The prestd configuration is via an environment variable or toml file.
|PREST_HTTP_PORT or PORT||3000||PORT is cloud factor, _when declaring this variable overwritten PREST_HTTP_PORT|
|PREST_PG_URL or DATABASE_URL||cloud factor, when declaring this variable all the previous connection fields are overwritten|
|PREST_CACHE_ENABLED||false||embedded cache system|
|PREST_CACHE_TIME||10||TTL in minute (time to live)|
|PREST_CACHE_STORAGEPATH||./||path where the cache file will be created|
|PREST_CACHE_SUFIXFILE||.cache.prestd.db||suffix of the name of the file that is created|
|PREST_PLUGINPATH||./lib||path to plugin storage
Optionally the prestd can be configured by TOML file.
You can follow this sample and create your own
prest.toml file and put this on the same folder that you run
1migrations = "./migrations" 2 3# debug = true 4# enabling debug mode will disable JWT authorization 5 6[http] 7port = 6000 8# Port 6000 is blocked on windows. You must change to 8080 or any unblocked port 9 10[jwt] 11key = "secret" 12algo = "HS256" 13 14[auth] 15enabled = true 16type = "body" 17encrypt = "MD5" 18table = "prest_users" 19username = "username" 20password = "password" 21 22[pg] 23host = "127.0.0.1" 24user = "postgres" 25pass = "mypass" 26port = 5432 27database = "prest" 28single = true 29## or used cloud factor 30# URL = "postgresql://user:pass@localhost/mydatabase/?sslmode=disable" 31 32[ssl] 33mode = "disable" 34sslcert = "./PATH" 35sslkey = "./PATH" 36sslrootcert = "./PATH"
JWT middleware is enabled by default. To disable JWT need to set default to false. Enabling debug mode will also disable it.
1[jwt] 2default = false
1Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiYWRtaW4iOnRydWV9.TJVA95OrM7E2cBab30RMHrHDcEfxjoYZgeFONFh7HgQ
HS256 algorithm is used by default.
The JWT algorithm can be specified by using either the environment variable
PREST_JWT_ALGO or the
algo parameter in the section
[jwt] of the
prest.toml configuration file.
The supported signing algorithms are:
- The HMAC signing method:
- The RSA signing method:
- The ECDSA signing method:
By default the endpoints
/auth do not require JWT, the whitelist option serves to configure which endpoints will not ask for jwt token
1[jwt] 2default = true 3whitelist = ["\/auth", "\/ping", "\/ping\/.*"]
pREST has support in jwt token generation based on two fields (example user and password), being possible to use an existing table from your database to login configuring some parameters in the configuration file (or environment variable), by default this feature is disabled.
1[auth] 2enabled = true 3type = "body" 4encrypt = "MD5" 5table = "prest_users" 6username = "username" 7password = "password"
|enabled||Boolean field that activates or deactivates token generation endpoint support|
|type||Type that will receive the login, support for body and http basic authentication|
|encrypt||Type of encryption used in password field, support for MD5 and SHA1|
|table||Table name we will consult (query)|
|username||User field that will be consulted - if your software uses email just abstract name username (at pREST code level it was necessary to define an internal standard)|
|password||Password field that will be consulted|
to validate all endpoints with generated jwt token must be activated jwt option
There is 4 options to set on ssl mode:
require- Always SSL (skip verification) by default
disable- SSL off
verify-ca- Always SSL (verify that the certificate presented by the server was signed by a trusted CA)
verify-full- Always SSL (verify that the certification presented by the server was signed by a trusted CA and the server host name matches the one in the certificate)
Set environment variable
debug=true on top of prest.toml file.
While serving multiple databases over the same API with pREST is doable, it's by default a single database setup. This is this way to prevent unwanted behavior that may make prest instable for users, in order to change that It's possible to pass a variable on your
toml file to disable it under the
[pg] tag as shown bellow.
1[pg] 2 single = false
Cross-Origin Resource Sharing
Read the specific topic where we talk about CROS here.