diff --git a/.env.local.example b/.env.local.example new file mode 100644 index 0000000..85fac19 --- /dev/null +++ b/.env.local.example @@ -0,0 +1,14 @@ +# Copy this file to .env.local and fill in real values. +# .env.local is gitignored — never commit real keys. + +# Project Settings -> API -> Project URL +NEXT_PUBLIC_SUPABASE_URL= + +# Project Settings -> API -> anon public key. Safe to expose to the +# browser: every query it makes is filtered by RLS. +NEXT_PUBLIC_SUPABASE_ANON_KEY= + +# Project Settings -> API -> service_role key. NEVER exposed to the +# browser. Only imported in server-only files (src/lib/supabase/service.ts), +# used only inside /app/api/* route handlers. Bypasses RLS entirely. +SUPABASE_SERVICE_ROLE_KEY= diff --git a/.gitignore b/.gitignore index 5ef6a52..3639bc5 100644 --- a/.gitignore +++ b/.gitignore @@ -32,6 +32,7 @@ yarn-error.log* # env files (can opt-in for committing if needed) .env* +!.env*.example # vercel .vercel