use serde::{Deserialize, Serialize};
#[derive(Debug, Clone, Serialize, Deserialize, Default)]
pub struct SecurityConfig {
pub strict_csp: bool,
pub rate_limiting: bool,
pub enforce_https: bool,
pub allowed_hosts: Vec<String>,
pub acme_enabled: bool,
pub acme_domain: Option<String>,
pub acme_email: Option<String>,
pub acme_certs_dir: String,
}
impl SecurityConfig {
pub fn from_env() -> Self {
let strict_csp = std::env::var("STRICT_CSP")
.map(|v| v.parse().unwrap_or(true))
.unwrap_or(true);
let rate_limiting = std::env::var("RATE_LIMITING")
.map(|v| v.parse().unwrap_or(true))
.unwrap_or(true);
let enforce_https = std::env::var("ENFORCE_HTTPS")
.map(|v| v.parse().unwrap_or(false))
.unwrap_or(false);
let allowed_hosts: Vec<String> = std::env::var("ALLOWED_HOSTS")
.map(|v| v.split(',').map(|s| s.trim().to_string()).collect())
.unwrap_or_else(|_| vec!["localhost".to_string(), "127.0.0.1".to_string()]);
let acme_enabled = std::env::var("ACME_ENABLED")
.map(|v| v.parse().unwrap_or(false))
.unwrap_or(false);
let acme_domain = std::env::var("ACME_DOMAIN").ok().filter(|s| !s.is_empty());
let acme_email = std::env::var("ACME_EMAIL").ok().filter(|s| !s.is_empty());
let acme_certs_dir = std::env::var("ACME_CERTS_DIR")
.ok()
.filter(|s| !s.is_empty())
.unwrap_or_else(|| "./certs".to_string());
Self {
strict_csp,
rate_limiting,
enforce_https,
allowed_hosts,
acme_enabled,
acme_domain,
acme_email,
acme_certs_dir,
}
}
}