You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: custom/conf/app.example.ini
+5-1Lines changed: 5 additions & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -556,14 +556,16 @@ IMPORT_LOCAL_PATHS = false
556
556
; It also enables them to access other resources available to the user on the operating system that is running the Gitea instance and perform arbitrary actions in the name of the Gitea OS user.
557
557
; WARNING: This maybe harmful to you website or your operating system.
558
558
DISABLE_GIT_HOOKS = true
559
+
; Set to true to disable webhooks feature.
560
+
DISABLE_WEBHOOKS = false
559
561
; Set to false to allow pushes to gitea repositories despite having an incomplete environment - NOT RECOMMENDED
560
562
ONLY_ALLOW_PUSH_IF_GITEA_ENVIRONMENT_SET = true
561
563
;Comma separated list of character classes required to pass minimum complexity.
562
564
;If left empty or no valid values are specified, the default is off (no checking)
563
565
;Classes include "lower,upper,digit,spec"
564
566
PASSWORD_COMPLEXITY = off
565
567
; Password Hash algorithm, either "argon2", "pbkdf2", "scrypt" or "bcrypt"
566
-
PASSWORD_HASH_ALGO = argon2
568
+
PASSWORD_HASH_ALGO = pbkdf2
567
569
; Set false to allow JavaScript to read CSRF cookie
568
570
CSRF_COOKIE_HTTP_ONLY = true
569
571
; Validate against https://haveibeenpwned.com/Passwords to see if a password has been exposed
Copy file name to clipboardExpand all lines: docs/content/doc/advanced/config-cheat-sheet.en-us.md
+4-2Lines changed: 4 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -396,11 +396,12 @@ relation to port exhaustion.
396
396
It also enables them to access other resources available to the user on the operating system that is running the
397
397
Gitea instance and perform arbitrary actions in the name of the Gitea OS user.
398
398
This maybe harmful to you website or your operating system.
399
+
-`DISABLE_WEBHOOKS`: **false**: Set to `true` to disable webhooks feature.
399
400
-`ONLY_ALLOW_PUSH_IF_GITEA_ENVIRONMENT_SET`: **true**: Set to `false` to allow local users to push to gitea-repositories without setting up the Gitea environment. This is not recommended and if you want local users to push to gitea repositories you should set the environment appropriately.
400
401
-`IMPORT_LOCAL_PATHS`: **false**: Set to `false` to prevent all users (including admin) from importing local path on server.
401
402
-`INTERNAL_TOKEN`: **\<random at every install if no uri set\>**: Secret used to validate communication within Gitea binary.
402
403
-`INTERNAL_TOKEN_URI`: **<empty>**: Instead of defining internal token in the configuration, this configuration option can be used to give Gitea a path to a file that contains the internal token (example value: `file:/etc/gitea/internal_token`)
403
-
-`PASSWORD_HASH_ALGO`: **argon2**: The hash algorithm to use \[argon2, pbkdf2, scrypt, bcrypt\].
404
+
-`PASSWORD_HASH_ALGO`: **pbkdf2**: The hash algorithm to use \[argon2, pbkdf2, scrypt, bcrypt\], argon2 will spend more memory than others.
404
405
-`CSRF_COOKIE_HTTP_ONLY`: **true**: Set false to allow JavaScript to read CSRF cookie.
405
406
-`MIN_PASSWORD_LENGTH`: **6**: Minimum password length for new users.
406
407
-`PASSWORD_COMPLEXITY`: **off**: Comma separated list of character classes required to pass minimum complexity. If left empty or no valid values are specified, checking is disabled (off):
@@ -465,6 +466,7 @@ relation to port exhaustion.
465
466
-`DEFAULT_ALLOW_ONLY_CONTRIBUTORS_TO_TRACK_TIME`: **true**: Only allow users with write permissions to track time.
466
467
-`EMAIL_DOMAIN_WHITELIST`: **\<empty\>**: If non-empty, list of domain names that can only be used to register
467
468
on this instance.
469
+
-`EMAIL_DOMAIN_BLOCKLIST`: **\<empty\>**: If non-empty, list of domain names that cannot be used to register on this instance
468
470
-`SHOW_REGISTRATION_BUTTON`: **! DISABLE\_REGISTRATION**: Show Registration Button
469
471
-`SHOW_MILESTONES_DASHBOARD_PAGE`: **true** Enable this to show the milestones dashboard page - a view of all the user's milestones
470
472
-`AUTO_WATCH_NEW_REPOS`: **true**: Enable this to let all organisation users watch new repos when they are created
@@ -549,7 +551,7 @@ Define allowed algorithms and their minimum key length (use -1 to disable a type
Copy file name to clipboardExpand all lines: docs/content/doc/help/faq.en-us.md
+6-5Lines changed: 6 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -120,13 +120,14 @@ For more information, refer to Gitea's [API docs]({{< relref "doc/developers/api
120
120
121
121
There are multiple things you can combine to prevent spammers.
122
122
123
-
1. By only whitelisting certain domains with OpenID (see below)
124
-
2. Setting `ENABLE_CAPTCHA` to `true` in your `app.ini` and properly configuring `RECAPTCHA_SECRET` and `RECAPTCHA_SITEKEY`
125
-
3. Settings `DISABLE_REGISTRATION` to `true` and creating new users via the [CLI]({{< relref "doc/usage/command-line.en-us.md" >}}), [API]({{< relref "doc/developers/api-usage.en-us.md" >}}), or Gitea's Admin UI
123
+
1. By whitelisting or blocklisting certain email domains
124
+
2. By only whitelisting certain domains with OpenID (see below)
125
+
3. Setting `ENABLE_CAPTCHA` to `true` in your `app.ini` and properly configuring `RECAPTCHA_SECRET` and `RECAPTCHA_SITEKEY`
126
+
4. Settings `DISABLE_REGISTRATION` to `true` and creating new users via the [CLI]({{< relref "doc/usage/command-line.en-us.md" >}}), [API]({{< relref "doc/developers/api-usage.en-us.md" >}}), or Gitea's Admin UI
126
127
127
-
### Only allow certain email domains
128
+
### Only allow/block certain email domains
128
129
129
-
You can configure `EMAIL_DOMAIN_WHITELIST` in your app.ini under `[service]`
130
+
You can configure `EMAIL_DOMAIN_WHITELIST`or `EMAIL_DOMAIN_BLOCKLIST`in your app.ini under `[service]`
0 commit comments