config.sample.php 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138
  1. <?php
  2. // Configuration file for the webshop
  3. // Site settings
  4. define('SITE_NAME', 'Feuerwehr Freising Test Shop');
  5. define('SITE_URL', '/shop'); // Leave empty for relative URLs
  6. // Disclaimer (placeholder text shown on start page)
  7. define('DISCLAIMER_LINES', [
  8. 'Dieser Shop ist ein internes System für Mitglieder der Freiwilligen Feuerwehr Freising.',
  9. 'Diese Produkte können nicht von externen Personen bestellt werden.',
  10. ]);
  11. // Admin settings
  12. // Default password: admin123
  13. // Change these hashes after first login!
  14. //
  15. // To generate a new password hash in bash (using Python bcrypt):
  16. // python3 -c "import bcrypt; print(bcrypt.hashpw(b'your_new_password', bcrypt.gensalt(rounds=10, prefix=b'2y')).decode())"
  17. //
  18. // Alternative using htpasswd (if Apache tools are installed):
  19. // htpasswd -bnBC 10 "" your_new_password | sed 's/^://' | sed 's/\$2y\$/\$2y\$/'
  20. //
  21. // To add a new admin user:
  22. // 1) Create a new hash for the password (see commands above).
  23. // 2) Add a new entry to ADMIN_USERS: 'username' => 'hash'
  24. //
  25. // Note:
  26. // Runtime login source of truth is data/admins.json.
  27. // ADMIN_USERS is kept only as optional legacy reference.
  28. //
  29. // Example:
  30. // 'max' => '$2y$10$your_hash_here'
  31. //
  32. define('ADMIN_USERS', [
  33. 'admin' => '$2y$10$gArNDW.HhPmDcwYJ/xWRiOPkNop3695UIYzkV.G8WHQRUtLJVPLhy',
  34. 'manager' => '$2y$10$gArNDW.HhPmDcwYJ/xWRiOPkNop3695UIYzkV.G8WHQRUtLJVPLhy'
  35. ]);
  36. // Reservation settings
  37. define('RESERVATION_EXPIRY_DAYS', 60);
  38. define('ORDER_PREFIX', 'FWFS'); // Prefix for order number pattern: PREFIX-YEAR-SEQ
  39. // Browser-linked order history settings (no login required)
  40. define('ORDER_HISTORY_COOKIE_NAME', 'fw_shop_order_history');
  41. define('ORDER_HISTORY_COOKIE_TTL_DAYS', 365);
  42. define('ORDER_HISTORY_MAX_IDS', 10);
  43. define('ORDER_HISTORY_COOKIE_SECRET', 'change-this-order-history-secret'); // Change this to a long random secret
  44. // Email settings
  45. define('ADMIN_EMAIL', 'inbox@medowar.de'); // Fallback recipient if no admin account emails are configured
  46. define('FROM_EMAIL', 'shop@med0.de'); // Change to your sender email
  47. define('FROM_NAME', SITE_NAME);
  48. // Data file paths
  49. define('DATA_DIR', __DIR__ . '/data/');
  50. define('PRODUCTS_FILE', DATA_DIR . 'products.json');
  51. define('RESERVATIONS_FILE', DATA_DIR . 'reservations.json');
  52. define('ADMINS_FILE', DATA_DIR . 'admins.json');
  53. define('CATEGORIES_FILE', DATA_DIR . 'categories.json');
  54. define('FAQ_FILE', DATA_DIR . 'faq.json');
  55. // Backup and update client (Manage server)
  56. // -----------------------------------------------------------------------------
  57. // Connection. Instance and token come from the Manage server when the instance
  58. // is created there; the token is displayed exactly once. Leaving any of the
  59. // three empty disables backup upload, update check and heartbeat - the settings
  60. // page then says so instead of failing.
  61. define('MANAGE_SERVER_URL', 'https://manage.example.org'); // no trailing slash, no /api
  62. define('MANAGE_INSTANCE', '');
  63. define('MANAGE_TOKEN', '');
  64. // Seconds per HTTP request. Package download and backup upload use the long one.
