· 8 years ago · May 25, 2018, 10:42 PM
1
2DataSource:
3 # What type of database do you want to use?
4 # Valid values: SQLITE, MYSQL
5 backend: 'MYSQL'
6 # Enable the database caching system, should be disabled on bungeecord environments
7 # or when a website integration is being used.
8 caching: true
9 # Database host address
10 mySQLHost: '***'
11 # Database port
12 mySQLPort: '3306'
13 # Connect to MySQL database over SSL
14 mySQLUseSSL: true
15 # Username to connect to the MySQL database
16 mySQLUsername: '***'
17 # Password to connect to the MySQL database
18 mySQLPassword: '***'
19 # Database Name, use with converters or as SQLITE database name
20 mySQLDatabase: '***'
21 # Table of the database
22 mySQLTablename: 'authme'
23 # Column of IDs to sort data
24 mySQLColumnId: 'id'
25 # Column for storing or checking players nickname
26 mySQLColumnName: 'username'
27 # Column for storing or checking players RealName
28 mySQLRealName: 'realname'
29 # Column for storing players passwords
30 mySQLColumnPassword: 'password'
31 # Column for storing players emails
32 mySQLColumnEmail: 'email'
33 # Column for storing if a player is logged in or not
34 mySQLColumnLogged: 'isLogged'
35 # Column for storing if a player has a valid session or not
36 mySQLColumnHasSession: 'hasSession'
37 # Column for storing the player's last IP
38 mySQLColumnIp: 'ip'
39 # Column for storing players lastlogins
40 mySQLColumnLastLogin: 'lastlogin'
41 # Column storing the registration date
42 mySQLColumnRegisterDate: 'regdate'
43 # Column for storing the IP address at the time of registration
44 mySQLColumnRegisterIp: 'regip'
45 # Column for storing player LastLocation - X
46 mySQLlastlocX: 'x'
47 # Column for storing player LastLocation - Y
48 mySQLlastlocY: 'y'
49 # Column for storing player LastLocation - Z
50 mySQLlastlocZ: 'z'
51 # Column for storing player LastLocation - World Name
52 mySQLlastlocWorld: 'world'
53 # Column for storing player LastLocation - Yaw
54 mySQLlastlocYaw: 'yaw'
55 # Column for storing player LastLocation - Pitch
56 mySQLlastlocPitch: 'pitch'
57 # Overrides the size of the DB Connection Pool, -1 = Auto
58 poolSize: -1
59 # The maximum lifetime of a connection in the pool, default = 1800 seconds
60 # You should set this at least 30 seconds less than mysql server wait_timeout
61 maxLifetime: 1800
62ExternalBoardOptions:
63 # Column for storing players passwords salts
64 mySQLColumnSalt: ''
65 # Column for storing players groups
66 mySQLColumnGroup: ''
67 # -1 means disabled. If you want that only activated players
68 # can log into your server, you can set here the group number
69 # of unactivated users, needed for some forum/CMS support
70 nonActivedUserGroup: -1
71 # Other MySQL columns where we need to put the username (case-sensitive)
72 mySQLOtherUsernameColumns: []
73 # How much log2 rounds needed in BCrypt (do not change if you do not know what it does)
74 bCryptLog2Round: 10
75 # phpBB table prefix defined during the phpBB installation process
76 phpbbTablePrefix: 'phpbb_'
77 # phpBB activated group ID; 2 is the default registered group defined by phpBB
78 phpbbActivatedGroupId: 2
79 # IP Board table prefix defined during the IP Board installation process
80 IPBTablePrefix: 'ipb_'
81 # IP Board default group ID; 3 is the default registered group defined by IP Board
82 IPBActivatedGroupId: 3
83 # Xenforo table prefix defined during the Xenforo installation process
84 XFTablePrefix: 'xf_'
85 # XenForo default group ID; 2 is the default registered group defined by Xenforo
86 XFActivatedGroupId: 2
87 # Wordpress prefix defined during WordPress installation
88 wordpressTablePrefix: 'wp_'
89settings:
90 sessions:
91 # Do you want to enable the session feature?
92 # If enabled, when a player authenticates successfully,
93 # his IP and his nickname is saved.
