Configuration reference¶
Every setting resolves in this order:
FINGERPRINT_ATTENDANCE = {...}in your Django settings- an environment variable
FPA_<NAME> - the default below
Environment values are cast to the setting's type:
| Type | Environment format |
|---|---|
| bool | 1/0, true/false, yes/no, on/off |
| int / float | number |
| list | comma separated (a,b) or JSON array |
| int list | comma separated integers or JSON array |
| dict / json | JSON |
| duration | seconds (90), 90s, 15m, 2h, 7d, 1w, HH:MM:SS or ISO 8601 |
| time | HH:MM[:SS] |
| path | dotted import path, or one of the listed aliases |
Nullable settings accept none/null/empty in the environment. Settings naming a class or
function take a dotted path, so you can swap in your own implementation. Values are validated
by Django system checks at startup (IDs fpa.E0xx / fpa.W0xx, see System checks).
Identity¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
EMPLOYEE_MODEL |
FPA_EMPLOYEE_MODEL |
str | settings.AUTH_USER_MODEL |
Model enrollees link to (app_label.Model). Set before the first migrate, like AUTH_USER_MODEL. |
EMPLOYEE_DISPLAY_FIELD |
FPA_EMPLOYEE_DISPLAY_FIELD |
str (nullable) | None |
Employee attribute used as the name sent to devices (__ traverses relations), or a dotted path to callable(employee) -> str. None uses get_full_name()/str(). |
EMPLOYEE_LOOKUP_FIELD |
FPA_EMPLOYEE_LOOKUP_FIELD |
str | 'pk' |
Employee field the API accepts to identify an employee when creating enrollees. |
Device PIN¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
PIN_GENERATOR |
FPA_PIN_GENERATOR |
path | 'sequential' |
callable(employee) -> str producing a device PIN. Aliases: sequential, employee_field. Aliases: sequential, employee_field. |
PIN_SOURCE_FIELD |
FPA_PIN_SOURCE_FIELD |
str (nullable) | None |
Employee field used by the employee_field PIN generator (defaults to EMPLOYEE_LOOKUP_FIELD). |
PIN_START |
FPA_PIN_START |
int | 1 |
First PIN issued by the sequential generator. |
PIN_MAX_LENGTH |
FPA_PIN_MAX_LENGTH |
int | 9 |
Maximum PIN length accepted by your devices (many ZKTeco models: 9 digits). |
PIN_NUMERIC_ONLY |
FPA_PIN_NUMERIC_ONLY |
bool | True |
Reject PINs that are not all digits. |
PIN_REUSE_ALLOWED |
FPA_PIN_REUSE_ALLOWED |
bool | False |
Allow a PIN of a deleted enrollee to be issued again. When false, retired PINs are remembered so old punches are never attributed to a new person. |
ADMS¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
ADMS_ENABLED |
FPA_ADMS_ENABLED |
bool | True |
Serve the ADMS/Push endpoints. |
ADMS_URL_PREFIX |
FPA_ADMS_URL_PREFIX |
str | 'iclock/' |
URL prefix the devices call (set the device's server path accordingly). |
ADMS_AUTO_REGISTER_DEVICES |
FPA_ADMS_AUTO_REGISTER_DEVICES |
bool | True |
Create a Device row when an unknown serial number connects. |
ADMS_REQUIRE_DEVICE_APPROVAL |
FPA_ADMS_REQUIRE_DEVICE_APPROVAL |
bool | True |
Auto-registered devices start as pending_approval; their data is refused (and kept on the device) until approved. |
