# For supported YAML types @see TYPO3\CMS\Install\Service\LocalConfigurationValueService->recursiveConfigurationFetching() docblock
GFX:
type: container
description: 'Image Processing'
items:
thumbnails:
type: bool
description: 'Enables the use of thumbnails in the backend interface.'
imagefile_ext:
type: list
description: 'Commalist of file extensions perceived as images by TYPO3. List should be set to "gif,png,jpeg,jpg" if ImageMagick is not available. Lowercase and no spaces between! To configure default conversion formats, please manually configure the extra array "imageFileConversionFormats" in settings.php.'
imageFileConversionFormats:
type: map
arrayKey: Input format (extension)
arrayValue: Output format (extension)
description: 'Define how image files are converted by default for preview output in the frontend when referenced with Image ViewHelpers for example. This settings allows to specify a map of input/output formats. The key "Input format (extension)" specifies a file extension like "jpg" (no dot). The right hand value "Output format (extension)" specifies the image file type/extension that files will be converted to. The special input format "default" will set the default preview creation format (usually "png" to preserve alpha-channel transparency). Any source file extension that should be kept when being rendered needs to be specified here, like jpeg=>jpeg, jpeg=>jpg, png=>png. Any other format listed in the "imagefile_ext" list, but not here, will use the "default" format. You can just set "default=>webp" for example to force every image being converted to webp. Non-convertible formats will be saved as png if possible, or else passed through.'
processor_enabled:
type: bool
description: 'Enables the use of Image- or GraphicsMagick.'
processor_path:
type: text
readonly: true
description: 'Path to the IM tools ''convert'', ''combine'', ''identify''.'
processor:
type: dropdown
allowedValues:
'ImageMagick': 'Choose ImageMagick for processing images'
'GraphicsMagick': 'Choose GraphicsMagick for processing images'
description: 'Select which external software on the server should process images - see also the Preset functionality to see what is available.'
processor_effects:
type: bool
description: 'If enabled, apply blur and sharpening in ImageMagick/GraphicMagick functions'
processor_allowUpscaling:
type: bool
description: 'If set, images can be scaled up if told so (in \TYPO3\CMS\Core\Imaging\GraphicalFunctions)'
processor_allowFrameSelection:
type: bool
description: 'If set, the [x] frame selector is appended to input filenames in stdgraphic. This speeds up image processing for PDF files considerably. Disable if your image processor or environment can''t cope with the frame selection.'
processor_stripColorProfileByDefault:
type: bool
description: 'If set, the processor_stripColorProfileParameters is used with all processor image operations by default. See tsRef for setting this parameter explicitly for IMAGE generation.'
processor_stripColorProfileParameters:
type: element-list
description: 'List of parameters: Specify the parameters to strip the profile information, which can reduce thumbnail size up to 60KB. Command can differ in IM/GM, IM also knows the -strip command. See imagemagick.org for details'
processor_colorspace:
type: text
description: 'String: Specify the colorspace to use. Defaults to "RGB" when using GraphicsMagick as processor and "sRGB" when using ImageMagick. Images would be rendered darker than the original when using ImageMagick in combination with "RGB".
Possible Values: CMY, CMYK, Gray, HCL, HSB, HSL, HWB, Lab, LCH, LMS, Log, Luv, OHTA, Rec601Luma, Rec601YCbCr, Rec709Luma, Rec709YCbCr, RGB, sRGB, Transparent, XYZ, YCbCr, YCC, YIQ, YCbCr, YUV'
processor_interlace:
type: text
description: 'String: Specify the interlace option to use. The result differs in different GM / IM versions. See manual of GraphicsMagick or ImageMagick for right option.
