appweb.conf 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511
  1. #
  2. # appweb.conf -- Complete Configuration for the Embedthis Appweb HTTP Server
  3. #
  4. # This file shows most of the Appweb configuration directives. You do not need
  5. # all directives and most have sensible defaults. Consult the typical-server
  6. # sample for a smaller appweb.conf configuration file.
  7. #
  8. # This configuration file controls the operation of the Appweb server. The
  9. # order of configuration directives matters as this file is parsed only once.
  10. # You must put the server root and error log definitions first to ensure
  11. # configuration errors are logged.
  12. #
  13. #
  14. # Server home directory for Appweb to find configuration files.
  15. # Appweb will change directory to this location when it runs.
  16. #
  17. Home "."
  18. #
  19. # Define the logging configuration first so any errors are logged.
  20. # This is for errors and debug trace. This log file is for the whole
  21. # server including virtual hosts.
  22. #
  23. ErrorLog "error.log" size=10MB level=2 backup=5 anew
  24. #
  25. # Request and operational trace log. This includes HTTP headers.
  26. #
  27. # TraceLog "trace.log" level=0 size=10MB backup=5 anew formatter=pretty
  28. # TraceLog "access.log" level=5 size=10MB backup=5 anew formatter=common format="%h %l %u %t "%r" %>s %b %n"
  29. #
  30. # This directive defines the levels at which various events are logged.
  31. #
  32. # Trace debug=1 error=1 request=2 result=2 headers=3 context=4 packet=5 detail=6 content=10K
  33. #
  34. # Enable emitting debug error messages back to the client. Defaults to "off".
  35. # WARNING: this may disclose unwanted information. Do not enable in production releases.
  36. #
  37. ShowErrors off
  38. #
  39. # The user name and group to become. The fake name APPWEB will change
  40. # user/group to the Appweb default user/group if running as root/adminstrator.
  41. # This is www on MAC, nobody/nogroup on Linux, and administrator on Windows.
  42. # The fake name _unchanged_ means don't change the user or group.
  43. # NOTE: ESP requires write access to the cache directory If you wish to
  44. # backup log files, you must have write permission to the log file directory.
  45. #
  46. GroupAccount APPWEB
  47. UserAccount APPWEB
  48. #
  49. # Bind Appweb to listen for incoming requests on this address. Formats
  50. # include (IP, IP:PORT, PORT). If an IP address is omitted, Appweb will
  51. # listen on all interfaces. If a port is omitted, then port 80 is used.
  52. # If the O/S has a dual-stack network, then connections on both IPv4
  53. # and IPv6 will be accepted. Use [::]:port to explicitly listen to only
  54. # IPv6 requests. [::1] is the IPv6 loopback. Use 0.0.0.0:port to listen
  55. # to only IPv4 requests.
  56. #
  57. Listen 8080
  58. #
  59. # SSL/TLS configuration
  60. #
  61. <if SSL_MODULE>
  62. ListenSecure 4443
  63. #
  64. # SECURITY NOTE: you must generate the certificate and key.
  65. # Use a decrypted key here so it won't prompt for the password when
  66. # the server is restarted.
  67. #
  68. SSLCertificateFile "../../src/certs/samples/self.crt"
  69. SSLCertificateKeyFile "../../src/certs/samples/self.key"
  70. </if>
  71. #
  72. # Name of the server to use for redirects and error responses to clients.
  73. # Uncomment this line and replace it with the public name of your server.
  74. # This host name and port do not get used for listening on sockets. If
  75. # unspecified, Appweb will use the IP address for the host name.
  76. # NOTE: Only define a CanonicalName if you are not using a ListenSecure
  77. # directive for SSL. Otherwise, redirects will always go to the address
  78. # you define here regardless of http or https. If you need to use a
  79. # CanonicalName with SSL, use a VirtualHost to define your SSL endpoint.
  80. #
  81. # CanonicalName http://example.com
  82. #
  83. # Location for documents for the primary server host. Routes and virtual
  84. # hosts may define their own document root.
  85. #
  86. Documents web
  87. #
  88. # Select the type of authentication password store. Select "system" for the default
  89. # system password store. Currenly only support Unix PAM. Set to "system" for the
  90. # file-based password store in auth.conf.
  91. #
  92. # AuthStore system
  93. #
  94. # Authorization directives. You can add these directives to apply to the entire
  95. # server and all routes after this point. Alternatively, put inside a VirtualHost
  96. # or Route block to localize to that block. By convention, the auth.conf file
  97. # contains User and Role definitions. This can be used when using the "system" auth
  98. # store to provide users, passwords and roles. If using the "system" store, it
  99. # can be used to map user groups to Appweb roles and abilities.
