Table of Contents

Configuration

Products: FastReport Corporate Server

FastReport Corporate Server is configured through the appsettings.json files, which are located in the application directory. These files by default already have a number of properties that can be overridden in one of three ways:

  1. Via appsettings.{Environment}.json, by default, the Environment variable is set to the Productionvalue, so just change the content of the appsettings.Production.json file. It is case-sensitive!

    To change the value, use the environment variables: ASPNETCORE_ENVIRONMENT and DOTNET_ENVIRONMENT.

    export ASPNETCORE_ENVIRONMENT=Production
    export DOTNET_ENVIRONMENT=Production
    
  2. Via environment variables. The details are described below.

Prioritize configuration loading appsettings.json -> appsettings.{Environment}.json -> environment variables. This means that the configuration will be loaded from left to right, in other words, the files on the right will overwrite the configuration of the previous ones.

Description of appsettings.json

Each section will have an example configuration and a descriptive part: key -> value.

{
   "Logging":[
      {
         "Name":"ToEmail"
      }
   ]
}

This key can be used as an environment variable:

export Logging__0__Name=ToEmail

Here the entry Logging__0__Name means accessing the Logging section, the element with 0 index, and the Name property.

Kestrel section

It allows you to configure http server to listen on a specific port or use a certificate. Example configuration:

{
   "Kestrel":{
      "Endpoints":{
         "Http":{
            "Url":"http://localhost:5000"
         },
         "Https":{
            "Url":"https://localhost:5001",
            "Certificate":{
               "Path":"<path to .pfx files>",
               "Password":"<certificate password>"
            }
         }
      }
   }
}
Key Type Description
Kestrel__Endpoints__Http_Url string (uri) Access point for listening to http.
Kestrel__Endpoints__Https_Url string (uri) Access point for listening to https.
Kestrel__Endpoints__Https_Certificate_Path string (local path) Path to the .pfx certificate file for https traffic.
Kestrel__Endpoints__Https_Certificate_Password string Password to access the .pfx file.

Auth section

It allows you to configure the authentication and authorization process.

{
   "Auth":{
      "ClientId":"<openid client>",
      "Scopes":"openid and other scopes",
      "Authority":"https://id.fast-report.com",
      "Audience":"https://fastreport.cloud",
      "Secret":"<secret for for openid client>",
      "UseApiKeys":true,
      "UseOpenId":true,
      "UseLocal":false,
      "AllowLocalSignUp":false,
      "RsaXml":"<xml encoded object>",
      "UserInfoEndpoint":"https://example.com/userinfo",
      "TokenEndpoint":"https://example.com/token",
      "MetadataEndpoint":"https://example.com/.well-known/openid-configuration"

   }
}
Key Type Description
Auth__ClientId string Unique identifier on the authentication server using the protocol openid.
Auth__Scopes string List of client areas by protocol openid.
Auth__Authority string (uri) Access point Authority from which the access token will be requested via the openid protocol.
Auth__Audience string (uri) Access point Audience for which the access token will be requested via the openid protocol.
Auth__Secret string Secret token to confirm authorization via the openid protocol.
Auth__UseApiKeys boolean It enables or disables the ability to authorize via access keys.
Auth__UseOpenId boolean It enables or disables authorization via openid protocol. Note, that the client must be configured for authorization via code flow.
Auth__UseLocal boolean Enables or disables the ability to log in by email and password. In this case, user data is stored locally in the server database.
Auth__AllowLocalSignUp boolean Enables or disables user registration. If disabled, registration is available only to administrators.
Auth__RsaXml string (xml) RSA serialized to XML. For example, <RSAKeyValue><Modulus>{base64}</Modulus><Exponent>{base64}</Exponent><P>{base64}</P><Q>{base64}</Q><DP>{base64}</DP><DQ>{base64}</DQ><InverseQ>{base64}</InverseQ><D>{base64}</D></RSAKeyValue>
Auth__UserInfoEndpoint string (uri) Access point used to request user data via openid protocol.
Auth__TokenEndpoint string (uri) Access point used to request user token via openid protocol.
Auth__MetadataEndpoint string (uri) Access point well-known with metadata for openid.

MainConfig section

It allows you to configure the basic configuration of FastReport Corporate Server.