ADMS_ALLOWED_IPS |
FPA_ADMS_ALLOWED_IPS |
list | [] |
IP addresses / CIDR networks allowed to call ADMS endpoints (empty = any). |
ADMS_TRUSTED_PROXY_IPS |
FPA_ADMS_TRUSTED_PROXY_IPS |
list | [] |
Reverse proxies whose X-Forwarded-For header is trusted for the device IP. |
ADMS_DEVICE_TOKEN_REQUIRED |
FPA_ADMS_DEVICE_TOKEN_REQUIRED |
bool | False |
Require a per-device token (query param, X-FPA-Device-Token header or pushcommkey). |
ADMS_TOKEN_PARAM |
FPA_ADMS_TOKEN_PARAM |
str | 'token' |
Query parameter carrying the device token. |
ADMS_ERROR_DELAY |
FPA_ADMS_ERROR_DELAY |
int | 30 |
Handshake ErrorDelay (seconds between retries). |
ADMS_DELAY |
FPA_ADMS_DELAY |
int | 10 |
Handshake Delay (seconds between getrequest polls). |
ADMS_TRANS_TIMES |
FPA_ADMS_TRANS_TIMES |
str | '00:00;14:05' |
Handshake TransTimes. |
ADMS_TRANS_INTERVAL |
FPA_ADMS_TRANS_INTERVAL |
int | 1 |
Handshake TransInterval (minutes). |
ADMS_TRANS_FLAG |
FPA_ADMS_TRANS_FLAG |
str | 'TransData AttLog\tOpLog\tEnrollUser\tChgUser\tEnrollFP\tChgFP' |
Handshake TransFlag (which data the device uploads). |
ADMS_REALTIME |
FPA_ADMS_REALTIME |
bool | True |
Handshake Realtime (upload punches immediately). |
ADMS_ENCRYPT |
FPA_ADMS_ENCRYPT |
str | 'None' |
Handshake Encrypt value. |
ADMS_TIMEZONE_OPTION |
FPA_ADMS_TIMEZONE_OPTION |
int (nullable) | None |
Force the handshake TimeZone value; None computes it from the device timezone. |
ADMS_SERVER_VERSION |
FPA_ADMS_SERVER_VERSION |
str | '2.4.1' |
ServerVer reported in the handshake. |
ADMS_PUSH_PROTOCOL_VERSION |
FPA_ADMS_PUSH_PROTOCOL_VERSION |
str | '2.4.1' |
PushProtVer reported in the handshake. |
ADMS_HANDSHAKE_EXTRA_OPTIONS |
FPA_ADMS_HANDSHAKE_EXTRA_OPTIONS |
dict | {} |
Extra key=value lines appended to every handshake (device options override these). |
ADMS_MAX_COMMANDS_PER_REQUEST |
FPA_ADMS_MAX_COMMANDS_PER_REQUEST |
int | 20 |
Maximum commands handed out per getrequest. |
ADMS_PROTOCOL_ADAPTER |
FPA_ADMS_PROTOCOL_ADAPTER |
path | 'fingerprint_attendance.adms.adapter.ADMSProtocolAdapter' |
Class parsing/rendering the protocol. Subclass for unusual firmware (a device can also name one in options['protocol_adapter']). |
ADMS_MAX_REQUEST_BYTES |
FPA_ADMS_MAX_REQUEST_BYTES |
int | 20971520 |
Maximum ADMS request body size (larger requests get HTTP 413). |
ADMS_RATE_LIMIT |
FPA_ADMS_RATE_LIMIT |
str (nullable) | '600/m' |
Per-device request rate limit (N/s\|m\|h) using the Django cache. None disables. |
ADMS_BODY_ENCODINGS |
FPA_ADMS_BODY_ENCODINGS |
list | ['utf-8', 'gbk', 'latin-1'] |
Encodings tried, in order, when decoding device uploads. |
ADMS_ACCEPT_FROM_PENDING_DEVICES |
FPA_ADMS_ACCEPT_FROM_PENDING_DEVICES |
bool | False |
Store punches from devices awaiting approval (flagged pending_device) instead of refusing them. |
ADMS_STORE_OPERLOG_EVENTS |
FPA_ADMS_STORE_OPERLOG_EVENTS |
bool | True |
Store OPLOG lines as DeviceEventLog rows. |
Pull¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
PULL_ENABLED |
FPA_PULL_ENABLED |
bool | False |
