mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-02 10:53:44 +00:00
- resources/*.ini list the 73 settings the catalog knew but the files left out (dashboard AI helper, backups, metrics, public status, strikes, property rent and reputation, chat log, contraband, logins...), with their title, description and default. The test ShippedFilesListEveryCatalogSetting keeps it that way; with DLU_WRITE_INI_TEMPLATES=1 it writes the missing ones. - ConfigSync forgets a setting row when its key has left a file the server read: from the file, no value set on the dashboard, not a permission level. Before, rows of removed keys stayed forever. - Docs: where setting rows come from and when they go, the templates. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
292 lines
13 KiB
INI
292 lines
13 KiB
INI
# Web Dashboard Configuration
|
|
|
|
# The port to listen on for HTTP/WebSocket connections
|
|
port=2006
|
|
|
|
# UDP port for the dashboard's connection to the master server (the next port is used too). It must not clash with
|
|
# another server's ports: auth uses 1500-1501, chat 2005-2006, worlds 3000 and up.
|
|
net_port=2010
|
|
|
|
# The IP address to bind to
|
|
# Use 127.0.0.1 for localhost only (recommended for security)
|
|
# Use 0.0.0.0 to allow external access; prefer a reverse proxy with HTTPS and secure_cookies=1
|
|
listen_ip=127.0.0.1
|
|
|
|
# How often to broadcast updates to connected clients (in milliseconds)
|
|
broadcast_interval=2000
|
|
|
|
# Minimum GM level required to access the dashboard (default: 0 = any user)
|
|
min_dashboard_gm_level=0
|
|
|
|
# Secret used to sign login tokens (at least 32 characters). If empty, a random secret is generated
|
|
# on first start and stored in dashboard_jwt_secret next to the binary. Changing it signs everyone out.
|
|
jwt_secret=
|
|
|
|
# Set to 1 when the dashboard is served over HTTPS (e.g. behind a reverse proxy) so the session
|
|
# cookie is only ever sent over encrypted connections.
|
|
secure_cookies=0
|
|
|
|
# Set to 1 if a reverse proxy sits in front of the dashboard, so rate limits use the client's address
|
|
# from X-Forwarded-For instead of the proxy's. Only enable this when the dashboard is not reachable directly.
|
|
behind_proxy=0
|
|
|
|
# Threads converting the game client's models for the 3D views, so the dashboard keeps answering meanwhile.
|
|
# 0 picks half the CPU cores (2 to 4). Read at startup.
|
|
scenery_workers=0
|
|
|
|
# Allow players to create accounts at /register
|
|
allow_registration=0
|
|
|
|
# Require a valid play key to register (keys are managed on the Play Keys page)
|
|
registration_requires_play_key=1
|
|
|
|
# Allow GM 8+ to replace a character's XML from the character page. The owner is disconnected first.
|
|
enable_char_xml_upload=0
|
|
|
|
# ---- Email (password resets and address confirmation) ----
|
|
# Email is enabled once smtp_host, smtp_from_address and dashboard_url are all set.
|
|
|
|
# Public address of the dashboard, used for links in emails, e.g. https://dashboard.example.com
|
|
# Links are never built from the request's Host header, so this must be set explicitly.
|
|
dashboard_url=
|
|
|
|
# Where the dashboard reaches the UGC server (normally on the same machine) for its status and the files it made;
|
|
# the dashboard's pages load them through the dashboard, so the browser never needs to reach the UGC server.
|
|
# Empty: http://127.0.0.1:2008
|
|
ugc_internal_url=
|
|
|
|
# The UGC server's public address, only for "open on the UGC server" links, e.g. https://ugc.example.com. Empty: none.
|
|
ugc_public_url=
|
|
|
|
# SMTP server and port. Typical: 587 with starttls, or 465 with tls.
|
|
smtp_host=
|
|
smtp_port=587
|
|