{
   "MainConfig":{
      "Database":{
         "ConnectionString":"<connection string>",
         "DatabaseName":"ReportstoreDb",
         "ExportsCollectionName":"Exports",
         "ReportsCollectionName":"Reports",
         "TemplatesCollectionName":"Templates",
         "TemplateFoldersCollectionName":"TemplateFolders",
         "ReportFoldersCollectionName":"ReportFolders",
         "ExportFoldersCollectionName":"ExportFolders",
         "UsersCollectionName":"Users",
         "SubscriptionPlansCollectionName":"SubscriptionPlans",
         "SubscriptionsCollectionName":"Subscriptions",
         "SubscriptionInvitesCollectionName":"SubscriptionInvites",
         "GroupsCollectionName":"Groups",
         "DataSourceCollectionName":"DataSources",
         "GridFSFilesCollectionName":"fs.files",
         "MigrationsCollectionName":"Migrations",
         "CurrentTasksCollectionName":"CurrentTasks",
         "TasksCollectionName": "Tasks",
         "AuditCollectionName": "Audit",
         "ContactsCollectionName": "Contacts",
         "ContactGroupsCollectionName": "ContactGroups",
         "FontsCollectionName": "Fonts",
         "UserFontsCollectionName": "UserFonts"
      },
      "Server": {
         "Title": "<Application title>",
         "Copyright": "<Short description of copyright>",
         "LogoLink" : "<path to logo, displayed in the user panel>",
         "FaviconLink": "<path to ico, displayed in the user panel>",
         "LastSlaUpdate": "2022-11-28",
         "CorporateServerMode": true,
         "SlaLink": "<Link to the user agreement>",
         "FirstStepsVideoLink": "<Link to tutorial video>",
         "AboutLink": "<Link to page about product>",
         "HomePageLink": "<Link to product home page>",
         "AuthServerName": "<Name of ID Server>",
         "UsersPerWorkSpace": null,
         "DataSourcesPerWorkSpace": null,
         "GroupsPerWorkSpace": null,
         "PublicPathBase": ""
      },
      "Rabbit":{
         "Host":"my-rabbit-server.com",
         "Port":5672,
         "UserName":"<user name>",
         "Password":"<user password>",
         "DirectExchangeName":"DirectEx",
         "AlternateExchangeName":"AExchange",
         "UnroutedQueueName":"Default"
      },
      "SecurityAdvisor":{
         "RestrictUnsafe":true,
         "RestrictUnmanaged":true,
         "RestrictExtern":true,
         "RestrictAsync":true,
         "RestrictTypeOf":true,
         "Whitelist":[
            "^\\w+:\\s+FastReport.*$",
            "^\\w+\\:.*System\\.Math.*$",
            "^\\w+\\:.*System\\.DateTime.*$",
            "^\\w+\\:.*System\\.Environment.*$"
         ],
         "Blacklist":[
            "^Method\\:.*\\.GetType\\(\\)$",
            "^\\w+\\:.*System\\.IO.*$",
            "^\\w+\\:.*FastReport\\.Utils\\.Config.*$",
            "^\\w+\\:.*System\\.Environment.*$",
            "^\\w+\\:.*System\\.Diagnostics.*$",
            "^\\w+\\:.*System\\.Reflection.*$",
            "^\\w+\\:.*System\\.Net.*$",
            "^\\w+\\:.*System\\.Threading.*$",
            "^\\w+\\:.*System\\.Runtime.*$"
         ]
      },
      "License": "",
      "SmtpServer": {
         "EnableSsl": true,
         "Server": "smtp.s.com",
         "Port": 587,
         "Username": "--",
         "From": "--",
         "Password": "--"
      },
      "Tasks": {
         "Attempts": 3
      },
      "Frontend": {
         "Mixins": {
            "Head": "",
            "Body": ""
         }
      },
      "Rfc2898CryptorSettings": {
         "Salt": "",
         "Password": "",
         "IV": ""
      },
      "DataSourcesConfig": {
         "XmlConfig": { "CommandTimeout": 30 },
         "JsonConfig": { "CommandTimeout": 30 },
         "CsvConfig": { "CommandTimeout": 30 },
         "MySqlConfig": { "CommandTimeout": 30 },
         "PostgreSqlConfig": { "CommandTimeout": 30 },
         "MsSqlConfig": { "CommandTimeout": 30 },
         "OracleDbConfig": { "CommandTimeout": 30 },
         "FirebirdConfig": { "CommandTimeout": 30 },
         "MongoDbConfig": { "CommandTimeout": 30 },
         "ClickHouseConfig": { "CommandTimeout": 30 }
      },
      "FontServerAddress": "http://fr-fonts.fr-cloud:80"
   }
}
Key Type Description
MainConfig__Database__ConnectionString string String to connect to the MongoDB (FerretDB) database.
MainConfig__Database__DatabaseName string MongoDB (FerretDB) server database name.
MainConfig__Database__ExportsCollectionName string Collection name for storing a list of exports.
MainConfig__Database__ReportsCollectionName string Collection name for storing a list of reports.
MainConfig__Database__TemplatesCollectionName string Collection name for storing a list of templates.
