---
title: "Configuration - Server"
canonical: "https://support.appfire.com/space/MARKDOWN/72385596/Configuration%20-%20Server"
format: markdown
---
> Macro (aura-html)

<span style="color: #000000">After </span>[installing](https://bobswift.atlassian.net/wiki/x/BgD6B) <span style="color: #000000">or updating the app, you can configure the app settings in the Configuration screen. </span>

<span style="color: #000000">To navigate to the screen:</span>

1. <span style="color: #000000">Log in as an administrator and select </span>***<span style="color: #000000">Cog menu (</span>***> Macro (inline-media-image)

***<span style="color: #000000">) > Manage apps</span>***<span style="color: #000000">.</span>
2. <span style="color: #000000">Select </span>*<span style="color: #000000">Markdown</span>*<span style="color: #000000"> under the </span>*<span style="color: #000000">BOB SWIFT CONFIGURATION</span>*<span style="color: #000000"> section in the sidebar.</span>

> ⚠️ **Migrating app from server to cloud?**
> ⚠️ 
> ⚠️ <span style="color: #000000">From version 3.6.0, migrating from server to cloud now transfers the app global configurations as well as the app data automatically. Refer to the </span>[Migration guide](https://bobswift.atlassian.net/wiki/x/iQYsP)<span style="color: #333333"> for more detailed information about the migration process.</span>

# <span style="color: #000000">Configuration screen</span>

<span style="color: #000000">The app configuration options are categorized under the following tabs:</span>

- [<span style="color: #000000">Global Configuration</span>](#Configuration-Server-md_configGlobal)
- [<span style="color: #000000">Profiles</span>](#Configuration-Server-md_configProfiles)

## > Macro (anchor)

<span style="color: #000000">Global Configuration </span>

![image](media://22c53cc3-2aff-4557-9830-3024e830979b)