|
|
# starttls, tls (implicit TLS from the first byte) or none (only for a relay on the same machine)
|
|
smtp_security=starttls
|
|
|
|
# How to sign in to the SMTP server: password, or oauth2 (required for Microsoft 365, recommended for Gmail)
|
|
smtp_auth=password
|
|
|
|
# Login for the SMTP server. Credentials are never sent without TLS.
|
|
# With oauth2, smtp_username is the mailbox address (defaults to smtp_from_address) and no password is used.
|
|
smtp_username=
|
|
smtp_password=
|
|
|
|
# ---- OAuth2 (smtp_auth=oauth2) ----
|
|
# microsoft, google or custom. microsoft and google fill in the URLs, scopes and SMTP server for you.
|
|
smtp_oauth2_provider=
|
|
# From your app registration (Azure portal / Google Cloud console)
|
|
smtp_oauth2_client_id=
|
|
smtp_oauth2_client_secret=
|
|
# authorization_code: an operator clicks "Connect mail account" on their account page once.
|
|
# client_credentials: Microsoft 365 app-only sending (SMTP.SendAsApp); needs smtp_oauth2_tenant.
|
|
smtp_oauth2_grant=authorization_code
|
|
# Microsoft only: your tenant ID or domain (defaults to common)
|
|
smtp_oauth2_tenant=
|
|
# Only needed for provider=custom
|
|
smtp_oauth2_authorize_url=
|
|
smtp_oauth2_token_url=
|
|
smtp_oauth2_scope=
|
|
|
|
# Sender shown to players
|
|
smtp_from_address=
|
|
smtp_from_name=DarkflameServer
|
|
|
|
# Server certificates are checked against the system's trusted certificates. Point this at a PEM bundle to
|
|
# trust a private CA instead. Set smtp_verify_certificate=0 only for local testing.
|
|
smtp_ca_file=
|
|
smtp_verify_certificate=1
|
|
|
|
# Seconds to wait for the SMTP server
|
|
smtp_timeout=20
|
|
|
|
# Require an email address when registering (only when email is enabled)
|
|
registration_requires_email=0
|
|
|
|
# ---- Two-factor login ----
|
|
# Staff at or above this GM level must set up two-factor login (authenticator app) before using the dashboard.
|
|
# 0 turns the requirement off; anyone can still turn it on for their own account.
|
|
require_2fa_gm_level=0
|
|
# Name shown in authenticator apps
|
|
totp_issuer=DarkflameServer
|
|
# 64 hex characters used to encrypt two-factor secrets. Leave empty to generate dashboard_totp_key next to the
|
|
# server; back that file up with the database, or everyone's two-factor login stops working.
|
|
totp_key=
|
|
|
|
# ---- Economy checks (run each night for the day before; schedule and on/off on the dashboard's Tasks page) ----
|
|
# Flag a character who earned more than this many times the median player, and more than the minimum, in a day
|
|
anomaly_coin_multiplier=20
|
|
anomaly_coin_minimum=100000
|
|
# Flag an item created more than this many times its usual daily amount, and more than the minimum, in a day
|
|
anomaly_item_multiplier=10
|
|
anomaly_item_minimum=200
|
|
# Also scan every character for duplicated items each night (reads all character data)
|
|
economy_duplicate_scan=1
|
|
|
|
# ---- Economy ledger size ----
|
|
# Daily detail older than this many days is merged into one row per month
|
|
economy_detail_days=180
|
|
economy_map_days=90
|
|
# Trades and mail older than this many days are deleted
|
|
economy_transfer_days=730
|
|
|
|
# ---- Log retention, in days (0 keeps everything). Pruned by the log_pruning task, once a day by default. ----
|
|
log_activity_days=365
|
|
log_command_days=365
|
|
log_audit_days=730
|
|
log_cheat_detection_days=365
|
|
# Finished runs of scheduled tasks, with their logs
|
|
log_task_days=90
|
|
|
|
# ---- Permissions ----
|
|
# Change the lowest GM level (1-9) allowed to do something on the dashboard, e.g. permission_accounts_ban=3.
|
|
# Every permission and its name is listed on the dashboard's Permissions page, where GM 9 can also change them;
|