MainConfig__Database__TemplateFoldersCollectionName string Collection name for storing a tree structure of templates.
MainConfig__Database__ReportFoldersCollectionName string Collection name for storing a tree structure of reports.
MainConfig__Database__ExportFoldersCollectionName string Collection name for storing a tree structure of exports.
MainConfig__Database__UsersCollectionName string Collection name for storing a list of users.
MainConfig__Database__SubscriptionPlansCollectionName string Collection name for storing a list of subscription plans.
MainConfig__Database__SubscriptionsCollectionName string Collection name for storing a list of subscriptions.
MainConfig__Database__SubscriptionInvitesCollectionName string Collection name for storing a list of invitations.
MainConfig__Database__GroupsCollectionName string Collection name for storing a list of groups
MainConfig__Database__DataSourceCollectionName string Collection name for storing a list of data sources.
MainConfig__Database__GridFSFilesCollectionName string Collection name for storing a list of files.
MainConfig__Database__MigrationsCollectionName string Collection name for storing a list of applied migrations.
MainConfig__Database__CurrentTasksCollectionName string Collection name for storing a list of tasks. Helper collection for current tasks.
MainConfig__Database__TasksCollectionName string Collection name for storing a list of tasks.
MainConfig__Database__AuditCollectionName string Collection name for storing a list of audits.
MainConfig__Database__ContactsCollectionName string Collection name for storing a list of contacts.
MainConfig__Database__ContactGroupsCollectionName string Collection name for storing a list of contact groups
MainConfig__Database__FontsCollectionName string Collection name for storing a list of fonts.
MainConfig__Database__UserFontsCollectionName string Collection name for storing a list of user fonts.
MainConfig__Server__Title string Name for the server that the application will use in the header.
MainConfig__Server__Copyright string Text for copyright information (or any other information that will be displayed at the bottom of the user application page).
MainConfig__Server__LogoLink string Url to logo image file.
MainConfig__Server__FaviconLink string Url to favicon ico file.
MainConfig__Server__LastSLAUpdate string The date of the last modification of the user agreement, if you change this date to a newer one, when you open the user application, a dialog will open in which there will be a link to the updated conditions (from the field SlaLink).
MainConfig__Server__CorporateServerMode boolean This field changes the behavior of a part of the API, for example, if false is specified, then workspaces cannot be deleted in the admin panel. It also controls whether the admin Swagger document is shown in Swagger UI.
MainConfig__Server__FirstStepsVideoLink string A link to the video tutorial to the corporate server that will appear when you first log in to the custom application or when you click on the ?  at the bottom of the page.
MainConfig__Server__AboutLink string Link to product information.
MainConfig__Server__HomePageLink string Link to the home page of the product.
MainConfig__Server__AuthServerName string The name for the authorization server specified in the AuthConfig section used in the user application.
MainConfig__Server__UsersPerWorkSpace integer? The maximum number of users in a workspace set by an administrator.
MainConfig__Server__DataSourcesPerWorkSpace integer? The maximum number of data sources in a workspace set by an administrator.
MainConfig__Server__GroupsPerWorkSpace integer? The maximum number of groups in a workspace set by an administrator.
MainConfig__Server__PublicPathBase string The public base path (URL prefix) the product is deployed under (e.g., /reports). Empty by default — the product occupies the domain root. See Deploying under a custom base path for details.
MainConfig__Rabbit__Host string Host address to access RabbitMQ.
MainConfig__Rabbit__Port string Port to access RabbitMQ.
MainConfig__Rabbit__UserName string Username to access RabbitMQ.
MainConfig__Rabbit__Password string Password to access RabbitMQ.
MainConfig__Rabbit__DirectExchangeName string The name of the RabbitMQ exchange that is used to direct messages to users’ subscription queues. The reporting platform suffix will be appended to this variable, for example .VCL.
MainConfig__Rabbit__AlternateExchangeName string The name of the RabbitMQ exchange that will be processed by default when a subscription has not yet been created for the user. The reporting platform suffix will be appended to this variable, for example .VCL.