| <span style="color: #000000">**Parameter**</span> | <span style="color: #000000">**Default**</span> | <span style="color: #000000">**Description**</span> |
| --- | --- | --- |
| <span style="color: #000000">Restrict URL access</span> | <span style="color: #000000">Off</span> | <span style="color: #000000">Available since version 3.3. This parameter </span><span style="color: #000000">restricts access to remote locations through the</span><span style="color: #000000"> </span>*<span style="color: #000000">URL to markdown file</span>*<span style="color: #000000"> </span><span style="color: #000000">parameter of the</span><span style="color: #000000"> </span>*<span style="color: #000000">Markdown from a URL</span>*<span style="color: #000000"> macro</span><span style="color: #000000">. </span><span style="color: #000000">The specified URLs in the macro editors must conform to the Confluence Allowlist; provided, the allowlist is enabled. </span><br><span style="color: #000000">Confluence allows the administrator to turn on the allowlist to restrict incoming and outgoing connections to only those connections that are configured in the Allowlist settings. If enabled, the</span><span style="color: #000000"> </span>*<span style="color: #000000">URL to markdown file</span>*<span style="color: #000000"> </span><span style="color: #000000">parameter of the</span><span style="color: #000000"> </span>*<span style="color: #000000">Markdown from a URL</span>*<span style="color: #000000"> macro</span><span style="color: #000000"> is also restricted to the URLs that are configured in the </span><span style="color: #000000">Allowlist</span><span style="color: #000000"> settings for Confluence only.</span> |
| <span style="color: #000000">Allow JavaScript</span> | <span style="color: #000000">On</span> | <span style="color: #000000">Available since version 3.4. </span><span style="color: #000000">This option controls Javascript usage in the </span>*<span style="color: #000000">Markdown for Confluence</span>*<span style="color: #000000"> app. Enable this option to allow execution of Javascript within the macros.</span><br>> ℹ️ - <span style="color: #000000">You can also control JavaScript usage on pages that use the </span>*<span style="color: #000000">Markdown for Confluence</span>*<span style="color: #000000"> app. To restrict the usage of JavaScript in the </span>*<span style="color: #000000">Markdown</span>*<span style="color: #000000"> macros from the Macro Security for Confluence Configuration page:</span>
> ℹ️   - <span style="color: #000000">Enable the </span>*<span style="color: #000000">markdown.allowJavaScript </span>*<span style="color: #000000">macro for </span>*<span style="color: #000000">markdown</span>*<span style="color: #000000"> macro.</span>
> ℹ️   - <span style="color: #000000">Enable the </span>*<span style="color: #000000">markdown-url.allowJavaScript </span>*<span style="color: #000000">macro for </span>*<span style="color: #000000">markdown-url</span>*<span style="color: #000000"> macro.</span>
> ℹ️   - <span style="color: #000000">Enable the </span>*<span style="color: #000000">markdown-attachment.allowJavaScript </span>*<span style="color: #000000">macro for </span>*<span style="color: #000000">markdown-attachment</span>*<span style="color: #000000"> macro.</span>
> ℹ️ 
> ℹ️ <span style="color: #000000">To enable these macros, refer to </span>[<span style="color: #000000">Macro Security Configuration</span>](https://bobswift.atlassian.net/wiki/spaces/CMSP/pages/558432346/Macro+Security+Configuration+-+4.x)<span style="color: #000000">.</span>
> ℹ️ 
> ℹ️ - <span style="color: #000000">To know the security vulnerabilities prevented by this feature, refer to the </span>[<span style="color: #000000">List of security vulnerabilities prevented</span>](https://appfire.atlassian.net/wiki/spaces/MARKDOWN/pages/72385200)<span style="color: #000000">.</span> |
| <span style="color: #000000">Show JavaScript warning</span> | <span style="color: #000000">Off</span> | <span style="color: #000000">Available since 3.8. Enable this option to control the display of a warning if usage of JavaScript in the macros is restricted. </span><br>> ⚠️ <span style="color: #000000">This option is enabled only if </span>*<span style="color: #000000">Allow JavaScript</span>*<span style="color: #000000"> is disabled.</span><br><span style="color: #000000">If the </span>*<span style="color: #000000">Allow JavaScript</span>*<span style="color: #000000"> parameter is disabled and users then add JavaScript content in macros,</span><span style="color: #000000"> a warning is displayed</span><span style="color: #000000">. Use this parameter to hide this warning message.</span> |
| <span style="color: #000000">Blacklist domains</span> | <span style="color: #000000">Off</span> | <span style="color: #000000">Available since version 3.5. This option controls whether or not certain domains are blacklisted. By default, this option is disabled for backward compatibility.</span><br><span style="color: #000000">If enabled, and if a request from any of these sites is received, an error message is displayed. However, if users still need to access a blacklisted site, they must contact their administrator to disable this option. Click the link named </span>***<span style="color: #000000">listed</span>***<span style="color: #000000"> (in the description beneath the option) to view a pre-defined list of the most commonly blacklisted domains in a pop-up window. </span><span style="color: #000000">The following sites are blacklisted, by default:</span><br>- <span style="color: #000000">10.0.0.0/8</span>
- <span style="color: #000000">100.64.0.0/10</span>
- <span style="color: #000000">127.0.0.0/8</span>
- <span style="color: #000000">169.254.0.0/16</span>
- <span style="color: #000000">172.16.0.0/12</span>
- <span style="color: #000000">192.168.0.0/16</span>
- <span style="color: #000000">192.0.0.0/24</span>
- <span style="color: #000000">198.18.0.0/15</span>
- <span style="color: #000000">255.255.255.255/32</span>
- <span style="color: #000000">0.0.0.0/32</span>
- <span style="color: #000000">192.0.2.0/24</span>
- <span style="color: #000000">192.88.99.0/24</span>
- <span style="color: #000000">198.51.100.0/24</span>
- <span style="color: #000000">203.0.113.0/24</span>
- <span style="color: #000000">224.0.0.0/4</span>
- <span style="color: #000000">240.0.0.0/4</span> |