94 # The next time the player joins the server, if his IP
95 # is the same as last time and the timeout hasn't
96 # expired, he will not need to authenticate.
97 enabled: true
98 # After how many minutes should a session expire?
99 # A player's session ends after the timeout or if his IP has changed
100 timeout: 60
101 # Message language, available languages:
102 # https://github.com/AuthMe/AuthMeReloaded/blob/master/docs/translations.md
103 messagesLanguage: 'ru'
104 # Forces authme to hook into Vault instead of a specific permission handler system.
105 forceVaultHook: false
106 # Log level: INFO, FINE, DEBUG. Use INFO for general messages,
107 # FINE for some additional detailed ones (like password failed),
108 # and DEBUG for debugging
109 logLevel: 'FINE'
110 # By default we schedule async tasks when talking to the database. If you want
111 # typical communication with the database to happen synchronously, set this to false
112 useAsyncTasks: true
113 # By default we handle the AsyncPlayerPreLoginEvent which makes the plugin faster
114 # but it is incompatible with any permission plugin not included in our compatibility list.
115 # If you have issues with permission checks on player join please disable this option.
116 useAsyncPreLoginEvent: false
117 restrictions:
118 # Can not authenticated players chat?
119 # Keep in mind that this feature also blocks all commands not
120 # listed in the list below.
121 allowChat: false
122 # Hide the chat log from players who are not authenticated?
123 hideChat: true
124 # Allowed commands for unauthenticated players
125 allowCommands:
126 - '/login'
127 - '/register'
128 - '/l'
129 - '/reg'
130 - '/email'
131 - '/captcha'
132 # Max number of allowed registrations per IP
133 # The value 0 means an unlimited number of registrations!
134 maxRegPerIp: 2
135 # Minimum allowed username length
136 minNicknameLength: 3
137 # Maximum allowed username length
138 maxNicknameLength: 16
139 # When this setting is enabled, online players can't be kicked out
140 # due to "Logged in from another Location"
141 # This setting will prevent potential security exploits.
142 ForceSingleSession: true
143 ForceSpawnLocOnJoin:
144 # If enabled, every player that spawn in one of the world listed in
145 # "ForceSpawnLocOnJoin.worlds" will be teleported to the spawnpoint after successful
146 # authentication. The quit location of the player will be overwritten.
147 # This is different from "teleportUnAuthedToSpawn" that teleport player
148 # to the spawnpoint on join.
149 enabled: false
150 # WorldNames where we need to force the spawn location
151 # Case-sensitive!
152 worlds:
153 - 'world'
154 - 'world_nether'
155 - 'world_the_end'
156 # This option will save the quit location of the players.
157 SaveQuitLocation: false
158 # To activate the restricted user feature you need
159 # to enable this option and configure the AllowedRestrictedUser field.
160 AllowRestrictedUser: false
161 # The restricted user feature will kick players listed below
162 # if they don't match the defined IP address. Names are case-insensitive.
163 # You can use * as wildcard (127.0.0.*), or regex with a "regex:" prefix regex:127\.0\.0\..*
164 # Example:
165 # AllowedRestrictedUser:
166 # - playername;127.0.0.1
167 # - playername;regex:127\.0\.0\..*
168 AllowedRestrictedUser: []
169 # Ban unknown IPs trying to log in with a restricted username?
170 banUnsafedIP: false
171 # Should unregistered players be kicked immediately?
172 kickNonRegistered: false
173 # Should players be kicked on wrong password?
174 kickOnWrongPassword: true
175 # Should not logged in players be teleported to the spawn?
176 # After the authentication they will be teleported back to
177 # their normal position.
178 teleportUnAuthedToSpawn: false
179 # Can unregistered players walk around?
180 allowMovement: false
181 # After how many seconds should players who fail to login or register
182 # be kicked? Set to 0 to disable.
183 timeout: 60
184 # Regex pattern of allowed characters in the player name.
185 allowedNicknameCharacters: '[a-zA-Z0-9_]*'
186 # How far can unregistered players walk?
187 # Set to 0 for unlimited radius
188 allowedMovementRadius: 100
189 # Should we protect the player inventory before logging in? Requires ProtocolLib.
