Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Reference: [auth], users and roles

⟳: reloaded at runtime; no mark: taken at restart. See Hot reload.

[auth]

See Authentication, Password hashing.

KeyTypeDefaultEffect
authtable(required)authentication and the role sources
auth.jwt_sentinel_usernamestringjwtthe SSH name that requests JWT authentication (the token as password)
auth.timeout_secsinteger5timeout of a call to the authorization service
auth.authz_base_urlURLabsentservice that translates authorities into role names (POST /authz/resolve); without it, only authorities that are role names count
auth.roles_filepathroles.toml next to it, if it existsfile of [[roles]] and [[backends]]; its content is reloaded at runtime
auth.users_filepathusers.toml next to it, if it existsfile of [[users]]; its content is reloaded at runtime
auth.hash_workersintegerthe CPUs seen (cgroup quota included), at most 2threads that verify passwords, concurrently; each holds the argon2 m of its hash; 1 to 1024; CRAFT_FILE_GATE_HASH_WORKERS
auth.hash_queueinteger1024verifications that can wait for a thread; 1 to 65536; CRAFT_FILE_GATE_HASH_QUEUE
auth.hash_per_addressinteger4verifications in flight or queued for one address; 1 to 66560; no cap for an address in the whitelist_ips of the door’s ban list
auth.users ⟳array of tables-[[auth.users]], like [[users]]; the root wins
auth.roles ⟳array of tables-[[auth.roles]], like [[roles]]; the root wins
auth.backends ⟳array of tables-[[auth.backends]], like [[backends]]; the root wins

[auth.methods]

KeyTypeDefaultEffect
auth.methodstable-the active identity sources
auth.methods.jwttable-the JWT method
auth.methods.jwt.enabledbooleantrueaccept JWTs (SFTP under the sentinel name, REST as Bearer); requires [auth.jwt]
auth.methods.localtable-the local user store
auth.methods.local.enabledbooleanfalseenable the local store ([[users]] or users_file)
auth.methods.local.passwordbooleantrueaccept a password as proof
auth.methods.local.pubkeybooleantrueaccept an SSH public key as proof
auth.methods.local.allow_sha512_cryptbooleanfalsealso accept sha512-crypt hashes, $6$ (migration)
auth.methods.local.allow_bcryptbooleanfalsealso accept bcrypt hashes, $2a$, $2b$, $2y$ (migration)
auth.methods.local.users_filepathabsentusers file, like auth.users_file
auth.methods.local.max_argon2_memory_kibintegerabsent: nothing is checkedmemory budget of one verification, in KiB; a hash that exceeds it is named at load time; at least 1

[auth.jwt]

KeyTypeDefaultEffect
auth.jwttableabsent: no JWT verifiedJWT verification: a key source, and the claims
auth.jwt.secretstringabsentHMAC secret (HS256/384/512); CRAFT_FILE_GATE_JWT_SECRET or _FILE
auth.jwt.public_key_filepathabsentPEM public key (RS*, ES*)
auth.jwt.jwks_urlURLabsentJWKS endpoint of the identity provider; exclusive with secret and public_key_file
auth.jwt.jwks_refresh_interval_secsinteger3600JWKS refresh period; at least 1
auth.jwt.algorithmstringHS256HS256, HS384, HS512, RS256, RS384, RS512, ES256 or ES384
auth.jwt.username_pathstring/subJSON Pointer to the user name in the token
auth.jwt.authorities_pathstring/groupsJSON Pointer to the user’s authorities (roles)
auth.jwt.issuerstringabsentif set, iss is required and compared
auth.jwt.audiencestringabsentif set, aud is required and compared

[[users]]

KeyTypeDefaultEffect
users ⟳array of tables-the local users; also in users_file
users[].username ⟳string(required)the name; unique
users[].password_hash ⟳string(required)argon2 hash (craft-file-gate hash-password); never in clear text
users[].authorized_keys ⟳list[]SSH public keys, one authorized_keys line each
users[].authorities ⟳list[]the names of the user’s roles

[[roles]]

See Users, roles and mounts.

KeyTypeDefaultEffect
roles ⟳array of tables(required), here or in roles_filethe roles; also in roles_file
roles[].name ⟳string(required)the role name, unique; it is what authorities cite
roles[].user_key_algorithms ⟳list[]SSH key signature algorithms additionally allowed to the local users of this role, by name (see The SFTP door)
roles[].mounts ⟳array of tables(required)the role’s mounts, [[roles.mounts]]; at least one

[[roles.mounts]]

KeyTypeDefaultEffect
roles[].mounts[].backend ⟳string(required)the mounted backend, by the name of a [[backends]]
roles[].mounts[].mount_path ⟳path/where the mount appears to the user: absolute, without ., .., // or a trailing /
roles[].mounts[].home_dir ⟳path/where the mount starts on the storage; {username} there becomes the user’s name
roles[].mounts[].create_home ⟳booleanfalsecreate home_dir at login if missing; local backend only, see Local
roles[].mounts[].max_file_mb ⟳integerabsent: no capmaximum size of an uploaded file, in MB (1,048,576 bytes); 0: no upload
roles[].mounts[].acl ⟳array of tables[]: everything refusedthe mount’s rights, [[roles.mounts.acl]], see ACL
roles[].mounts[].hidden_stores ⟳tablethe backend’satomic writes of this mount, key by key (see Atomic writes)
roles[].mounts[].hidden_stores.enabled ⟳booleanthe backend’ssee server.hidden_stores.enabled
roles[].mounts[].hidden_stores.prefix ⟳stringthe backend’ssee server.hidden_stores.prefix
roles[].mounts[].hidden_stores.extension ⟳stringthe backend’ssee server.hidden_stores.extension

[[roles.mounts.acl]]

KeyTypeDefaultEffect
roles[].mounts[].acl[].path ⟳path(required)governed path, relative to the mount
roles[].mounts[].acl[].rights ⟳list(required)among read, write, list, delete, rename
roles[].mounts[].acl[].recursive ⟳booleanfalsetrue: the entry also governs everything under path