Possible values: None, Line, Plane, Partition'
jpg_quality:
type: int
description: 'Integer: Default JPEG generation quality'
webp_quality:
type: int
description: 'Integer: Default WebP generation quality'
avif_quality:
type: int
description: 'Integer: Default AVIF generation quality'
SYS:
type: container
description: 'System'
items:
fileCreateMask:
type: text
description: 'File mode mask for Unix file systems (when files are uploaded/created).'
folderCreateMask:
type: text
description: 'As above, but for folders.'
createGroup:
type: text
description: 'Group for newly created files and folders (Unix only). Group ownership can be changed on Unix file systems (see above). Set this if you want to change the group ownership of created files/folders to a specific group. This makes sense in all cases where the webserver is running with a different user/group as you do. Create a new group on your system and add you and the webserver user to the group. Now you can safely set the last bit in fileCreateMask/folderCreateMask to 0 (e.g. 770). Important: The user who is running your webserver needs to be a member of the group you specify here! Otherwise you might get some error messages.'
sitename:
type: text
description: 'Name of the base-site.'
cookieDomain:
type: text
description: 'Restricts the domain name for FE and BE session cookies. When setting the value to ".domain.com" (replace domain.com with your domain!), login sessions will be shared across subdomains. Alternatively, if you have more than one domain with sub-domains, you can set the value to a regular expression to match against the domain of the HTTP request. The result of the match is used as the domain for the cookie. eg. /\.(example1|example2)\.com$/ or /\.(example1\.com)|(example2\.net)$/. Separate domains for FE and BE can be set using $TYPO3_CONF_VARS[''FE''][''cookieDomain''] and $TYPO3_CONF_VARS[''BE''][''cookieDomain''] respectively.'
trustedHostsPattern:
type: text
description: 'Regular expression pattern that matches all allowed hostnames (including their ports) of this TYPO3 installation, or the string "SERVER_NAME" (default). The default value SERVER_NAME checks if the HTTP Host header equals the SERVER_NAME and SERVER_PORT. This is secure in correctly configured hosting environments and does not need further configuration. If you cannot change your hosting environment, you can enter a regular expression here. Examples: .*\.domain\.com matches all hosts that end with .domain.com with all corresponding subdomains. (.*\.domain|.*\.otherdomain)\.com matches all hostnames with subdomains from .domain.com and .otherdomain.com. Be aware that HTTP Host header may also contain a port. If your installation runs on a specific port, you need to explicitly allow this in your pattern, e.g. www\.domain\.com:88 allows only www.domain.com:88, not www.domain.com. To disable this check completely (not recommended because it is insecure) you can use ".*" as pattern.'
devIPmask:
type: text
description: 'Defines a list of IP addresses which will allow development-output to display. The debug() function will use this as a filter. See the function \TYPO3\CMS\Core\Utility\GeneralUtility::cmpIP() for details on syntax. Setting this to blank value will deny all. Setting to "*" will allow all.'
ddmmyy:
type: text
description: 'Format of dates (without times) - see PHP-function date()'
hhmm:
type: text
description: 'Format of times (without dates) - see PHP-function date()'
defaultScheme:
type: text
allowedValues:
'http': 'http'
'https': 'https'
description: 'Default URI scheme to be used in case none was given, e.g. "www.typo3.org" becomes "http://www.typo3.org"'
loginCopyrightWarrantyProvider:
type: text
description: 'If you provide warranty for TYPO3 to your customers insert you (company) name here. It will appear in the login-dialog as the warranty provider. (You must also set URL below).'
loginCopyrightWarrantyURL:
type: text
description: 'Add the URL where you explain the extend of the warranty you provide. This URL is displayed in the login dialog as the place where people can learn more about the conditions of your warranty. Must be set (more than 10 chars) in addition with the ''loginCopyrightWarrantyProvider'' message.'
textfile_ext:
type: text
description: 'Text file extensions. Those that can be edited. Executable PHP files may not be editable if disallowed!'
mediafile_ext:
type: text
description: 'Commalist of file extensions perceived as media files by TYPO3. Lowercase and no spaces between!'
miscfile_ext:
type: list
description: "Commalist of file extensions that don't logically fit into `textfile_ext` or `mediafile_ext` (like `zip` or `xz`). Lowercase and no spaces between!"
binPath:
type: text
description: 'List of absolute paths where external programs should be searched for. Eg. /usr/local/webbin/,/home/xyz/bin/. (ImageMagick path have to be configured separately)'
binSetup:
type: multiline
description: 'List of programs (separated by newline or comma). By default programs will be searched in default paths and the special paths defined by binPath. When PHP has openbasedir enabled the programs can not be found and have to be configured here. Example: perl=/usr/bin/perl,unzip=/usr/local/bin/unzip'
setMemoryLimit:
type: int
description: 'Integer: memory_limit in MB: If more than 16, TYPO3 will try to use ini_set() to set the memory limit of PHP to the value. This works only if the function ini_set() is not disabled by your sysadmin.'
phpTimeZone:
type: text
description: 'timezone to force for all date() and mktime() functions. A list of supported values can be found at php.net. If this is not set, a valid fallback will be searched for by PHP (php.ini''s date.timezone setting, server defaults, etc); and if no fallback is found, the value of "UTC" is used instead.'
