diff --git a/conf/snipeit.env b/conf/snipeit.env index a0d057d..1c8d827 100644 --- a/conf/snipeit.env +++ b/conf/snipeit.env @@ -18,6 +18,7 @@ PUBLIC_FILESYSTEM_DISK=local_public #PRIVATE_FILESYSTEM_DISK=s3_private #PUBLIC_FILESYSTEM_DISK=s3_public + # -------------------------------------------- # REQUIRED: DATABASE SETTINGS # -------------------------------------------- @@ -41,6 +42,7 @@ DB_SSL_KEY_PATH=null DB_SSL_CERT_PATH=null DB_SSL_CA_PATH=null DB_SSL_CIPHER=null +DB_SSL_VERIFY_SERVER=null # -------------------------------------------- # REQUIRED: OUTGOING MAIL SERVER SETTINGS @@ -50,12 +52,16 @@ MAIL_HOST=127.0.0.1 MAIL_PORT=25 MAIL_USERNAME=__APP__ MAIL_PASSWORD=__MAIL_PWD__ -MAIL_ENCRYPTION=null MAIL_FROM_ADDR=__APP__@__DOMAIN__ MAIL_FROM_NAME='Snip-IT' MAIL_REPLYTO_ADDR=__APP__@__DOMAIN__ MAIL_REPLYTO_NAME='Snipe-IT' MAIL_AUTO_EMBED_METHOD='attachment' +MAIL_TLS_VERIFY_PEER=true + +# MAIL_ENCRYPTION is no longer supported. SymfonyMailer will use tls if it's +# advertised, and won't if it's not. If you want to use your mail server's IP but it's failing +# because of certificate errors, set MAIL_TLS_VERIFY_PEER-true # -------------------------------------------- # REQUIRED: IMAGE LIBRARY @@ -63,6 +69,7 @@ MAIL_AUTO_EMBED_METHOD='attachment' # -------------------------------------------- IMAGE_LIB=gd + # -------------------------------------------- # OPTIONAL: BACKUP SETTINGS # -------------------------------------------- @@ -83,6 +90,8 @@ COOKIE_NAME=snipeit_session COOKIE_DOMAIN=null SECURE_COOKIES=false API_TOKEN_EXPIRATION_YEARS=15 +BS_TABLE_STORAGE=cookieStorage +BS_TABLE_DEEPLINK=true # -------------------------------------------- # OPTIONAL: SECURITY HEADER SETTINGS @@ -91,6 +100,7 @@ APP_TRUSTED_PROXIES=192.168.1.1,10.0.0.1 ALLOW_IFRAMING=false REFERRER_POLICY=same-origin ENABLE_CSP=false +ADDITIONAL_CSP_URLS=null CORS_ALLOWED_ORIGINS=null ENABLE_HSTS=false @@ -146,6 +156,7 @@ AWS_DEFAULT_REGION=null # -------------------------------------------- LOGIN_MAX_ATTEMPTS=5 LOGIN_LOCKOUT_DURATION=60 +LOGIN_AUTOCOMPLETE=false # -------------------------------------------- # OPTIONAL: FORGOTTEN PASSWORD SETTINGS @@ -173,6 +184,15 @@ REQUIRE_SAML=false API_THROTTLE_PER_MINUTE=120 CSV_ESCAPE_FORMULAS=true +# -------------------------------------------- +# OPTIONAL: HASHING +# -------------------------------------------- +HASHING_DRIVER='bcrypt' +BCRYPT_ROUNDS=10 +ARGON_MEMORY=1024 +ARGON_THREADS=2 +ARGON_TIME=2 + # -------------------------------------------- # OPTIONAL: SCIM # --------------------------------------------