forked from KatherLab/wsi-viewer
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathconfig.example.yml
More file actions
executable file
·65 lines (58 loc) · 1.84 KB
/
Copy pathconfig.example.yml
File metadata and controls
executable file
·65 lines (58 loc) · 1.84 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
# Directories exposed to users in the UI
roots:
- path: "/path/to/slides"
label: "Slides"
exclude:
- "__pycache__"
- "tmp"
- ".git"
- "*.zip"
extensions:
- ".svs"
- ".tif"
- ".tiff"
- ".ndpi"
- ".scn"
- ".mrxs"
- ".bif"
- ".czi"
- ".dcm"
- ".vms"
- ".vmu"
- ".svslide"
- ".qptiff"
cache:
enabled: true
# Use Docker service name for Redis
redis_url: "redis://redis:6379/0"
ttl_seconds:
tree: 60
thumb: 86400
tile: 3600
thumbnails:
max_px: 512
prefer_associated: true
cors_allow_origins: ["*"]
# Authentication & authorization.
# When enabled=false, ALL requests are anonymous full-access (dev/legacy).
# All auth config lives here in config.yml (config.yml is gitignored, so secrets
# are safe). Generate a session secret with: openssl rand -hex 32
auth:
enabled: true
# FreeIPA LDAP. Use ldaps:// (TLS) or ldap:// (StartTLS) in production.
ldap_url: "ldaps://ipa.example.com"
# Bind DN template — {username} is substituted with the login username.
# Default FreeIPA user layout; replace the DC suffix with yours.
user_dn_template: "uid={username},cn=users,cn=accounts,dc=example,dc=com"
# Groups are NOT resolved from LDAP: the NFS server resolves group membership
# server-side from the UID, so we only need uid+primary gid (read from the
# user entry after a successful bind).
# Session cookie signing secret. MUST be set when enabled=true.
session_secret: "CHANGE_ME_run_openssl_rand_hex_32"
session_ttl: 86400 # seconds
# Redis TTLs for authz decisions (cached per user+path).
authz_ttl: 300 # allow
authz_ttl_deny: 60 # deny (shorter so newly-granted access propagates)
# aclcheckd daemon socket (started by the container entrypoint as root).
acl_socket: "/run/wsi/aclcheck.sock"
check_timeout: 5.0 # seconds per access check