CORE_BASE_URL=http://127.0.0.1:8080 PLUGIN_HOST=127.0.0.1 PLUGIN_PORT=8091 # Optional public path when mounted behind a reverse proxy, e.g. # /extensions/qiu.subscription-admin PLUGIN_PUBLIC_BASE_PATH= # Limit the session cookie to the plugin mount path in production. PLUGIN_COOKIE_PATH= # Set true only behind HTTPS. Non-loopback listeners fail closed when false. PLUGIN_COOKIE_SECURE=false # lax (same-site proxy), strict, or none (cross-site iframe; requires Secure). PLUGIN_COOKIE_SAMESITE=lax # Space-separated frame ancestors. Keep 'self' for same-origin proxying. PLUGIN_FRAME_ANCESTORS='self' # Set true only when the immediate reverse proxy is trusted and supplies XFF. PLUGIN_TRUST_PROXY=false