| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511 |
- #
- # appweb.conf -- Complete Configuration for the Embedthis Appweb HTTP Server
- #
- # This file shows most of the Appweb configuration directives. You do not need
- # all directives and most have sensible defaults. Consult the typical-server
- # sample for a smaller appweb.conf configuration file.
- #
- # This configuration file controls the operation of the Appweb server. The
- # order of configuration directives matters as this file is parsed only once.
- # You must put the server root and error log definitions first to ensure
- # configuration errors are logged.
- #
- #
- # Server home directory for Appweb to find configuration files.
- # Appweb will change directory to this location when it runs.
- #
- Home "."
- #
- # Define the logging configuration first so any errors are logged.
- # This is for errors and debug trace. This log file is for the whole
- # server including virtual hosts.
- #
- ErrorLog "error.log" size=10MB level=2 backup=5 anew
- #
- # Request and operational trace log. This includes HTTP headers.
- #
- # TraceLog "trace.log" level=0 size=10MB backup=5 anew formatter=pretty
- # TraceLog "access.log" level=5 size=10MB backup=5 anew formatter=common format="%h %l %u %t "%r" %>s %b %n"
- #
- # This directive defines the levels at which various events are logged.
- #
- # Trace debug=1 error=1 request=2 result=2 headers=3 context=4 packet=5 detail=6 content=10K
- #
- # Enable emitting debug error messages back to the client. Defaults to "off".
- # WARNING: this may disclose unwanted information. Do not enable in production releases.
- #
- ShowErrors off
- #
- # The user name and group to become. The fake name APPWEB will change
- # user/group to the Appweb default user/group if running as root/adminstrator.
- # This is www on MAC, nobody/nogroup on Linux, and administrator on Windows.
- # The fake name _unchanged_ means don't change the user or group.
- # NOTE: ESP requires write access to the cache directory If you wish to
- # backup log files, you must have write permission to the log file directory.
- #
- GroupAccount APPWEB
- UserAccount APPWEB
- #
- # Bind Appweb to listen for incoming requests on this address. Formats
- # include (IP, IP:PORT, PORT). If an IP address is omitted, Appweb will
- # listen on all interfaces. If a port is omitted, then port 80 is used.
- # If the O/S has a dual-stack network, then connections on both IPv4
- # and IPv6 will be accepted. Use [::]:port to explicitly listen to only
- # IPv6 requests. [::1] is the IPv6 loopback. Use 0.0.0.0:port to listen
- # to only IPv4 requests.
- #
- Listen 8080
- #
- # SSL/TLS configuration
- #
- <if SSL_MODULE>
- ListenSecure 4443
- #
- # SECURITY NOTE: you must generate the certificate and key.
- # Use a decrypted key here so it won't prompt for the password when
- # the server is restarted.
- #
- SSLCertificateFile "../../src/certs/samples/self.crt"
- SSLCertificateKeyFile "../../src/certs/samples/self.key"
- </if>
- #
- # Name of the server to use for redirects and error responses to clients.
- # Uncomment this line and replace it with the public name of your server.
- # This host name and port do not get used for listening on sockets. If
- # unspecified, Appweb will use the IP address for the host name.
- # NOTE: Only define a CanonicalName if you are not using a ListenSecure
- # directive for SSL. Otherwise, redirects will always go to the address
- # you define here regardless of http or https. If you need to use a
- # CanonicalName with SSL, use a VirtualHost to define your SSL endpoint.
- #
- # CanonicalName http://example.com
- #
- # Location for documents for the primary server host. Routes and virtual
- # hosts may define their own document root.
- #
- Documents web
- #
- # Select the type of authentication password store. Select "system" for the default
- # system password store. Currenly only support Unix PAM. Set to "system" for the
- # file-based password store in auth.conf.