UTF8filesystem:
type: bool
description: |
If TRUE then TYPO3 uses utf-8 to store file names. This allows for accented Latin letters as well as any other non-latin characters like Cyrillic and Chinese.
IMPORTANT: This requires a UTF-8 compatible locale in order to work. Otherwise problems with filenames containing special characters will occur.
See [SYS][systemLocale] and setlocale().
systemLocale:
type: text
description: 'Locale used for certain system related functions, e.g. escaping shell commands. If problems with filenames containing special characters occur, the value of this option is probably wrong. See setlocale(). Available locales: '
reverseProxyIP:
type: list
description: 'List of IP addresses. If TYPO3 is behind one or more (intransparent) reverse proxies the IP addresses must be added here and [SYS][reverseProxyHeaderMultiValue] must be set to ''first'' or ''last''.'
reverseProxyHeaderMultiValue:
type: text
allowedValues:
'none': 'Do not evaluate the reverse proxy header'
'first': 'Use the first IP address in the proxy header'
'last': 'Use the last IP address in the proxy header'
description: 'Position of the authoritative IP address within the "X-Forwarded-For" header (e.g. "X-Forwarded-For: 1.2.3.4, 2.3.4.5, 3.4.5.6" uses "1.2.3.4" with "first" and "3.4.5.6" with "last").'
reverseProxyPrefix:
type: text
description: 'Optional prefix to be added to the internal URL (SCRIPT_NAME and REQUEST_URI). Example: When proxying ext-domain.com to int-server.com/prefix this has to be set to prefix'
reverseProxySSL:
type: text
description: '''*'' or list of IP addresses of proxies that use SSL (https) for the connection to the client, but an unencrypted connection (http) to the server. If ''*'' all proxies defined in [SYS][reverseProxyIP] use SSL.'
reverseProxyPrefixSSL:
type: text
description: 'Prefix to be added to the internal URL (SCRIPT_NAME and REQUEST_URI) when accessing the server via an SSL proxy. This setting overrides [SYS][reverseProxyPrefix].'
displayErrors:
type: int
allowedValues:
'-1': 'TYPO3 does not touch the PHP setting. If [SYS][devIPmask] matches the user''s IP address, the configured [SYS][debugExceptionHandler] is used instead of the [SYS][productionExceptionHandler] to handle exceptions.'
'0': 'Live: Do not display any PHP error message. Sets "display_errors=0". Overrides the value of [SYS][exceptionalErrors] and sets it to 0 (= no errors are turned into exceptions). The configured [SYS][productionExceptionHandler] is used as exception handler.'
'1': 'Debug: Display error messages with the registered [SYS][errorHandler]. Sets "display_errors=1". The configured [SYS][debugExceptionHandler] is used as exception handler.'
description: 'Configures whether PHP errors or Exceptions should be displayed, effectively setting the PHP option display_errors during runtime.'
productionExceptionHandler:
type: phpClass
description: 'Classname to handle exceptions that might happen in the TYPO3-code. Leave empty to disable exception handling. Default: "TYPO3\CMS\Core\Error\ProductionExceptionHandler". This exception handler displays a nice error message when something went wrong. The error message is logged to the configured logs. Note: The configured "productionExceptionHandler" is used if [SYS][displayErrors] is set to "0" or is set to "-1" and [SYS][devIPmask] doesn''t match the user''s IP.'
debugExceptionHandler:
type: phpClass
description: 'Classname to handle exceptions that might happen in the TYPO3-code. Leave empty to disable exception handling. Default: "TYPO3\CMS\Core\Error\DebugExceptionHandler". This exception handler displays the complete stack trace of any encountered exception. The error message and the stack trace is logged to the configured logs. Note: The configured "debugExceptionHandler" is used if [SYS][displayErrors] is set to "1" or is set to "-1" and the [SYS][devIPmask] matches the user''s IP.'