Enable pull mode (requires the [pull] extra). |
PULL_ADAPTER |
FPA_PULL_ADAPTER |
path | 'fingerprint_attendance.pull.pyzk_adapter.PyZKPullAdapter' |
BasePullAdapter subclass used to talk to devices on the LAN. |
PULL_DEFAULT_PORT |
FPA_PULL_DEFAULT_PORT |
int | 4370 |
Default device TCP/UDP port. |
PULL_TIMEOUT |
FPA_PULL_TIMEOUT |
int | 10 |
Connection timeout in seconds. |
PULL_COMM_KEY |
FPA_PULL_COMM_KEY |
int | 0 |
Default device comm key (password). |
PULL_FORCE_UDP |
FPA_PULL_FORCE_UDP |
bool | False |
Force UDP (older devices). |
PULL_POLL_INTERVAL |
FPA_PULL_POLL_INTERVAL |
duration | 1m |
Interval between polls for fpa_pull_attendance --loop. |
PULL_RECONNECT_BACKOFF_MAX |
FPA_PULL_RECONNECT_BACKOFF_MAX |
duration | 5m |
Maximum reconnect backoff for live capture. |
PULL_DISABLE_DEVICE_DURING_SYNC |
FPA_PULL_DISABLE_DEVICE_DURING_SYNC |
bool | True |
Lock the device keypad while bulk reading/writing. |
Enrollment¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
FINGERS_REQUIRED_MIN |
FPA_FINGERS_REQUIRED_MIN |
int | 1 |
Minimum enrolled fingers an enrollee must have when a session completes. |
FINGERS_ALLOWED_MAX |
FPA_FINGERS_ALLOWED_MAX |
int | 10 |
Maximum fingers stored per enrollee. |
ALLOWED_FINGER_INDEXES |
FPA_ALLOWED_FINGER_INDEXES |
int_list | [0, 1, 2, 3, 4, 5, 6, 7, 8, 9] |
Finger indexes (0-9, ZKTeco numbering) that may be enrolled. |
ENROLLMENT_SESSION_TTL |
FPA_ENROLLMENT_SESSION_TTL |
duration | 10m |
Lifetime of an enrollment session. |
ENROLLMENT_REQUIRE_CONSENT |
FPA_ENROLLMENT_REQUIRE_CONSENT |
bool | True |
Refuse to store templates for enrollees without active consent. |
ENROLLMENT_RETRY_COUNT |
FPA_ENROLLMENT_RETRY_COUNT |
int | 3 |
RETRY parameter of remote enroll commands. |
ENROLLMENT_OVERWRITE |
FPA_ENROLLMENT_OVERWRITE |
bool | True |
OVERWRITE parameter of remote enroll commands. |
ACCEPT_DEVICE_ENROLLMENTS |
FPA_ACCEPT_DEVICE_ENROLLMENTS |
bool | True |
Accept templates enrolled at the device (walk-up) and fan them out. |
DELETE_REJECTED_DEVICE_TEMPLATES |
FPA_DELETE_REJECTED_DEVICE_TEMPLATES |
bool | True |
When a walk-up template is refused (no consent, finger not allowed, unknown PIN), queue its deletion on that device. |
AGENT_CAN_START_SESSIONS |
FPA_AGENT_CAN_START_SESSIONS |
bool | False |
Allow desktop agents to open enrollment sessions themselves. |
AGENT_AUTH_SCHEME |
FPA_AGENT_AUTH_SCHEME |
str | 'Agent' |
Authorization: <scheme> <key> scheme for agent requests. |
AGENT_RATE_LIMIT |
FPA_AGENT_RATE_LIMIT |
str (nullable) | '120/m' |
Per-agent request rate limit. |
Templates¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
TEMPLATE_ENCRYPTION_ENABLED |
FPA_TEMPLATE_ENCRYPTION_ENABLED |
bool | True |
Encrypt templates at rest. |
TEMPLATE_ENCRYPTION_KEYS |
FPA_TEMPLATE_ENCRYPTION_KEYS |
list | [] |
Fernet keys, newest first. Old keys still decrypt (rotation); run fpa_rotate_template_keys after adding a key. |
TEMPLATE_STORAGE_BACKEND |
FPA_TEMPLATE_STORAGE_BACKEND |
path | 'fingerprint_attendance.crypto.DatabaseTemplateStorage' |
