Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes14kdownloads
config.py933 linesDownload Raw Back to web
1# -*- coding: utf-8 -*-2 3##########################################################################4#5# pgAdmin 4 - PostgreSQL Tools6#7# Copyright (C) 2013 - 2024, The pgAdmin Development Team8# This software is released under the PostgreSQL Licence9#10# config.py - Core application configuration settings11#12##########################################################################13 14import builtins15import logging16import os17import sys18from collections import OrderedDict19 20# We need to include the root directory in sys.path to ensure that we can21# find everything we need when running in the standalone runtime.22root = os.path.dirname(os.path.realpath(__file__))23if sys.path[0] != root:24    sys.path.insert(0, root)25 26# The config database connection pool size.27# Setting this to 0 will remove any limit.28CONFIG_DATABASE_CONNECTION_POOL_SIZE = 529# The number of connections allowed to overflow beyond30# the connection pool size.31CONFIG_DATABASE_CONNECTION_MAX_OVERFLOW = 10032 33from pgadmin.utils import env, IS_WIN, fs_short_path34from version import APP_VERSION, APP_RELEASE, APP_REVISION, APP_SUFFIX, \35    APP_VERSION_INT36from branding import APP_NAME, APP_ICON, APP_COPYRIGHT, APP_PATH, \37    APP_WIN_PATH, APP_SHORT_NAME, APP_DEFAULT_EMAIL38 39##########################################################################40# Misc stuff41##########################################################################42 43# Path to the online help.44HELP_PATH = '../../../docs/en_US/_build/html/'45 46# Languages we support in the UI47LANGUAGES = {48    'en': 'English',49    'zh': 'Chinese (Simplified)',50    'cs': 'Czech',51    'fr': 'French',52    'de': 'German',53    'id': 'Indonesian',54    'it': 'Italian',55    'ja': 'Japanese',56    'ko': 'Korean',57    'pl': 'Polish',58    'pt_BR': 'Portuguese (Brazilian)',59    'ru': 'Russian',60    'es': 'Spanish',61}62 63# DO NOT CHANGE UNLESS YOU KNOW WHAT YOU ARE DOING!64# List of modules to skip when dynamically loading65MODULE_BLACKLIST = ['test']66 67# DO NOT CHANGE UNLESS YOU KNOW WHAT YOU ARE DOING!68# List of treeview browser nodes to skip when dynamically loading69NODE_BLACKLIST = []70 71##########################################################################72# Server settings73##########################################################################74 75# The server mode determines whether or not we're running on a web server76# requiring user authentication, or desktop mode which uses an automatic77# default login.78#79# DO NOT DISABLE SERVER MODE IF RUNNING ON A WEBSERVER!!80#81# We only set SERVER_MODE if it's not already set. That's to allow the82# runtime to force it to False.83#84# NOTE: If you change the value of SERVER_MODE or DATA_DIR in an included85#       config file, you may also need to redefine any values below that are86#       derived from it, notably various paths such as LOG_FILE, SQLITE_PATH,87#       SESSION_DB_PATH, STORAGE_DIR, KERBEROS_CCACHE_DIR, and88#       AZURE_CREDENTIAL_CACHE_DIR89 90if (not hasattr(builtins, 'SERVER_MODE')) or builtins.SERVER_MODE is None:91    SERVER_MODE = True92else:93    SERVER_MODE = builtins.SERVER_MODE94 95# HTTP headers to search for CSRF token when it is not provided in the form.96# Default is ['X-CSRFToken', 'X-CSRF-Token']97WTF_CSRF_HEADERS = ['X-pgA-CSRFToken']98 99# User ID (email address) to use for the default user in desktop mode.100# The default should be fine here, as it's not exposed in the app.101DESKTOP_USER = APP_DEFAULT_EMAIL102 103# This option allows the user to host the application on a LAN104# Default hosting is on localhost (DEFAULT_SERVER='localhost').105# To host pgAdmin4 over LAN set DEFAULT_SERVER='0.0.0.0' (or a specific106# adaptor address.107#108# NOTE: This is NOT recommended for production use, only for debugging109# or testing. Production installations should be run as a WSGI application110# behind Apache HTTPD.111DEFAULT_SERVER = '127.0.0.1'112 113# The default port on which the app server will listen if not set in the114# environment by the runtime115DEFAULT_SERVER_PORT = 5050116 117# This param is used to override the default web server information about118# the web technology and the frameworks being used in the application119# An attacker could use this information to fingerprint underlying operating120# system and research known exploits for the specific version of121# software in use122WEB_SERVER = 'Python'123 124# Enable X-Frame-Option protection.125# Set to one of "SAMEORIGIN", "ALLOW-FROM origin" or "" to disable.126# Note that "DENY" is NOT supported (and will be silently ignored).127# See https://tools.ietf.org/html/rfc7034 for more info.128X_FRAME_OPTIONS = "SAMEORIGIN"129 130# The Content-Security-Policy header allows you to restrict how resources131# such as JavaScript, CSS, or pretty much anything that the browser loads.132# see https://content-security-policy.com/#source_list for more info133# e.g. "default-src https: data: 'unsafe-inline' 'unsafe-eval';"134CONTENT_SECURITY_POLICY = "default-src ws: http: data: blob: 'unsafe-inline'" \135                          " 'unsafe-eval';"136 137# STRICT_TRANSPORT_SECURITY_ENABLED when set to True will set the138# Strict-Transport-Security header139STRICT_TRANSPORT_SECURITY_ENABLED = False140 141# The Strict-Transport-Security header tells the browser to convert all HTTP142# requests to HTTPS, preventing man-in-the-middle (MITM) attacks.143# e.g. 