MainConfig__Rabbit__UnroutedQueueName string The name of the RabbitMQ queue that will be processed by default when a subscription has not yet been created for the user. The reporting platform suffix will be appended to this variable, for example .VCL.
MainConfig__SecurityAdvisor__RestrictUnsafe string It enables or disables the unsafe keyword in the script.
MainConfig__SecurityAdvisor__RestrictUnmanaged string It enables or disables the unmanaged keyword in the script.
MainConfig__SecurityAdvisor__RestrictExtern string (uri) It enables or disables the extern keyword in the script.
MainConfig__SecurityAdvisor__RestrictAsync string (uri) It enables or disables the async keyword in the script.
MainConfig__SecurityAdvisor__RestrictTypeOf string It enables or disables the typeof keyword in the script.
MainConfig__SecurityAdvisor__Whitelist__0 boolean It specifies the list of APIs that can be used without warnings in the report script. The number indicates the sequence number in the list.
MainConfig__SecurityAdvisor__Blacklist__0 boolean It specifies the list of APIs that cannot be used in the report script. The number indicates the sequence number in the list.
MainConfig__License string License key. It is provided with the product.
MainConfig__SmtpServer__Server string Mail server address.
MainConfig__SmtpServer__Port integer SMTP server port.
MainConfig__SmtpServer__Username string SMTP server user name.
MainConfig__SmtpServer__Password string SMTP server user password
MainConfig__SmtpServer__From string Sender’s mail address (displayed in the email).
MainConfig__Tasks__Attempts integer Number of attempts to start the task by the worker.
MainConfig__Frontend__Mixins__Head string Mixes embedded in the header of the user panel (e.g., analytics code).
MainConfig__Frontend__Mixins__Body string Mixes embedded in the body of the user panel (e.g., analytics code).
MainConfig__Rfc2898CryptorSettings__Salt string Cryptographic algorithm salt (used to encrypt passwords).
MainConfig__Rfc2898CryptorSettings__Password string Cryptographic algorithm password.
MainConfig__Rfc2898CryptorSettings__IV string Cryptographic algorithm vector.
MainConfig__InvariantLocale string Permanent localization. It works independently of the browser language.
MainConfig__DataSourcesConfig__XmlConfig__CommandTimeout integer Queue time for a response from the XML data source in seconds. If you do not specify a value, the default timeout for that data source will be used.
MainConfig__DataSourcesConfig__JsonConfig__CommandTimeout integer Queue time for a response from the JSON data source in seconds. If you do not specify a value, the default timeout for that data source will be used.
MainConfig__DataSourcesConfig__CsvConfig__CommandTimeout integer Queue time for a response from the CSV data source in seconds. If you do not specify a value, the default timeout for that data source will be used.
MainConfig__DataSourcesConfig__MySqlConfig__CommandTimeout integer Queue time for a response from the MySQL data source in seconds. If you do not specify a value, the default timeout for that data source will be used.
MainConfig__DataSourcesConfig__PostgreSqlConfig__CommandTimeout integer Queue time for a response from the PostgreSQL data source in seconds. If you do not specify a value, the default timeout for that data source will be used.
MainConfig__DataSourcesConfig__MsSqlConfig__CommandTimeout integer Queue time for a response from the MS SQL data source in seconds. If you do not specify a value, the default timeout for that data source will be used.
MainConfig__DataSourcesConfig__OracleDbConfig__CommandTimeout integer Queue time for a response from the Oracle DB data source in seconds. If you do not specify a value, the default timeout for that data source will be used.
MainConfig__DataSourcesConfig__FirebirdConfig__CommandTimeout integer Queue time for a response from the Firebird data source in seconds. If you do not specify a value, the default timeout for that data source will be used.
MainConfig__DataSourcesConfig__MongoDbConfig__CommandTimeout integer Queue time for a response from the Mongo DB data source in seconds. If you do not specify a value, the default timeout for that data source will be used.
MainConfig__DataSourcesConfig__ClickHouseConfig__CommandTimeout integer Queue time for a response from the ClickHouse data source in seconds. If you do not specify a value, the default timeout for that data source will be used.
FontServerAddress string (uri) Absolute link to access the font server.

