Everything previously under www/src now are under www/ Moved style.CSS under www/ressources, to allow blocking http requests to www/lib completly Moved <head> and <header> generation under lib/PHP/output/sections.php to reduce redundancy within files. Also implemented a system to allow them to generate relatif paht for href to ressources depending on their deepness within www/ hierarchy.
34 lines
1,019 B
PHP
34 lines
1,019 B
PHP
<?php
|
|
|
|
// The user privileges constants.
|
|
// Always loaded with update.php included
|
|
define("ACCOUNT_PRIV_ADMIN", 'administrator');
|
|
define("ACCOUNT_PRIV_MODERATOR", 'moderator');
|
|
define("ACCOUNT_PRIV_REVIEWER", 'reviewer');
|
|
define("ACCOUNT_PRIV_USER", 'contributor');
|
|
|
|
|
|
// The session name.
|
|
// Also the name of the session cookie.
|
|
$sessionconfig_name = 'PBDE_auth';
|
|
|
|
// A value of 0 implies the cookie last until browser closed.
|
|
// By default, 18 minutes.
|
|
$sessioncookie_lifetime = 18*60;
|
|
|
|
// Path under which the cookie is valid.
|
|
// By default, '/'.
|
|
$sessioncookie_path = '/';
|
|
|
|
// Whether to allow sending the cookie only through https.
|
|
// For ease of testing, by default, false.
|
|
// Should be true when deploying.
|
|
$sessioncookie_secure = false;
|
|
|
|
// Whether to allow access to the cookie outside of http requests.
|
|
// For security, by default, true.
|
|
$sessioncookie_httponly = true;
|
|
|
|
//Whether to allow the cookie to be send by CSR in GET request.
|
|
// By default, 'strict' (do no allow).
|
|
$sessioncookie_samesite = 'strict';
|