'max-age=31536000; includeSubDomains'144STRICT_TRANSPORT_SECURITY = "max-age=31536000; includeSubDomains"145 146# The X-Content-Type-Options header forces the browser to honor the response147# content type instead of trying to detect it, which can be abused to148# generate a cross-site scripting (XSS) attack.149# e.g. nosniff150X_CONTENT_TYPE_OPTIONS = "nosniff"151 152# The browser will try to prevent reflected XSS attacks by not loading the153# page if the request contains something that looks like JavaScript and the154# response contains the same data. e.g. '1; mode=block'155X_XSS_PROTECTION = "1; mode=block"156 157# This param is used to validate ALLOWED_HOSTS for the application158# This will be used to avoid Host Header Injection attack159# ALLOWED_HOSTS = ['225.0.0.0/8', '226.0.0.0/7', '228.0.0.0/6']160# ALLOWED_HOSTS = ['127.0.0.1', '192.168.0.1']161# if ALLOWED_HOSTS= [] then it will accept all ips (and application will be162# vulnerable to Host Header Injection attack)163ALLOWED_HOSTS = []164 165# Hashing algorithm used for password storage166SECURITY_PASSWORD_HASH = 'pbkdf2_sha512'167 168# Minimum password length169PASSWORD_LENGTH_MIN = 6170 171# Reverse Proxy parameters172# You must tell the middleware how many proxies set each header173# so it knows what values to trust.174# See https://tinyurl.com/yyg7r9av175# for more information.176 177# Number of values to trust for X-Forwarded-For178PROXY_X_FOR_COUNT = 1179 180# Number of values to trust for X-Forwarded-Proto.181PROXY_X_PROTO_COUNT = 1182 183# Number of values to trust for X-Forwarded-Host.184PROXY_X_HOST_COUNT = 0185 186# Number of values to trust for X-Forwarded-Port.187PROXY_X_PORT_COUNT = 1188 189# Number of values to trust for X-Forwarded-Prefix.190PROXY_X_PREFIX_COUNT = 0191 192# NOTE: CSRF_SESSION_KEY, SECRET_KEY and SECURITY_PASSWORD_SALT are no193#       longer part of the main configuration, but are stored in the194#       configuration databases 'keys' table and are auto-generated.195 196# COMPRESSION197COMPRESS_MIMETYPES = [198    'text/html', 'text/css', 'text/xml', 'text/javascript',199    'application/json', 'application/javascript'200]201COMPRESS_LEVEL = 9202COMPRESS_MIN_SIZE = 500203 204# Set the cache control max age for static files in flask to 1 year205SEND_FILE_MAX_AGE_DEFAULT = 31556952206 207# This will be added to static urls as url parameter with value as208# APP_VERSION_INT for cache busting on version upgrade. If the value is set as209# None or empty string then it will not be added.210# eg - http:localhost:5050/pgadmin.css?intver=3.13211APP_VERSION_PARAM = 'ver'212 213# Add the internal version param to below extensions only214APP_VERSION_EXTN = ('.css', '.js', '.html', '.svg', '.png', '.gif', '.ico')215 216# Data directory for storage of config settings etc. This shouldn't normally217# need to be changed - it's here as various other settings depend on it.218# On Windows, we always store data in %APPDATA%\$(APP_WIN_PATH). On other219# platforms, if we're in server mode we use /var/lib/$(APP_PATH),220# otherwise ~/.$(APP_PATH)221if IS_WIN:222    # Use the short path on windows223    DATA_DIR = os.path.realpath(224        os.path.join(fs_short_path(env('APPDATA')), APP_WIN_PATH)225    )226else:227    if SERVER_MODE:228        DATA_DIR = os.path.join('/var/lib/', APP_PATH)229    else:230        DATA_DIR = os.path.realpath(231            os.path.expanduser('~/' + '.' + APP_PATH + '/')232        )233 234# An optional login banner to show security warnings/disclaimers etc. at235# login and password recovery etc. HTML may be included for basic formatting,236# For example:237# LOGIN_BANNER = "<h4>Authorised Users Only!