190 ProtectInventoryBeforeLogIn: true
191 # Should we deny the tabcomplete feature before logging in? Requires ProtocolLib.
192 DenyTabCompleteBeforeLogin: false
193 # Should we display all other accounts from a player when he joins?
194 # permission: /authme.admin.accounts
195 displayOtherAccounts: true
196 # Spawn priority; values: authme, essentials, multiverse, default
197 spawnPriority: 'essentials'
198 # Maximum Login authorized by IP
199 maxLoginPerIp: 2
200 # Maximum Join authorized by IP
201 maxJoinPerIp: 2
202 # AuthMe will NEVER teleport players if set to true!
203 noTeleport: false
204 # Regex syntax for allowed chars in passwords. The default [!-~] allows all visible ASCII
205 # characters, which is what we recommend. See also http://asciitable.com
206 # You can test your regex with https://regex101.com
207 allowedPasswordCharacters: '[!-~]*'
208 # Threshold of the other accounts command, a value less than 2 means disabled.
209 otherAccountsCmdThreshold: 0
210 # Command to run when a user has more accounts than the configured threshold.
211 # Available variables: %playername%, %playerip%
212 otherAccountsCmd: 'say Игрок %playername% Ñ IP %playerip% имеет неÑколько аккаунтов.'
213 GameMode:
214 # Force survival gamemode when player joins?
215 ForceSurvivalMode: false
216 unrestrictions:
217 # Below you can list all account names that AuthMe will ignore
218 # for registration or login. Configure it at your own risk!!
219 # This option adds compatibility with BuildCraft and some other mods.
220 # It is case-insensitive! Example:
221 # UnrestrictedName:
222 # - 'npcPlayer'
223 # - 'npcPlayer2'
224 UnrestrictedName: []
225 security:
226 # Minimum length of password
227 minPasswordLength: 6
228 # Maximum length of password
229 passwordMaxLength: 30
230 # Possible values: SHA256, BCRYPT, BCRYPT2Y, PBKDF2, SALTEDSHA512,
231 # MYBB, IPB3, PHPBB, PHPFUSION, SMF, XENFORO, XAUTH, JOOMLA, WBB3, WBB4, MD5VB,
232 # PBKDF2DJANGO, WORDPRESS, ROYALAUTH, ARGON2, CUSTOM (for developers only). See full list at
233 # https://github.com/AuthMe/AuthMeReloaded/blob/master/docs/hash_algorithms.md
234 # If you use ARGON2, check that you have the argon2 c library on your system
235 passwordHash: 'SHA256'
236 # If a password check fails, AuthMe will also try to check with the following hash methods.
237 # Use this setting when you change from one hash method to another.
238 # AuthMe will update the password to the new hash. Example:
239 # legacyHashes:
240 # - 'SHA1'
241 legacyHashes: []
242 # Salt length for the SALTED2MD5 MD5(MD5(password)+salt)
243 doubleMD5SaltLength: 8
244 # Number of rounds to use if passwordHash is set to PBKDF2. Default is 10000
245 pbkdf2Rounds: 10000
246 # Prevent unsafe passwords from being used; put them in lowercase!
247 # You should always set 'help' as unsafePassword due to possible conflicts.
248 # unsafePasswords:
249 # - '123456'
250 # - 'password'
251 # - 'help'
252 unsafePasswords:
253 - '123456'
254 - '654321'
255 - 'password'
256 - 'qwerty'
257 - '12345'
258 - '54321'
259 - '123456789'
260 - 'help'
261 registration:
262 # Enable registration on the server?
263 enabled: true
264 # Send every X seconds a message to a player to
265 # remind him that he has to login/register
266 messageInterval: 5
267 # Only registered and logged in players can play.
268 # See restrictions for exceptions
269 force: true
270 # Type of registration: PASSWORD or EMAIL
271 # PASSWORD = account is registered with a password supplied by the user;
272 # EMAIL = password is generated and sent to the email provided by the user.
273 # More info at https://github.com/AuthMe/AuthMeReloaded/wiki/Registration
274 type: 'PASSWORD'
275 # Second argument the /register command should take: NONE = no 2nd argument
276 # CONFIRMATION = must repeat first argument (pass or email)
277 # EMAIL_OPTIONAL = for password register: 2nd argument can be empty or have email address
278 # EMAIL_MANDATORY = for password register: 2nd argument MUST be an email address
279 secondArg: 'CONFIRMATION'
280 # Do we force kick a player after a successful registration?
