Web configuration

Web configuration

Every environment variable Ignis.Web (the BFF) reads.

Required

VariableNotes
IGNIS_AUTH_ISSUERPublic URL of the authorization server (normally the API URL). Must match AuthSettings:Issuer on the API.
IGNIS_WEB_APP_URLPublic URL of the Web app — scheme + host[:port], no path, no trailing slash. OAuth redirect URI is built as <IGNIS_WEB_APP_URL>/auth/callback, which must appear in the client's RedirectUris on the API.
IGNIS_WEB_CLIENT_IDOAuth client ID registered in Ignis.Api. Must match an entry in AuthSettings:Clients.
IGNIS_WEB_CLIENT_SECRETMatching client secret.
IGNIS_WEB_SESSION_SECRET32 bytes of hex, encrypts the BFF session cookie. Generate with openssl rand -hex 32. Rotating invalidates all logged-in sessions.

Optional

VariableNotes
IGNIS_WEB_FHIR_BASE_URLBase URL for the FHIR API. Defaults to same-origin /fhir/ on the Web app host; set when the API is served from a different origin.
IGNIS_WEB_FOOTER_LINKSLinks shown in the site footer, as JSON — see below. Unset means no footer.
IGNIS_WEB_HEAD_SCRIPTSThird-party scripts added to <head>, as JSON — see below. Unset means none.

Footer links

Which documents a deployment publishes is not something the app can know, so the footer's links are configuration rather than message-catalogue entries — labels for every language included:

json
[
{ "href": "/pages/terms", "label": { "en": "Terms of use", "nb": "Vilkår" } },
{ "href": "https://github.com/incendilabs/ignis", "label": "GitHub" }
]

Both fields take a plain string, used in every language, or an object keyed by locale. Writing the href once is the point: a shared URL cannot drift out of step with one language's copy of it. A missing translation falls back to the base locale rather than dropping the link. Off-site links open in a new tab.

Only http, https, mailto and tel hrefs are rendered, along with relative ones; anything else is skipped. Setting this variable already means controlling the deployment, so this is not a privilege boundary — it is there so the links stay safe if they ever come from somewhere less trusted. Configuration that will not parse is logged and the footer left out; a footer is not worth a failed boot.

Analytics and other head scripts

json
[
{
"src": "https://analytics.example.com/script.js",
"defer": true,
"data-website-id": "…",
"data-exclude-search": "true"
}
]

src must be https, http or a relative path. Beyond data-*, only defer, async, nomodule, type, integrity, crossorigin and referrerpolicy are kept; everything else is dropped. Unparseable configuration is logged and no script is added.

Scripts load on every page, the console included.

Local dev server

These are read by src/Ignis.Web/vite.config.ts and src/Ignis.Web/react-router.config.ts during local development.

VariableNotes
IGNIS_WEB_DEV_PORTVite dev server port. Defaults to 5202.
IGNIS_WEB_DEV_HTTPSSet to "true" to serve Web over HTTPS locally.
IGNIS_WEB_DEV_HTTPS_KEYPath to the local HTTPS key file, relative to src/Ignis.Web/vite.config.ts or absolute.
IGNIS_WEB_DEV_HTTPS_CERTPath to the local HTTPS cert file, relative to src/Ignis.Web/vite.config.ts or absolute.
IGNIS_WEB_DEV_ALLOWED_HOSTSComma-separated Vite allowed hosts for dev-server requests.
IGNIS_WEB_DEV_ALLOWED_ACTION_ORIGINSComma-separated hosts allowed to submit React Router actions. Include host and port, no scheme.

See Local Development Setup for a complete local setup.

Feature flags

All default to off. Set to "true" to enable.

VariableNotes
IGNIS_WEB_FEATURES_ADMINEnables the admin UI at /admin/*. Requires IGNIS_WEB_FEATURES_AUTH=true. See Admin UI.
IGNIS_WEB_FEATURES_AUTHMaster switch for the OAuth/BFF login flow. Most other features require this.
IGNIS_WEB_FEATURES_OPERATIONSEnables the operations log at /admin/operations. Requires IGNIS_WEB_FEATURES_ADMIN=true.
IGNIS_WEB_FEATURES_RESOURCES_UIEnables the resource browser at /resources. Requires IGNIS_WEB_FEATURES_AUTH=true.
IGNIS_WEB_FEATURES_VALIDATION_ANONYMOUSServes the validator at /validation to visitors with no session. Needs no other flag — a deployment can publish the validator alone, with auth off entirely.

Signed-in users reach the validator wherever IGNIS_WEB_FEATURES_RESOURCES_UI is on, with or without this flag.

Anonymous validation

This flag only stops the bounce to login; the API decides what it serves (FeatureManagement:AllowAnonymousValidation, see api-configuration.md). Set here but not there, and the page loads while every validation fails.

Two panels come with it, on /validation:

  • About this server — CapabilityStatement.implementation.description verbatim, so the real-patient-data warning is the deployment's own words. Hidden when the server says nothing.
  • Explore the whole server — for visitors with no session, when IGNIS_WEB_FEATURES_AUTH is on. Points at login.

Cross-references with the API

These must agree on both sides — update API and Web together.

Web BFF env varAPI config key
IGNIS_AUTH_ISSUERAuthSettings:Issuer (api-configuration.md)
IGNIS_WEB_APP_URLAuthSettings:Clients[n]:RedirectUris (must contain <IGNIS_WEB_APP_URL>/auth/callback)
IGNIS_WEB_CLIENT_IDAuthSettings:Clients[n]:ClientId
IGNIS_WEB_CLIENT_SECRETAuthSettings:Clients[n]:ClientSecret
IGNIS_WEB_FEATURES_VALIDATION_ANONYMOUSFeatureManagement:AllowAnonymousValidation
Edit this page