</h4>" \238#                "Unauthorised use is strictly forbidden."239LOGIN_BANNER = ""240 241##########################################################################242# Log settings243##########################################################################244 245# Debug mode?246DEBUG = False247 248# Application log level - one of:249#   CRITICAL 50250#   ERROR    40251#   WARNING  30252#   SQL      25253#   INFO     20254#   DEBUG    10255#   NOTSET    0256CONSOLE_LOG_LEVEL = logging.WARNING257FILE_LOG_LEVEL = logging.WARNING258 259# Log format.260JSON_LOGGER = False261CONSOLE_LOG_FORMAT_JSON = OrderedDict([262    ("time", "asctime"),263    ("message", "message"),264    ("level", "levelname")265])266 267FILE_LOG_FORMAT_JSON = OrderedDict([268    ("time", "asctime"),269    ("message", "message"),270    ("level", "levelname")271])272 273 274CONSOLE_LOG_FORMAT = '%(asctime)s: %(levelname)s\t%(name)s:\t%(message)s'275FILE_LOG_FORMAT = '%(asctime)s: %(levelname)s\t%(name)s:\t%(message)s'276 277# Log file name. This goes in the data directory, except on non-Windows278# platforms in server mode.279if SERVER_MODE and not IS_WIN:280    LOG_FILE = os.path.join('/var/log', APP_PATH, APP_SHORT_NAME + '.log')281else:282    LOG_FILE = os.path.join(DATA_DIR, APP_SHORT_NAME + '.log')283 284# Log rotation setting285# Log file will be rotated considering values for LOG_ROTATION_SIZE286# & LOG_ROTATION_AGE. Rotated file will be named in format287# - LOG_FILE.Y-m-d_H-M-S288LOG_ROTATION_SIZE = 10  # In MBs289LOG_ROTATION_AGE = 1440  # In minutes290LOG_ROTATION_MAX_LOG_FILES = 90  # Maximum number of backups to retain291##########################################################################292# Server Connection Driver Settings293##########################################################################294 295# The default driver used for making connection with PostgreSQL296PG_DEFAULT_DRIVER = 'psycopg3'297 298# Maximum allowed idle time in minutes before which releasing the connection299# for the particular session. (in minutes)300MAX_SESSION_IDLE_TIME = 60301 302##########################################################################303# External Database Settings304#305# All configuration settings are stored by default in the SQLite database.306# In order to use external databases like PostgreSQL sets the value of307# CONFIG_DATABASE_URI like below:308# dialect+driver://username:password@host:port/database309#310# PostgreSQL:311# postgresql://username:password@host:port/database312# Specify Schema Name313# postgresql://username:password@host:port/database?options=-csearch_path=pgadmin314# Using PGPASS file315# postgresql://username@host:port?options=-csearch_path=pgadmin316##########################################################################317CONFIG_DATABASE_URI = ''318 319##########################################################################320# User account and settings storage321##########################################################################322 323# The default path to the SQLite database used to store user accounts and324# settings. This default places the file in the same directory as this325# config file, but generates an absolute path for use througout the app.326SQLITE_PATH = env('SQLITE_PATH') or \327    os.path.join(DATA_DIR, APP_SHORT_NAME + '.db')328 329# SQLITE_TIMEOUT will define how long to wait before throwing the error -330# OperationError due to database lock. On slower system, you may need to change331# this to some higher value.332# (Default: 500 milliseconds)333SQLITE_TIMEOUT = 500334 335# Allow database connection passwords to be saved if the user chooses.336# Set to False to disable password saving.337ALLOW_SAVE_PASSWORD = True338 339# Maximum number of history queries stored per user/server/database340MAX_QUERY_HIST_STORED = 20341 342##########################################################################343# Server-side session storage path344#345# SESSION_DB_PATH (Default: $HOME/.pgadmin4/sessions)346##########################################################################347#348# We use SQLite for server-side session storage. There will be one349# SQLite database object per session created.350#351# Specify the path used to store your session objects.352#353# If the specified directory does not exist, the setup script will create354# it with permission mode 700 to keep the session database secure.355#356# On certain systems, you can use shared memory (tmpfs) for maximum357# scalability, for example, on Ubuntu:358#359# SESSION_DB_PATH = '/run/shm/pgAdmin4_session'360#361##########################################################################362SESSION_DB_PATH = os.path.join(DATA_DIR, 'sessions')363 364SESSION_COOKIE_NAME = 'pga4_session'365 366##########################################################################367# Mail server settings368##########################################################################369 370# These settings are used when running in web server mode for confirming371# and resetting passwords etc.372# See: http://pythonhosted.org/Flask-Mail/ for more info373MAIL_SERVER = 'localhost'374MAIL_PORT = 25375MAIL_USE_SSL = False376MAIL_USE_TLS = False377MAIL_USERNAME = ''378MAIL_PASSWORD = ''379MAIL_DEBUG = False380 381# Flask-Security overrides Flask-Mail's