- #
- # AuthStore system
- #
- # Authorization directives. You can add these directives to apply to the entire
- # server and all routes after this point. Alternatively, put inside a VirtualHost
- # or Route block to localize to that block. By convention, the auth.conf file
- # contains User and Role definitions. This can be used when using the "system" auth
- # store to provide users, passwords and roles. If using the "system" store, it
- # can be used to map user groups to Appweb roles and abilities.
- #
- # include auth.conf
- #
- # Route unauthenticated traffic over SSL.
- # SECURITY NOTE: The authentication type of "basic" or "form" should
- # only ever be employed over a secure SSL connection. Otherwise, the
- # plain-text password will be sent in the clear over the network.
- #
- # Redirect secure
- #
- # This will force browsers to insist on TLS connections only for one year
- #
- # Strict-Transport-Security max-age=31536000; includeSubDomains
- #
- # Form-based authentication. The realm is required if not using PAM password
- # stores. This redirects unauthenticated accesses to https /admin/login.esp
- # which is a login form The /login url is used to process a posted with
- # username and password fields. For more details, see:
- # https://www.embedthis.com/appweb/doc/users/authentication.html.
- #
- # AuthType form example.com https:///admin/login.esp https:///login /logout /home.html
- #
- # Location of the mime translation file to map content types to file
- # extensions. For other types, you can use AddType.
- # "AddType application/x-other other"
- #
- # TypesConfig mime.types
- #
- # Search path for dynamically loadable modules. If modules have been
- # statically linked into Appweb, this directive and LoadModule directives
- # will be ignored. This directive must be before any LoadModule directives.
- # The default path is: dir-containing-executable : /usr/lib/appweb/bin
- # Use ";" as a separator on windows.
- #
- # LoadModulePath "/directory/to/modules:/other/directory"
- LoadModulePath "../../${PLATFORM}/bin"
- #
- # Notes on the request processing pipeline. The pipeline consists of a set
- # of stages comprised of a handler, possible filters and one network
- # connector.
- #
- # The request processing pipeline can be configured at various levels:
- # globally, virtual hosts and location blocks. At each level, a set of
- # processing stages can be defined. Inner levels inherit the pipeline from
- # the outer levels. The pipeline can be reset at a level by using
- # "Reset pipeline". Each stage may be defined for all requests or only for a
- # specific file extension or location path prefix.
- #
- # If you use the AddConnector, AddFilter or AddHandler directives, the
- # stage is defined for both input and output processing. For filters you can
- # use AddInputFilter AddOutputFilter directives to define for a single
- # direction.
- #
- # Multiple handlers can be defined, but only the first matching handler will
- # be activated when a request is processed.
- #
- #
- # For file upload, Handlers receive form variables that refer to the uploaded file.
- # SECURITY NOTE: Check the LimitUpload to cap the maximum upload.
- #
- # <Route /upload-uri>
- # UploadDir /tmp
- # UploadAutoDelete on
- # LimitUpload 200MB
- # </Route>
- #
- # For CGI scripts, such as your Perl scripts make sure that you have
- # "#!/PerlPath" as the first line. This works on Windows as well.
- # The .bat and .cmd extensions are really only for Windows.
- #
- <if CGI_MODULE>
- #
- # WARNING: for information about CGI security, read: http://www.w3.org/Security/faq/wwwsf4.html
- #
- AddHandler cgiHandler exe cgi cgi-nph out bat cmd pl py php
- ScriptAlias /cgi-bin/ "$DOCUMENT_ROOT/../cgi-bin"
- #
- # These actions specify the program to run for each Perl or Python
- # script. They map to the extensions specified in the mime.types for for
- # these mime types. Alternatively, you may use put all your scripts in
- # the subdirectories specified by the releavant Route blocks below.
- # For perl and python, you can also put "#!/path/to/program" as the first
- # line. This works on Windows as well. The .bat and .cmd extensions are
- # really only for Windows. For Windows, update the program paths with
- # the right paths.
