1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
# ==============================================================================
# 🐕 Brum Master Configuration File
# Location: ~/projects/brum/config.toml
# ==============================================================================
# --- Core Server Settings ---
[]
= "0.0.0.0" # "0.0.0.0" to listen on all network interfaces, "127.0.0.1" for local-only
= 3140 # Brum standard default port
= "/" # Root filesystem path
= 20480 # Max file upload size in MB (10 GB)
= true # Enable authentication (automatically disabled in --standalone mode)
= 72 # JWT session expiry duration in hours
= "brum.db" # SQLite local metadata and session database
# --- Authentication & Access Control ---
[]
= "mixed" # Options: "mixed" (PAM + Built-in), "builtin", "pam", "none"
= "login" # Linux PAM service name
= false # Allow anonymous guest access
= "admin" # Initial admin username
= "brum" # Initial admin password
# --- Storage Roots & Filesystem Sandboxing ---
[]
= true # When true, admin users have unrestricted access to all local drives and system roots
= "/home/{username}" # Template path for newly created virtual/DB users (e.g. "/data/users/{username}" or "C:/Users/{username}")
= "auto" # Options: "auto" (smart auto-creation & fallback cascade), "roots_only" (pure storage roots, no home), "strict"
= true # Automatically create missing user home directories on login/init if writable
# Linux / Standard Mount Example
#[[storage.roots]]
#id = "storage"
#name = "Mass Storage"
#path = "/mnt/storage"
#read_only = false
# allowed_roles = ["admin", "user"]
#[[storage.roots]]
#id = "data"
#name = "Application Data"
#path = "/data"
#read_only = false
#[[storage.roots]]
#id = "backups"
#name = "Backups (Read-Only)"
#path = "/mnt/backups"
#read_only = true
# Windows Local Drive Example (supports forward slashes "D:/Media", single quotes 'D:\Media', or escaped "D:\\Media")
# [[storage.roots]]
# id = "d-drive"
# name = "D: Media Storage"
# path = "D:/Media"
# read_only = false
# Windows / Samba Network UNC Share Example (supports '//nas/share', '\\nas\share', or "\\\\nas\\share")
# [[storage.roots]]
# id = "nas-share"
# name = "Samba Public Share"
# path = "//192.168.1.100/share"
# read_only = false
# --- Remote SFTP / SSH Host Key Security ---
[]
= "tofu" # Host key verification policy: "tofu" (Trust On First Use / auto-record), "strict" (must pre-exist in known_hosts), "auto_accept" (ignore/skip verification)
# known_hosts_file = "~/.ssh/known_hosts" # Optional custom known_hosts path (defaults to ~/.ssh/known_hosts or ~/.config/brum/known_hosts)
# --- User Interface & Panels ---
[]
= 2 # Default number of visible panes on startup (1 to 4)
= "dual-vertical" # Options: "single", "dual-vertical", "dual-horizontal", "triple", "quad"
= true # Show hidden files and dotfiles (e.g. .bashrc, .git)
= "details" # Options: "details", "compact", "grid"
= true # Set to false for seamless borderless/frameless mode in Hyprland / tiling WMs
= false # Minimal header (off by default; individual panes have dedicated refresh controls)
# --- Web Terminal (Bite!) & PTY Security ---
[]
= true # Enable / disable the web terminal feature
= ["admin", "root"] # Roles allowed to spawn terminal shells ("admin", "user", "*" for all)
= false # Allow virtual/DB accounts without a local POSIX user (disabled by default for security)
= true # Drop root privileges to match authenticated user when running as root daemon
# default_shell = "/bin/bash" # Override default shell executable
# --- Standalone Desktop Window & System Tray ---
[]
= true # Minimize window to system tray when closed instead of terminating
= true # Enable system tray icon
= "Super+C" # System-wide shortcut to summon/focus Brum (e.g. "Super+C", "Ctrl+Alt+Space")
= false # Launch directly to system tray on system boot / autostart
# --- Color Themes & Aesthetics ---
[]
= "amber-charcoal" # Active theme ID: "amber-charcoal", "zink", "catppuccin-mocha", "nord", "gruvbox", etc.
# Modular themes are located in themes/*.toml or ~/.config/brum/themes/*.toml
# --- Paranoid File Integrity & Safety ---
[]
= true # Pre-flight collision checks and integrity verification
= "sha256" # "sha256", "crc32"
= true # Verify bit-for-bit checksums after copy/move
= true # Write to temp file first before renaming
= true # Move to system trash instead of permanent delete
= true # Prompt before deleting files
= true # Prompt before overwriting existing files
# --- Syncthing P2P Integration ---
[]
= true
= "http://127.0.0.1:8384"
= "" # Leave blank to auto-discover from ~/.config/syncthing/config.xml
# --- NoteDog Notes & Markdown Studio ---
[]
= "~/Notes" # Custom path to notes directory (e.g. "~/Notes", "/mnt/storage/Notes", "~/Documents/Notes")
# --- Context Menu Custom Script Actions ---
[[]]
= "sha256-calc"
= "Calculate SHA-256 Checksum"
= "shield-check"
= "builtin:checksum:sha256"
= "file"
= false
[[]]
= "folder-diff"
= "Compare with Other Pane (Diff)"
= "columns-2"
= "builtin:diff"
= "all"
= false
[[]]
= "compress-zip"
= "Compress to .zip"
= "archive"
= "builtin:archive:zip"
= "all"
= true
[[]]
= "compress-targz"
= "Compress to .tar.gz"
= "archive"
= "builtin:archive:targz"
= "all"
= true
[[]]
= "extract-here"
= "Extract Archive Here"
= "unarchive"
= "builtin:archive:extract"
= "archive"
= true
# --- Default Bookmarks & Favorite Paths ---
[[]]
= "home"
= "Home Directory"
= "local"
= "~"
[[]]
= "root"
= "Root Filesystem"
= "local"
= "/"