errorHandler:
type: phpClass
description: 'Classname to handle PHP errors. E.g.: TYPO3\CMS\Core\Error\ErrorHandler. This class displays and logs all errors that are registered as [SYS][errorHandlerErrors]. Leave empty to disable error handling. Errors will be logged and can be sent to the optionally installed developer log or to the "syslog" database table. If an error is registered in [SYS][exceptionalErrors] it will be turned into an exception to be handled by the configured exceptionHandler.'
errorHandlerErrors:
type: errors
description: 'The E_* constant that will be handled by the [SYS][errorHandler]. Not all PHP error types can be handled! E_USER_DEPRECATED will always be handled, regardless of this setting. Default is 30466 = E_ALL & ~(E_STRICT | E_NOTICE | E_COMPILE_WARNING | E_COMPILE_ERROR | E_CORE_WARNING | E_CORE_ERROR | E_PARSE | E_ERROR) (see PHP documentation).'
exceptionalErrors:
type: errors
description: 'The E_* constant that will be converted into an exception by the default [SYS][errorHandler]. Default is 4096 = E_ALL & ~(E_STRICT | E_NOTICE | E_COMPILE_WARNING | E_COMPILE_ERROR | E_CORE_WARNING | E_CORE_ERROR | E_PARSE | E_ERROR | E_DEPRECATED | E_USER_DEPRECATED | E_WARNING | E_USER_ERROR | E_USER_NOTICE | E_USER_WARNING) (see PHP documentation). E_USER_DEPRECATED is always excluded to avoid exceptions to be thrown for deprecation messages.'
belogErrorReporting:
type: errors
description: 'Configures which PHP errors should be logged to the "syslog" database table (extension: belog). If set to "0" no PHP errors are logged to the sys_log table. Default is 30711 = E_ALL & ~(E_STRICT | E_NOTICE) (see PHP documentation).'
allowedPhpDisableFunctions:
type: element-list
description: 'A list of function names, which will not trigger an error but only a warning, if they can be found in your php.ini setting "disable_functions".'
generateApacheHtaccess:
type: bool
description: 'TYPO3 can create .htaccess files which are used by Apache Webserver. They are useful for access protection or performance improvements. Currently .htaccess files in the following directories are created, if they do not exist:
Referer header. Enabling this option is recommended.'
security.frontend.enforceContentSecurityPolicy:
type: bool
description: 'An HTTP Content-Security-Policy header is applied to all frontend requests. The policy can be overridden using a csp.yaml site configuration.'
security.frontend.reportContentSecurityPolicy:
type: bool
description: 'An HTTP Content-Security-Policy-Report-Only header is applied to all frontend requests. The policy can be overridden using a csp.yaml site configuration.'
security.frontend.allowInsecureFrameOptionInShowImageController:
type: bool
description: 'Allows the tx_cms_showpic eID script to accept the frame GET parameter without signature validation. This is not recommended, as it may allow uncontrolled resource consumption.'
security.frontend.allowInsecureSiteResolutionByQueryParameters:
type: bool
description: 'Site resolution can be overridden using the &id=...&L=... parameters. The URI path and host are then used only as defaults.'
security.system.enforceAllowedFileExtensions:
type: bool
description: 'Only file extensions configured in textfile_ext, mediafile_ext, and miscfile_ext are allowed to be processed by the File Abstraction Layer (FAL).'
security.system.enforceFileExtensionMimeTypeConsistency:
type: bool
description: 'Restricts file processing in the File Abstraction Layer (FAL) to files whose extension is consistent with their expected MIME type.'
rateLimiter:
type: array
description: 'Override rate limiter configuration by limiter ID. Each key is a limiter ID (e.g. "typo3-login-BE", "backend-password-recovery"), and each value is an array with keys like "limit", "interval", and/or "policy" to override the programmatic defaults.'
availablePasswordHashAlgorithms:
type: array
description: 'A list of available password hash mechanisms. Extensions may register additional mechanisms here. This is usually not extended in system/settings.php.'