- #
- Action application/x-perl /usr/bin/perl
- Action application/x-python /usr/bin/python
- Action application/x-lua /usr/bin/lua
- Action application/x-ruby /usr/bin/ruby
- Action application/x-php /usr/bin/php-cgi
- CgiPrefix CGI_
- CgiEscape on
- LimitProcesses 10
- </if>
- #
- # Directory listings. This provides a HTML directory list of the directory
- # corresponding to the URI.
- # SECURITY: This enables attackers to read directory contents.
- # SECURITY: Do not do this outside a scoping route.
- #
- # <if DIR_MODULE>
- # <Route /URI-to-list>
- # Options Indexes
- # IndexOrder ascending name
- # IndexOptions FancyIndexing FoldersFirst
- # </Route>
- # </if>
- #
- # Enable the action handler for simple URI to "C" bindings
- # This is used by the web-form Auth mechanism
- #
- <Route ^/action/>
- SetHandler actionHandler
- </Route>
- <if ESP_MODULE>
- AddHandler espHandler esp
- </if>
- #
- # The fileHandler matches all other extensions
- #
- AddHandler fileHandler
- #
- # Add the trace method if required
- #
- # Methods add TRACE
- #
- # WARNING: this will enable the PUT and DELETE methods to upload and remove
- # documents. Only do this inside routes intended for that purpose.
- #
- # <Route /putable>
- # Documents ./modifyable
- # PutMethod on
- # </Route>
- #
- # Set a default response cache lifespan
- #
- Cache 1day
- #
- # Session state duration.
- #
- SessionTimeout 30mins
- #
- # Set the cookie name and determine if the cookie is visible to Javascript
- # (default is httponly, invisible to scripts). Making cookies visible
- # increases the XSS potential.
- #
- # SessionCookie name=NAME visible=false
- #
- # Maximum duration to parse the request headers
- #
- RequestParseTimeout 5sec
- #
- # Maximum request duration.
- #
- RequestTimeout 10mins
- #
- # Maximum request and connection inactivity duration
- #
- InactivityTimeout 1min
- #
- # Request timeout when appweb is terminating or restarting
- #
- ExitTimeout 30secs
- #
- # Maximum number of worker threads in the Appweb worker pool. Must have at
- # least one. One thread will effectively single-thread the server. Appweb
- # will automatically adjust the number of workers between the minimum
- # specified by the MinWorkers and the maximum specified here. Every ten
- # minutes, Appweb will prune workers that have been idle for five minutes.
- # Appweb has two non-worker threads: one for the master event loop and one
- # for the garbage collector. So the total number of Appweb threads will be
- # two plus the number of active workers.
- #
- LimitWorkers 4
- #
- # Minimum number of worker threads. Pre-start and always preserve this
- # number of workers threads.
- #
- # MinWorkers 5
- #
- # Memory allocation error policy. This defines what Appweb will do if
- # the memory limit defined by LimitMemory is exceeded. Choose from "continue"
- # to prune non-critical response cache and session state, but continue on.
- # This make the memory limit a soft limit. Or select "restart" to do a
- # graceful shutdown and then appman will restart appweb.
- #
- MemoryPolicy restart
- #
- # Maximum application memory. Invokes MemoryPolicy if exceeded.
- # Redline at 95%.
- #
- LimitMemory 100MB
- #
- # Maximum cache size for response caching and sessions
- #
- LimitCache 10MB
- #
- # Maximum item size that can be cached
- #
- LimitCacheItem 200K
- #
- # Maximum number of total client connections.
- #
- LimitConnections 50
- #
- # Maximum number of simultaneous client systems. Set to zero for unlimited.
- #
- LimitClients 20
- #
- # Maximum number of open files/sockets on unix systems.
- # Set to zero for the maximum possible value.
- #
- LimitFiles 0
- #
- # Maximum packet size for pipeline queues
- #
- LimitPacket 32K
- #
- # Maximum number of network connections per client (IP). This helps prevent denial of service attacks.
- #
- LimitConnectionsPerClient 20
- #
- # Maximum number of simultaneous requests per client (IP). This helps prevent denial of service attacks.