  65. define('MANAGE_HTTP_TIMEOUT', 15);
  66. define('MANAGE_HTTP_TIMEOUT_LONG', 300);
  67. // Where the installed version lives. Never written by the client - it changes
  68. // when a release is rolled out over the installation.
  69. define('MANAGE_APP_ROOT', __DIR__);
  70. define('MANAGE_VERSION_FILE', __DIR__ . '/includes/version.php');
  71. define('MANAGE_VERSION_CONSTANT', 'APP_VERSION');
  72. // Working directories. Must be writable by PHP and must not be web-readable;
  73. // the root .htaccess denies all of data/.
  74. define('MANAGE_DIR', DATA_DIR . 'manage/');
  75. define('MANAGE_BACKUP_DIR', MANAGE_DIR . 'backups/'); // local archives
  76. define('MANAGE_WORK_DIR', MANAGE_DIR . 'work/'); // update staging, cleared after each run
  77. define('MANAGE_UPDATE_BACKUP_DIR', MANAGE_DIR . 'updates/'); // files an update overwrote
  78. define('MANAGE_LOG_FILE', MANAGE_DIR . 'manage-client.log');
  79. define('MANAGE_HEARTBEAT_STATE', MANAGE_DIR . 'heartbeat.json');
  80. define('MANAGE_MIGRATIONS_STATE', MANAGE_DIR . 'migrations.json');
  81. define('MANAGE_MIGRATIONS_DIR', __DIR__ . '/migrations');
  82. // What goes into a backup archive, relative to MANAGE_APP_ROOT.
  83. // 'glob' => shell glob, non-recursive 'dir' => recursive 'file' => single file
  84. // 'as' => path prefix inside the ZIP
  85. // assets/images holds product images uploaded through the admin UI; they exist
  86. // nowhere else, so a data-only backup would not survive a restore.
  87. // config.php is deliberately absent: backups are downloadable by anyone with a
  88. // Manage server login, and this file holds secrets.
  89. define('MANAGE_BACKUP_SOURCES', [
  90. ['as' => 'data', 'glob' => 'data/*.json'],
  91. ['as' => 'assets/images', 'dir' => 'assets/images'],
  92. ]);
  93. // Local archives kept on the server (minimum 1). Retention on the Manage server
  94. // is configured there and is usually much higher.
  95. define('MANAGE_BACKUP_LOCAL_RETENTION', 4);
  96. // This host has no cron, so an automatic backup is triggered by the admin
  97. // dashboard once this many seconds have passed since the last one. 0 disables
  98. // it and leaves only the button on the settings page.
  99. define('MANAGE_BACKUP_AUTO_INTERVAL_SECONDS', 604800); // 7 days
  100. // Compress archive entries (needs zlib) and upload every new backup.
  101. define('MANAGE_BACKUP_COMPRESS', true);
  102. define('MANAGE_BACKUP_UPLOAD', true);
  103. // Paths an update must never overwrite. A trailing slash marks a directory.
  104. // assets/images is deliberately NOT protected: the updater only touches paths
  105. // contained in the release package, so uploaded images survive anyway, while a
  106. // release can still ship its own images.
  107. define('MANAGE_UPDATE_PROTECTED_PATHS', ['config.php', 'data/', '.git/']);
  108. // A release package must contain at least one of these, otherwise it is
  109. // rejected before a single file is copied.
  110. define('MANAGE_UPDATE_SANITY_PATHS', ['admin/index.php', 'includes/functions.php']);
  111. // Callback after a successful deployment; see includes/after-update.php.
  112. define('MANAGE_UPDATE_POST_HOOK', [
  113. 'file' => __DIR__ . '/includes/after-update.php',
  114. 'callback' => 'shopAfterUpdate',
  115. ]);
  116. // Session settings
  117. if (session_status() === PHP_SESSION_NONE) {
  118. session_start();
  119. }