  100. #
  101. # include auth.conf
  102. #
  103. # Route unauthenticated traffic over SSL.
  104. # SECURITY NOTE: The authentication type of "basic" or "form" should
  105. # only ever be employed over a secure SSL connection. Otherwise, the
  106. # plain-text password will be sent in the clear over the network.
  107. #
  108. # Redirect secure
  109. #
  110. # This will force browsers to insist on TLS connections only for one year
  111. #
  112. # Strict-Transport-Security max-age=31536000; includeSubDomains
  113. #
  114. # Form-based authentication. The realm is required if not using PAM password
  115. # stores. This redirects unauthenticated accesses to https /admin/login.esp
  116. # which is a login form The /login url is used to process a posted with
  117. # username and password fields. For more details, see:
  118. # https://www.embedthis.com/appweb/doc/users/authentication.html.
  119. #
  120. # AuthType form example.com https:///admin/login.esp https:///login /logout /home.html
  121. #
  122. # Location of the mime translation file to map content types to file
  123. # extensions. For other types, you can use AddType.
  124. # "AddType application/x-other other"
  125. #
  126. # TypesConfig mime.types
  127. #
  128. # Search path for dynamically loadable modules. If modules have been
  129. # statically linked into Appweb, this directive and LoadModule directives
  130. # will be ignored. This directive must be before any LoadModule directives.
  131. # The default path is: dir-containing-executable : /usr/lib/appweb/bin
  132. # Use ";" as a separator on windows.
  133. #
  134. # LoadModulePath "/directory/to/modules:/other/directory"
  135. LoadModulePath "../../${PLATFORM}/bin"
  136. #
  137. # Notes on the request processing pipeline. The pipeline consists of a set
  138. # of stages comprised of a handler, possible filters and one network
  139. # connector.
  140. #
  141. # The request processing pipeline can be configured at various levels:
  142. # globally, virtual hosts and location blocks. At each level, a set of
  143. # processing stages can be defined. Inner levels inherit the pipeline from
  144. # the outer levels. The pipeline can be reset at a level by using
  145. # "Reset pipeline". Each stage may be defined for all requests or only for a
  146. # specific file extension or location path prefix.
  147. #
  148. # If you use the AddConnector, AddFilter or AddHandler directives, the
  149. # stage is defined for both input and output processing. For filters you can
  150. # use AddInputFilter AddOutputFilter directives to define for a single
  151. # direction.
  152. #
  153. # Multiple handlers can be defined, but only the first matching handler will
  154. # be activated when a request is processed.
  155. #
  156. #
  157. # For file upload, Handlers receive form variables that refer to the uploaded file.
  158. # SECURITY NOTE: Check the LimitUpload to cap the maximum upload.
  159. #
  160. # <Route /upload-uri>
  161. # UploadDir /tmp
  162. # UploadAutoDelete on
  163. # LimitUpload 200MB
  164. # </Route>
  165. #
  166. # For CGI scripts, such as your Perl scripts make sure that you have
  167. # "#!/PerlPath" as the first line. This works on Windows as well.
  168. # The .bat and .cmd extensions are really only for Windows.
  169. #
  170. <if CGI_MODULE>
  171. #
  172. # WARNING: for information about CGI security, read: http://www.w3.org/Security/faq/wwwsf4.html
  173. #
  174. AddHandler cgiHandler exe cgi cgi-nph out bat cmd pl py php
  175. ScriptAlias /cgi-bin/ "$DOCUMENT_ROOT/../cgi-bin"
  176. #
  177. # These actions specify the program to run for each Perl or Python
  178. # script. They map to the extensions specified in the mime.types for for
  179. # these mime types. Alternatively, you may use put all your scripts in
  180. # the subdirectories specified by the releavant Route blocks below.
  181. # For perl and python, you can also put "#!/path/to/program" as the first
  182. # line. This works on Windows as well. The .bat and .cmd extensions are
  183. # really only for Windows. For Windows, update the program paths with
  184. # the right paths.
  185. #
  186. Action application/x-perl /usr/bin/perl
  187. Action application/x-python /usr/bin/python
  188. Action application/x-lua /usr/bin/lua
  189. Action application/x-ruby /usr/bin/ruby
  190. Action application/x-php /usr/bin/php-cgi
  191. CgiPrefix CGI_
  192. CgiEscape on
  193. LimitProcesses 10
  194. </if>
  195. #
  196. # Directory listings. This provides a HTML directory list of the directory
  197. # corresponding to the URI.