Class storing template bytes (e.g. to use an external vault). |
EXPOSE_TEMPLATE_DATA_IN_API |
FPA_EXPOSE_TEMPLATE_DATA_IN_API |
bool | False |
Allow the API to return template bytes to callers holding the view_template_data permission. |
ALGORITHM_COMPATIBILITY_MAP |
FPA_ALGORITHM_COMPATIBILITY_MAP |
dict | {} |
{device_algorithm: [template_algorithms...]}. Unlisted devices accept only their own algorithm. |
DEFAULT_ALGORITHM_VERSION |
FPA_DEFAULT_ALGORITHM_VERSION |
str | '10' |
Algorithm assumed when a device does not report one. |
SYNC_TO_UNKNOWN_ALGORITHM_DEVICES |
FPA_SYNC_TO_UNKNOWN_ALGORITHM_DEVICES |
bool | True |
Push templates to devices that never reported an algorithm version. |
TEMPLATE_MAX_BYTES |
FPA_TEMPLATE_MAX_BYTES |
int | 65536 |
Largest template accepted. |
Sync¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
SYNC_STRATEGY |
FPA_SYNC_STRATEGY |
path | 'all' |
Which devices receive an enrollee. Aliases all, groups, or a dotted path to callable(enrollee) -> QuerySet[Device] or a BaseSyncStrategy subclass. Aliases: all, groups. |
SYNC_UNGROUPED_TO_ALL |
FPA_SYNC_UNGROUPED_TO_ALL |
bool | False |
With the groups strategy, send enrollees without groups to every device. |
SYNC_ON_ENROLL |
FPA_SYNC_ON_ENROLL |
bool | True |
Fan templates out when stored. |
SYNC_ON_DELETE |
FPA_SYNC_ON_DELETE |
bool | True |
Queue device deletes on deactivation, deletion or consent withdrawal. |
SYNC_ON_DEVICE_APPROVAL |
FPA_SYNC_ON_DEVICE_APPROVAL |
bool | True |
Backfill all in-scope enrollees onto a newly approved device. |
SYNC_USERS_WITHOUT_TEMPLATES |
FPA_SYNC_USERS_WITHOUT_TEMPLATES |
bool | False |
Push the user record to devices even before any template exists. |
Commands¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
COMMAND_MAX_RETRIES |
FPA_COMMAND_MAX_RETRIES |
int | 5 |
Retries for a failed or unacknowledged command. |
COMMAND_RETRY_BACKOFF |
FPA_COMMAND_RETRY_BACKOFF |
duration | 1m |
Base retry delay (doubles per attempt). |
COMMAND_RETRY_BACKOFF_MAX |
FPA_COMMAND_RETRY_BACKOFF_MAX |
duration | 1h |
Maximum retry delay. |
COMMAND_ACK_TIMEOUT |
FPA_COMMAND_ACK_TIMEOUT |
duration | 15m |
A sent command without a result after this long is retried. |
COMMAND_EXPIRY |
FPA_COMMAND_EXPIRY |
dict | {'reboot': '1h', 'set_time': '1h', 'enroll_fingerprint': '30m', 'check': '1h', 'info': '1h', 'clear_logs': '1d', 'clear_data': '1d'} |
Per command type expiry (duration or None). Key default applies to unlisted types; template/user adds and deletes never expire unless listed. |
Punches¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
DEDUPE_WINDOW_SECONDS |
FPA_DEDUPE_WINDOW_SECONDS |
int | 60 |
Repeat punches by the same PIN within this window are soft duplicates (0 disables). |
DEDUPE_WINDOW_ACTION |
FPA_DEDUPE_WINDOW_ACTION |
str | 'flag' |
flag stores soft duplicates with the duplicate flag (excluded from processing, keeps device/server counts reconcilable); skip drops them. |
DEDUPE_KEY_BUILDER |
FPA_DEDUPE_KEY_BUILDER |
