| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | <?php | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  | /** | 
					
						
							|  |  |  |  * Session configuration options. | 
					
						
							|  |  |  |  * | 
					
						
							|  |  |  |  * Changes to these config files are not supported by BookStack and may break upon updates. | 
					
						
							|  |  |  |  * Configuration should be altered via the `.env` file or environment variables. | 
					
						
							|  |  |  |  * Do not edit this file unless you're happy to maintain any changes yourself. | 
					
						
							|  |  |  |  */ | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  | return [ | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Default session driver
 | 
					
						
							|  |  |  |     // Options: file, cookie, database, redis, memcached, array
 | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  |     'driver' => env('SESSION_DRIVER', 'file'), | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Session lifetime, in minutes
 | 
					
						
							| 
									
										
										
										
											2017-11-12 02:30:55 +08:00
										 |  |  |     'lifetime' => env('SESSION_LIFETIME', 120), | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Expire session on browser close
 | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  |     'expire_on_close' => false, | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Encrypt session data
 | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  |     'encrypt' => false, | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Location to store session files
 | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  |     'files' => storage_path('framework/sessions'), | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Session Database Connection
 | 
					
						
							|  |  |  |     // When using the "database" or "redis" session drivers, you can specify a
 | 
					
						
							|  |  |  |     // connection that should be used to manage these sessions. This should
 | 
					
						
							|  |  |  |     // correspond to a connection in your database configuration options.
 | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  |     'connection' => null, | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Session database table, if database driver is in use
 | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  |     'table' => 'sessions', | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Session Sweeping Lottery
 | 
					
						
							|  |  |  |     // Some session drivers must manually sweep their storage location to get
 | 
					
						
							|  |  |  |     // rid of old sessions from storage. Here are the chances that it will
 | 
					
						
							|  |  |  |     // happen on a given request. By default, the odds are 2 out of 100.
 | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  |     'lottery' => [2, 100], | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Session Cookie Name
 | 
					
						
							|  |  |  |     // Here you may change the name of the cookie used to identify a session
 | 
					
						
							|  |  |  |     // instance by ID. The name specified here will get used every time a
 | 
					
						
							|  |  |  |     // new session cookie is created by the framework for every driver.
 | 
					
						
							| 
									
										
										
										
											2018-09-22 18:41:46 +08:00
										 |  |  |     'cookie' => env('SESSION_COOKIE_NAME', 'bookstack_session'), | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Session Cookie Path
 | 
					
						
							|  |  |  |     // The session cookie path determines the path for which the cookie will
 | 
					
						
							|  |  |  |     // be regarded as available. Typically, this will be the root path of
 | 
					
						
							|  |  |  |     // your application but you are free to change this when necessary.
 | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  |     'path' => '/', | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Session Cookie Domain
 | 
					
						
							|  |  |  |     // Here you may change the domain of the cookie used to identify a session
 | 
					
						
							|  |  |  |     // in your application. This will determine which domains the cookie is
 | 
					
						
							|  |  |  |     // available to in your application. A sensible default has been set.
 | 
					
						
							| 
									
										
										
										
											2018-05-20 16:38:27 +08:00
										 |  |  |     'domain' => env('SESSION_DOMAIN', null), | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // HTTPS Only Cookies
 | 
					
						
							|  |  |  |     // By setting this option to true, session cookies will only be sent back
 | 
					
						
							|  |  |  |     // to the server if the browser has a HTTPS connection. This will keep
 | 
					
						
							|  |  |  |     // the cookie from being sent to you if it can not be done securely.
 | 
					
						
							| 
									
										
										
										
											2018-05-20 16:38:27 +08:00
										 |  |  |     'secure' => env('SESSION_SECURE_COOKIE', false), | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // HTTP Access Only
 | 
					
						
							|  |  |  |     // Setting this value to true will prevent JavaScript from accessing the
 | 
					
						
							|  |  |  |     // value of the cookie and the cookie will only be accessible through the HTTP protocol.
 | 
					
						
							| 
									
										
										
										
											2018-05-20 16:38:27 +08:00
										 |  |  |     'http_only' => true, | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-24 00:26:39 +08:00
										 |  |  |     // Same-Site Cookies
 | 
					
						
							|  |  |  |     // This option determines how your cookies behave when cross-site requests
 | 
					
						
							|  |  |  |     // take place, and can be used to mitigate CSRF attacks. By default, we
 | 
					
						
							|  |  |  |     // do not enable this as other CSRF protection services are in place.
 | 
					
						
							|  |  |  |     // Options: lax, strict
 | 
					
						
							| 
									
										
										
										
											2018-05-20 16:38:27 +08:00
										 |  |  |     'same_site' => null, | 
					
						
							| 
									
										
										
										
											2015-07-13 03:01:42 +08:00
										 |  |  | ]; |