## > Macro (anchor)

<span style="color: #000000">Profiles</span>

<span style="color: #000000">Profiles are a set of basic parameters required to access Markdown content from a remote location and render the content on Confluence pages.</span>

<span style="color: #000000">Use profiles to:</span>

- <span style="color: #000000">Allow user authentication as required by some URLs to be hidden from page viewers and editors. Only Confluence administrators have access to this information.</span>
- <span style="color: #000000">Enable macro editors to quickly configure the macro by reusing a shared definition for URL access. </span>
- <span style="color: #000000">Make lesser changes to page contents </span><span style="color: #000000">when base URLs are relocated as r</span><span style="color: #000000">elative addressing is used in profiles. </span>
- <span style="color: #000000">Macro configured URL (that is not a full URL) is appended to the profile provided URL. This absolute URL then points to the actual location of the content to be rendered. </span>

![image](media://327cdd47-8336-4018-a353-5fd8399100b9)

<span style="color: #000000">The page displays a list of profiles available for the macros. </span><span style="color: #000000">You can perform the following actions on this page:</span>

- <span style="color: #000000">Click </span>> Macro (inline-media-image)

<span style="color: #000000"> </span><span style="color: #000000">to edit the profile details.</span>
- <span style="color: #000000">Click </span>> Macro (inline-media-image)

<span style="color: #000000"> to remove the profile.</span>

<span style="color: #000000">To create a new profile, click</span><span style="color: #000000"> </span>**<span style="color: #000000">Add Profile</span>**<span style="color: #000000"> </span><span style="color: #000000">to open a pop-up window as:</span>

![image](media://17878077-aea0-4a64-8cb2-bffa1e04b5b9)


