Skip to main content

Client Configuration

After installing the client cabinet, check src/config.php. It should contain only local website settings: database connection, public API URL, cookie domain, system paths, and basic runtime options.

Project settings, menus, servers, payment methods, visual theme, and modules are configured in the SaaS panel and delivered to the client automatically.

Database​

Set the database connection for the installed client:

src/config.php
$config['db']['host'] = 'MySQL-8.4';
$config['db']['port'] = '3306';
$config['db']['username'] = 'root';
$config['db']['password'] = '';
$config['db']['dbname'] = 'mmoweb_front';
$config['db']['charset'] = 'utf8mb4';

Verify the connection in the installer or in the connection check section after uploading project settings.

Public API​

Enter the API base URL without the /graphql path. The client adds the required paths automatically:

src/config.php
$config['api']['url'] = 'https://api.mmo-web.dev';
$config['api']['max_connections'] = 3;
$config['api']['timeout'] = 2;

During installation, the client is securely enrolled with the selected project using a one-time code from the panel. No permanent update key needs to be copied into src/config.php or a template.

Client Salt​

globalSalt is generated locally by the installer. It is used to sign CSRF/cookie values and must not be empty.

src/config.php
$config['globalSalt'] = '64-character-generated-value';

Do not copy globalSalt between installations or replace it manually unless required: this can invalidate active sessions and CSRF tokens.

Cookies and Domain​

Set the cookie domain to the actual cabinet domain:

src/config.php
$config['cookie'] = [
'prefix' => 'mw_',
'path' => '/',
'domain' => 'cabinet.mmo-web.dev',
];

For local installation, use the OpenServer domain, for example demo.mmo-web.loc.

Local Client Admin​

The local client admin is only for technical operations related to the installed website. Main project settings are managed in the SaaS panel.

src/config.php
$config['admin']['enabled'] = true;
$config['admin']['ip'] = '127.0.0.1';

Do not leave * access on a public server. Restrict access to trusted IP addresses.

src/config.php
- $config['admin']['ip'] = '*';
+ $config['admin']['ip'] = '127.0.0.1';

Paths and Cache​

Keep the default paths unless the client directory structure was changed:

src/config.php
$config['internalDataPath'] = 'internal_data';
$config['externalDataPath'] = 'data';
$config['templatePath'] = 'template';
$config['cachePath'] = '%s/cache';

The internal_data directory must be blocked from direct web access.

Realtime Notifications​

When Centrifugo is enabled for a project, expose its WebSocket endpoint through the same domain as the cabinet, for example wss://cabinet.example.com/connection/websocket. The browser can then send the HttpOnly session cookie without exposing its identifier to JavaScript.

Allow only the original Cookie and Origin transport headers in the connect and refresh proxies. Add the proxy secret as a separate static header, and never list its name in http_headers or emulated_headers:

centrifugo.json
{
"client": {
"allowed_origins": ["https://cabinet.example.com"],
"proxy": {
"connect": {
"enabled": true,
"endpoint": "http://client-app/api/centrifugo/connect",
"timeout": "3s",
"http_headers": ["Cookie", "Origin"],
"http": {
"static_headers": {
"X-Centrifugo-Proxy-Secret": "replace-with-project-proxy-secret"
}
}
},
"refresh": {
"enabled": true,
"endpoint": "http://client-app/api/centrifugo/refresh",
"timeout": "3s",
"http_headers": ["Cookie", "Origin"],
"http": {
"static_headers": {
"X-Centrifugo-Proxy-Secret": "replace-with-project-proxy-secret"
}
}
}
}
}
}

The static header value must match the project's Proxy Secret. The connection closes after logout or session expiration.

centrifugo.json
- "http_headers": ["Cookie", "Origin", "X-Centrifugo-Proxy-Secret"]
+ "http_headers": ["Cookie", "Origin"]

Updates and Site Migration​

The installation identity is stored in the protected part of internal_data and is not overwritten by a normal update. When moving the site, transfer internal_data together with the other user data.

If the identity file is lost, the site continues to work with its current data, but client updates and delivery of new project settings become unavailable. Revoke the old installation in the project card, generate a new one-time code, and enroll the installation again in the local client admin.

Managed in the SaaS Panel​

  • game platforms and servers;
  • website and cabinet menus;
  • sign-in, registration, and recovery methods;
  • PIN protection for sensitive actions;
  • payment systems, currencies, and limits;
  • cabinet visual theme;
  • purchased module availability per server.