Magento 1.x Security Patch Notice
For Magento Open Source 1.5 to 1.9, Magento is providing software security patches through June 2020 to ensure those sites remain secure and compliant. Visit our information page for more details about our software maintenance policy and other considerations for your business.
System
System > Configuration > Advanced > System
Field |
Description |
|
---|---|---|
Add Secret Key To Url |
Store View |
Provides protection against cross-site request forgery (CSRF) by adding a secret key to store URLs. Options: Yes / No |
Security Notice! We recommend that all merchants immediately set their mail sending configuration to protect against a recently identified potential remote code execution exploit. Until this issue is resolved, we highly recommend that you avoid using Sendmail for email communications. In the Mail Sending Settings, make sure that Set Return Path is set to "No." To learn more, see the Magento Security Center posting.
Field |
Description |
|||||||
---|---|---|---|---|---|---|---|---|
Enable Log |
Global |
Determines when the system log of events is saved. Options:
|
||||||
Save Log, Days |
Global |
Determines the number of days the system log is saved. |
||||||
Enable Log Cleaning |
Global |
Determines if the system log is periodically cleaned. Options: Yes / No |
||||||
Start Time |
Global |
Sets the hour, minute, and second that log cleaning is scheduled to start. |
||||||
Frequency |
Global |
Determines how often the system logs are cleaned. Options: Daily Weekly Monthly |
||||||
Error Email Recipient |
Global |
The email address of the person who is to receive notification of any error that occurs during system log cleaning. Separate multiple addresses with a comma. |
||||||
Error Email Sender |
Global |
Identifies the store contact that appears as the sender of the log cleaning error notification. Options: General Contact Sales Representative Customer Support Custom Email 1 Custom Email 2 |
||||||
Error Email Template |
Global |
Identifies the email template that is used for the log cleaning error notification. Default template: Log cleanup Warnings |
Field |
Description |
|
---|---|---|
Enable External Cache |
Global |
Determines if an external full-page cache is used. Options: Yes / No |
Cookie Lifetime (seconds) |
Global |
Determines the lifetime of the full-page cache cookie, in seconds. |
External Cache Control |
Store View |
Identifies the external service that manages the full-page cache. Options: Zend Full Page Cache
|
Field |
Description |
|
---|---|---|
Page size for import configurable products |
Global |
Determines the maximum number of configurable product records that can be imported. For unlimited page size, enter zero. Default: 1000 |
Field |
Description |
|
---|---|---|
Escape CSV Fields |
Global |
As a security measure, adds an escape character to CSV fields to protect against possible Excel formula injection. |