# Web Dashboard Configuration # The port to listen on for HTTP/WebSocket connections port=2006 # UDP port for the dashboard's connection to the master server (the next port is used too). It must not clash with # another server's ports: auth uses 1500-1501, chat 2005-2006, worlds 3000 and up. net_port=2010 # The IP address to bind to # Use 127.0.0.1 for localhost only (recommended for security) # Use 0.0.0.0 to allow external access; prefer a reverse proxy with HTTPS and secure_cookies=1 listen_ip=127.0.0.1 # How often to broadcast updates to connected clients (in milliseconds) broadcast_interval=2000 # Minimum GM level required to access the dashboard (default: 0 = any user) min_dashboard_gm_level=0 # Secret used to sign login tokens (at least 32 characters). If empty, a random secret is generated # on first start and stored in dashboard_jwt_secret next to the binary. Changing it signs everyone out. jwt_secret= # Set to 1 when the dashboard is served over HTTPS (e.g. behind a reverse proxy) so the session # cookie is only ever sent over encrypted connections. secure_cookies=0 # Set to 1 if a reverse proxy sits in front of the dashboard, so rate limits use the client's address # from X-Forwarded-For instead of the proxy's. Only enable this when the dashboard is not reachable directly. behind_proxy=0 # Threads converting the game client's models for the 3D views, so the dashboard keeps answering meanwhile. # 0 picks half the CPU cores (2 to 4). Read at startup. scenery_workers=0 # Allow players to create accounts at /register allow_registration=0 # Require a valid play key to register (keys are managed on the Play Keys page) registration_requires_play_key=1 # Allow GM 8+ to replace a character's XML from the character page. The owner is disconnected first. enable_char_xml_upload=0 # ---- Email (password resets and address confirmation) ---- # Email is enabled once smtp_host, smtp_from_address and dashboard_url are all set. # Public address of the dashboard, used for links in emails, e.g. https://dashboard.example.com # Links are never built from the request's Host header, so this must be set explicitly. dashboard_url= # Where the browser loads previews (icons, meshes) from the UGC server, e.g. https://ugc.example.com # Empty: the dashboard's host name on port 2008 ugc_public_url= # SMTP server and port. Typical: 587 with starttls, or 465 with tls. smtp_host= smtp_port=587 # starttls, tls (implicit TLS from the first byte) or none (only for a relay on the same machine) smtp_security=starttls # How to sign in to the SMTP server: password, or oauth2 (required for Microsoft 365, recommended for Gmail) smtp_auth=password # Login for the SMTP server. Credentials are never sent without TLS. # With oauth2, smtp_username is the mailbox address (defaults to smtp_from_address) and no password is used. smtp_username= smtp_password= # ---- OAuth2 (smtp_auth=oauth2) ---- # microsoft, google or custom. microsoft and google fill in the URLs, scopes and SMTP server for you. smtp_oauth2_provider= # From your app registration (Azure portal / Google Cloud console) smtp_oauth2_client_id= smtp_oauth2_client_secret= # authorization_code: an operator clicks "Connect mail account" on their account page once. # client_credentials: Microsoft 365 app-only sending (SMTP.SendAsApp); needs smtp_oauth2_tenant. smtp_oauth2_grant=authorization_code # Microsoft only: your tenant ID or domain (defaults to common) smtp_oauth2_tenant= # Only needed for provider=custom smtp_oauth2_authorize_url= smtp_oauth2_token_url= smtp_oauth2_scope= # Sender shown to players smtp_from_address= smtp_from_name=DarkflameServer # Server certificates are checked against the system's trusted certificates. Point this at a PEM bundle to # trust a private CA instead. Set smtp_verify_certificate=0 only for local testing. smtp_ca_file= smtp_verify_certificate=1 # Seconds to wait for the SMTP server smtp_timeout=20 # Require an email address when registering (only when email is enabled) registration_requires_email=0 # ---- Two-factor login ---- # Staff at or above this GM level must set up two-factor login (authenticator app) before using the dashboard. # 0 turns the requirement off; anyone can still turn it on for their own account. require_2fa_gm_level=0 # Name shown in authenticator apps totp_issuer=DarkflameServer # 64 hex characters used to encrypt two-factor secrets. Leave empty to generate dashboard_totp_key next to the # server; back that file up with the database, or everyone's two-factor login stops working. totp_key= # ---- Economy checks (run each night for the day before; schedule and on/off on the dashboard's Tasks page) ---- # Flag a character who earned more than this many times the median player, and more than the minimum, in a day anomaly_coin_multiplier=20 anomaly_coin_minimum=100000 # Flag an item created more than this many times its usual daily amount, and more than the minimum, in a day anomaly_item_multiplier=10 anomaly_item_minimum=200 # Also scan every character for duplicated items each night (reads all character data) economy_duplicate_scan=1 # ---- Economy ledger size ---- # Daily detail older than this many days is merged into one row per month economy_detail_days=180 economy_map_days=90 # Trades and mail older than this many days are deleted economy_transfer_days=730 # ---- Log retention, in days (0 keeps everything). Pruned by the log_pruning task, once a day by default. ---- log_activity_days=365 log_command_days=365 log_audit_days=730 log_cheat_detection_days=365 # Finished runs of scheduled tasks, with their logs log_task_days=90 # ---- Permissions ---- # Change the lowest GM level (1-9) allowed to do something on the dashboard, e.g. permission_accounts_ban=3. # Every permission and its name is listed on the dashboard's Permissions page, where GM 9 can also change them; # a level set there beats this file.