path | 'fingerprint_attendance.ingestion.dedupe.default_dedupe_key' |
callable(candidate) -> str building the exact-duplicate key. |
PUNCH_STATE_RESOLVER |
FPA_PUNCH_STATE_RESOLVER |
path | 'trust_device' |
Resolves check-in/out. Aliases trust_device, alternate, first_last or a BasePunchStateResolver subclass path. Aliases: trust_device, alternate, first_last. |
PUNCH_STATE_MAP |
FPA_PUNCH_STATE_MAP |
dict | {'0': 'check_in', '1': 'check_out', '2': 'break_out', '3': 'break_in', '4': 'overtime_in', '5': 'overtime_out'} |
Device status code -> punch state (used by trust_device). |
ACCEPT_UNKNOWN_PIN_PUNCHES |
FPA_ACCEPT_UNKNOWN_PIN_PUNCHES |
bool | True |
Store punches whose PIN matches no enrollee (flagged unknown_pin). |
LINK_UNKNOWN_PUNCHES_ON_ENROLL |
FPA_LINK_UNKNOWN_PUNCHES_ON_ENROLL |
bool | True |
Attach earlier unknown-PIN punches when an enrollee with that PIN is created. |
FUTURE_PUNCH_TOLERANCE |
FPA_FUTURE_PUNCH_TOLERANCE |
duration | 5m |
Punches later than received_at + this are flagged future. |
CLOCK_DRIFT_WARNING_SECONDS |
FPA_CLOCK_DRIFT_WARNING_SECONDS |
int | 120 |
Device clock drift above this is flagged and signalled. |
LATE_SYNC_THRESHOLD |
FPA_LATE_SYNC_THRESHOLD |
duration | 15m |
Punches received later than this after they happened are flagged late_sync. |
BACKLOG_SIGNAL_THRESHOLD |
FPA_BACKLOG_SIGNAL_THRESHOLD |
int | 20 |
Batches with at least this many new punches (or any late ones) emit backlog_synced. |
PUNCH_BULK_CHUNK_SIZE |
FPA_PUNCH_BULK_CHUNK_SIZE |
int | 1000 |
Rows per bulk_create call. |
PUNCH_EVENT_BATCH_LIMIT |
FPA_PUNCH_EVENT_BATCH_LIMIT |
int (nullable) | 1000 |
Batches larger than this emit only batch-level events (punches_received, backlog_synced) instead of one punch_received per punch. None = no limit. |
AUTO_CORRECT_DEVICE_TIME |
FPA_AUTO_CORRECT_DEVICE_TIME |
bool | False |
Queue a set-time command when drift exceeds the warning threshold. |
MAX_AUTO_TIME_CORRECTION |
FPA_MAX_AUTO_TIME_CORRECTION |
duration | 1h |
Larger drifts are only reported, never corrected automatically. |
Processing¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
ATTENDANCE_PROCESSOR |
FPA_ATTENDANCE_PROCESSOR |
path (nullable) | 'fingerprint_attendance.processing.default.FirstInLastOutProcessor' |
BaseAttendanceProcessor subclass; None disables processing entirely. |
PROCESS_ON_INGEST |
FPA_PROCESS_ON_INGEST |
bool | True |
Recompute affected days after punches are ingested (via the task backend). |
DAY_BOUNDARY_RESOLVER |
FPA_DAY_BOUNDARY_RESOLVER |
path | 'calendar_day' |
Maps a punch to a work date. Aliases calendar_day, offset (uses DAY_START_TIME), shift_aware (overnight shifts from the schedule provider). Aliases: calendar_day, offset, shift_aware. |
DAY_START_TIME |
FPA_DAY_START_TIME |
time | 00:00 |
Local time a work day starts (offset boundary). |
ATTENDANCE_TIMEZONE |
FPA_ATTENDANCE_TIMEZONE |
str (nullable) | None |
Timezone used to assign work dates; None uses DEFAULT_DEVICE_TIMEZONE. |
OVERNIGHT_SHIFT_MARGIN |
FPA_OVERNIGHT_SHIFT_MARGIN |
duration | 4h |
