hsa-app/secret.sh
Jean-Michel Tremblay 8b7252dad4 Initial commit: HSA receipt tracker
Go app for capturing and archiving HSA-eligible receipts: OIDC/PKCE auth
against Authelia, SQLite storage with dual-write (filesystem + DB blob),
mobile-first upload, and DB export.

Adds AI receipt classification: a config.json catalog of people and
categories (seeded into the DB on startup), a prompt builder that derives
name-order/initial variants from the data (with same-surname ambiguity
handling), and an Anthropic tool-use client behind POST /classify. Tests
run against a mock endpoint; a live integration test is env-gated to the
cheapest model.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-17 21:40:12 -04:00

14 lines
590 B
Bash
Executable file

#!/usr/bin/env bash
# Generates a random OIDC client secret and prints:
# - the plaintext → goes in the app's .env as OIDC_CLIENT_SECRET
# - the Authelia hash → goes in Authelia's configuration.yml client_secret field
# Run this on the Authelia host (needs openssl + authelia in PATH).
set -euo pipefail
SECRET=$(openssl rand -base64 48 | tr -d '/+=' | cut -c1-64)
echo "=== Plaintext secret (app .env → OIDC_CLIENT_SECRET) ==="
echo "$SECRET"
echo ""
echo "=== Authelia hash (configuration.yml → client_secret) ==="
authelia crypto hash generate argon2 --password "$SECRET"