d6918a2fdfcc7a675ce87a000f6ba3560fc1b720
[squirrelmail.git] / config / config_local.example.php
1 <?php
2
3 /**
4 * Local config overrides.
5 *
6 * You can override the config.php settings here.
7 * Don't do it unless you know what you're doing.
8 * Use standard PHP syntax, see config.php for examples.
9 *
10 * @copyright 2002-2022 The SquirrelMail Project Team
11 * @license http://opensource.org/licenses/gpl-license.php GNU Public License
12 * @version $Id$
13 * @package squirrelmail
14 * @subpackage config
15 */
16
17
18 /**
19 * What follows are notes about "hidden" settings that
20 * are not defined in config.php and are only meant to
21 * be optionally defined by administrators who need to
22 * suit specific (unusual) setups. This file, of course,
23 * is not limited to setting these values - you can still
24 * specify overrides for anything in config.php.
25 *
26 * $custom_session_handlers (array) allows the definition
27 * of custom PHP session handlers. This feature is well
28 * documented in the code in include/init.php
29 *
30 * $hide_squirrelmail_header (must be defined as a constant:
31 * define('hide_squirrelmail_header', 1);
32 * This allows the administrator to force SquirrelMail never
33 * to add its own Received headers with user information in
34 * them. This is VERY DANGEROUS and is HIGHLY DISCOURAGED
35 *
36 * $show_timezone_name allows (boolean) the addition of the
37 * timezone name to the Date header in outgoing messages.
38 * Turning this on violates RFC 822 syntax and can result in
39 * more serious problems (unencoded 8 bit characters in headers)
40 * on some systems.
41 *
42 * $force_crlf_default (string) Can be used to force CRLF or LF
43 * line endings in decoded message parts. In some environments
44 * this allows attachments to be downloaded with operating-system
45 * friendly line endings. This setting may be overridden by
46 * certain plugins or on systems running PHP versions less than
47 * 4.3.0. Set to 'CRLF' or 'LF' or, to force line endings to be
48 * unmolested, set to some other string, such as 'NOCHANGE'
49 *
50 * $subfolders_of_inbox_are_special (boolean) can be set to TRUE
51 * if any subfolders of the INBOX should be treated as "special"
52 * (those that are displayed in a different color than other
53 * "normal" mailboxes).
54 *
55 * $hash_dirs_use_md5 (boolean) If set to TRUE, forces the
56 * hashed preferences directory calculation to use MD5 instead
57 * of CRC32.
58 *
59 * $hash_dirs_strip_domain (boolean) If set to TRUE, and if
60 * usernames are in full email address format, the domain
61 * part (beginning with "@") will be stripped before
62 * calculating the CRC or MD5.
63 *
64 * $default_htmlspecialchars_encoding (string) is used to
65 * specify the charset that is used for htmlspecialchars()
66 * calls when an invalid charset was requested (PHP's
67 * htmlspecialchars() only supports a limited number of
68 * encodings). SquirrelMail defaults to iso-8859-1, but if
69 * you want to change the default to something like utf-8,
70 * you can use this setting for that.
71 *
72 * $smtp_stream_options allows more control over the SSL context
73 * used when connecting to the SMTP server over SSL/TLS. See:
74 * http://www.php.net/manual/context.php and in particular
75 * http://php.net/manual/context.ssl.php
76 * For example, you can specify a CA file that corresponds
77 * to your server's certificate and make sure that the
78 * server's certificate is validated when connecting:
79 * $smtp_stream_options = array(
80 * 'ssl' => array(
81 * 'cafile' => '/etc/pki/tls/certs/ca-bundle.crt',
82 * 'verify_peer' => true,
83 * 'verify_depth' => 3,
84 * ),
85 * );
86 *
87 * $imap_stream_options allows more control over the SSL
88 * context used when connecting to the IMAP server over
89 * SSL/TLS. See: http://www.php.net/manual/context.php
90 * and in particular http://php.net/manual/context.ssl.php
91 * For example, you can specify a CA file that corresponds
92 * to your server's certificate and make sure that the
93 * server's certificate is validated when connecting:
94 * $imap_stream_options = array(
95 * 'ssl' => array(
96 * 'cafile' => '/etc/pki/tls/certs/ca-bundle.crt',
97 * 'verify_peer' => true,
98 * 'verify_depth' => 3,
99 * ),
100 * );
101 *
102 * $disable_pdo (boolean) tells SquirrelMail not to use
103 * PDO to access the user preferences and address book
104 * databases as it normally would. When this is set to
105 * TRUE, Pear DB will be used instead, but this is not
106 * recommended.
107 *
108 * $pdo_show_sql_errors (boolean) causes the actual
109 * database error to be displayed when one is encountered.
110 * When set to FALSE, generic errors are displayed,
111 * preventing internal database information from being
112 * exposed. This should be set to TRUE only for debugging
113 * purposes.
