'hash' // // Note: // Runtime login source of truth is data/admins.json. // ADMIN_USERS is kept only as optional legacy reference. // // Example: // 'max' => '$2y$10$your_hash_here' // define('ADMIN_USERS', [ 'admin' => '$2y$10$gArNDW.HhPmDcwYJ/xWRiOPkNop3695UIYzkV.G8WHQRUtLJVPLhy', 'manager' => '$2y$10$gArNDW.HhPmDcwYJ/xWRiOPkNop3695UIYzkV.G8WHQRUtLJVPLhy' ]); // Reservation settings define('RESERVATION_EXPIRY_DAYS', 60); define('ORDER_PREFIX', 'FWFS'); // Prefix for order number pattern: PREFIX-YEAR-SEQ // Browser-linked order history settings (no login required) define('ORDER_HISTORY_COOKIE_NAME', 'fw_shop_order_history'); define('ORDER_HISTORY_COOKIE_TTL_DAYS', 365); define('ORDER_HISTORY_MAX_IDS', 10); define('ORDER_HISTORY_COOKIE_SECRET', 'change-this-order-history-secret'); // Change this to a long random secret // Email settings define('ADMIN_EMAIL', 'inbox@medowar.de'); // Fallback recipient if no admin account emails are configured define('FROM_EMAIL', 'shop@med0.de'); // Change to your sender email define('FROM_NAME', SITE_NAME); // Data file paths define('DATA_DIR', __DIR__ . '/data/'); define('PRODUCTS_FILE', DATA_DIR . 'products.json'); define('RESERVATIONS_FILE', DATA_DIR . 'reservations.json'); define('ADMINS_FILE', DATA_DIR . 'admins.json'); define('CATEGORIES_FILE', DATA_DIR . 'categories.json'); define('FAQ_FILE', DATA_DIR . 'faq.json'); // Backup and update client (Manage server) // ----------------------------------------------------------------------------- // Connection. Instance and token come from the Manage server when the instance // is created there; the token is displayed exactly once. Leaving any of the // three empty disables backup upload, update check and heartbeat - the settings // page then says so instead of failing. define('MANAGE_SERVER_URL', 'https://manage.example.org'); // no trailing slash, no /api define('MANAGE_INSTANCE', ''); define('MANAGE_TOKEN', ''); // Seconds per HTTP request. Package download and backup upload use the long one. define('MANAGE_HTTP_TIMEOUT', 15); define('MANAGE_HTTP_TIMEOUT_LONG', 300); // Where the installed version lives. Never written by the client - it changes // when a release is rolled out over the installation. define('MANAGE_APP_ROOT', __DIR__); define('MANAGE_VERSION_FILE', __DIR__ . '/includes/version.php'); define('MANAGE_VERSION_CONSTANT', 'APP_VERSION'); // Working directories. Must be writable by PHP and must not be web-readable; // the root .htaccess denies all of data/. define('MANAGE_DIR', DATA_DIR . 'manage/'); define('MANAGE_BACKUP_DIR', MANAGE_DIR . 'backups/'); // local archives define('MANAGE_WORK_DIR', MANAGE_DIR . 'work/'); // update staging, cleared after each run define('MANAGE_UPDATE_BACKUP_DIR', MANAGE_DIR . 'updates/'); // files an update overwrote define('MANAGE_LOG_FILE', MANAGE_DIR . 'manage-client.log'); define('MANAGE_HEARTBEAT_STATE', MANAGE_DIR . 'heartbeat.json'); define('MANAGE_MIGRATIONS_STATE', MANAGE_DIR . 'migrations.json'); define('MANAGE_MIGRATIONS_DIR', __DIR__ . '/migrations'); // What goes into a backup archive, relative to MANAGE_APP_ROOT. // 'glob' => shell glob, non-recursive 'dir' => recursive 'file' => single file // 'as' => path prefix inside the ZIP // assets/images holds product images uploaded through the admin UI; they exist // nowhere else, so a data-only backup would not survive a restore. // config.php is deliberately absent: backups are downloadable by anyone with a // Manage server login, and this file holds secrets. define('MANAGE_BACKUP_SOURCES', [ ['as' => 'data', 'glob' => 'data/*.json'], ['as' => 'assets/images', 'dir' => 'assets/images'], ]); // Local archives kept on the server (minimum 1). Retention on the Manage server // is configured there and is usually much higher. define('MANAGE_BACKUP_LOCAL_RETENTION', 4); // This host has no cron, so an automatic backup is triggered by the admin // dashboard once this many seconds have passed since the last one. 0 disables // it and leaves only the button on the settings page. define('MANAGE_BACKUP_AUTO_INTERVAL_SECONDS', 604800); // 7 days // Compress archive entries (needs zlib) and upload every new backup. define('MANAGE_BACKUP_COMPRESS', true); define('MANAGE_BACKUP_UPLOAD', true); // Paths an update must never overwrite. A trailing slash marks a directory. // assets/images is deliberately NOT protected: the updater only touches paths // contained in the release package, so uploaded images survive anyway, while a // release can still ship its own images. define('MANAGE_UPDATE_PROTECTED_PATHS', ['config.php', 'data/', '.git/']); // A release package must contain at least one of these, otherwise it is // rejected before a single file is copied. define('MANAGE_UPDATE_SANITY_PATHS', ['admin/index.php', 'includes/functions.php']); // Callback after a successful deployment; see includes/after-update.php. define('MANAGE_UPDATE_POST_HOOK', [ 'file' => __DIR__ . '/includes/after-update.php', 'callback' => 'shopAfterUpdate', ]); // Session settings if (session_status() === PHP_SESSION_NONE) { session_start(); }