LANG:
type: container
description: 'Language and Localization'
items:
loader:
type: map
description: |
Loader for localization files. Defaults to ['xlf' => 'TYPO3\\CMS\\Core\\Localization\\Loader\\XliffLoader'] for XLIFF files.
requireApprovedLocalizations:
type: bool
description: 'If set, translations are only taken into account if the according "approved" attribute is set to "yes" within the XLF file. Otherwise, all available translations are used.'
availableLocales:
type: element-list
description: 'Array of available locales for the system.'
resourceOverrides:
type: map
description: 'List of overrides for localization resources.'
EXT:
type: container
description: 'Extension Installation'
items:
excludeForPackaging:
type: list
description: 'List of directories and files which will not be packaged into extensions nor taken into account otherwise by the Extension Manager. Perl regular expression syntax!'
BE:
type: container
description: 'Backend'
items:
entryPoint:
type: text
description: 'URL slug for the TYPO3 backend. Defaults to "typo3".'
fileadminDir:
type: text
description: 'Path to the primary directory of files for editors. This is relative to the public web dir, DefaultStorage will be created with that configuration, do not access manually but via \TYPO3\CMS\Core\Resource\ResourceFactory::getDefaultStorage().'
lockRootPath:
type: element-list
description: 'List of absolute root path prefixes to be allowed for file operations (including FAL storages). The project root path is allowed in any case and does not need to be defined here. Ending slashes are enforced!'
lockBackendFile:
type: text
description: 'Optional file location to check whether the backend shall be locked. When not specified, uses the former default locations (legacy: "typo3conf/LOCK_BACKEND", composer "var/lock/LOCK_BACKEND"). Directory must be relative to the project root and must include the file name. The file must be writable for the PHP user and should be stored in a location that does not change between TYPO3 deployments (shared directory).'
userHomePath:
type: text
description: 'Combined folder identifier of the directory where TYPO3 backend-users have their home-dirs. A combined folder identifier looks like this: [storageUid]:[folderIdentifier]. Eg. 2:users/. A home for backend user 2 would be: 2:users/2/. Ending slash required!'
groupHomePath:
type: text
description: 'Combined folder identifier of the directory where TYPO3 backend-groups have their home-dirs. A combined folder identifier looks like this: [storageUid]:[folderIdentifier]. Eg. 2:groups/. A home for backend group 1 would be: 2:groups/1/. Ending slash required!'
userUploadDir:
type: text
description: 'Suffix to the user home dir which is what gets mounted in TYPO3. Eg. if the user dir is ../123_user/ and this value is /upload then ../123_user/upload gets mounted.'
warning_email_addr:
type: text
description: 'Email address that will receive notification whenever an attempt to login to the Install Tool is made and that will also receive warnings whenever more than 3 failed backend login attempts (regardless of user) are detected within an hour.'
warning_mode:
type: int
allowedValues:
'0': 'Do not send notification-emails upon backend-login'
'1': 'Send a notification-email every time a backend user logs in'
'2': 'Send a notification-email every time an ADMIN backend user logs in'
description: 'Send emails to warning_email_addr upon backend-login'
passwordReset:
type: bool
description: 'Enable password reset functionality on the backend login for TYPO3 Backend users. Can be disabled for systems where only e.g. LDAP / OAuth login is allowed. Password reset will then still work on CLI and for admins in the backend.'
passwordResetForAdmins:
type: bool
description: 'Enable password reset functionality for TYPO3 Administrators. This will affect all places such as backend login or CLI. Disable this option for increased security.'
requireMfa:
type: int
allowedValues:
'0': 'Do not require multi-factor authentication'
'1': 'Require multi-factor authentication for all users'
'2': 'Require multi-factor authentication only for non-admin users'
'3': 'Require multi-factor authentication only for admin users'
'4': 'Require multi-factor authentication only for system maintainers'
description: 'Define users which should be required to set up multi-factor authentication.'
recommendedMfaProvider:
type: text
description: 'Set the identifier of the multi-factor authentication provider, recommended for all users.'
loginRateLimit:
type: int
description: 'Maximum amount of login attempts for the time interval in [BE][loginRateLimitInterval], before further login requests will be denied. Setting this value to "0" will disable login rate limiting.'
loginRateLimitInterval:
type: dropdown
allowedValues:
'1 minute': '1 minute'
'5 minutes': '5 minutes'
'15 minutes': '15 minutes'
'30 minutes': '30 minutes'
description: 'Allowed time interval for the configured rate limit. Individual values using PHP relative formats can be set in system/additional.php.'