MAIL_DEFAULT_SENDER setting, so382# that should be set as such:383SECURITY_EMAIL_SENDER = 'no-reply@localhost'384 385##########################################################################386# Mail content settings387##########################################################################388 389# These settings define the content of password reset emails390SECURITY_EMAIL_SUBJECT_PASSWORD_RESET = "Password reset instructions for %s" \391                                        % APP_NAME392SECURITY_EMAIL_SUBJECT_PASSWORD_NOTICE = "Your %s password has been reset" \393                                         % APP_NAME394SECURITY_EMAIL_SUBJECT_PASSWORD_CHANGE_NOTICE = \395    "Your password for %s has been changed" % APP_NAME396 397##########################################################################398# Email address validation399##########################################################################400CHECK_EMAIL_DELIVERABILITY = False401SECURITY_EMAIL_VALIDATOR_ARGS = \402    {"check_deliverability": CHECK_EMAIL_DELIVERABILITY}403 404##########################################################################405# Upgrade checks406##########################################################################407 408# Check for new versions of the application?409UPGRADE_CHECK_ENABLED = True410 411# Where should we get the data from?412UPGRADE_CHECK_URL = 'https://www.pgadmin.org/versions.json'413 414# What key should we look at in the upgrade data file?415UPGRADE_CHECK_KEY = 'pgadmin4'416 417# Which CA file should we use?418# Default to cacert.pem in the same directory as config.py et al.419CA_FILE = os.path.join(os.path.dirname(os.path.realpath(__file__)),420                       "cacert.pem")421 422# Check if the detected browser is supported423CHECK_SUPPORTED_BROWSER = True424 425##########################################################################426# Storage Manager storage url config settings427# If user sets STORAGE_DIR to empty it will show all volumes if platform428# is Windows, '/' if it is Linux, Mac or any other unix type system.429 430# For example:431# 1. STORAGE_DIR = get_drive("C") or get_drive() # return C:/ by default432# where C can be any drive character such as "D", "E", "G" etc433# 2. Set path manually like434# STORAGE_DIR = "/path/to/directory/"435##########################################################################436STORAGE_DIR = os.path.join(DATA_DIR, 'storage')437 438##########################################################################439# Default locations for binary utilities (pg_dump, pg_restore etc)440#441# These are intentionally left empty in the main config file, but are442# expected to be overridden by packagers in config_distro.py.443#444# A default location can be specified for each database driver ID, in445# a dictionary. Either an absolute or relative path can be specified.446#447# Version-specific defaults can also be specified, which will take priority448# over un-versioned paths.449#450# In cases where it may be difficult to know what the working directory451# is, "$DIR" can be specified. This will be replaced with the path to the452# top-level pgAdmin4.py file. For example, on macOS we might use:453#454# $DIR/../../SharedSupport455#456##########################################################################457DEFAULT_BINARY_PATHS = {458    "pg": "",459    "pg-12": "",460    "pg-13": "",461    "pg-14": "",462    "pg-15": "",463    "pg-16": "",464    "ppas": "",465    "ppas-12": "",466    "ppas-13": "",467    "ppas-14": "",468    "ppas-15": "",469    "ppas-16": ""470}471 472##########################################################################473 474# Admin can specify fixed binary paths to prevent users from changing.475# It will take precedence over DEFAULT_BINARY_PATHS.476 477FIXED_BINARY_PATHS = {478    "pg": "",479    "pg-12": "",480    "pg-13": "",481    "pg-14": "",482    "pg-15": "",483    "pg-16": "",484    "ppas": "",485    "ppas-12": "",486    "ppas-13": "",487    "ppas-14": "",488    "ppas-15": "",489    "ppas-16": ""490}491 492##########################################################################493# Test settings - used primarily by the regression suite, not for users494##########################################################################495 496# The default path for SQLite database for testing497TEST_SQLITE_PATH = os.path.join(DATA_DIR, 'test_pgadmin4.db')498 499##########################################################################500# Allows flask application to response to the each request asynchronously501##########################################################################502THREADED_MODE = True503 504##########################################################################505# Do not allow SQLALCHEMY to track modification as it is going to be506# deprecated