| <span style="color: #000000">**Parameter**</span> | <span style="color: #000000">**Description**</span> |
| --- | --- |
| <span style="color: #000000">Profile name</span> | <span style="color: #000000">Enter a name for the profile. Profile names given here are populated in the </span><span style="color: #000000">*Profile*</span>* *<span style="color: #000000">field in the macro editor. </span><br>> ⚠️ <span style="color: #000000">This name must be unique; else, the details specified overwrites the details of the existing profile. This may cause errors in pages where the profile is used.</span> |
| <span style="color: #000000">Profile type</span> | <span style="color: #000000">Specify whether this is a </span>*<span style="color: #000000">URL, GitLab, or GitHub </span>*<span style="color: #000000">address.</span><span style="color: #091e42"> </span><span style="color: #000000">The default option for this parameter is</span><span style="color: #000000"> </span>*<span style="color: #000000">URL</span>*<span style="color: #000000">.</span> |
| <span style="color: #000000">URL</span> | <span style="color: #000000">Enter the URL of the remote location to be accessed. It is recommended to provide the base URL here. </span><br>> ⚠️ <span style="color: #000000">A raw URL must be provided in the </span>*<span style="color: #000000">URL to markdown file</span>*<span style="color: #000000"> </span><span style="color: #000000">parameter of the</span><span style="color: #000000"> </span>*<span style="color: #000000">Markdown from a URL</span>*<span style="color: #000000"> macro editor.</span> |
| <span style="color: #000000">User; Password</span> | <span style="color: #000000">Enter the username and password, if required, to access the specified URL. </span><br>> ⚠️ <span style="color: #000000">Specify either the</span><span style="color: #000000"> </span>*User*<span style="color: #000000"> </span><span style="color: #000000">and</span><span style="color: #000000"> </span>*Password*<span style="color: #000000"> </span><span style="color: #000000">parameters or the</span><span style="color: #000000"> </span>*Access token,*<span style="color: #000000"> </span><span style="color: #000000">as an access token is also a means of user authentication. </span><span style="color: #000000">It is recommended to use either of the user authentication methods but not both.</span> |
| <span style="color: #000000">Always use credentials given here?</span> | <span style="color: #000000">Enable this to ensure that these credentials are are always used instead of user's credentials that may be available if an Application Link is defined for this URL.</span><br><span style="color: #000000">Note: This is available from release 3.8.1.</span> |
| <span style="color: #000000">Access token</span> | <span style="color: #000000">Enter an access token or an API token for the application or service to be connected with. </span><br>> ⚠️ <span style="color: #000000">If this parameter is specified, ensure that the</span><span style="color: #000000"> </span>*<span style="color: #000000">User</span>*<span style="color: #000000"> </span><span style="color: #000000">and</span><span style="color: #000000"> </span>*<span style="color: #000000">Password</span>*<span style="color: #000000"> </span><span style="color: #000000">parameters are left empty. It is recommended to use either of the user authentication methods but not both.</span><br><span style="color: #000000">Each application has its own method of generating tokens. </span>A<span style="color: #000000">ccess tokens</span> <span style="color: #000000">or API tokens are a means of user authentication; so, if mentioned, this token is used for authentication instead of using user credentials.</span><br>- <span style="color: #000000">Tokens are generated for a user after the application or service to be connected verifies the user's credentials. </span>
- <span style="color: #000000">Enter the generated token here for a seamless connection between the app's macros and the application or service.</span><br><span style="color: #000000">Here are some of the links associated with GitLab and GitHub applications to generate a personal access token:</span><br>- <span style="color: #000000">GitLab: Use </span>[<span style="color: #000000">this article</span>](https://docs.gitlab.com/ee/user/profile/personal_access_tokens.html)<span style="color: #000000"> </span><span style="color: #000000">to generate an access token from </span>[<span style="color: #000000">https://gitlab.com/profile/personal_access_tokens</span>](https://gitlab.com/profile/personal_access_tokens)<span style="color: #000000">.</span>
- <span style="color: #000000">GitHub: Use</span><span style="color: #000000"> </span>[<span style="color: #000000">this article</span>](https://help.github.com/en/github/authenticating-to-github/creating-a-personal-access-token-for-the-command-line)<span style="color: #000000"> to generate an access token from </span>[<span style="color: #000000">https://github.com/settings/tokens</span>](https://github.com/settings/tokens)<span style="color: #000000">. </span> |
| <span style="color: #000000">URL parameters</span> | <span style="color: #000000">Mention any extra parameters (for the query string) that must be appended to the specified URL here.</span> |
| <span style="color: #000000">Request headers</span> | <span style="color: #000000">Displays the request headers created as per the given information. </span><span style="color: #000000">Request headers are name or value pairs that are added to the request. For example, GitHub requires the following request headers be specified:</span><span style="color: #000000"> </span>*<span style="color: #000000">Authorization: token $accessToken, Accept:application/vnd.github.v3.raw</span>*<br><span style="color: #000000">T</span><span style="color: #000000">his field is automatically populated with a </span><span style="color: #000000">comma-separated list of</span><span style="color: #000000"> </span><span style="color: #000000">name or value pairs using the provided information. If required, enter additional name or value pairs separated with commas.</span> |

<span style="color: #000000">Click</span><span style="color: #000000"> </span>**Save profile**<span style="color: #000000"> </span><span style="color: #000000">to create the profile.</span>

> ℹ️ The **Help us improve the product**<span style="color: #172B4D"> </span><span style="color: #172B4D">parameter was removed.</span><span style="color: #172B4D"> </span><span style="color: #172B4D">We do not collect or transmit private user data or personally identifiable information.</span><span style="color: #172B4D"> </span><span style="color: #172B4D">Refer to the</span><span style="color: #172B4D"> </span>[Appfire Trust Center](https://appfire.atlassian.net/wiki/x/t4XGNw)<span style="color: #172B4D"> </span><span style="color: #172B4D">for EULA and other</span><span style="color: #172B4D"> policies.</span>