22 lines
1018 B
Bash
22 lines
1018 B
Bash
CORE_BASE_URL=http://127.0.0.1:8080
|
|
PLUGIN_HOST=127.0.0.1
|
|
PLUGIN_PORT=8091
|
|
# Optional public path when mounted behind a reverse proxy, e.g.
|
|
# /extensions/qiu.subscription-admin
|
|
PLUGIN_PUBLIC_BASE_PATH=
|
|
# Limit the session cookie to the plugin mount path in production.
|
|
PLUGIN_COOKIE_PATH=
|
|
# Set true only behind HTTPS. Non-loopback listeners fail closed when false.
|
|
PLUGIN_COOKIE_SECURE=false
|
|
# lax (same-site proxy), strict, or none (cross-site iframe; requires Secure).
|
|
PLUGIN_COOKIE_SAMESITE=lax
|
|
# Space-separated frame ancestors. Keep 'self' for same-origin proxying.
|
|
PLUGIN_FRAME_ANCESTORS='self'
|
|
# Set true only when the immediate reverse proxy is trusted and supplies XFF.
|
|
PLUGIN_TRUST_PROXY=false
|
|
# Development-only compatibility endpoints. Keep false in production; the
|
|
# unified Plugin Admin owns login, sessions and subscription BFF routes.
|
|
# Compatibility login/API is accepted only with PLUGIN_ENV=development and a
|
|
# loopback PLUGIN_HOST. Production should leave this false.
|
|
PLUGIN_STANDALONE_AUTH=false
|