# --------------------------------- # DO NOT EDIT THIS FILE! # This is reserved for system use! # --------------------------------- name: Wiki.js defaults: config: # File defaults port: 80 db: host: localhost port: 5432 user: wikijs pass: wikijsrocks db: wiki ssl: false sslOptions: auto: true schema: wiki ssl: enabled: false pool: min: 1 bindIP: 0.0.0.0 logLevel: info logFormat: default offline: false dataPath: ./data # In BYTES. Fastify's `bodyLimit` takes an integer and refuses anything else at boot, unlike the # 2.x body parser this default was written for, which took '5mb'. bodyParserLimit: 5242880 icons: # Iconify API the wiki fetches icons from the first time they are used. Point this at a # self-hosted Iconify API to keep icon lookups inside your network. apiUrl: 'https://api.iconify.design' files: # How much of /cache/files the served copies of uploaded files may take up, in bytes. # Trimmed back oldest-first once it is exceeded. Set to 0 to serve every request from the # database instead. cacheMaxSize: 536870912 scheduler: workers: 3 pollingCheck: 5 scheduledCheck: 300 maxRetries: 2 retryBackoff: 60 historyExpiration: 90000 # How long, in seconds, a job running in a worker thread may take before the scheduler stops # waiting for it and counts it as failed. A safety net rather than a schedule: a worker thread # that dies mid-task never answers at all, and without a ceiling the scheduler waits forever. taskTimeout: 300 # How long, in seconds, a job may sit marked as running before it is assumed that whatever was # running it is gone, and it is requeued. Deliberately generous: it has to outlast the longest # job the instance legitimately runs, since the alternative is starting a second copy of one. staleJobTimeout: 3600 # DB defaults api: isEnabled: false audit: # How many days of audit log to keep. Rows older than this are deleted by the `purgeAuditLog` # task, which runs daily. Set to 0 to keep everything for ever. # # Either 0 or at least 30: a shorter window would let somebody act and have the record of it # purged before anybody had reason to look. A value between the two is read as 30 rather than # honoured, wherever it came from. retentionDays: 90 mail: senderName: '' senderEmail: '' # Where links in emails point. Left empty, the host the request came in on is used instead — # which is right for a small instance and wrong behind a proxy or on a private address. defaultBaseURL: '' host: '' port: 465 name: '' secure: true verifySSL: true user: '' pass: '' useDKIM: false dkimDomainName: '' dkimKeySelector: '' dkimPrivateKey: '' metrics: isEnabled: false # The URL path the Prometheus exposition is served at. While the endpoint is enabled it takes # this path over from the page tree; turned off, nothing is registered and a page here is # served normally. path: '/metrics' # Which addresses may scrape without credentials. Anything else has to carry an API key or a # session holding `read:metrics`. Note that what an address means depends on # `security.trustProxy`: with it off, a wiki behind a reverse proxy sees the proxy's address # for every request. allowAnonymousLocal: true allowAnonymousPrivate: true allowAnonymousExternal: false # Which groups of metrics the exposition carries: the Node.js process (CPU, memory, GC, event # loop) and the wiki itself (content totals, job queue, scheduler health). The wiki group is # off by default because every one of its gauges is a count read fresh, so a scrape of it costs # about a dozen database queries. includeRuntime: true includeWiki: false scim: # SCIM 2.0 provisioning, served at /_scim/v2. Off by default: it is a directory's write access # to the wiki's user and group lists, and nothing about it is useful until an administrator has # deliberately turned it on and minted a key for it. isEnabled: false # What DELETE /Users/:id does to an account the client owns. `deactivate` clears its sessions # and its group memberships but keeps the row, so authorship on pages and history survives; # `delete` removes the row. Deactivation is the default because a wiki's users are authors. deleteAction: 'deactivate' # Where a provisioned account's email address is read from. `userName` is the SCIM attribute # every connector sends and is right wherever the login name is the mailbox; `emails` reads the # primary (or first work) entry of `emails[]` instead, for a directory whose UPN is not. emailSource: 'userName' # Whether POST /Groups may create a wiki group. A created group holds no permissions and no # page rules, so it grants nothing until an administrator fills it in. Off, a directory may # only manage the membership of groups that already exist here. allowGroupCreate: true # Per-address rate limit on /_scim/v2, counted the same way the login limit is and sharing the # same postgres-backed counter, so instances behind a load balancer agree about it. # # Far more generous than the auth limit, because the traffic is not the same shape: a first # sync of a large directory is hundreds of requests in a minute, and that is the endpoint # working. The ban is short for the same reason -- a connector that trips this should recover # on its next cycle rather than leave provisioning broken for a quarter of an hour. rateLimitEnabled: true rateLimitMax: 600 rateLimitWindow: '1m' rateLimitBan: '1m' # Addresses allowed to reach /_scim/v2 at all, as single addresses or CIDR subnets. EMPTY # means no restriction: the bearer token is then the only thing standing in front of the # endpoint. Note that what an address means depends on `security.trustProxy` -- with it off, a # wiki behind a reverse proxy sees the proxy for every request. ipAllowList: [] auth: autoLogin: false enforce2FA: false hideLocal: false loginBgUrl: '' secret: 'abcdef1234567890abcdef1234567890abcdef' # Whether passkeys may be used at all. Off, a passkey can neither be registered nor signed in # with — the ones already registered are kept, and work again the moment it is back on. allowPasskeys: true # Whether a user may edit their own profile — their name, their location, their avatar. Off # for an instance whose user records come from an identity provider and are written there. allowProfileEditing: true security: corsMode: 'OFF' corsConfig: '' enforceCsp: false trustProxy: false enforceHsts: false hstsDuration: 0 cspDirectives: '' uploadScanSVG: true disallowIframe: true uploadMaxFiles: 20 uploadMaxFileSize: 10485760 forceAssetDownload: true disallowOpenRedirect: true enforceSameOriginReferrerPolicy: true authRateLimitEnabled: true authRateLimitMax: 10 authRateLimitWindow: '2m' authRateLimitBan: '15m' flags: experimental: false authDebug: false sqlLog: false userDefaults: timezone: 'America/New_York' dateFormat: 'YYYY-MM-DD' timeFormat: '12h' # System defaults channel: NEXT cors: credentials: true maxAge: 600 methods: 'GET,POST' origin: true maintainerEmail: security@requarks.io tsDictMappings: ar: arabic hy: armenian eu: basque ca: catalan da: danish nl: dutch en: english fi: finnish fr: french de: german el: greek hi: hindi hu: hungarian id: indonesian ga: irish it: italian lt: lithuanian ne: nepali no: norwegian pt: portuguese ro: romanian ru: russian sr: serbian es: spanish sv: swedish ta: tamil tr: turkish yi: yiddish editors: asciidoc: contentType: adoc config: {} excalidraw: contentType: excalidraw config: {} markdown: contentType: markdown config: allowHTML: true linkify: true lineBreaks: true typographer: false underline: false wikiLinks: true tabWidth: 2 latexEngine: katex kroki: true plantuml: true multimdTable: true visual: contentType: markdown config: {} systemIds: localAuthId: '5a528c4c-0a82-4ad2-96a5-2b23811e6588' guestsGroupId: '10000000-0000-4000-8000-000000000001' usersGroupId: '20000000-0000-4000-8000-000000000002' groups: defaultPermissions: - 'read:pages' - 'read:assets' - 'read:comments' - 'write:comments' defaultRules: - name: Default Rule mode: ALLOW match: START roles: - 'read:pages' - 'read:assets' - 'read:comments' - 'write:comments' path: '' locales: [] sites: []