281 # Do not use with login feature below
282 forceKickAfterRegister: false
283 # Does AuthMe need to enforce a /login after a successful registration?
284 forceLoginAfterRegister: false
285 # Enable to display the welcome message (welcome.txt) after a login
286 # You can use colors in this welcome.txt + some replaced strings:
287 # {PLAYER}: player name, {ONLINE}: display number of online players,
288 # {MAXPLAYERS}: display server slots, {IP}: player ip, {LOGINS}: number of players logged,
289 # {WORLD}: player current world, {SERVER}: server name
290 # {VERSION}: get current bukkit version, {COUNTRY}: player country
291 useWelcomeMessage: false
292 # Broadcast the welcome message to the server or only to the player?
293 # set true for server or false for player
294 broadcastWelcomeMessage: false
295 # Should we delay the join message and display it once the player has logged in?
296 delayJoinMessage: false
297 # The custom join message that will be sent after a successful login,
298 # keep empty to use the original one.
299 # Available variables:
300 # {PLAYERNAME}: the player name (no colors)
301 # {DISPLAYNAME}: the player display name (with colors)
302 # {DISPLAYNAMENOCOLOR}: the player display name (without colors)
303 customJoinMessage: ''
304 # Should we remove the leave messages of unlogged users?
305 removeUnloggedLeaveMessage: true
306 # Should we remove join messages altogether?
307 removeJoinMessage: true
308 # Should we remove leave messages altogether?
309 removeLeaveMessage: true
310 # Do we need to add potion effect Blinding before login/reigster?
311 applyBlindEffect: false
312 # Do we need to prevent people to login with another case?
313 # If Xephi is registered, then Xephi can login, but not XEPHI/xephi/XePhI
314 preventOtherCase: true
315GroupOptions:
316 # Enables switching a player to defined permission groups before they log in.
317 # See below for a detailed explanation.
318 enablePermissionCheck: false
319 # This is a very important option: if a registered player joins the server
320 # AuthMe will switch him to unLoggedInGroup. This should prevent all major exploits.
321 # You can set up your permission plugin with this special group to have no permissions,
322 # or only permission to chat (or permission to send private messages etc.).
323 # The better way is to set up this group with few permissions, so if a player
324 # tries to exploit an account they can do only what you've defined for the group.
325 # After login, the player will be moved to his correct permissions group!
326 # Please note that the group name is case-sensitive, so 'admin' is different from 'Admin'
327 # Otherwise your group will be wiped and the player will join in the default group []!
328 # Example: registeredPlayerGroup: 'NotLogged'
329 registeredPlayerGroup: ''
330 # Similar to above, unregistered players can be set to the following
331 # permissions group
332 unregisteredPlayerGroup: ''
333Email:
334 # Email SMTP server host
335 mailSMTP: 'smtp.gmail.com'
336 # Email SMTP server port
337 mailPort: 465
338 # Only affects port 25: enable TLS/STARTTLS?
339 useTls: true
340 # Email account which sends the mails
341 mailAccount: '***@gmail.com'
342 # Email account password
343 mailPassword: '***'
344 # Email address, fill when mailAccount is not the email address of the account
345 mailAddress: ''
346 # Custom sender name, replacing the mailAccount name in the email
347 mailSenderName: 'server'
348 # Recovery password length
349 RecoveryPasswordLength: 8
350 # Mail Subject
351 mailSubject: 'ВоÑÑтановление доÑтупа к аккаунту'
352 # Like maxRegPerIP but with email
353 maxRegPerEmail: 1
354 # Recall players to add an email?
355 recallPlayers: false
356 # Delay in minute for the recall scheduler
357 delayRecall: 5
358 # Blacklist these domains for emails
359 emailBlacklisted:
360 - '10minutemail.com'
361 # Whitelist ONLY these domains for emails
362 emailWhitelisted: []
363 # Send the new password drawn in an image?
364 generateImage: false
365 # The OAuth2 token
366 emailOauth2Token: ''
367Hooks:
368 # Do we need to hook with multiverse for spawn checking?