  198. # SECURITY: This enables attackers to read directory contents.
  199. # SECURITY: Do not do this outside a scoping route.
  200. #
  201. # <if DIR_MODULE>
  202. # <Route /URI-to-list>
  203. # Options Indexes
  204. # IndexOrder ascending name
  205. # IndexOptions FancyIndexing FoldersFirst
  206. # </Route>
  207. # </if>
  208. #
  209. # Enable the action handler for simple URI to "C" bindings
  210. # This is used by the web-form Auth mechanism
  211. #
  212. <Route ^/action/>
  213. SetHandler actionHandler
  214. </Route>
  215. <if ESP_MODULE>
  216. AddHandler espHandler esp
  217. </if>
  218. #
  219. # The fileHandler matches all other extensions
  220. #
  221. AddHandler fileHandler
  222. #
  223. # Add the trace method if required
  224. #
  225. # Methods add TRACE
  226. #
  227. # WARNING: this will enable the PUT and DELETE methods to upload and remove
  228. # documents. Only do this inside routes intended for that purpose.
  229. #
  230. # <Route /putable>
  231. # Documents ./modifyable
  232. # PutMethod on
  233. # </Route>
  234. #
  235. # Set a default response cache lifespan
  236. #
  237. Cache 1day
  238. #
  239. # Session state duration.
  240. #
  241. SessionTimeout 30mins
  242. #
  243. # Set the cookie name and determine if the cookie is visible to Javascript
  244. # (default is httponly, invisible to scripts). Making cookies visible
  245. # increases the XSS potential.
  246. #
  247. # SessionCookie name=NAME visible=false
  248. #
  249. # Maximum duration to parse the request headers
  250. #
  251. RequestParseTimeout 5sec
  252. #
  253. # Maximum request duration.
  254. #
  255. RequestTimeout 10mins
  256. #
  257. # Maximum request and connection inactivity duration
  258. #
  259. InactivityTimeout 1min
  260. #
  261. # Request timeout when appweb is terminating or restarting
  262. #
  263. ExitTimeout 30secs
  264. #
  265. # Maximum number of worker threads in the Appweb worker pool. Must have at
  266. # least one. One thread will effectively single-thread the server. Appweb
  267. # will automatically adjust the number of workers between the minimum
  268. # specified by the MinWorkers and the maximum specified here. Every ten
  269. # minutes, Appweb will prune workers that have been idle for five minutes.
  270. # Appweb has two non-worker threads: one for the master event loop and one
  271. # for the garbage collector. So the total number of Appweb threads will be
  272. # two plus the number of active workers.
  273. #
  274. LimitWorkers 4
  275. #
  276. # Minimum number of worker threads. Pre-start and always preserve this
  277. # number of workers threads.
  278. #
  279. # MinWorkers 5
  280. #
  281. # Memory allocation error policy. This defines what Appweb will do if
  282. # the memory limit defined by LimitMemory is exceeded. Choose from "continue"
  283. # to prune non-critical response cache and session state, but continue on.
  284. # This make the memory limit a soft limit. Or select "restart" to do a
  285. # graceful shutdown and then appman will restart appweb.
  286. #
  287. MemoryPolicy restart
  288. #
  289. # Maximum application memory. Invokes MemoryPolicy if exceeded.
  290. # Redline at 95%.
  291. #
  292. LimitMemory 100MB
  293. #
  294. # Maximum cache size for response caching and sessions
  295. #
  296. LimitCache 10MB
  297. #
  298. # Maximum item size that can be cached
  299. #
  300. LimitCacheItem 200K
  301. #
  302. # Maximum number of total client connections.
  303. #
  304. LimitConnections 50
  305. #
  306. # Maximum number of simultaneous client systems. Set to zero for unlimited.
  307. #
  308. LimitClients 20
  309. #
  310. # Maximum number of open files/sockets on unix systems.
  311. # Set to zero for the maximum possible value.
  312. #
  313. LimitFiles 0
  314. #
  315. # Maximum packet size for pipeline queues
  316. #
  317. LimitPacket 32K
  318. #
  319. # Maximum number of network connections per client (IP). This helps prevent denial of service attacks.
  320. #
  321. LimitConnectionsPerClient 20
  322. #
  323. # Maximum number of simultaneous requests per client (IP). This helps prevent denial of service attacks.
