ONHOST.UK

Configuration reference

Understand ONHOST CMS runtime configuration, database connection, mail settings, security controls and module flags.

## Runtime configuration ONHOST CMS reads safe defaults from `config/app.php`. The installer stores host-specific settings in `storage/generated/app.php`, which is merged at boot. Environment variables can override deployment values when your host supports them. Keep this generated file private and writable by PHP. ``` APP_ENV=production APP_URL=https://portal.example.com APP_FORCE_HTTPS=true APP_TIMEZONE=Europe/London DB_DRIVER=mysql DB_HOST=127.0.0.1 DB_PORT=3306 DB_DATABASE=onhost DB_USERNAME=onhost_user DB_PASSWORD=use-a-long-unique-password DB_CHARSET=utf8mb4 DB_COLLATION=utf8mb4_unicode_ci ``` The database settings also support `DB_CONNECT_TIMEOUT`, `DB_CONNECT_RETRIES` and `DB_RETRY_DELAY_MS` for hosts with short-lived database connection issues. Use the lowest retry values that make sense for your provider; retries are for transient failures, not an unavailable database. ## Administration settings Use **Admin → Settings** for values that belong to the running platform rather than the web host: branding, legal details, currencies, tax, invoice settings, SMTP, payment providers, OAuth, CAPTCHA, security policy and maintenance mode. Sensitive provider credentials are stored through the administration workflow and are not returned to the browser after saving. ## Email Use SMTP for production. Configure the host, port, username, password and TLS mode, then send a test message before enabling account verification or payment emails. Set a monitored support address; customers receive it in account and transaction messages. ## Security controls - Enable Force HTTPS only after the domain has a valid certificate. - Set trusted reverse-proxy addresses through `TRUSTED_PROXIES` when TLS terminates upstream. - Keep sessions in the private storage path and use a production `APP_ENV`. - Configure CAPTCHA and authentication limits before opening public registration. - Use the module manager for product delivery features instead of removing source files. ## Private storage Product releases are stored in `storage/private/downloads`. Never map that directory into a public web alias. The application validates entitlement, a short-lived signed token, expiry, file integrity and download limits before streaming a release.