loginRateLimitIpExcludeList:
type: list
description: 'IP-numbers (with *-wildcards) that are excluded from rate limiting. Syntax similar to [BE][IPmaskList]. An empty value disables the exclude list check.'
passwordPolicy:
type: text
description: 'Name of the password policy to use.'
lockIP:
type: int
allowedValues:
'0': 'Default: Do not lock Backend User sessions to their IP address at all'
'1': 'Use the first part of the editors'' IPv4 address (e.g. "192.") as part of the session locking of Backend Users'
'2': 'Use the first two parts of the editors'' IPv4 address (e.g. "192.168") as part of the session locking of Backend Users'
'3': 'Use the first three parts of the editors'' IPv4 address (e.g. "192.168.13") as part of the session locking of Backend Users'
'4': 'Use the editors'' full IPv4 address (e.g. "192.168.13.84") as part of the session locking of Backend Users (highest security)'
description: 'Session IP locking for backend users. See [FE][lockIP] for details.'
lockIPv6:
type: int
allowedValues:
'0': 'Default: Do not lock Backend User sessions to their IP address at all'
'1': 'Use the first block (16 bits) of the editors'' IPv6 address (e.g. "2001:") as part of the session locking of Backend Users'
'2': 'Use the first two blocks (32 bits) of the editors'' IPv6 address (e.g. "2001:0db8") as part of the session locking of Backend Users'
'3': 'Use the first three blocks (48 bits) of the editors'' IPv6 address (e.g. "2001:0db8:85a3") as part of the session locking of Backend Users'
'4': 'Use the first four blocks (64 bits) of the editors'' IPv6 address (e.g. "2001:0db8:85a3:08d3") as part of the session locking of Backend Users'
'5': 'Use the first five blocks (80 bits) of the editors'' IPv6 address (e.g. "2001:0db8:85a3:08d3:1319") as part of the session locking of Backend Users'
'6': 'Use the first six blocks (96 bits) of the editors'' IPv6 address (e.g. "2001:0db8:85a3:08d3:1319:8a2e") as part of the session locking of Backend Users'
'7': 'Use the first seven blocks (112 bits) of the editors'' IPv6 address (e.g. "2001:0db8:85a3:08d3:1319:8a2e:0370") as part of the session locking of Backend Users'
'8': 'Use the editors'' full IPv6 address (e.g. "2001:0db8:85a3:08d3:1319:8a2e:0370:7344") as part of the session locking of Backend Users (highest security)'
description: 'Session IPv6 locking for backend users. See [FE][lockIPv6] for details.'
sessionTimeout:
type: int
description: 'Session time out for backend users in seconds. The value must be at least 180 to avoid side effects. Default is 28.800 seconds = 8 hours.'
IPmaskList:
type: list
description: 'Lets you define a list of IP-numbers (in CIDR-notation, e.g. 194.168.0.0/16,2002::1234:abcd:ffff:c0a8:101/64) that are the ONLY ones allowed access to ANY backend activity. On error an error header is sent and the script exits. Works like IP masking for users configurable through TSconfig. See syntax for that (or look up syntax for the function \TYPO3\CMS\Core\Utility\GeneralUtility::cmpIP())'
lockSSL:
type: bool
description: 'If set, the backend can only be operated from an SSL-encrypted connection (https). A redirect to the SSL version of a URL will happen when a user tries to access non-https admin-urls'
lockSSLPort:
type: int
description: 'Use a non-standard HTTPS port for lockSSL. Set this value if you use lockSSL and the HTTPS port of your webserver is not 443.'
cookieDomain:
type: text
description: 'Same as $TYPO3_CONF_VARS[''SYS''][''cookieDomain''] but only for BE cookies. If empty, $TYPO3_CONF_VARS[''SYS''][''cookieDomain''] value will be used.'
cookieName:
type: text
description: 'Set the name for the cookie used for the back-end user session'
cookieSameSite:
type: text
allowedValues:
'lax': 'Cookies set by TYPO3 are only available for the current site, third-party integrations are not allowed to read cookies, except for links and simple HTML forms'
'strict': 'Cookies sent by TYPO3 are only available for the current site, never shared to other third-party packages'
'none': 'Allow cookies set by TYPO3 to be sent to other sites as well, please note - this only works with HTTPS connections'
description: 'Indicates that the cookie should send proper information where the cookie can be shared (first-party cookies vs. third-party cookies) in TYPO3 Backend.'
