./storage/media
     
    5256# The core app, all updates and Cirkels are free. A handful of extras
    5357# (newsletter, statistics, EPK, link-in-bio, embeddable player, show agenda,
    54 # release planning, download-for-email) are unlocked by a one-time Patreon
    55 # supporter link — that's what funds the project:
     58# release planning, download-for-email, paid posts) are unlocked by a one-time
     59# Patreon supporter link — that's what funds the project:
    5660# klonkt.com / patreon.com/c/roboburr. Leave this on.
    5761KLONKT_PREMIUM_ENABLED=on
  • README.md

    r4590e66 rf574435  
    1515- **Grow**: newsletter, download-for-email, EPK/press kit, link-in-bio,
    1616  show calendar, and **cookie-free statistics**.
     17- **Paid posts** — put a post behind your **own Patreon**. Supporters unlock it
     18  with a **passkey**: no account on your site, no cookie, and a patron's identity
     19  (name/email) is never stored — only a pseudonymous, expiring entitlement. You
     20  connect your Patreon once in the admin and pick a minimum amount per post.
    1721- **Circles** — a curated feed of the makers you choose: feature accounts (other Klonkt
    1822  sites, Mastodon, PeerTube — any fediverse server) and their public posts appear in your
     
    161165| Variable | Required | What |
    162166|---|---|---|
    163 | `SESSION_SECRET` | ✅ | Random string of ≥32 characters |
     167| `SESSION_SECRET` | auto | Signs login sessions. Leave empty to auto-generate (`storage/.session-secret`), or set a random ≥32-char string. |
    164168| `PUBLIC_BASE_URL` | ✅ | Canonical URL (e.g. `https://yourdomain.com`) |
     169| `PAID_SECRET` | auto | Encrypts the stored Patreon secrets for **paid posts**. Leave empty to auto-generate on first use (`storage/.paid-secret`), or set your own ≥16-char string. |
    165170| `SMTP_HOST` / `_PORT` / `_USER` / `_PASS` / `_FROM` | — | Email for password reset + newsletter |
    166171| `KLONKT_DEFAULT_LANG` | — | Default language for visitors (`en`/`nl`/`de`) |
    167172| `KLONKT_AUDIO` | — | `off` = lite mode (no audio/ffmpeg) |
     173| `KLONKT_PREMIUM_ENABLED` | — | `on` (default) enables the Patreon-unlocked extras (incl. paid posts) |
    168174| `HSTS_STRICT` | — | `1` = stricter HTTPS header (`includeSubDomains` + `preload`). Only set this if Klonkt owns the **whole** domain and all its subdomains are HTTPS — it forces every subdomain to HTTPS and can bake your domain into browsers near-permanently. Leave unset otherwise; the default is already safe. |
     175
     176### Auto-generated secrets & backups
     177
     178You never have to hand-edit the env for these: Klonkt generates them on first use
     179and keeps them stable across restarts and updates.
     180
     181- `SESSION_SECRET` → `storage/.session-secret` (signs login sessions)
     182- `PAID_SECRET` → `storage/.paid-secret` (encrypts the stored Patreon secrets for
     183  paid posts)
     184
     185The paid-posts key lives **outside** the database on purpose: encrypting the
     186Patreon secrets would be pointless if the key sat in the same file a database
     187dump would leak. Set either variable in `.env` to override the generated one.
     188
     189**Back up the whole `storage/` directory** (database, media *and* these key
     190files). Restoring the database without `storage/.paid-secret` leaves the stored
     191Patreon secrets unreadable — you'd have to reconnect Patreon.
    169192
    170193## Stack
     
    175198- **Templates:** EJS (server-rendered) + **htmx 1.9** (vendored, no build step)
    176199- **Audio:** ffmpeg-static (bundled)
    177 - **Fediverse / Circles:** ActivityPub (HTTP Signatures) — federates with Mastodon, PeerTube and other Klonkt sites
     200- **Fediverse / Circles:** ActivityPub (HTTP Signatures) — federates with Mastodon, PeerTube and other Klonkt sites. See [FEDERATION.md](FEDERATION.md) for the supported activities and FEPs.
    178201- **Fonts:** self-hosted variable woff2 (Fraunces / Plus Jakarta Sans)
    179202
Note: See TracChangeset for help on using the changeset viewer.