Gateway section

It allows you to configure the FastReport Corporate Server access gateway.

{
   "Gateway":{
      "WhiteListForDisabled":{
         "<any_claim_name>":"<claim_value>"
      },
      "IsDisabled":false,
      "ExcludePaths":[
         "/account",
         "/disabled"
      ],
      "IsSignInRequired":false
   }
}
Key Type Description
Gateway__WhiteListForDisabled__<any_claim_name> string List of user assertions in the token to access the disabled FastReport Cloud.
Gateway__IsDisabled boolean It enables or disables access to FastReport Cloud.
Gateway__ExcludePaths__0 string List of paths that can be accessed even when access to FastReport Cloud is disabled. The number indicates the sequence number in the list.
Gateway__IsSignInRequired boolean It enables or disables the need to log in for the user to access FastReport Cloud.

Services section

It allows you to configure a list of services for gateway routing.

{
   "Services":{
      "HealthCheckInterval":30,
      "Items":{
         "<name>":{
            "Urls":[
               "http://localhost:5555"
            ],
            "Scheme":"http",
            "Port":5555,
            "K8sServiceName":"fr-rp",
            "HostType":"WebApp",
            "PathBase":"/api/rp/swagger",
            "Namespace":"fr-cloud",
            "Type":"K8s",
            "PingPath":"/api/rp/v1/healthcheck",
            "IsSignInRequired":true,
            "Priority":10,
            "PingResponseCode":200,
            "LoadBalanceMode":"Random",
            "HealthCheckAttemptsNumber":3,
            "WhiteListClaims":{
               "<claim_name>":"<claim_value>"
            }
         }
      }
   }
}
Key Type Description
Services__HealthCheckInterval integer Interval for service health check, it is set in seconds.
Services__Items__<name>__Urls__0 string (url) List of url URLs for accessing static services. The number indicates the sequence number in the list.
Services__Items__<name>__Scheme string Service access scheme: http or https.
Services__Items__<name>__Port integer Service access port.
Services__Items__<name>__K8sServiceName string Service name in Kubernetes.
Services__Items__<name>__HostType string The type of service to process the redirection by the gateway, it can take the values: WebApp, API, External, Websocket.
Services__Items__<name>__PathBase string Basic path for the service.
Services__Items__<name>__Namespace string Service namespace in Kubernetes.
Services__Items__<name>__Type string Type of service for access processing by the gateway; it can take the values: Static, K8s.
Services__Items__<name>__PingPath string Part of a query string to retrieve service health information.
Services__Items__<name>__IsSignInRequired string It specifies the need for authorization before users can access the service.
Services__Items__<name>__Priority number Service priority over others; the less the value is, the stronger it is.
Services__Items__<name>__PingResponseCode integer Status response code to be expected from health check.
Services__Items__<name>__LoadBalanceMode string t specifies the type of load balancing for this service; it can take one of the following values: Random, AverageMetric.
Services__Items__<name>__HealthCheckAttemptsNumber integer Number of attempts to check service health.
Services__Items__<name>__WhiteListClaims__<claim_name> string It indicates an assertion to the user to gain access to the service.

Instead <name> service name should be used; the list of services can be found in the following file appsettings.json.

Constants section

It allows you to limit the size of the request body in the application.

{
   "Constants": {
      "LimitsMaxRequestBodySize": 2097152000
   }
}
Key Type Description
Constants__LimitsMaxRequestBodySize long The maximum size of the request body. If this limit is exceeded, the request will be rejected.

Designer section

Allows you to configure some components of the online designer.