369 multiverse: false
370 # Do we need to hook with BungeeCord?
371 bungeecord: false
372 # Send player to this BungeeCord server after register/login
373 sendPlayerTo: ''
374 # Do we need to disable Essentials SocialSpy on join?
375 disableSocialSpy: false
376 # Do we need to force /motd Essentials command on join?
377 useEssentialsMotd: false
378Protection:
379 # Enable some servers protection (country based login, antibot)
380 enableProtection: false
381 # Apply the protection also to registered usernames
382 enableProtectionRegistered: true
383 # Countries allowed to join the server and register. For country codes, see
384 # http://dev.maxmind.com/geoip/legacy/codes/iso3166/
385 # PLEASE USE QUOTES!
386 countries:
387 - 'UA'
388 - 'RU'
389 - 'BY'
390 - 'PL'
391 - 'MD'
392 - 'CZ'
393 - 'EE'
394 - 'LV'
395 - 'LT'
396 - 'KZ'
397 - 'GR'
398 - 'KG'
399 - 'SE'
400 - 'IT'
401 - 'FR'
402 # Countries not allowed to join the server and register
403 # PLEASE USE QUOTES!
404 countriesBlacklist:
405 - 'A1'
406 # Do we need to enable automatic antibot system?
407 enableAntiBot: true
408 # The interval in seconds
409 antiBotInterval: 5
410 # Max number of players allowed to login in the interval
411 # before the AntiBot system is enabled automatically
412 antiBotSensibility: 10
413 # Duration in minutes of the antibot automatic system
414 antiBotDuration: 5
415 # Delay in seconds before the antibot activation
416 antiBotDelay: 3
417Purge:
418 # If enabled, AuthMe automatically purges old, unused accounts
419 useAutoPurge: false
420 # Number of days after which an account should be purged
421 daysBeforeRemovePlayer: 180
422 # Do we need to remove the player.dat file during purge process?
423 removePlayerDat: false
424 # Do we need to remove the Essentials/userdata/player.yml file during purge process?
425 removeEssentialsFile: false
426 # World in which the players.dat are stored
427 defaultWorld: 'world'
428 # Remove LimitedCreative/inventories/player.yml, player_creative.yml files during purge?
429 removeLimitedCreativesInventories: false
430 # Do we need to remove the AntiXRayData/PlayerData/player file during purge process?
431 removeAntiXRayFile: false
432 # Do we need to remove permissions?
433 removePermissions: false
434Security:
435 SQLProblem:
436 # Stop the server if we can't contact the sql database
437 # Take care with this, if you set this to false,
438 # AuthMe will automatically disable and the server won't be protected!
439 stopServer: true
440 console:
441 # Remove passwords from console?
442 removePassword: false
443 # Copy AuthMe log output in a separate file as well?
444 logConsole: true
445 captcha:
446 # Enable captcha when a player uses wrong password too many times
447 useCaptcha: false
448 # Max allowed tries before a captcha is required
449 maxLoginTry: 5
450 # Captcha length
451 captchaLength: 5
452 # Minutes after which login attempts count is reset for a player
453 captchaCountReset: 60
454 tempban:
455 # Tempban a user's IP address if they enter the wrong password too many times
456 enableTempban: false
457 # How many times a user can attempt to login before their IP being tempbanned
458 maxLoginTries: 10
459 # The length of time a IP address will be tempbanned in minutes
460 # Default: 480 minutes, or 8 hours
461 tempbanLength: 120
462 # How many minutes before resetting the count for failed logins by IP and username
463 # Default: 480 minutes (8 hours)
464 minutesBeforeCounterReset: 120
465 # The command to execute instead of using the internal ban system, empty if disabled.
466 # Available placeholders: %player%, %ip%
467 customCommand: ''
468 recoveryCode:
469 # Number of characters a recovery code should have (0 to disable)
470 length: 8
471 # How many hours is a recovery code valid for?
472 validForHours: 4
473 # Max number of tries to enter recovery code
474 maxTries: 3
475 # How long a player has after password recovery to change their password
476 # without logging in. This is in minutes.
