login.yaml 3.9 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758
  1. enabled: true # Enable the plugin
  2. built_in_css: true # Use built-in CSS
  3. route: # Specific route for Login page (default is '/login')
  4. redirect_to_login: true # If you try to access a page you don't have access to, should you redirect to login route
  5. redirect_after_login: # Path to redirect to after a successful login (eg '/user_profile')
  6. redirect_after_logout: '/' # Path to redirect to after a successful logout (eg '/')
  7. route_activate: '/activate_user' # Route for the user activation process
  8. route_forgot: '/forgot_password' # Route for the forgot password process
  9. route_reset: '/reset_password' # Route for the reset password process
  10. route_profile: '/user_profile' # Route for the user profile page
  11. route_register: '/user_register' # Route for the user registration page
  12. route_unauthorized: '/user_unauthorized' # Route for a page to display if user is unauthorized
  13. twofa_enabled: false # Two factor authentication enabled
  14. dynamic_page_visibility: false # Integrate access into page visibility so things can be shown or hidden in the menu
  15. parent_acl: false # Look to parent `access` rules for access requirements
  16. protect_protected_page_media: false # Take `access` rules into account when directly accessing a page's media
  17. rememberme:
  18. enabled: true # Enable 'remember me' functionality
  19. timeout: 604800 # Timeout in seconds. Defaults to 1 week
  20. name: grav-rememberme # Name prefix of the session cookie
  21. max_pw_resets_count: 2 # Number of password resets in a specific time frame (0 = unlimited)
  22. max_pw_resets_interval: 60 # Time in minutes to track password resets
  23. max_login_count: 5 # Number of failed login attempts in a specific time frame (0 = unlimited)
  24. max_login_interval: 10 # Time in minutes to track login attempts
  25. ipv6_subnet_size: 64 # Size of IPv6 block to track login attempts
  26. user_registration:
  27. enabled: false # Enable User Registration Process
  28. fields: # List of fields to validate and store during user registration
  29. - 'username' # This should match up with your registration form definition
  30. - 'password'
  31. - 'email'
  32. - 'fullname'
  33. - 'title'
  34. - 'level'
  35. - 'twofa_enabled'
  36. default_values: # Any default values for fields you would like to set
  37. level: Newbie # Here the 'level' field will be pre-populated with 'Newbie' text
  38. access: # Default access to set for users created during registration
  39. site:
  40. login: 'true'
  41. redirect_after_registration: '' # Route to redirect to after registration
  42. options:
  43. validate_password1_and_password2: true # Ensure that password1 and password2 match during registration (allows you to have just 1 pw field or 2)
  44. set_user_disabled: false # Set this `true` if you want a user to activate their account via email
  45. login_after_registration: false # Automatically login after registration
  46. send_activation_email: false # Send an email that requires a special link to be clicked in order to activate the account
  47. manually_enable: false # When using activation email, don't enable until an admin does it manually
  48. send_notification_email: false # Send an email to the site administrator to indicate a user has registered
  49. send_welcome_email: false # Send a welcome email to the user (probably should not be used with `send_activation_email`