|
# a level set there beats this file.
|
|
|
|
# ---- Dashboard sign-in ----
|
|
# Password reset with recovery codes: Players with two-factor login can choose a new password on /forgot_password with a
|
|
# code from their authenticator app and one of their recovery codes, no email needed.
|
|
password_reset_recovery_codes=1
|
|
|
|
# ---- OAuth2 sign-in ----
|
|
# Refresh token: Set by Connect mail account; only set it by hand for a token from elsewhere. Read when the server
|
|
# starts.
|
|
smtp_oauth2_refresh_token=
|
|
|
|
# ---- Tools ----
|
|
# Challenge milestones: Percentages of a community challenge announced in game as it gets there, e.g. 25,50,75
|
|
# (completing it is always announced).
|
|
challenge_milestones=25,50,75,100
|
|
|
|
# ---- Public pages ----
|
|
# Public server status: The page at /status, its JSON at /api/public/status (for server lists) and a widget for other
|
|
# sites.
|
|
public_status=0
|
|
# Server name: Shown on the status page and widget.
|
|
public_server_name=DarkflameServer
|
|
# Players per world: How many players are in each world.
|
|
public_status_players=1
|
|
# Names of players online: Character names (never staff, never account names) by world.
|
|
public_status_names=0
|
|
# Uptime: How long the server has been up, and how much of the last day and week.
|
|
public_status_uptime=1
|
|
# Server health: Whether login and chat are up, and how many worlds are running.
|
|
public_status_health=1
|
|
# Leaderboard places: The top places of every leaderboard. 0 leaves leaderboards out. (places)
|
|
public_status_leaderboard_top=3
|
|
# Community challenges: Public challenges that are running or finished in the last week, with their progress.
|
|
public_status_challenges=1
|
|
# Live events: Live events running now (their title, where, and until when).
|
|
public_status_events=1
|
|
# Widget for other sites: A small page at /status/widget other sites may show in an iframe.
|
|
public_status_widget=1
|
|
# Refresh every: The status is worked out at most this often, however many people ask. (seconds)
|
|
public_status_cache_seconds=60
|
|
# Property showcase for everyone: Let people who aren't signed in browse approved public properties at /showcase.
|
|
# Signed-in players need the showcase_view permission.
|
|
showcase_public=0
|
|
|
|
# ---- Metrics ----
|
|
# API key rate limit: Requests a minute an API key may make unless the key sets its own limit (up to 6000). (/min)
|
|
api_key_rate_limit=120
|
|
# Metrics endpoint: Off: /metrics answers 404. On: scrapers send an API token of an account with metrics_view, or the
|
|
# token below.
|
|
metrics_enabled=0
|
|
# Scraper token: A shared secret scrapers may send as Authorization: Bearer instead of an API token. At least 16
|
|
# characters; empty: API tokens only.
|
|
metrics_token=
|
|
# Allowed addresses: Comma separated addresses or IPv4 ranges (10.0.0.0/8) that may fetch metrics. Empty: any.
|
|
metrics_allowed_ips=
|
|
# Refresh every: Metrics are worked out at most this often, however often they are fetched. (seconds)
|
|
metrics_cache_seconds=10
|
|
|
|
# ---- Strikes ----
|
|
# Strikes count for: Older strikes stay on the account's record but no longer count. 0: they always count. (days)
|
|
strike_expiry_days=0
|
|
# Warn at: When an account reaches this many active strikes it gets a warning, shown to the player if they're online. 0:
|
|
# never. (strikes)
|
|
strike_warn_at=0
|
|
# Mute at: ...is muted for the days below. 0: never. (strikes)
|
|
strike_mute_at=0
|
|
# Mute for (days)
|
|
strike_mute_days=3
|
|
# Ban at: ...is banned for the days below. 0: never. (strikes)
|
|
strike_ban_at=0
|
|