477 # Default: 2 minutes
478 passwordChangeTimeout: 2
479 emailRecovery:
480 # Seconds a user has to wait for before a password recovery mail may be sent again
481 # This prevents an attacker from abusing AuthMe's email feature.
482 cooldown: 60
483 privacy:
484 # The mail shown using /email show will be partially hidden
485 # E.g. (if enabled)
486 # original email: my.email@example.com
487 # hidden email: my.***@***mple.com
488 enableEmailMasking: true
489 # Minutes after which a verification code will expire
490 verificationCodeExpiration: 10
491# Before a user logs in, various properties are temporarily removed from the player,
492# such as OP status, ability to fly, and walk/fly speed.
493# Once the user is logged in, we add back the properties we previously saved.
494# In this section, you may define how these properties should be handled.
495# Read more at https://github.com/AuthMe/AuthMeReloaded/wiki/Limbo-players
496limbo:
497 persistence:
498 # Besides storing the data in memory, you can define if/how the data should be persisted
499 # on disk. This is useful in case of a server crash, so next time the server starts we can
500 # properly restore things like OP status, ability to fly, and walk/fly speed.
501 # DISABLED: no disk storage,
502 # INDIVIDUAL_FILES: each player data in its own file,
503 # DISTRIBUTED_FILES: distributes players into different files based on their UUID, see below
504 type: 'INDIVIDUAL_FILES'
505 # This setting only affects DISTRIBUTED_FILES persistence. The distributed file
506 # persistence attempts to reduce the number of files by distributing players into various
507 # buckets based on their UUID. This setting defines into how many files the players should
508 # be distributed. Possible values: ONE, FOUR, EIGHT, SIXTEEN, THIRTY_TWO, SIXTY_FOUR,
509 # ONE_TWENTY for 128, TWO_FIFTY for 256.
510 # For example, if you expect 100 non-logged in players, setting to SIXTEEN will average
511 # 6.25 players per file (100 / 16).
512 # Note: if you change this setting all data will be migrated. If you have a lot of data,
513 # change this setting only on server restart, not with /authme reload.
514 distributionSize: 'SIXTEEN'
515 # Whether the player is allowed to fly: RESTORE, ENABLE, DISABLE, NOTHING.
516 # RESTORE sets back the old property from the player. NOTHING will prevent AuthMe
517 # from modifying the 'allow flight' property on the player.
518 restoreAllowFlight: 'RESTORE'
519 # Restore fly speed: RESTORE, DEFAULT, MAX_RESTORE, RESTORE_NO_ZERO.
520 # RESTORE: restore the speed the player had;
521 # DEFAULT: always set to default speed;
522 # MAX_RESTORE: take the maximum of the player's current speed and the previous one
523 # RESTORE_NO_ZERO: Like 'restore' but sets speed to default if the player's speed was 0
524 restoreFlySpeed: 'RESTORE'
525 # Restore walk speed: RESTORE, DEFAULT, MAX_RESTORE, RESTORE_NO_ZERO.
526 # See above for a description of the values.
527 restoreWalkSpeed: 'DEFAULT'
528BackupSystem:
529 # General configuration for backups: if false, no backups are possible
530 ActivateBackup: true
531 # Create backup at every start of server
532 OnServerStart: true
533 # Create backup at every stop of server
534 OnServerStop: true
535 # Windows only: MySQL installation path
536 MysqlWindowsPath: 'C:\Program Files\MySQL\MySQL Server 5.1\'
537# Converter settings: see https://github.com/AuthMe/AuthMeReloaded/wiki/Converters
538Converter:
539 Rakamak:
540 # Rakamak file name
541 fileName: 'users.rak'
542 # Rakamak use IP?
543 useIP: false
544 # Rakamak IP file name
545 ipFileName: 'UsersIp.rak'
546 CrazyLogin:
547 # CrazyLogin database file name
548 fileName: 'accounts.db'
549 loginSecurity:
550 # LoginSecurity: convert from SQLite; if false we use MySQL
551 useSqlite: true
552 mySql:
553 # LoginSecurity MySQL: database host
554 host: ''
555 # LoginSecurity MySQL: database name
556 database: ''
557 # LoginSecurity MySQL: database user
558 user: ''
559 # LoginSecurity MySQL: password for database user
560 password: ''