import type { Field } from 'payload'; import type { AccessOption } from './modules/access/types.js'; import type { ContentOption } from './modules/content/types.js'; import type { FormsOption } from './modules/forms/types.js'; import type { I18nConfig } from './modules/i18n/types.js'; import type { PagesOption } from './modules/pages/types.js'; import type { SeoOption } from './modules/seo/types.js'; /** * Configuration options for the IPAL plugin. * Passed by the client project in payload.config.ts. */ export type IpalOptions = { /** * Role-based access control. Injects a fixed `roles` field * (admin > editor > user) into the client's auth collection. */ access?: AccessOption; /** * Custom admin panel route, e.g. '/its' instead of the default '/admin'. * The plugin sets config.routes.admin. IMPORTANT: this alone isn't enough — * the project must ALSO move its panel folder to match: * app/(payload)/its/[[...segments]]/page.tsx (and the not-found). The plugin * can't create files in the project's app/. See docs/security.md. * * This is obscurity, not security: it hides the panel from dumb bots scanning * /admin, but real protection is strong auth + 2FA + rate limiting. */ adminRoute?: string; /** * Collections whose entries live under an archive page — blog posts, case * studies, anything with a listing. Adds an "archive page" assignment per * collection in SiteSettings; the assigned page's localized slug becomes the * URL segment (/pl/artykuly/moj-post, /en/articles/my-post). Requires `pages`. */ content?: ContentOption; /** Disable the plugin without uninstalling (keeps DB schema intact) */ enabled?: boolean; /** * Forms — form-builder collections (forms, form-submissions) plus the * callable submitForm (Turnstile + persistence + SMTP-from-panel email). */ forms?: FormsOption; /** Internationalization — locales, default locale, fallback behavior */ i18n: I18nConfig; /** Additional fields injected into SiteIntegrations global */ integrationsFields?: Field[]; /** * System-page assignments (homepage, privacy, cookies) in SiteSettings. * Provide the slug of the client's Pages collection to enable. */ pages?: PagesOption; /** * SEO — adds meta fields to chosen collections (via @payloadcms/plugin-seo) * and enables locale-aware metadata helpers. */ seo?: SeoOption; /** Additional fields injected into SiteSettings global */ siteSettingsFields?: Field[]; /** * Two-factor authentication (TOTP), ENFORCED for every user. Wires * @clocklimited/payload-2fa with forceSetup — no per-project opt-out. Every * user must configure an authenticator app after login; TOTP is checked before * data access (not just the admin UI). Requires the peer dep installed and an * issuer name (shown in the authenticator app). * * Pass `false` ONLY for a project that genuinely can't use 2FA (rare, discouraged) * — default is enforced. See docs/security.md. */ twoFactor?: { /** Auth collection slug. Defaults to 'users'. */ collectionSlug?: string; /** Name shown in the authenticator app (e.g. company/site name). */ issuer: string; } | false; };