The authentification only stay valud for the given time. After that time a automatic logout from the application will happen.
- auth.timeout = 1800
Ringo provides methods to allow users to register a new account or send requests to reset their passwords. Botch subsystems can be enabled by changing the following values.
- auth.register_user = false
- auth.password_reminder = false
To enable CSRF protection you can configure ringo to include a CSRF synchronizer token to each form to protect POST request against CSRF attacks.
- security.enable_csrf_check = true
However, for testing issues it might be usefull to disable this feature.
See Cookie options on for more details.
- security.cookie_secret = ‘secret’
- security.cookie_secure = false
- security.cookie_ip = false
- security.cookie_path = ‘/’
- security.cookie_httponly = false
The cookie_ip setting will only apply to the auth_tkt cookie for the authorisation. Other option apply for all cookies set.
See this page for more informations.
- security.header_secure = true
- security.header_clickjacking = true
- security.header_csp = false
You can define CSP Options by configuring one of the following options:
- security.csp.default_src
- security.csp.script_src
- security.csp.object_src
- security.csp.style_src
- security.csp.img_src
- security.csp.media_src
- security.csp.frame_src
- security.csp.font_src
- security.csp.connect_src
- security.csp.sandbox
Number of seconds the cached content will stay valid. A value of non means no caching at all and all elements are loaded on every request.
The enhance the security follwing the recommodation of measurement M 4.401 of BSI Grundschutz you should disable the caching.
- security.page_http_cache = 0
- security.static_http_cache = 3600
Note
The caching setting of the page currently only applies to the CRUD operations of the modules and not to the static pages like contact, home etc.
Warning
Caching of dynmic generated pages might result in some unexpected behaviour such as outdated items in overview lists. Therefor ther default disables caching here.
- mail.host =
- mail.default_sender =
- mail.username =
- mail.password =