shift_aware boundary: punches up to this long after an overnight shift ends still belong to the shift's start date. |
STATUS_RULES |
FPA_STATUS_RULES |
path_list | ['fingerprint_attendance.processing.rules.on_leave', 'fingerprint_attendance.processing.rules.non_working_day', 'fingerprint_attendance.processing.rules.absent', 'fingerprint_attendance.processing.rules.incomplete', 'fingerprint_attendance.processing.rules.late', 'fingerprint_attendance.processing.rules.early_leave', 'fingerprint_attendance.processing.rules.present'] |
Ordered status rule callables evaluated per attendance day. |
ABSENCE_GENERATION_ENABLED |
FPA_ABSENCE_GENERATION_ENABLED |
bool | True |
Allow fpa_generate_absences / the periodic task to create absent days. |
ABSENCE_CUTOFF_TIME |
FPA_ABSENCE_CUTOFF_TIME |
time | 23:59 |
Absences for a date are only generated after this local time. |
RECOMPUTE_ON_CALENDAR_CHANGE |
FPA_RECOMPUTE_ON_CALENDAR_CHANGE |
bool | True |
Recompute days when holidays, leave or schedules change. |
Calendar¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
CALENDAR_PROVIDER |
FPA_CALENDAR_PROVIDER |
path | 'fingerprint_attendance.calendar.providers.DefaultCalendarProvider' |
BaseCalendarProvider resolving day types. |
HOLIDAY_PROVIDER |
FPA_HOLIDAY_PROVIDER |
path | 'chained' |
BaseHolidayProvider. Aliases chained, settings, database, holidays. Aliases: chained, settings, database, holidays. |
HOLIDAY_PROVIDER_CHAIN |
FPA_HOLIDAY_PROVIDER_CHAIN |
path_list | ['database', 'settings'] |
Providers combined by chained, highest priority first (database overrides win). Aliases: settings, database, holidays. |
HOLIDAYS |
FPA_HOLIDAYS |
json | [] |
Static holidays: [{"date": "2026-10-01", "name": "Independence Day", "recurring": true}]. |
HOLIDAYS_COUNTRY |
FPA_HOLIDAYS_COUNTRY |
str (nullable) | None |
Country code for the holidays provider (e.g. NG). |
HOLIDAYS_SUBDIVISION |
FPA_HOLIDAYS_SUBDIVISION |
str (nullable) | None |
Subdivision for the holidays provider. |
WEEKEND_DAYS |
FPA_WEEKEND_DAYS |
int_list | [5, 6] |
Weekend weekdays (Monday=0). |
WEEKEND_DAYS_BY_GROUP |
FPA_WEEKEND_DAYS_BY_GROUP |
dict | {} |
{device_group_name: [weekdays]} overrides for enrollees in that group. |
LEAVE_PROVIDER |
FPA_LEAVE_PROVIDER |
path | 'fingerprint_attendance.calendar.providers.NullLeaveProvider' |
BaseLeaveProvider connecting your HR/leave system. |
SCHEDULE_PROVIDER |
FPA_SCHEDULE_PROVIDER |
path | 'settings' |
BaseScheduleProvider. Aliases settings (DEFAULT_SCHEDULE), database (WorkSchedule/ShiftAssignment models). Aliases: settings, database. |
DEFAULT_SCHEDULE |
FPA_DEFAULT_SCHEDULE |
dict (nullable) | None |
Fixed schedule, e.g. {"start": "09:00", "end": "17:00", "grace_in_minutes": 10}. None = no expected shift (no late/early statuses). |
SCHEDULE_MODELS_ENABLED |
FPA_SCHEDULE_MODELS_ENABLED |
bool | False |
Expose WorkSchedule/ShiftAssignment in the API and admin. |
Time¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
DEFAULT_DEVICE_TIMEZONE |
FPA_DEFAULT_DEVICE_TIMEZONE |