in future507##########################################################################508SQLALCHEMY_TRACK_MODIFICATIONS = False509 510##########################################################################511# Number of records to fetch in one batch in query tool when query result512# set is large.513##########################################################################514ON_DEMAND_RECORD_COUNT = 1000515 516##########################################################################517# Allow users to display Gravatar image for their username in Server mode518##########################################################################519SHOW_GRAVATAR_IMAGE = True520 521##########################################################################522# Set cookie path and options523##########################################################################524COOKIE_DEFAULT_PATH = '/'525COOKIE_DEFAULT_DOMAIN = None526SESSION_COOKIE_DOMAIN = None527SESSION_COOKIE_SAMESITE = 'Lax'528SESSION_COOKIE_SECURE = False529SESSION_COOKIE_HTTPONLY = True530 531#########################################################################532# Skip storing session in files and cache for specific paths533#########################################################################534SESSION_SKIP_PATHS = [535    '/misc/ping'536]537 538##########################################################################539# Session expiration support540##########################################################################541# SESSION_EXPIRATION_TIME is the interval in Days. Session will be542# expire after the specified number of *days*.543SESSION_EXPIRATION_TIME = 1544 545# Make SESSION_EXPIRATION_TIME to 1 week in DESKTOP mode546if not SERVER_MODE:547    SESSION_EXPIRATION_TIME = 7548 549# CHECK_SESSION_FILES_INTERVAL is interval in Hours. Application will check550# the session files for cleanup after specified number of *hours*.551CHECK_SESSION_FILES_INTERVAL = 24552 553# USER_INACTIVITY_TIMEOUT is interval in Seconds. If the pgAdmin screen is left554# unattended for <USER_INACTIVITY_TIMEOUT> seconds then the user will555# be logged out. When set to 0, the timeout will be disabled.556# If pgAdmin doesn't detect any activity in the time specified (in seconds),557# the user will be forcibly logged out from pgAdmin. Set to zero to disable558# the timeout.559# Note: This is applicable only for SERVER_MODE=True.560USER_INACTIVITY_TIMEOUT = 0561 562# OVERRIDE_USER_INACTIVITY_TIMEOUT when set to True will override563# USER_INACTIVITY_TIMEOUT when long running queries in the Query Tool564# or Debugger are running. When the queries complete, the inactivity timer565# will restart in this case. If set to False, user inactivity may cause566# transactions or in-process debugging sessions to be aborted.567OVERRIDE_USER_INACTIVITY_TIMEOUT = True568 569##########################################################################570# SSH Tunneling supports only for Python 2.7 and 3.4+571##########################################################################572SUPPORT_SSH_TUNNEL = True573# Allow SSH Tunnel passwords to be saved if the user chooses.574# Set to False to disable password saving.575ALLOW_SAVE_TUNNEL_PASSWORD = False576 577##########################################################################578# Master password is used to encrypt/decrypt saved server passwords579# Applicable for desktop mode only580##########################################################################581MASTER_PASSWORD_REQUIRED = True582 583##########################################################################584 585# pgAdmin encrypts the database connection and ssh tunnel password using a586# master password or pgAdmin login password (for other authentication sources)587# before storing it in the pgAdmin configuration database.588#589# Below setting is used to allow the user to specify the path to a script590# or program that will return an encryption key which will be used to591# encrypt the passwords. This setting is used only in server mode when592# auth sources are oauth, Kerberos, and webserver.593#594# You can pass the current username as an argument to the external script595# by specifying %u in config value.596# E.g. - MASTER_PASSWORD_HOOK = '<PATH>/passwdgen_script.sh %u'597##########################################################################598MASTER_PASSWORD_HOOK = None599 600##########################################################################601 602# Allows pgAdmin4 to create session cookies based on IP address, so even603# if a cookie is stolen, the attacker will not be able to connect to the604# server using that stolen cookie.605# Note: This can cause problems when the server is deployed in dynamic IP606# address hosting environments, such as Kubernetes or behind load607# balancers. In such