Configuration

Configuration values in imspr/app/Config are source declarations, not verified deployment settings. Use the files below to locate application behavior boundaries, then verify the environment, selected boot variant, and effective runtime values separately.

[!WARNING] Several effective values remain deployment-dependent. App.php hard-codes $baseURL while Constants.php separately derives BASEURL from getenv('app.baseURL'); the source does not establish precedence or the effective deployed URL. Environment-derived values, database credentials, encryption material, and the selected boot variant are also unverified. Review the deployed configuration before relying on these declarations.

The source security defaults declare forced HTTPS, secure cookies, HTTP-only cookies, and CSP as disabled. CSRF regeneration and redirect-on-failure are declared enabled, but runtime enforcement is outside this page's evidence. Treat these settings as deployment review items.

Application and request settings

imspr/app/Config/App.php defines the application URL, session storage, cookie behavior, and request-security flags for Config\App.

Boundary Source-defined declaration
Application URL $baseURL = https://dev.novusoftit.com/
Session driver $sessionDriver = CodeIgniter\\Session\\Handlers\\FileHandler
Session cookie $sessionCookieName = ci_session; $sessionExpiration = 7200; $sessionSavePath = WRITEPATH . 'session'
Cookie security $cookieSecure = false; $cookieHTTPOnly = false
HTTPS enforcement $forceGlobalSecureRequests = false
CSRF naming and behavior $CSRFTokenName = csrf_test_name; $CSRFRegenerate = true; $CSRFRedirect = true
Content Security Policy $CSPEnabled = false

Environment-derived bindings

imspr/app/Config/Constants.php defines application constants from environment lookups and path expressions. The source does not provide the resulting deployed values.

Constant Source-defined expression
BASEURL getenv('app.baseURL')
PROJECTNAME getenv('project.name')
DEFAULTLOGO getenv('app.baseURL').getenv('project.default.logo')
PUBLICROOTPATH ROOTPATH.getenv('project.path.public')
MAINDB getenv('database.default.database')
HASHSALT getenv('project.hash.salt')

Database profiles

imspr/app/Config/Database.php declares the default and test profiles.

Profile Source-defined settings
default Host localhost; blank username, password, and database; DBDriver MySQLi; pConnect false; cacheOn false; DBDebug is enabled when ENVIRONMENT !== 'production'; port 3306
tests Host 127.0.0.1; blank username and password; database :memory:; DBDriver SQLite3; DBPrefix db_; port 3306
Testing override When ENVIRONMENT === 'testing', defaultGroup is tests. If getenv('DB') supplies a group and TESTPATH . 'travis/Database.php' exists, a non-empty $dbconfig containing the requested group key replaces the tests profile.

Other configuration surfaces

Surface Source-defined boundary
Encryption — imspr/app/Config/Encryption.php $driver selects OpenSSL; the file also declares an encryption key seed, but the effective deployed key is not verified.
Logging — imspr/app/Config/Logger.php $threshold is 3; $dateFormat is Y-m-d H:i:s. The CodeIgniter\\Log\\Handlers\\FileHandler handles critical, alert, emergency, debug, error, info, notice, and warning; fileExtension is blank and filePermissions is 0644.
Validation rule sets — imspr/app/Config/Validation.php $ruleSets lists \CodeIgniter\Validation\Rules, \CodeIgniter\Validation\FormatRules, \CodeIgniter\Validation\FileRules, and \CodeIgniter\Validation\CreditCardRules.
Validation templates — imspr/app/Config/Validation.php $templates maps list to CodeIgniter\\Validation\\Views\\list and single to CodeIgniter\\Validation\\Views\\single.

[!NOTE] imspr/app/Config/Services.php contains a line-commented example service factory. It is not an active application-specific service declaration and should not be treated as an available example service.

Boot variants

These files declare alternative error and debug settings. The evidence does not establish which variant a deployment selects.

Variant Source-defined declarations
imspr/app/Config/Boot/development.php error_reporting(-1); display_errors = 1; SHOW_DEBUG_BACKTRACE = true; CI_DEBUG = 1
imspr/app/Config/Boot/production.php display_errors = 0; error_reporting excludes notices, deprecations, strict messages, and their user-level counterparts; CI_DEBUG = 0
imspr/app/Config/Boot/testing.php error_reporting(-1); display_errors = 1; SHOW_DEBUG_BACKTRACE = true; CI_DEBUG = 1

Development and testing declarations therefore expose errors and debug backtraces, while the production declaration suppresses displayed errors.

Updated