str | settings.TIME_ZONE |
Timezone of devices without their own (everything is stored in UTC). |
Tasks¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
TASK_BACKEND |
FPA_TASK_BACKEND |
path | 'sync' |
Runs background work. Aliases sync (inline), celery, django (Django 6 tasks), or a BaseTaskBackend path. Aliases: sync, celery, django. |
TASK_BACKEND_OPTIONS |
FPA_TASK_BACKEND_OPTIONS |
dict | {} |
Backend options (queue for Celery, queue_name/backend for Django tasks). |
Devices¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
DEVICE_OFFLINE_AFTER |
FPA_DEVICE_OFFLINE_AFTER |
duration | 5m |
A device not seen for this long is offline. |
DEFAULT_LOG_CAPACITY |
FPA_DEFAULT_LOG_CAPACITY |
int | 100000 |
Attendance log capacity assumed when the device does not report one. |
LOG_CAPACITY_WARNING_RATIO |
FPA_LOG_CAPACITY_WARNING_RATIO |
float | 0.9 |
Warn when a device's stored logs reach this fraction of capacity. |
Realtime¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
REALTIME_BACKEND |
FPA_REALTIME_BACKEND |
path | 'none' |
Broadcast backend. Aliases none, channels. Aliases: none, channels. |
REALTIME_GROUP_NAME_BUILDER |
FPA_REALTIME_GROUP_NAME_BUILDER |
path | 'fingerprint_attendance.realtime.backends.default_group_names' |
callable(event, payload) -> list[str] of channel group names. |
REALTIME_EVENTS |
FPA_REALTIME_EVENTS |
list | ['punch_received', 'device_online', 'device_offline', 'backlog_synced', 'enrollment_completed', 'command_failed'] |
Events broadcast to WebSocket clients. |
REALTIME_CONSUMER_PERMISSION |
FPA_REALTIME_CONSUMER_PERMISSION |
path | 'fingerprint_attendance.realtime.backends.staff_only' |
callable(scope) -> bool deciding who may subscribe. |
Webhooks¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
WEBHOOKS_ENABLED |
FPA_WEBHOOKS_ENABLED |
bool | False |
Deliver events to webhook endpoints. |
WEBHOOK_SIGNING_SECRET |
FPA_WEBHOOK_SIGNING_SECRET |
str (nullable) | None |
Default HMAC-SHA256 secret (endpoints may define their own). |
WEBHOOK_TIMEOUT |
FPA_WEBHOOK_TIMEOUT |
int | 10 |
HTTP timeout (seconds). |
WEBHOOK_MAX_RETRIES |
FPA_WEBHOOK_MAX_RETRIES |
int | 5 |
Delivery retries. |
WEBHOOK_RETRY_BACKOFF |
FPA_WEBHOOK_RETRY_BACKOFF |
duration | 1m |
Base retry delay (doubles per attempt). |
WEBHOOK_EVENTS |
FPA_WEBHOOK_EVENTS |
list | [] |
Event allowlist (empty = every event). |
WEBHOOK_SENDER |
FPA_WEBHOOK_SENDER |
path | 'fingerprint_attendance.webhooks.delivery.urllib_sender' |
callable(url, body: bytes, headers, timeout) -> (status, text). |
API¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
API_URL_PREFIX |
FPA_API_URL_PREFIX |
str | 'api/fingerprint/' |
Prefix used by fingerprint_attendance.urls for the REST API. |
API_URL_NAMESPACE |
FPA_API_URL_NAMESPACE |
str | 'fingerprint_attendance_api' |
URL namespace of the API. |
API_PERMISSION_CLASSES |
FPA_API_PERMISSION_CLASSES |
path_list | ['rest_framework.permissions.IsAdminUser'] |
Default permission classes for every viewset. |
API_VIEWSET_PERMISSION_CLASSES |