cases, this option should be set to False.608##########################################################################609ENHANCED_COOKIE_PROTECTION = True610 611##########################################################################612# External Authentication Sources613##########################################################################614 615# Default setting is internal616# External Supported Sources: ldap, kerberos, oauth2617# Multiple authentication can be achieved by setting this parameter to618# ['ldap', 'internal'] or ['oauth2', 'internal'] or619# ['webserver', 'internal'] etc.620# pgAdmin will authenticate the user with ldap/oauth2 whatever first in the621# list, in case of failure the second authentication option will be considered.622 623AUTHENTICATION_SOURCES = ['internal']624 625##########################################################################626# MAX_LOGIN_ATTEMPTS which sets the number of failed login attempts that627# are allowed. If this value is exceeded the account is locked and can be628# reset by an administrator. By setting the variable to the value zero629# this feature is deactivated.630##########################################################################631MAX_LOGIN_ATTEMPTS = 3632 633##########################################################################634# Only consider password to check the failed login attempts, email is635# excluded from this check636LOGIN_ATTEMPT_FIELDS = ['password']637##########################################################################638# LDAP Configuration639##########################################################################640 641# After ldap authentication, user will be added into the SQLite database642# automatically, if set to True.643# Set it to False, if user should not be added automatically,644# in this case Admin has to add the user manually in the SQLite database.645LDAP_AUTO_CREATE_USER = True646 647# Connection timeout648LDAP_CONNECTION_TIMEOUT = 10649 650# Server connection details (REQUIRED)651# example: ldap://<ip-address>:<port> or ldap://<hostname>:<port>652LDAP_SERVER_URI = 'ldap://<ip-address>:<port>'653 654# The LDAP attribute containing user names. In OpenLDAP, this may be 'uid'655# whilst in AD, 'sAMAccountName' might be appropriate. (REQUIRED)656LDAP_USERNAME_ATTRIBUTE = '<User-id>'657 658##########################################################################659# 3 ways to configure LDAP as follows (Choose anyone):660 661# 1. Dedicated User binding662 663# LDAP Bind User DN Example: cn=username,dc=example,dc=com664# Set this parameter to allow the connection to bind using a dedicated user.665# After the connection is made, the pgadmin login user will be further666# authenticated by the username and password provided667# at the login screen.668LDAP_BIND_USER = None669 670# LDAP Bind User Password671LDAP_BIND_PASSWORD = None672 673# OR ####################674# 2. Anonymous Binding675 676# Set this parameter to allow the anonymous bind.677# After the connection is made, the pgadmin login user will be further678# authenticated by the username and password provided679 680LDAP_ANONYMOUS_BIND = False681 682# OR ####################683# 3. Bind as pgAdmin user684 685# BaseDN (REQUIRED)686# AD example:687# (&(objectClass=user)(memberof=CN=MYGROUP,CN=Users,dc=example,dc=com))688# OpenLDAP example: CN=Users,dc=example,dc=com689LDAP_BASE_DN = '<Base-DN>'690 691# Configure the bind format string692# Default: LDAP_BIND_FORMAT="693#   {LDAP_USERNAME_ATTRIBUTE}={LDAP_USERNAME},{LDAP_BASE_DN}"694# The current available options are:695# LDAP_USERNAME_ATTRIBUTE, LDAP_USERNAME, LDAP_BASE_DN696# Example: LDAP_BIND_FORMAT="myldapuser@sales.example.com"697#          LDAP_BIND_FORMAT="NET\\myldapuser"698LDAP_BIND_FORMAT = '{LDAP_USERNAME_ATTRIBUTE}={LDAP_USERNAME},{LDAP_BASE_DN}'699 700##########################################################################701 702# Search ldap for further authentication (REQUIRED)703# It can be optional while bind as pgAdmin user704LDAP_SEARCH_BASE_DN = '<Search-Base-DN>'705 706# The LDAP attribute indicates whether the DN (Distinguished Names)707# are case sensitive or not708LDAP_DN_CASE_SENSITIVE = False709 710# Filter string for the user search.711# For OpenLDAP, '(cn=*)' may well be enough.712# For AD, you might use '(objectClass=user)' (REQUIRED)713LDAP_SEARCH_FILTER = '(objectclass=*)'714 715# Search scope for users (one of BASE, LEVEL or SUBTREE)716LDAP_SEARCH_SCOPE = 'SUBTREE'717 718# Use TLS? If the URI scheme is ldaps://, this is ignored.719LDAP_USE_STARTTLS = False720 721# TLS/SSL certificates. Specify if required, otherwise leave empty722LDAP_CA_CERT_FILE = ''723LDAP_CERT_FILE = ''724LDAP_KEY_FILE = ''725 726##########################################################################727 728# Some flaky LDAP servers returns