Configuration
Configuration values in imspr/app/Config are source declarations, not verified deployment settings. Use the files below to locate application behavior boundaries, then verify the environment, selected boot variant, and effective runtime values separately.
[!WARNING] Several effective values remain deployment-dependent.
App.phphard-codes $baseURL whileConstants.phpseparately derives BASEURL fromgetenv('app.baseURL'); the source does not establish precedence or the effective deployed URL. Environment-derived values, database credentials, encryption material, and the selected boot variant are also unverified. Review the deployed configuration before relying on these declarations.The source security defaults declare forced HTTPS, secure cookies, HTTP-only cookies, and CSP as disabled. CSRF regeneration and redirect-on-failure are declared enabled, but runtime enforcement is outside this page's evidence. Treat these settings as deployment review items.
Application and request settings
imspr/app/Config/App.php defines the application URL, session storage, cookie behavior, and request-security flags for Config\App.
| Boundary | Source-defined declaration |
|---|---|
| Application URL | $baseURL = https://dev.novusoftit.com/ |
| Session driver | $sessionDriver = CodeIgniter\\Session\\Handlers\\FileHandler |
| Session cookie | $sessionCookieName = ci_session; $sessionExpiration = 7200; $sessionSavePath = WRITEPATH . 'session' |
| Cookie security | $cookieSecure = false; $cookieHTTPOnly = false |
| HTTPS enforcement | $forceGlobalSecureRequests = false |
| CSRF naming and behavior | $CSRFTokenName = csrf_test_name; $CSRFRegenerate = true; $CSRFRedirect = true |
| Content Security Policy | $CSPEnabled = false |
Environment-derived bindings
imspr/app/Config/Constants.php defines application constants from environment lookups and path expressions. The source does not provide the resulting deployed values.
| Constant | Source-defined expression |
|---|---|
| BASEURL | getenv('app.baseURL') |
| PROJECTNAME | getenv('project.name') |
| DEFAULTLOGO | getenv('app.baseURL').getenv('project.default.logo') |
| PUBLICROOTPATH | ROOTPATH.getenv('project.path.public') |
| MAINDB | getenv('database.default.database') |
| HASHSALT | getenv('project.hash.salt') |
Database profiles
imspr/app/Config/Database.php declares the default and test profiles.
| Profile | Source-defined settings |
|---|---|
| default | Host localhost; blank username, password, and database; DBDriver MySQLi; pConnect false; cacheOn false; DBDebug is enabled when ENVIRONMENT !== 'production'; port 3306 |
| tests | Host 127.0.0.1; blank username and password; database :memory:; DBDriver SQLite3; DBPrefix db_; port 3306 |
| Testing override | When ENVIRONMENT === 'testing', defaultGroup is tests. If getenv('DB') supplies a group and TESTPATH . 'travis/Database.php' exists, a non-empty $dbconfig containing the requested group key replaces the tests profile. |
Other configuration surfaces
| Surface | Source-defined boundary |
|---|---|
Encryption — imspr/app/Config/Encryption.php |
$driver selects OpenSSL; the file also declares an encryption key seed, but the effective deployed key is not verified. |
Logging — imspr/app/Config/Logger.php |
$threshold is 3; $dateFormat is Y-m-d H:i:s. The CodeIgniter\\Log\\Handlers\\FileHandler handles critical, alert, emergency, debug, error, info, notice, and warning; fileExtension is blank and filePermissions is 0644. |
Validation rule sets — imspr/app/Config/Validation.php |
$ruleSets lists \CodeIgniter\Validation\Rules, \CodeIgniter\Validation\FormatRules, \CodeIgniter\Validation\FileRules, and \CodeIgniter\Validation\CreditCardRules. |
Validation templates — imspr/app/Config/Validation.php |
$templates maps list to CodeIgniter\\Validation\\Views\\list and single to CodeIgniter\\Validation\\Views\\single. |
[!NOTE]
imspr/app/Config/Services.phpcontains a line-commentedexampleservice factory. It is not an active application-specific service declaration and should not be treated as an availableexampleservice.
Boot variants
These files declare alternative error and debug settings. The evidence does not establish which variant a deployment selects.
| Variant | Source-defined declarations |
|---|---|
imspr/app/Config/Boot/development.php |
error_reporting(-1); display_errors = 1; SHOW_DEBUG_BACKTRACE = true; CI_DEBUG = 1 |
imspr/app/Config/Boot/production.php |
display_errors = 0; error_reporting excludes notices, deprecations, strict messages, and their user-level counterparts; CI_DEBUG = 0 |
imspr/app/Config/Boot/testing.php |
error_reporting(-1); display_errors = 1; SHOW_DEBUG_BACKTRACE = true; CI_DEBUG = 1 |
Development and testing declarations therefore expose errors and debug backtraces, while the production declaration suppresses displayed errors.
Updated