FPA_API_VIEWSET_PERMISSION_CLASSES |
dict | {} |
{"devices": [...], "punches.create_manual": [...]} per viewset / action overrides. |
API_AUTHENTICATION_CLASSES |
FPA_API_AUTHENTICATION_CLASSES |
path_list (nullable) | None |
Authentication classes (None = DRF defaults). |
API_PAGINATION_CLASS |
FPA_API_PAGINATION_CLASS |
path (nullable) | 'fingerprint_attendance.api.pagination.StandardPagination' |
Pagination class for list endpoints. |
API_PAGE_SIZE |
FPA_API_PAGE_SIZE |
int | 50 |
Default page size. |
PUNCH_PAGINATION_CLASS |
FPA_PUNCH_PAGINATION_CLASS |
path (nullable) | 'fingerprint_attendance.api.pagination.PunchCursorPagination' |
Pagination class for punches (cursor based). |
API_THROTTLE_CLASSES |
FPA_API_THROTTLE_CLASSES |
path_list (nullable) | None |
Throttle classes (None = DRF defaults). |
SERIALIZER_OVERRIDES |
FPA_SERIALIZER_OVERRIDES |
dict | {} |
{"devices": "myapp.MyDeviceSerializer"} (keys: viewset basename or basename.action). |
VIEWSET_OVERRIDES |
FPA_VIEWSET_OVERRIDES |
dict | {} |
{"devices": "myapp.MyDeviceViewSet"}. |
FILTERSET_OVERRIDES |
FPA_FILTERSET_OVERRIDES |
dict | {} |
{"punches": "myapp.MyPunchFilterSet"} (django-filter). |
API_FILTER_BACKEND |
FPA_API_FILTER_BACKEND |
str | 'auto' |
auto (django-filter when installed), django_filter or builtin. |
API_EXCEPTION_HANDLER |
FPA_API_EXCEPTION_HANDLER |
path (nullable) | 'fingerprint_attendance.api.exceptions.exception_handler' |
Exception handler used by package viewsets (None = DRF's configured handler). |
Privacy¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
RETENTION_DELETE_TEMPLATES_AFTER_DEACTIVATION |
FPA_RETENTION_DELETE_TEMPLATES_AFTER_DEACTIVATION |
duration (nullable) | None |
Delete stored templates this long after deactivation (None keeps them). |
RETENTION_PUNCHES_DAYS |
FPA_RETENTION_PUNCHES_DAYS |
int (nullable) | None |
Delete punches older than N days (None = keep forever). |
RETENTION_EVENT_LOG_DAYS |
FPA_RETENTION_EVENT_LOG_DAYS |
int (nullable) | 90 |
Delete device event logs older than N days. |
RETENTION_COMMANDS_DAYS |
FPA_RETENTION_COMMANDS_DAYS |
int (nullable) | 90 |
Delete finished commands older than N days. |
RETENTION_WEBHOOK_DELIVERIES_DAYS |
FPA_RETENTION_WEBHOOK_DELIVERIES_DAYS |
int (nullable) | 30 |
Delete webhook deliveries older than N days. |
RETENTION_AUDIT_LOG_DAYS |
FPA_RETENTION_AUDIT_LOG_DAYS |
int (nullable) | None |
Delete audit entries older than N days. |
AUDIT_LOG_ENABLED |
FPA_AUDIT_LOG_ENABLED |
bool | True |
Write AuditLog rows. |
LOG_REDACTION |
FPA_LOG_REDACTION |
bool | True |
Redact templates, tokens and keys from package log records. |
Hooks¶
| Setting | Env var | Type | Default | Description |
|---|---|---|---|---|
HOOKS |
FPA_HOOKS |
dict | {} |
{event_name: ["dotted.callable", ...]}; each is called as hook(event, payload). |
HOOKS_ASYNC |
FPA_HOOKS_ASYNC |
bool | True |
Run hooks through the task backend. |
EVENTS_ON_COMMIT |
FPA_EVENTS_ON_COMMIT |
bool | True |
Dispatch signals/hooks/webhooks after the surrounding transaction commits. |