malformed schema. If True, no exception729# will be raised and schema is thrown away but authentication will be done.730# This parameter should remain False, as recommended.731LDAP_IGNORE_MALFORMED_SCHEMA = False732 733##########################################################################734# Kerberos Configuration735##########################################################################736 737KRB_APP_HOST_NAME = DEFAULT_SERVER738 739# If the default_keytab_name is not set in krb5.conf or740# the KRB_KTNAME environment variable is not set then, explicitly set741# the Keytab file742 743KRB_KTNAME = '<KRB5_KEYTAB_FILE>'744 745# After kerberos authentication, user will be added into the SQLite database746# automatically, if set to True.747# Set it to False, if user should not be added automatically,748# in this case Admin has to add the user manually in the SQLite database.749 750KRB_AUTO_CREATE_USER = True751 752KERBEROS_CCACHE_DIR = os.path.join(DATA_DIR, 'krbccache')753 754#############################################################################755# Create local directory to store azure credential cache756#############################################################################757 758AZURE_CREDENTIAL_CACHE_DIR = os.path.join(DATA_DIR, 'azurecredentialcache')759 760##########################################################################761# OAuth2 Configuration762##########################################################################763 764# Multiple OAUTH2 providers can be added in the list like [{...},{...}]765# All parameters are required766 767OAUTH2_CONFIG = [768    {769        # The name of the of the oauth provider, ex: github, google770        'OAUTH2_NAME': None,771        # The display name, ex: Google772        'OAUTH2_DISPLAY_NAME': '<Oauth2 Display Name>',773        # Oauth client id774        'OAUTH2_CLIENT_ID': None,775        # Oauth secret776        'OAUTH2_CLIENT_SECRET': None,777        # URL to generate a token,778        # Ex: https://github.com/login/oauth/access_token779        'OAUTH2_TOKEN_URL': None,780        # URL is used for authentication,781        # Ex: https://github.com/login/oauth/authorize782        'OAUTH2_AUTHORIZATION_URL': None,783        # server metadata url might optional for your provider784        'OAUTH2_SERVER_METADATA_URL': None,785        # Oauth base url, ex: https://api.github.com/786        'OAUTH2_API_BASE_URL': None,787        # Name of the Endpoint, ex: user788        'OAUTH2_USERINFO_ENDPOINT': None,789        # Oauth scope, ex: 'openid email profile'790        # Note that an 'email' claim is required in the resulting profile791        'OAUTH2_SCOPE': None,792        # The claim which is used for the username. If the value is empty the793        # email is used as username, but if a value is provided,794        # the claim has to exist.795        'OAUTH2_USERNAME_CLAIM': None,796        # Font-awesome icon, ex: fa-github797        'OAUTH2_ICON': None,798        # UI button colour, ex: #0000ff799        'OAUTH2_BUTTON_COLOR': None,800        # The additional claims to check on user ID Token or Userinfo response.801        # This is useful to provide additional authorization checks802        # before allowing access.803        # Example for GitLab: allowing all maintainers teams, and a specific804        # developers group to access pgadmin:805        # 'OAUTH2_ADDITIONAL_CLAIMS': {806        #     'https://gitlab.org/claims/groups/maintainer': [807        #           'kuberheads/applications',808        #           'kuberheads/dba',809        #           'kuberheads/support'810        #      ],811        #     'https://gitlab.org/claims/groups/developer': [812        #           'kuberheads/applications/team01'813        #      ],814        # }815        # Example for AzureAD:816        # 'OAUTH2_ADDITIONAL_CLAIMS': {817        #     'groups': ["0760b6cf-170e-4a14-91b3-4b78e0739963"],818        #     'wids': ["cf1c38e5-3621-4004-a7cb-879624dced7c"],819        # }820        'OAUTH2_ADDITIONAL_CLAIMS': None,821        # Set this variable to False to disable SSL certificate verification822        # for OAuth2 provider.823        # This may need to set False, in case of self-signed certificates.824        # Ref: https://github.com/psf/requests/issues/6071825        'OAUTH2_SSL_CERT_VERIFICATION': True,826        # set this variable to invalidate the session of the oauth2 provider827        # Example for keycloak:828        # 'OAUTH2_LOGOUT_URL':829        # 'https://example.com/realms/master/protocol/openid-connect/logout?post_logout_redirect_uri={redirect_uri}&id_token_hint={id_token}'830        'OAUTH2_LOGOUT_URL': None831    }832]833 834# After Oauth authentication, user will be added into the SQLite database835# automatically, if set to True.836# Set it to False, if user should not be