showRefreshLoginPopup:
type: bool
description: 'If set, the Ajax relogin will show a real popup window for relogin after the count down. Some auth services need this as they add custom validation to the login form. If it''s not set, the Ajax relogin will show an inline relogin window.'
adminOnly:
type: int
allowedValues:
'-1': 'Total shutdown for maintenance purposes'
'0': 'Default: All users can access the TYPO3 Backend'
'1': 'Only administrators / system maintainers can log in, CLI interface is disabled as well'
'2': 'Only administrators / system maintainers have access to the TYPO3 Backend, CLI executions are allowed as well'
description: 'Restricts access to the TYPO3 Backend - especially useful when doing maintenance or updates'
disable_exec_function:
type: bool
description: 'Don''t use exec() function (except for ImageMagick which is disabled by [GFX][im]=0). If set, all file operations are done by the default PHP-functions. This is necessary under Windows! On Unix the system commands by exec() can be used, unless this is disabled.'
contentSecurityPolicyReportingUrl:
type: text
description: 'Content-Security-Policy reporting HTTP endpoint. If blank (""), the system default will be used. If set to zero ("0"), the reporting endpoint is disabled.'
fileDenyPattern:
type: text
readonly: true
description: 'A perl-compatible and JavaScript-compatible regular expression (without delimiters "/"!) that - if it matches a filename - will deny the file upload/rename or whatever. For security reasons, files with multiple extensions have to be denied on an Apache environment with mod_alias, if the filename contains a valid php handler in an arbitrary position. Also, ".htaccess" files have to be denied. Matching is done case-insensitive. Default value is stored in PHP constant FILE_DENY_PATTERN_DEFAULT'
versionNumberInFilename:
type: bool
description: |
If enabled, included asset files (like CSS, JS, SVG and other resources) loaded in the TYPO3 Backend will have their modification timestamp embedded in the referenced filename, ie. filename.1269312081.js.
This will make browsers and proxies reload the files if they change (thus avoiding caching issues).
IMPORTANT: This feature requires extra .htaccess rules to work (please refer to the typo3/sysext/install/Resources/Private/FolderStructureTemplateFiles/root-htaccess file shipped with TYPO3).config.debug = 0.'
pageNotFoundOnCHashError:
type: bool
description: 'If TRUE, a page not found call is made when cHash evaluation error occurs, otherwise caching is disabled and page output is displayed.'
pageUnavailable_force:
type: bool
description: 'If TRUE, every frontend page is shown as "unavailable". If the client matches [SYS][devIPmask], the page is shown as normal. This is useful during temporary site maintenance.'
checkFeUserPid:
type: bool
description: 'If set, the pid of fe_user logins must be sent in the form as the field ''pid'' and then the user must be located in the pid. If you unset this, you should change the fe_users.username eval-flag ''uniqueInPid'' to ''unique'' in $TCA. This will do: $TCA[''fe_users''][''columns''][''username''][''config''][''eval'']= ''nospace,lower,required,unique'';'
loginRateLimit:
type: int
description: 'Maximum amount of login attempts for the time interval in [FE][loginRateLimitInterval], before further login requests will be denied. Setting this value to "0" will disable login rate limiting.'
loginRateLimitInterval:
type: dropdown
allowedValues:
'1 minute': '1 minute'
'5 minutes': '5 minutes'
'15 minutes': '15 minutes'
'30 minutes': '30 minutes'
description: 'Allowed time interval for the configured rate limit. Individual values using PHP relative formats can be set in system/additional.php.'
loginRateLimitIpExcludeList:
type: list
description: 'IP-numbers (with *-wildcards) that are excluded from rate limiting. Syntax similar to [BE][IPmaskList]. An empty value disables the exclude list check.'
passwordPolicy:
type: text
description: 'Name of the password policy to use.'
