#!/bin/sh
# Thinkera Academy — settings applied after install. Safe to re-run: each line just sets a value.
#   ./harden.sh            (from platform/moodle)
# Every setting is also reachable in the admin UI; this file is the record of what we chose and why.
set -e
cfg() { docker compose exec -u www-data -T moodle php admin/cli/cfg.php --name="$1" --set="$2" >/dev/null && echo "  $1 = $2"; }

echo "language"
docker compose exec -u www-data -T moodle php admin/cli/install_language_pack.php --lang=ar >/dev/null 2>&1 || echo "  (Arabic pack: install from Site administration > Language if this failed)"
cfg lang ar
cfg langmenu 1
cfg country EG
cfg timezone Africa/Cairo

echo "who can see the content"
cfg forcelogin 1            # nothing on the site is readable without logging in
cfg forceloginforprofiles 1
cfg opentowebcrawlers 0     # the marketing site is public; the LMS is not
cfg guestloginbutton 0
cfg autologinguests 0
cfg enablecourserequests 0

echo "accounts and passwords"
cfg passwordpolicy 1
cfg minpasswordlength 8
# students sign up on phones: 8 characters with one digit (decided 18 September 2026)
cfg minpassworddigits 1
cfg minpasswordlower 0
cfg minpasswordupper 0
cfg minpasswordnonalphanum 0
cfg lockoutthreshold 10     # brute force: lock after 10 failed tries
cfg lockoutwindow 1800
cfg lockoutduration 1800
cfg displayloginfailures 1
cfg protectusernames 1
cfg sessiontimeout 7200

echo "content leaving the site"
cfg downloadcoursecontentallowed 0   # no "download course content" bundles
cfg enablemobilewebservice 0         # the Moodle app can keep content offline: off until you decide
cfg enablewebservices 0              # turn on only when something actually needs the API
cfg allowobjectembed 0
cfg enabletrusttext 0

echo "housekeeping"
cfg backup_auto_active 1 2>/dev/null || true
cfg enableanalytics 0
echo "done. Review Site administration > Reports > Security overview."
