| 1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
 | <?php defined("SYSPATH") or die("No direct script access.");
/**
 * Gallery - a web based photo album viewer and editor
 * Copyright (C) 2000-2009 Bharat Mediratta
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 2 of the License, or (at
 * your option) any later version.
 *
 * This program is distributed in the hope that it will be useful, but
 * WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 51 Franklin Street - Fifth Floor, Boston, MA  02110-1301, USA.
 */
/**
 * Base path of the web site. If this includes a domain, eg: localhost/kohana/
 * then a full URL will be used, eg: http://localhost/kohana/. If it only includes
 * the path, and a site_protocol is specified, the domain will be auto-detected.
 *
 * Here we do our best to autodetect the base path to Gallery.  If your url is something like:
 *   http://example.com/gallery3/index.php/album73/photo5.jpg?param=value
 *
 * We want the site_domain to be:
 *   /gallery3
 *
 * In the above example, $_SERVER["SCRIPT_NAME"] contains "/gallery3/index.php" so
 * dirname($_SERVER["SCRIPT_NAME"]) is what we need.  Except some low end hosts (namely 1and1.com)
 * break SCRIPT_NAME and it contains the extra path info, so in the above example it'd be:
 *   /gallery3/index.php/album73/photo5.jpg
 *
 * So dirname doesn't work.  So we do a tricky workaround where we look up the SCRIPT_FILENAME (in
 * this case it'd be "index.php" and we delete from that part onwards.  If you work at 1and1 and
 * you're reading this, please fix this bug!
 */
$config["site_domain"] =
  substr($_SERVER["SCRIPT_NAME"], 0,
         strpos($_SERVER["SCRIPT_NAME"], basename($_SERVER["SCRIPT_FILENAME"])));
/**
 * Force a default protocol to be used by the site. If no site_protocol is
 * specified, then the current protocol is used, or when possible, only an
 * absolute path (with no protocol/domain) is used.
 */
$config["site_protocol"] = "";
/**
 * Name of the front controller for this application. Default: index.php
 *
 * This can be removed by using URL rewriting.
 */
$config["index_page"] = isset($_GET["kohana_uri"]) ? "" : "index.php";
/**
 * Fake file extension that will be added to all generated URLs. Example: .html
 */
$config["url_suffix"] = "";
/**
 * Length of time of the internal cache in seconds. 0 or FALSE means no caching.
 * The internal cache stores file paths and config entries across requests and
 * can give significant speed improvements at the expense of delayed updating.
 */
$config["internal_cache"] = FALSE;
$config["internal_cache_path"] = VARPATH . "tmp/";
/**
 * Enable or disable gzip output compression. This can dramatically decrease
 * server bandwidth usage, at the cost of slightly higher CPU usage. Set to
 * the compression level (1-9) that you want to use, or FALSE to disable.
 *
 * Do not enable this option if you are using output compression in php.ini!
 */
$config["output_compression"] = FALSE;
/**
 * Enable or disable global XSS filtering of GET, POST, and SERVER data. This
 * option also accepts a string to specify a specific XSS filtering tool.
 */
$config["global_xss_filtering"] = TRUE;
/**
 * Enable or disable hooks. Setting this option to TRUE will enable
 * all hooks. By using an array of hook filenames, you can control
 * which hooks are enabled. Setting this option to FALSE disables hooks.
 */
$config["enable_hooks"] = TRUE;
/**
 * Log thresholds:
 *  0 - Disable logging
 *  1 - Errors and exceptions
 *  2 - Warnings
 *  3 - Notices
 *  4 - Debugging
 */
$config["log_threshold"] = 3;
/**
 * Message logging directory.
 */
$config["log_directory"] = VARPATH . "logs";
if (@!is_writable($config["log_directory"])) {
  $config["log_threshold"] = 0;
}
/**
 * Enable or disable displaying of Kohana error pages. This will not affect
 * logging. Turning this off will disable ALL error pages.
 */
$config["display_errors"] = TRUE;
/**
 * Enable or disable statistics in the final output. Stats are replaced via
 * specific strings, such as {execution_time}.
 *
 * @see http://docs.kohanaphp.com/general/configuration
 */
$config["render_stats"] = TRUE;
/**
 * Filename prefixed used to determine extensions. For example, an
 * extension to the Controller class would be named MY_Controller.php.
 */
$config["extension_prefix"] = "MY_";
/**
 * Additional resource paths, or "modules". Each path can either be absolute
 * or relative to the docroot. Modules can include any resource that can exist
 * in your application directory, configuration files, controllers, views, etc.
 */
$config["modules"] = array(
  MODPATH . "forge",
  MODPATH . "gallery",  // gallery must be *last* in the order
);
if (TEST_MODE) {
  array_splice($config["modules"], 0, 0,
               array(MODPATH . "gallery_unit_test",
                     MODPATH . "unit_test"));
}
/**
 * Setting the maintenance_mode to block all non administrative access.  In
 * this mode a user can attempt to logon, but will be unable to access anything.
 * The application will behave normally if an adminstrator logs on.
 */
//$config["maintenance_mode"] = true;
 |