114 *
115 * $pdo_identifier_quote_char (string) allows you to
116 * override the character used for quoting table and field
117 * names in database queries. Set this to the desired
118 * Quote character, for example:
119 * $pdo_identifier_quote_char = '"';
120 * Or you can tell SquirrelMail not to quote identifiers
121 * at all by setting this to "none". When this setting
122 * is empty or not found, SquirrelMail will attempt to
123 * quote table and field names with what it thinks is
124 * the appropriate quote character for the database type
125 * being used (backtick for MySQL (and thus MariaDB),
126 * double quotes for all others).
127 *
128 * $use_expiring_security_tokens (boolean) allows you to
129 * make SquirrelMail use short-lived anti-CSRF security
130 * tokens that expire as desired (not recommended, can
131 * cause user-facing issues when tokens expire unexpectedly).
132 *
133 * $max_token_age_days (integer) allows you to indicate how
134 * long a token should be valid for (in days) (only relevant
135 * when $use_expiring_security_tokens is enabled).
136 *
137 * $do_not_use_single_token (boolean) allows you to force
138 * SquirrelMail to generate a new token every time one is
139 * requested (which may increase obscurity through token
140 * randomness at the cost of some performance). Otherwise,
141 * only one token will be generated per user which will
142 * change only after it expires or is used outside of the
143 * validity period specified when calling
144 * sm_validate_security_token() (only relevant when
145 * $use_expiring_security_tokens is enabled).
146 *
147 * $head_tag_extra can be used to add custom tags inside
148 * the <head> section of *ALL* pages. The string
149 * "###SM BASEURI###" will be replaced with the base URI
150 * for this SquirrelMail installation. This may be used,
151 * for example, to add custom favicon tags. If this
152 * setting is empty here, SquirrelMail will add a favicon
153 * tag by default. If you want to retain the default favicon
154 * while using this setting, you must include the following
155 * as part of this setting:
156 * $head_tag_extra = '<link rel="shortcut icon" href="###SM BASEURI###favicon.ico" />...<YOUR CONTENT HERE>...';
157 *
158 * $imap_id_command_args (array) causes the IMAP ID
159 * command (RFC 2971) to be sent after every login,
160 * identifying the client to the server. Each key in this
161 * array is an attibute to be sent in the ID command to
162 * the server. Values will be sent as-is except if the
163 * value is "###REMOTE ADDRESS###" (without quotes) in
164 * which case the current user's real IP address will be
165 * substituted. If "###X-FORWARDED-FOR###" is used and a
166 * "X-FORWARDED-FOR" header is present in the client request,
167 * the contents of that header are used (careful, this can
168 * be forged). If "###X-FORWARDED-FOR OR REMOTE ADDRESS###"
169 * is used, then the "X-FORWARDED-FOR" header is used if it
170 * is present in the request, otherwise, the client's
171 * connecting IP address is used. The following attributes
172 * will always be added unless they are specifically
173 * overridden with a blank value:
174 * name, vendor, support-url, version
175 * A parsed representation of server's response is made
176 * available to plugins as both a global and session variable
177 * named "imap_server_id_response" (a simple key/value array)
178 * unless response parsing is turned off by way of setting a
179 * variable in this file named
180 * $do_not_parse_imap_id_command_response to TRUE, in which
181 * case, the stored response will be the unparsed IMAP response.
182 * $imap_id_command_args = array('remote-host' => '###REMOTE ADDRESS###');
183 * $do_not_parse_imap_id_command_response = FALSE;
184 *
185 * $remove_rcdata_rawtext_tags_and_content
186 * When displaying HTML-format email message content, a small
187 * number of HTML tags are parsed differently (RCDATA, RAWTEXT
188 * content), but can also be removed entirely (with their contents)
189 * if desired (in most cases, should be a safe thing with minimal
190 * impact). This would be done as a fallback security measure and
191 * can be enabled by adding this here:
192 * $remove_rcdata_rawtext_tags_and_content = TRUE;
193 *
194 * $php_self_pattern
195 * $php_self_replacement
196 * These may be used to modify the value of the global $PHP_SELF
197 * variable used throughout the SquirrelMail code (though that
198 * variable is used less frequently in version 1.5.x). The
199 * pattern should be a full regular expression including the
200 * delimiters. This may be helpful when the web server sees
201 * traffic from a proxy so the normal $PHP_SELF does not resolve
202 * to what it should be for the real client.
203 *
204 * $upload_filesize_divisor allows the administrator to specify
205 * the divisor used when converting the size of an uploaded file
206 * as given by PHP's filesize() and converted to human-digestable
207 * form. By default, 1000 is used, but 1024 may be necessary in
208 * some environments.
209 * $upload_filesize_divisor = 1024;
210 *
211 * $same_site_cookies allows override of how cookies are set
212 * with the "SameSite" attribute. Normally you won't want to
213 * do anything with this. If you do, you can set it to "Lax"
214 * "Strict" (which is default) or "None" -- or set it to an
215 * empty string to cause cookies to be sent without adding
216 * the SameSite attribute at all and use the browser's default
217 */