52 lines
1.6 KiB
TOML
52 lines
1.6 KiB
TOML
# nx9-auth Configuration Reference
|
|
# Copy this file to /etc/nx9-auth/config.toml and adjust for your environment.
|
|
|
|
[server]
|
|
# Interface to bind on. Use 127.0.0.1 if running behind a reverse proxy.
|
|
host = "0.0.0.0"
|
|
|
|
# Port the service listens on.
|
|
port = 8655
|
|
|
|
# Session cookie Secure flag.
|
|
# false = works over plain HTTP (typical self-hosted / LAN).
|
|
# true = required when the UI is served over HTTPS (or a TLS reverse proxy).
|
|
# If Secure=true on plain HTTP, browsers drop the cookie and login/password
|
|
# reset will appear broken (subsequent API calls return 401).
|
|
cookie_secure = false
|
|
|
|
# Production mode: refuses cookie_secure=false and enables HSTS headers.
|
|
# TLS is usually terminated at a reverse proxy; set cookie_secure=true there.
|
|
production = false
|
|
|
|
[database]
|
|
# Absolute path to the SQLite database file.
|
|
# The directory must be writable by the nx9-auth user.
|
|
path = "/var/lib/nx9-auth/auth.db"
|
|
|
|
[security]
|
|
# Session idle timeout in hours. Sessions unused for longer than this are expired.
|
|
session_ttl_hours = 24
|
|
|
|
# Session absolute lifetime in days. Sessions older than this are always expired,
|
|
# regardless of activity.
|
|
session_absolute_ttl_days = 30
|
|
|
|
# Default API token lifetime in days (365 = 1 year).
|
|
token_ttl_days = 365
|
|
|
|
# Argon2id memory cost in KiB. Higher = more secure but slower.
|
|
# Minimum recommended: 65536 (64 MiB)
|
|
argon2_memory = 65536
|
|
|
|
# Argon2id iteration count. Higher = more secure but slower.
|
|
argon2_iterations = 3
|
|
|
|
# Argon2id parallelism (number of threads).
|
|
argon2_parallelism = 1
|
|
|
|
[audit]
|
|
# Enable structured audit logging to the database.
|
|
# Disable only in development environments.
|
|
enabled = true
|