  324. #
  325. LimitRequestsPerClient 20
  326. #
  327. # Number of HTTP requests to accept on a single TCP/IP connection
  328. # Reduce this number to minimize the chance of DoS attacks.
  329. #
  330. LimitKeepAlive 200
  331. #
  332. # Maximum size of the total request content body (includes header)
  333. #
  334. LimitRequestBody 2MB
  335. #
  336. # Maximum size of a request form
  337. #
  338. LimitRequestForm 32K
  339. #
  340. # Maximum size of request header
  341. #
  342. LimitRequestHeader 32K
  343. #
  344. # Maximum number of request header lines
  345. #
  346. LimitRequestHeaderLines 64
  347. #
  348. # Maximum size of the maximum response body
  349. #
  350. LimitResponseBody 2GB
  351. #
  352. # Maximum response chunk size
  353. #
  354. LimitChunk 64K
  355. #
  356. # Maximum request URI size
  357. #
  358. LimitUri 8K
  359. #
  360. # WARNING: Change this very carefully. Typically operating systems with
  361. # virtual memory can effectively allocate the stack size. Systems with
  362. # non-virtual memory may need to define this.
  363. # ThreadStack 64K
  364. #
  365. # Cache these extensions at the client for 1day.
  366. # Clients will refresh only if content is stale in their local cache.
  367. # This causes Expires/Cache-Control headers to be generated.
  368. #
  369. # Cache client=1day extensions="html,gif,jpeg,jpg,png,pdf,ico,js"
  370. #
  371. # Cache at the server with a lifespan of one hour.
  372. # All requests with the same URI path, regardless of request params are
  373. # cached as one.
  374. #
  375. # Cache server=1hour /cache.esp /cache.cgi
  376. #
  377. # To define a document to present for errors. If the URI is local the
  378. # error document will be served with the original status code. If the URI
  379. # is not local (starts with http), then a redirect (302) status code will
  380. # be used to redirect the client to the error document.
  381. #
  382. # ErrorDocument 404 /notFound.html
  383. #
  384. # Other useful directives
  385. #
  386. # Redirect temp /pressRelease.html https://${request:serverName}/fixedPressRelease.html
  387. # Redirect temp /pressRelease.html /fixedPressRelease.html
  388. # Redirect 410 /membersOnly
  389. # AddLanguage en english
  390. # AddLanguageRoot en englishContentDir
  391. # DefaultLanguage fr
  392. # StreamInput [!] mimeType URI
  393. # TypesConfig "mime.types"
  394. #
  395. # Create a virtual host
  396. #
  397. # <VirtualHost *:5000>
  398. # Listen 5000
  399. # Documents web
  400. # </VirtualHost>
  401. #
  402. # Useful Route directives
  403. #
  404. # <Route /pattern>
  405. # # Restrict the permissible methods. Default is to allow all methods sans DELETE, PUT, TRACE.
  406. # # Also see TraceMethod and PutMethod directives
  407. # Methods POST
  408. # </Route>
  409. #
  410. # Serve gziped files if an equivalent file with a "*.gz" extension exists
  411. # Map compressed
  412. #
  413. # WebSockets with an ESP handler
  414. #
  415. # <Route ^/websockets/{controller}/{action}$>
  416. # Prefix /websockets
  417. # AddFilter webSocketFilter
  418. # AddHandler espHandler
  419. # Source websockets.c
  420. # Target run $1-$2
  421. #
  422. # # Optimal to have the frame limit smaller than the packet limit. This way complete frames can be transferred.
  423. # # The Frame limit is a soft limit and can be exceeded. Outgoing messages are broken into frames of this size.
  424. #
  425. # LimitWebSockets 50
  426. # LimitWebSocketsMessage 2GB
  427. # LimitWebSocketsPacket 8K
  428. # LimitWebSocketsFrame 4K
  429. # RequestTimeout 2days
  430. # InactivityTimeout 1hour
  431. # WebSocketsProtocol chat
  432. # WebSocketsPing 30sec
  433. # IgnoreEncodingErrors on
  434. # # PreserveFrames off
  435. # </Route>
  436. #
  437. # Emergency DOS protection
  438. # If under attack, these directives may be useful
  439. #
  440. # Deny IPaddr-or-hosts
  441. # LimitConnectionsPerClient 10
  442. # LimitRequestsPerClient 10
  443. # LimitParseTimeout 2sec
  444. # LimitKeepAlive 20
  445. # InactivityTimeout 15sec
  446. #
  447. # Include per-app configuration
  448. #
  449. Include apps/*.conf