Web configuration
Web configuration
Every environment variable Ignis.Web (the BFF) reads.
Required
| Variable | Notes |
|---|---|
IGNIS_AUTH_ISSUER | Public URL of the authorization server (normally the API URL). Must match AuthSettings:Issuer on the API. |
IGNIS_WEB_APP_URL | Public URL of the Web app — scheme + host[:port], no path, no trailing slash. OAuth redirect URI is built as <IGNIS_WEB_APP_URL>/auth/callback, which must appear in the client's RedirectUris on the API. |
IGNIS_WEB_CLIENT_ID | OAuth client ID registered in Ignis.Api. Must match an entry in AuthSettings:Clients. |
IGNIS_WEB_CLIENT_SECRET | Matching client secret. |
IGNIS_WEB_SESSION_SECRET | 32 bytes of hex, encrypts the BFF session cookie. Generate with openssl rand -hex 32. Rotating invalidates all logged-in sessions. |
Optional
| Variable | Notes |
|---|---|
IGNIS_WEB_FHIR_BASE_URL | Base URL for the FHIR API. Defaults to same-origin /fhir/ on the Web app host; set when the API is served from a different origin. |
IGNIS_WEB_FOOTER_LINKS | Links shown in the site footer, as JSON — see below. Unset means no footer. |
IGNIS_WEB_HEAD_SCRIPTS | Third-party scripts added to <head>, as JSON — see below. Unset means none. |
Footer links
Which documents a deployment publishes is not something the app can know, so the footer's links are configuration rather than message-catalogue entries — labels for every language included:
[{ "href": "/pages/terms", "label": { "en": "Terms of use", "nb": "Vilkår" } },{ "href": "https://github.com/incendilabs/ignis", "label": "GitHub" }]
Both fields take a plain string, used in every language, or an object keyed by locale. Writing the href once is the point: a shared URL cannot drift out of step with one language's copy of it. A missing translation falls back to the base locale rather than dropping the link. Off-site links open in a new tab.
Only http, https, mailto and tel hrefs are rendered, along with relative ones;
anything else is skipped. Setting this variable already means controlling the
deployment, so this is not a privilege boundary — it is there so the links stay safe
if they ever come from somewhere less trusted. Configuration that will not parse is
logged and the footer left out; a footer is not worth a failed boot.
Analytics and other head scripts
[{"src": "https://analytics.example.com/script.js","defer": true,"data-website-id": "…","data-exclude-search": "true"}]
src must be https, http or a relative path. Beyond data-*, only defer,
async, nomodule, type, integrity, crossorigin and referrerpolicy are
kept; everything else is dropped. Unparseable configuration is logged and no
script is added.
Scripts load on every page, the console included.
Local dev server
These are read by src/Ignis.Web/vite.config.ts and src/Ignis.Web/react-router.config.ts during local development.
| Variable | Notes |
|---|---|
IGNIS_WEB_DEV_PORT | Vite dev server port. Defaults to 5202. |
IGNIS_WEB_DEV_HTTPS | Set to "true" to serve Web over HTTPS locally. |
IGNIS_WEB_DEV_HTTPS_KEY | Path to the local HTTPS key file, relative to src/Ignis.Web/vite.config.ts or absolute. |
IGNIS_WEB_DEV_HTTPS_CERT | Path to the local HTTPS cert file, relative to src/Ignis.Web/vite.config.ts or absolute. |
IGNIS_WEB_DEV_ALLOWED_HOSTS | Comma-separated Vite allowed hosts for dev-server requests. |
IGNIS_WEB_DEV_ALLOWED_ACTION_ORIGINS | Comma-separated hosts allowed to submit React Router actions. Include host and port, no scheme. |
See Local Development Setup for a complete local setup.
Feature flags
All default to off. Set to "true" to enable.
| Variable | Notes |
|---|---|
IGNIS_WEB_FEATURES_ADMIN | Enables the admin UI at /admin/*. Requires IGNIS_WEB_FEATURES_AUTH=true. See Admin UI. |
IGNIS_WEB_FEATURES_AUTH | Master switch for the OAuth/BFF login flow. Most other features require this. |
IGNIS_WEB_FEATURES_OPERATIONS | Enables the operations log at /admin/operations. Requires IGNIS_WEB_FEATURES_ADMIN=true. |
IGNIS_WEB_FEATURES_RESOURCES_UI | Enables the resource browser at /resources. Requires IGNIS_WEB_FEATURES_AUTH=true. |
IGNIS_WEB_FEATURES_VALIDATION_ANONYMOUS | Serves the validator at /validation to visitors with no session. Needs no other flag — a deployment can publish the validator alone, with auth off entirely. |
Signed-in users reach the validator wherever IGNIS_WEB_FEATURES_RESOURCES_UI is on,
with or without this flag.
Anonymous validation
This flag only stops the bounce to login; the API decides what it serves
(FeatureManagement:AllowAnonymousValidation, see
api-configuration.md). Set here but not
there, and the page loads while every validation fails.
Two panels come with it, on /validation:
- About this server —
CapabilityStatement.implementation.descriptionverbatim, so the real-patient-data warning is the deployment's own words. Hidden when the server says nothing. - Explore the whole server — for visitors with no session, when
IGNIS_WEB_FEATURES_AUTHis on. Points at login.
Cross-references with the API
These must agree on both sides — update API and Web together.
| Web BFF env var | API config key |
|---|---|
IGNIS_AUTH_ISSUER | AuthSettings:Issuer (api-configuration.md) |
IGNIS_WEB_APP_URL | AuthSettings:Clients[n]:RedirectUris (must contain <IGNIS_WEB_APP_URL>/auth/callback) |
IGNIS_WEB_CLIENT_ID | AuthSettings:Clients[n]:ClientId |
IGNIS_WEB_CLIENT_SECRET | AuthSettings:Clients[n]:ClientSecret |
IGNIS_WEB_FEATURES_VALIDATION_ANONYMOUS | FeatureManagement:AllowAnonymousValidation |