# Ban for: 0: permanently. (days)
|
|
strike_ban_days=7
|
|
|
|
# ---- AI moderator helper ----
|
|
# AI moderator helper: Off: the Suggest buttons say the helper is off and nothing is sent.
|
|
ai_helper_enabled=0
|
|
# Claude API key: From console.anthropic.com. Never shown back or logged.
|
|
claude_api_key=
|
|
# API address: Only change it for a proxy or a local test server (http:// only for this machine).
|
|
claude_api_base=https://api.anthropic.com
|
|
# Model: Any model ID works. claude-sonnet-5 is a good balance; claude-haiku-4-5-20251001 is cheaper, claude-opus-5-5
|
|
# more careful.
|
|
claude_model=claude-sonnet-5
|
|
# Hold answers to a schema: Ask the API for JSON of the expected shape (structured outputs). Turn off only if a model
|
|
# refuses it; answers are checked either way.
|
|
claude_structured_output=1
|
|
# Server rules: Your code of conduct, as players know it. Sent with every request so suggestions follow your rules.
|
|
ai_helper_rules=
|
|
# Time out after: Per try; failed tries (busy API, network) are retried up to three times. (seconds)
|
|
ai_helper_timeout=60
|
|
# Longest answer: max_tokens per request: caps what one suggestion can cost. (tokens)
|
|
ai_helper_max_tokens=2000
|
|
# Requests per minute: For the whole dashboard. (requests)
|
|
ai_helper_per_minute=5
|
|
# Requests per day: For the whole dashboard, per UTC day. Asking about the same thing again reuses the stored suggestion
|
|
# and costs nothing. (requests)
|
|
ai_helper_per_day=200
|
|
# Chat around the item: How far before and after a report or message the player's chat is included. (minutes)
|
|
ai_helper_chat_minutes=10
|
|
|
|
# ---- Backups ----
|
|
# Backup folder: Relative to the server binaries unless absolute.
|
|
backup_folder=backups
|
|
# Backups to keep: Older backups are deleted after each new one. 0 keeps them all. (backups)
|
|
backup_keep=7
|
|
# mysqldump program: The mysqldump (or mariadb-dump) to run.
|
|
backup_mysqldump=mysqldump
|
|
|
|
# ---- Logs ----
|
|
# Chat log (days)
|
|
log_chat_days=90
|
|
# Login addresses: Addresses an account hasn't logged in from for this long are forgotten. (days)
|
|
log_login_address_days=90
|
|
# Server health history: Minute-by-minute player counts and uptime. (days)
|
|
health_days=30
|
|
# Server traffic history: Minute-by-minute packets, bytes and HTTP requests of every server (Diagnostics). The last hour
|
|
# at one second is only kept in memory. (days)
|
|
traffic_days=30
|
|
|
|
# ---- Log bundles ----
|
|
# At most: How much log text (before compression) one download may hold. Bundles are built in the system's temporary
|
|
# folder and deleted once sent. (MB)
|
|
log_bundle_max_mb=512
|
|
|
|
# ---- Player movement ----
|
|
# Record player movement: Keeps a player's position every few seconds while they move, and every 30 seconds while they
|
|
# stand still.
|
|
position_history=1
|
|
# Record every: While a player moves. Less often keeps the table smaller; replays then move in straighter lines.
|
|
# (seconds)
|
|
position_history_seconds=5
|
|
# Keep movement for: About 17,000 rows per player online around the clock per day at 5 seconds. (days)
|
|
position_history_days=3
|
|
|
|
# ---- Message inspector ----
|
|
# Keep captures for: 0: no age limit. (days)
|
|
inspector_session_days=30
|
|
# At most: When all saved captures together take more, the oldest are deleted. A busy 15 minute capture can take 50 MB.
|
|
# 0: no size limit. (MB)
|
|
inspector_max_mb=1024
|
|
|
|
# ---- Character history ----
|
|
# Snapshots: Older snapshots are deleted, but each character keeps its newest few (below). (days)
|
|
snapshot_days=90
|
|
# Always keep per character (snapshots)
|
|
snapshot_keep=10
|