Files
DarkflameServer/resources/dashboardconfig.ini
Aaron Kimbrell 95158f69b6 feat(dashboard): UGC gallery and viewer, reached through the dashboard
The /ugc page no longer needs the browser to reach the UGC server: the
dashboard fetches its status (/api/ugc/server/status), the files it made
(/api/ugc/files/<kind>/<id>/<file>) and its NIFs converted for the 3D view
(/api/ugc/mesh/<id>, NifFile like the scenery) from ugc_internal_url
(default http://127.0.0.1:2008) with libcurl on the worker threads, keeping
small answers briefly. ugc_public_url is only an "open on the UGC server"
link now.

The page gets an icon gallery beside the list, filtered by kind, state and a
search by id or owner (GetUgcProcessList/GetModularBuildProcessList take a
search), and a viewer: the generated NIF in 3D at any LOD, now or before it
was made again, with wireframe, vertex color and baked lighting switches, the
LXFML beside it, the icon now and before, and the stats with triangles before
and after hidden faces were removed. The status box shows CPU, memory, the
jobs' memory estimate with their limits, and throttling. The settings page
lists the UGC server's new settings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 22:31:07 -05:00

146 lines
6.0 KiB
INI

# Web Dashboard Configuration
# The port to listen on for HTTP/WebSocket connections
port=2006
# UDP port for the dashboard's connection to the master server (the next port is used too). It must not clash with
# another server's ports: auth uses 1500-1501, chat 2005-2006, worlds 3000 and up.
net_port=2010
# The IP address to bind to
# Use 127.0.0.1 for localhost only (recommended for security)
# Use 0.0.0.0 to allow external access; prefer a reverse proxy with HTTPS and secure_cookies=1
listen_ip=127.0.0.1
# How often to broadcast updates to connected clients (in milliseconds)
broadcast_interval=2000
# Minimum GM level required to access the dashboard (default: 0 = any user)
min_dashboard_gm_level=0
# Secret used to sign login tokens (at least 32 characters). If empty, a random secret is generated
# on first start and stored in dashboard_jwt_secret next to the binary. Changing it signs everyone out.
jwt_secret=
# Set to 1 when the dashboard is served over HTTPS (e.g. behind a reverse proxy) so the session
# cookie is only ever sent over encrypted connections.
secure_cookies=0
# Set to 1 if a reverse proxy sits in front of the dashboard, so rate limits use the client's address
# from X-Forwarded-For instead of the proxy's. Only enable this when the dashboard is not reachable directly.
behind_proxy=0
# Threads converting the game client's models for the 3D views, so the dashboard keeps answering meanwhile.
# 0 picks half the CPU cores (2 to 4). Read at startup.
scenery_workers=0
# Allow players to create accounts at /register
allow_registration=0
# Require a valid play key to register (keys are managed on the Play Keys page)
registration_requires_play_key=1
# Allow GM 8+ to replace a character's XML from the character page. The owner is disconnected first.
enable_char_xml_upload=0
# ---- Email (password resets and address confirmation) ----
# Email is enabled once smtp_host, smtp_from_address and dashboard_url are all set.
# Public address of the dashboard, used for links in emails, e.g. https://dashboard.example.com
# Links are never built from the request's Host header, so this must be set explicitly.
dashboard_url=
# Where the dashboard reaches the UGC server (normally on the same machine) for its status and the files it made;
# the dashboard's pages load them through the dashboard, so the browser never needs to reach the UGC server.
# Empty: http://127.0.0.1:2008
ugc_internal_url=
# The UGC server's public address, only for "open on the UGC server" links, e.g. https://ugc.example.com. Empty: none.
ugc_public_url=
# SMTP server and port. Typical: 587 with starttls, or 465 with tls.
smtp_host=
smtp_port=587
# starttls, tls (implicit TLS from the first byte) or none (only for a relay on the same machine)
smtp_security=starttls
# How to sign in to the SMTP server: password, or oauth2 (required for Microsoft 365, recommended for Gmail)
smtp_auth=password
# Login for the SMTP server. Credentials are never sent without TLS.
# With oauth2, smtp_username is the mailbox address (defaults to smtp_from_address) and no password is used.
smtp_username=
smtp_password=
# ---- OAuth2 (smtp_auth=oauth2) ----
# microsoft, google or custom. microsoft and google fill in the URLs, scopes and SMTP server for you.
smtp_oauth2_provider=
# From your app registration (Azure portal / Google Cloud console)
smtp_oauth2_client_id=
smtp_oauth2_client_secret=
# authorization_code: an operator clicks "Connect mail account" on their account page once.
# client_credentials: Microsoft 365 app-only sending (SMTP.SendAsApp); needs smtp_oauth2_tenant.
smtp_oauth2_grant=authorization_code
# Microsoft only: your tenant ID or domain (defaults to common)
smtp_oauth2_tenant=
# Only needed for provider=custom
smtp_oauth2_authorize_url=
smtp_oauth2_token_url=
smtp_oauth2_scope=
# Sender shown to players
smtp_from_address=
smtp_from_name=DarkflameServer
# Server certificates are checked against the system's trusted certificates. Point this at a PEM bundle to
# trust a private CA instead. Set smtp_verify_certificate=0 only for local testing.
smtp_ca_file=
smtp_verify_certificate=1
# Seconds to wait for the SMTP server
smtp_timeout=20
# Require an email address when registering (only when email is enabled)
registration_requires_email=0
# ---- Two-factor login ----
# Staff at or above this GM level must set up two-factor login (authenticator app) before using the dashboard.
# 0 turns the requirement off; anyone can still turn it on for their own account.
require_2fa_gm_level=0
# Name shown in authenticator apps
totp_issuer=DarkflameServer
# 64 hex characters used to encrypt two-factor secrets. Leave empty to generate dashboard_totp_key next to the
# server; back that file up with the database, or everyone's two-factor login stops working.
totp_key=
# ---- Economy checks (run each night for the day before; schedule and on/off on the dashboard's Tasks page) ----
# Flag a character who earned more than this many times the median player, and more than the minimum, in a day
anomaly_coin_multiplier=20
anomaly_coin_minimum=100000
# Flag an item created more than this many times its usual daily amount, and more than the minimum, in a day
anomaly_item_multiplier=10
anomaly_item_minimum=200
# Also scan every character for duplicated items each night (reads all character data)
economy_duplicate_scan=1
# ---- Economy ledger size ----
# Daily detail older than this many days is merged into one row per month
economy_detail_days=180
economy_map_days=90
# Trades and mail older than this many days are deleted
economy_transfer_days=730
# ---- Log retention, in days (0 keeps everything). Pruned by the log_pruning task, once a day by default. ----
log_activity_days=365
log_command_days=365
log_audit_days=730
log_cheat_detection_days=365
# Finished runs of scheduled tasks, with their logs
log_task_days=90
# ---- Permissions ----
# Change the lowest GM level (1-9) allowed to do something on the dashboard, e.g. permission_accounts_ban=3.
# Every permission and its name is listed on the dashboard's Permissions page, where GM 9 can also change them;
# a level set there beats this file.