lockIP:
type: int
allowedValues:
'0': 'Default: Do not lock Frontend User sessions to their IP address at all'
'1': 'Use the first part of the visitors'' IPv4 address (e.g. "192.") as part of the session locking of Frontend Users'
'2': 'Use the first two parts of the visitors'' IPv4 address (e.g. "192.168") as part of the session locking of Frontend Users'
'3': 'Use the first three parts of the visitors'' IPv4 address (e.g. "192.168.13") as part of the session locking of Frontend Users'
'4': 'Use the visitors'' full IPv4 address (e.g. "192.168.13.84") as part of the session locking of Frontend Users (highest security)'
description: 'If activated, Frontend Users are locked to (a part of) their public IP ($_SERVER[''REMOTE_ADDR'']) for their session, if REMOTE_ADDR is an IPv4-address. Enhances security but may throw off users that may change IP during their session (in which case you can lower it). The integer indicates how many parts of the IP address to include in the check for the session.'
lockIPv6:
type: int
allowedValues:
'0': 'Default: Do not lock Backend User sessions to their IP address at all'
'1': 'Use the first block (16 bits) of the editors'' IPv6 address (e.g. "2001:") as part of the session locking of Backend Users'
'2': 'Use the first two blocks (32 bits) of the editors'' IPv6 address (e.g. "2001:0db8") as part of the session locking of Backend Users'
'3': 'Use the first three blocks (48 bits) of the editors'' IPv6 address (e.g. "2001:0db8:85a3") as part of the session locking of Backend Users'
'4': 'Use the first four blocks (64 bits) of the editors'' IPv6 address (e.g. "2001:0db8:85a3:08d3") as part of the session locking of Backend Users'
'5': 'Use the first five blocks (80 bits) of the editors'' IPv6 address (e.g. "2001:0db8:85a3:08d3:1319") as part of the session locking of Backend Users'
'6': 'Use the first six blocks (96 bits) of the editors'' IPv6 address (e.g. "2001:0db8:85a3:08d3:1319:8a2e") as part of the session locking of Backend Users'
'7': 'Use the first seven blocks (112 bits) of the editors'' IPv6 address (e.g. "2001:0db8:85a3:08d3:1319:8a2e:0370") as part of the session locking of Backend Users'
'8': 'Use the visitors'' full IPv6 address (e.g. "2001:0db8:85a3:08d3:1319:8a2e:0370:7344") as part of the session locking of Backend Users (highest security)'
description: 'If activated, Frontend Users are locked to (a part of) their public IP ($_SERVER[''REMOTE_ADDR'']) for their session, if REMOTE_ADDR is an IPv6-address. Enhances security but may throw off users that may change IP during their session (in which case you can lower it). The integer indicates how many parts of the IP address to include in the check for the session.'
lifetime:
type: int
description: 'If >0 and the option permalogin is >=0, the cookie of FE users will have a lifetime of the number of seconds this value indicates. Otherwise it will be a session cookie (deleted when browser is shut down). Setting this value to 604800 will result in automatic login of FE users during a whole week, 86400 will keep the FE users logged in for a day.'
sessionTimeout:
type: int
description: 'Server side session timeout for frontend users in seconds. Will be overwritten by the lifetime property if the lifetime is longer.'
sessionDataLifetime:
type: int
description: 'If >0, the session data of an anonymous session will timeout and be removed after the number of seconds given (86400 seconds represents 24 hours).'
permalogin:
type: text
description: 'fileadmin/templates/template_workspace_preview_logout.html. Inside you can put the marker %1$s to insert the URL to go back to. Use this in <a href="%1$s">Go back...</a> links.'
versionNumberInFilename:
type: bool
description: |
If enabled, included asset files (like CSS, JS, SVG and other resources) loaded in the TYPO3 Frontend will have their modification timestamp embedded in the referenced filename, ie. filename.1269312081.js.
This will make browsers and proxies reload the files if they change (thus avoiding caching issues).
IMPORTANT: This feature requires extra .htaccess rules to work (please refer to the typo3/sysext/install/Resources/Private/FolderStructureTemplateFiles/root-htaccess file shipped with TYPO3).egulias/email-validator, namespace \Egulias\EmailValidator\Validation\. Currently these are:\Egulias\EmailValidator\Validation\DNSCheckValidation\Egulias\EmailValidator\Validation\NoRFCWarningsValidation\Egulias\EmailValidator\Validation\RFCValidation (enabled by default)\Egulias\EmailValidator\Validation\SpoofCheckValidationsystem/additional.php; see the documentation for details.system/additional.php; see the documentation for details.