  "Designer": {
    "IntellisenseEnabled" : true,
        "DataSources" : {
            "Edit" : true,
            "Create" : true,
            "Remove" : true
        },
    "CodeRestricted" : false
  },

| Designer__IntellisenseEnabled | boolean | This field allows you to enable or disable hints while writing code inside the template in the online designer. | | Designer__CodeRestricted | boolean | This field allows you to enable or disable the "code" tab in the online designer entirely. | | Designer__DataSources__Create | boolean | Enables / disables the ability to connect new datasources to the template. | | Designer__DataSources__Edit | boolean | Enables / disables the ability to edit the existing datasources in the template. | | Designer__DataSources__Remove | boolean | Enables / disables the ability to remove datasources from the template. |

This section also includes "InternalHeaders" and "BackendUrl" fields, they are described below in their own chapter.

Additional Migrations Section for MainConfig

Allows configuring migration execution settings.

{
  "MainConfig": {
    "Migrations": {
      "DataBaseCheckInterval": 1,
      "LockDoubleCheckInterval": 5,
      "MigrationTimeOut": 60
    }
  }
}
Key Type Description
MainConfig__Migrations__DataBaseCheckInterval double Interval (in seconds) to check database availability before starting migrations. Default: 1.
MainConfig__Migrations__LockDoubleCheckInterval double Interval (in seconds) for re-checking migration lock. May need to be increased (~20 + ping time) if a replica set is used. Default: 5.
MainConfig__Migrations__MigrationTimeOut double Time (in seconds) to wait for migration to complete before timing out. Default: 60.

Here's the English translation of your text:


Additional Section InternalHeaders for MainConfig

The InternalHeaders section is used to configure internal authorization between system services.
Each service must use a unique key for identification during internal communication. These keys must be generated by the user independently — using values from the example is not allowed for security reasons.

{
  "Designer": {
    "BackendUrl": "http://fr-backend.fr-cloud:80",
    "InternalKey": "fc51a5d6-95c3-4679-8c03-c9ac6536bf5d"
  },
  "Fonts": {
    "BackendUrl": "http://fr-backend.fr-cloud:80",
    "InternalKey": "22788120-f7cd-43f2-938b-327d6c3ceed4"
  },
  "Scheduler": {
    "BackendUrl": "http://fr-backend.fr-cloud:80",
    "InternalKey": "9da6cb50-8796-42cc-b3a7-53c1761f0ac9"
  },
  "WorkerCore": {
    "BackendUrl": "http://fr-backend.fr-cloud:80",
    "InternalKey": "ee444483-e0f1-4ec2-9b4e-5cbacdfaa07f"
  },
  "Gateway": {
    "BackendUrl": "http://fr-backend.fr-cloud:80",
    "InternalKey": "4632ab6a-3e20-4430-9f13-2fe1851809db"
  },
  "MainConfig": {
    "InternalHeaders": {
      "ee444483-e0f1-4ec2-9b4e-5cbacdfaa07f": "000000000000000000000001",
      "fc51a5d6-95c3-4679-8c03-c9ac6536bf5d": "000000000000000000000002",
      "4632ab6a-3e20-4430-9f13-2fe1851809db": "000000000000000000000003",
      "9da6cb50-8796-42cc-b3a7-53c1761f0ac9": "000000000000000000000004",
      "22788120-f7cd-43f2-938b-327d6c3ceed4": "000000000000000000000005"
    }
  }
}
Key Type Description
Designer__BackendUrl string Backend URL of the Designer service.
Designer__InternalKey string Unique key for internal authorization of the Designer service.
Fonts__BackendUrl string Backend URL of the Fonts service.
Fonts__InternalKey string Unique key for internal authorization of the Fonts service.
Scheduler__BackendUrl string Backend URL of the Scheduler service.
Scheduler__InternalKey string Unique key for internal authorization of the Scheduler service.
WorkerCore__BackendUrl string Backend URL of the WorkerCore service.
WorkerCore__InternalKey string Unique key for internal authorization of the WorkerCore service.
Gateway__BackendUrl string Backend URL of the Gateway service.
Gateway__InternalKey string Unique key for internal authorization of the Gateway service.
MainConfig__InternalHeaders__<key> string Mapping of InternalKey to internal service identifier.

Important: The InternalKey values and their corresponding entries in InternalHeaders must be unique and generated by the user. Using values from the example is not permitted.

Key Generation Recommendations

  • Keys can be represented as GUIDs or arbitrary complex strings.
  • It is recommended to use cryptographically secure random string generators.
  • Keys must be long and unique enough to prevent collisions or brute-force attempts.