- #
- LimitRequestsPerClient 20
- #
- # Number of HTTP requests to accept on a single TCP/IP connection
- # Reduce this number to minimize the chance of DoS attacks.
- #
- LimitKeepAlive 200
- #
- # Maximum size of the total request content body (includes header)
- #
- LimitRequestBody 2MB
- #
- # Maximum size of a request form
- #
- LimitRequestForm 32K
- #
- # Maximum size of request header
- #
- LimitRequestHeader 32K
- #
- # Maximum number of request header lines
- #
- LimitRequestHeaderLines 64
- #
- # Maximum size of the maximum response body
- #
- LimitResponseBody 2GB
- #
- # Maximum response chunk size
- #
- LimitChunk 64K
- #
- # Maximum request URI size
- #
- LimitUri 8K
- #
- # WARNING: Change this very carefully. Typically operating systems with
- # virtual memory can effectively allocate the stack size. Systems with
- # non-virtual memory may need to define this.
- # ThreadStack 64K
- #
- # Cache these extensions at the client for 1day.
- # Clients will refresh only if content is stale in their local cache.
- # This causes Expires/Cache-Control headers to be generated.
- #
- # Cache client=1day extensions="html,gif,jpeg,jpg,png,pdf,ico,js"
- #
- # Cache at the server with a lifespan of one hour.
- # All requests with the same URI path, regardless of request params are
- # cached as one.
- #
- # Cache server=1hour /cache.esp /cache.cgi
- #
- # To define a document to present for errors. If the URI is local the
- # error document will be served with the original status code. If the URI
- # is not local (starts with http), then a redirect (302) status code will
- # be used to redirect the client to the error document.
- #
- # ErrorDocument 404 /notFound.html
- #
- # Other useful directives
- #
- # Redirect temp /pressRelease.html https://${request:serverName}/fixedPressRelease.html
- # Redirect temp /pressRelease.html /fixedPressRelease.html
- # Redirect 410 /membersOnly
- # AddLanguage en english
- # AddLanguageRoot en englishContentDir
- # DefaultLanguage fr
- # StreamInput [!] mimeType URI
- # TypesConfig "mime.types"
- #
- # Create a virtual host
- #
- # <VirtualHost *:5000>
- # Listen 5000
- # Documents web
- # </VirtualHost>
- #
- # Useful Route directives
- #
- # <Route /pattern>
- # # Restrict the permissible methods. Default is to allow all methods sans DELETE, PUT, TRACE.
- # # Also see TraceMethod and PutMethod directives
- # Methods POST
- # </Route>
- #
- # Serve gziped files if an equivalent file with a "*.gz" extension exists
- # Map compressed
- #
- # WebSockets with an ESP handler
- #
- # <Route ^/websockets/{controller}/{action}$>
- # Prefix /websockets
- # AddFilter webSocketFilter
- # AddHandler espHandler
- # Source websockets.c
- # Target run $1-$2
- #
- # # Optimal to have the frame limit smaller than the packet limit. This way complete frames can be transferred.
- # # The Frame limit is a soft limit and can be exceeded. Outgoing messages are broken into frames of this size.
- #
- # LimitWebSockets 50
- # LimitWebSocketsMessage 2GB
- # LimitWebSocketsPacket 8K
- # LimitWebSocketsFrame 4K
- # RequestTimeout 2days
- # InactivityTimeout 1hour
- # WebSocketsProtocol chat
- # WebSocketsPing 30sec
- # IgnoreEncodingErrors on
- # # PreserveFrames off
- # </Route>
- #
- # Emergency DOS protection
- # If under attack, these directives may be useful
- #
- # Deny IPaddr-or-hosts
- # LimitConnectionsPerClient 10
- # LimitRequestsPerClient 10
- # LimitParseTimeout 2sec
- # LimitKeepAlive 20
- # InactivityTimeout 15sec
- #
- # Include per-app configuration
- #
- Include apps/*.conf
|