"""Service configuration & limits (env-overridable).""" from __future__ import annotations import os from pathlib import Path # Max upload size in bytes. Bank-statement PDFs are small; cap to stop abuse. MAX_UPLOAD_BYTES = int(os.getenv("EBS_MAX_UPLOAD_BYTES", str(15 * 1024 * 1024))) # 15 MB # Local scratch dir for uploads. Must be a real on-disk path: the engine # rasterises pages for OCR *next to* the PDF, and Tesseract/Leptonica can't # always read the system /tmp. Kept out of git (see .gitignore). WORK_DIR = Path( os.getenv("EBS_WORK_DIR", str(Path(__file__).resolve().parents[2] / "_work")) ) # CORS allow-list (comma-separated). "*" for local dev; lock to the web origin # before public launch. ALLOWED_ORIGINS = [ o.strip() for o in os.getenv("EBS_ALLOWED_ORIGINS", "*").split(",") if o.strip() ] # Shared secret the web BFF must send (header X-API-Key). When set, direct # callers without it are rejected — so nobody can hit the extractor and bypass # the web app's quota. Unset in local dev = open (for convenience). API_KEY = os.getenv("EBS_API_KEY") or None