CORE_BASE_URL=http://127.0.0.1:8080 PLUGIN_ENV=production PLUGIN_HOST=127.0.0.1 PLUGIN_PORT=8090 PLUGIN_REGISTRY_DIR=/var/lib/sub2api-add/plugin-admin PLUGIN_PUBLIC_BASE_PATH=/extensions/qiu.plugin-admin # Externally reachable Plugin Admin base URL (without /admin). Required when # applying the subscription module menu so Core always opens the shared Shell. PLUGIN_PUBLIC_URL=https://CORE_ORIGIN/extensions/qiu.plugin-admin PLUGIN_COOKIE_PATH=/extensions/qiu.plugin-admin/ PLUGIN_COOKIE_SECURE=false PLUGIN_COOKIE_SAMESITE=lax PLUGIN_FRAME_ANCESTORS='self' # Accept X-Forwarded-For only when the immediate proxy is loopback/trusted. PLUGIN_TRUST_PROXY=false PLUGIN_ALLOW_UNSIGNED=false PLUGIN_CONFIG_KEY=generate-and-replace-with-a-random-32-byte-secret # JSON object: {"publisher-key-id":"BASE64_ED25519_PUBLIC_KEY"} PLUGIN_TRUSTED_PUBLISHERS={} # The default catalog is a local file. For a remote catalog use an HTTPS URL # and list its exact host (including port when non-standard) below. PLUGIN_MARKETPLACE_INDEX=/var/lib/sub2api-add/plugin-admin/marketplace/index.json PLUGIN_MARKETPLACE_ALLOWED_HOSTS= # Required for a remote production catalog; pin the exact catalog bytes. PLUGIN_MARKETPLACE_INDEX_SHA256=