added automatically,837# in this case Admin has to add the user manually in the SQLite database.838 839OAUTH2_AUTO_CREATE_USER = True840 841##########################################################################842# Webserver Configuration843##########################################################################844 845WEBSERVER_AUTO_CREATE_USER = True846 847# REMOTE_USER variable will be used to check the environment variable848# is set or not first, if not available,849# request header will be checked for the same.850# Possible values: REMOTE_USER, HTTP_X_FORWARDED_USER, X-Forwarded-User851 852WEBSERVER_REMOTE_USER = 'REMOTE_USER'853 854##########################################################################855# Two-factor Authentication Configuration856##########################################################################857 858# Set it to True, to enable the two-factor authentication859MFA_ENABLED = True860 861# Set it to True, to ask the users to register forcefully for the862# two-authentication methods on logged-in.863MFA_FORCE_REGISTRATION = False864 865# pgAdmin supports Two-factor authentication by either sending an one-time code866# to an email, or using the TOTP based application like Google Authenticator.867MFA_SUPPORTED_METHODS = ["email", "authenticator"]868 869# NOTE: Please set the 'Mail server settings' to use 'email' as two-factor870#       authentication method.871 872# Subject for the email verification code873# Default: <APP_NAME> - Verification Code874# e.g.  pgAdmin 4 - Verification Code875MFA_EMAIL_SUBJECT = None876 877##########################################################################878# PSQL tool settings879##########################################################################880# This will enable PSQL tool in pgAdmin when running in server mode.881# PSQL is always enabled in Desktop mode, however in server mode it is882# disabled by default because users can run arbitrary commands on the883# server through it.884ENABLE_PSQL = False885 886##########################################################################887# ENABLE_BINARY_PATH_BROWSING setting is used to enable the browse button888# while selecting binary path for the database server in server mode.889# In Desktop mode it is always enabled and setting is of no use.890##########################################################################891ENABLE_BINARY_PATH_BROWSING = False892 893##########################################################################894# In server mode, the SHARED_STORAGE setting is used to enable shared storage.895# Specify the name, path, and restricted_access values that should be shared896# between users. When restricted_access is set to True, non-admin users cannot897# upload/add, delete, or rename files/folders in shared storage, only admins898# can do that. Users must provide the absolute path to the folder, and the name899# can be anything they see on the user interface.900# [{ 'name': 'Shared 1', 'path': '/shared_folder',901#   'restricted_access': True/False}]902##########################################################################903SHARED_STORAGE = []904 905#############################################################################906# AUTO_DISCOVER_SERVERS setting is used to enable the pgAdmin to discover the907# database server automatically on the local machine.908# When it is set to False, pgAdmin will not discover servers installed on909# the local machine.910#############################################################################911AUTO_DISCOVER_SERVERS = True912 913#############################################################################914# SERVER_HEARTBEAT_TIMEOUT is used to send the server heartbeat to server915# from the client. This will resolve the orphan database issue once916# browser tab is closed.917#############################################################################918SERVER_HEARTBEAT_TIMEOUT = 30  # In seconds919 920#############################################################################921# ENABLE_SERVER_PASS_EXEC_CMD is used to enable/disable Password exec command922# field in server properties. This is used to specify a shell command to be923# executed to retrieve a password to be used for server authentication.924# This setting is applicable only for server mode.925#############################################################################926ENABLE_SERVER_PASS_EXEC_CMD = False927 928#############################################################################929# Patch the default config with custom config and other manipulations930#############################################################################931from pgadmin.evaluate_config import evaluate_and_patch_config932locals().update(evaluate_and_patch_config(locals()))933 
codekingpro/portable-devtools · Team Ai