mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-01 13:41:10 +00:00
1b1274486c
Introduces gitproxy module which spawns a small forward proxy as scanner for git calls Replaces hostmatcher with matchlist which supports port rules Deprecates ALLOWED_DOMAINS/BLOCKED_DOMAINS and ALLOW_LOCALNETWORKS settings in migration in favor of full names we have in security configs. Removes `external` preset in favor of lax/strict modes, strict mode requiring explicit ports if they aren't standard http/s ones. Breaking changes: - `external` preset no longer works as deny rule. To enforce that, use `strict` mode and allow ranges to connect to - Wildcards are no longer accepted in IP addresses - `*` is no longer allowed as entry in lists - domain rules now use curl like syntax `*.example.com` matching subdomains but not `example.com`, `example.com` matching itself and all subdomains. `example.*` is not a valid rule - In the default `lax` mode, `[security] ALLOWED_HOST_LIST` no longer restricts public hosts, set `EGRESS_MODE = strict` to keep an exclusive list. A startup warning flags this - Invalid list entries are logged at startup, invalid `BLOCKED_HOST_LIST`/`BLOCKED_DOMAINS` entries stop it Docs: https://gitea.com/gitea/docs/pulls/557 Signed-off-by: wxiaoguang <wxiaoguang@gmail.com> Co-authored-by: silverwind <me@silverwind.io> Co-authored-by: bircni <bircni@icloud.com> Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
120 lines
3.0 KiB
Handlebars
120 lines
3.0 KiB
Handlebars
WORK_PATH = {{TEST_WORK_PATH}}
|
|
APP_NAME = Gitea: Git with a cup of tea
|
|
RUN_MODE = prod
|
|
|
|
[database]
|
|
DB_TYPE = postgres
|
|
HOST = {{TEST_PGSQL_HOST}}
|
|
NAME = {{TEST_PGSQL_DBNAME}}
|
|
USER = {{TEST_PGSQL_USERNAME}}
|
|
PASSWD = {{TEST_PGSQL_PASSWORD}}
|
|
SCHEMA = {{TEST_PGSQL_SCHEMA}}
|
|
SSL_MODE = disable
|
|
|
|
[indexer]
|
|
REPO_INDEXER_ENABLED = true
|
|
|
|
[queue.issue_indexer]
|
|
TYPE = level
|
|
|
|
[queue]
|
|
TYPE = immediate
|
|
|
|
[queue.code_indexer]
|
|
TYPE = immediate
|
|
|
|
[queue.push_update]
|
|
TYPE = immediate
|
|
|
|
[queue.webhook_sender]
|
|
TYPE = immediate
|
|
|
|
[repository.signing]
|
|
SIGNING_KEY = none
|
|
|
|
[server]
|
|
SSH_DOMAIN = localhost
|
|
HTTP_PORT = 3002
|
|
ROOT_URL = http://localhost:3002/
|
|
LOCAL_ROOT_URL = http://127.0.0.1:3002/
|
|
DISABLE_SSH = false
|
|
SSH_LISTEN_HOST = localhost
|
|
SSH_PORT = 2202
|
|
START_SSH_SERVER = true
|
|
LFS_START_SERVER = true
|
|
LFS_JWT_SECRET = Tv_MjmZuHqpIY6GFl12ebgkRAMt4RlWt0v4EHKSXO0w
|
|
BUILTIN_SSH_SERVER_USER = git
|
|
SSH_TRUSTED_USER_CA_KEYS = ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCb4DC1dMFnJ6pXWo7GMxTchtzmJHYzfN6sZ9FAPFR4ijMLfGki+olvOMO5Fql1/yGnGfbELQa1S6y4shSvj/5K+zUFScmEXYf3Gcr87RqilLkyk16RS+cHNB1u87xTHbETaa3nyCJeGQRpd4IQ4NKob745mwDZ7jQBH8AZEng50Oh8y8fi8skBBBzaYp1ilgvzG740L7uex6fHV62myq0SXeCa+oJUjq326FU8y+Vsa32H8A3e7tOgXZPdt2TVNltx2S9H2WO8RMi7LfaSwARNfy1zu+bfR50r6ef8Yx5YKCMz4wWb1SHU1GS800mjOjlInLQORYRNMlSwR1+vLlVDciOqFapDSbj+YOVOawR0R1aqlSKpZkt33DuOBPx9qe6CVnIi7Z+Px/KqM+OLCzlLY/RS+LbxQpDWcfTVRiP+S5qRTcE3M3UioN/e0BE/1+MpX90IGpvVkA63ILYbKEa4bM3ASL7ChTCr6xN5XT+GpVJveFKK1cfNx9ExHI4rzYE=
|
|
|
|
[mailer]
|
|
ENABLED = true
|
|
PROTOCOL = dummy
|
|
FROM = pgsql-integration-test@gitea.io
|
|
|
|
[migrations]
|
|
ALLOWED_HOST_LIST = private, loopback
|
|
|
|
[service]
|
|
REGISTER_EMAIL_CONFIRM = false
|
|
REGISTER_MANUAL_CONFIRM = false
|
|
DISABLE_REGISTRATION = false
|
|
ENABLE_CAPTCHA = false
|
|
REQUIRE_SIGNIN_VIEW = false
|
|
DEFAULT_KEEP_EMAIL_PRIVATE = false
|
|
DEFAULT_ALLOW_CREATE_ORGANIZATION = true
|
|
NO_REPLY_ADDRESS = noreply.example.org
|
|
ENABLE_NOTIFY_MAIL = true
|
|
|
|
[session]
|
|
PROVIDER = file
|
|
|
|
[log]
|
|
MODE = {{TEST_LOGGER}}
|
|
ENABLE_SSH_LOG = true
|
|
logger.xorm.MODE = file
|
|
|
|
[log.test]
|
|
LEVEL = Info
|
|
COLORIZE = true
|
|
|
|
[log.file]
|
|
LEVEL = Debug
|
|
|
|
[security]
|
|
INSTALL_LOCK = true
|
|
SECRET_KEY = 9pCviYTWSb
|
|
INTERNAL_TOKEN = eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJuYmYiOjE0OTU1NTE2MTh9.hhSVGOANkaKk3vfCd2jDOIww4pUk0xtg9JRde5UogyQ
|
|
DISABLE_QUERY_AUTH_TOKEN = true
|
|
|
|
[lfs]
|
|
MINIO_BASE_PATH = lfs/
|
|
|
|
[attachment]
|
|
MINIO_BASE_PATH = attachments/
|
|
|
|
[avatars]
|
|
MINIO_BASE_PATH = avatars/
|
|
|
|
[repo-avatars]
|
|
MINIO_BASE_PATH = repo-avatars/
|
|
|
|
[storage]
|
|
STORAGE_TYPE = minio
|
|
SERVE_DIRECT = false
|
|
MINIO_ENDPOINT = {{TEST_MINIO_ENDPOINT}}
|
|
MINIO_ACCESS_KEY_ID = 123456
|
|
MINIO_SECRET_ACCESS_KEY = 12345678
|
|
MINIO_BUCKET = gitea
|
|
MINIO_LOCATION = us-east-1
|
|
MINIO_USE_SSL = false
|
|
MINIO_CHECKSUM_ALGORITHM = md5
|
|
|
|
[packages]
|
|
ENABLED = true
|
|
|
|
[actions]
|
|
ENABLED = true
|
|
|
|
[webhook]
|
|
ALLOWED_HOST_LIST = 127.0.0.1
|