Reference · Toller
The Toller's settings, files and commands
Every setting with its default, where the Toller keeps its files, its command line, and its local API.
- Article
- 1703
- Applies to
- Toller 0.1.1
- Last reviewed
- For
- For developers
Settings#
On its page, under Settings in the title bar. Each shows its value, its default and a line on what it does, with Reset to default. They're kept in %USERPROFILE%\.toller\settings.json.
| Setting | Default | What it does |
|---|---|---|
| What entered your projects | On | New and changed dependencies in your repositories. |
| What entered your tools | On | Extensions, global tools, PATH, git hooks and git settings. |
| Dev servers open to your network | On | Developer runtimes listening on every network. |
| Secrets left in the open | On | Keys, tokens and private keys. |
| Where it looks for secrets | All three | Your repositories, PowerShell and bash histories, Text and JSON files in Downloads. |
| More folders with repositories | None | A folder holding repositories, or one repository's folder, beyond what Castellan and Reeve know and the usual folders. Up to 30. |
| Projects it doesn't look at | None | Their names as the page shows them, or their folders. |
| A round every | 60 minutes | 15 minutes to a day. Run now runs one at any time. |
| Changes kept (Advanced) | 30 days | 7 to 365. A change it reported is let go after this long, unless you mark it seen sooner. What's still there, a secret or an open server, stays while it's there. |
Files#
All in %USERPROFILE%\.toller:
| File | What's in it |
|---|---|
settings.json | Its settings. |
state.json | The findings, the ones marked seen, the changes of the last rounds, the last round's outcome, and this PC's fingerprint key. |
baseline.json | What it saw at the last look, to tell what's new: each project's lockfiles, extensions, tools, PATH, hooks and git settings. |
cache.json | The files already read for secrets (their size, time, and what was found, by kind, line and fingerprint), so a round reads only what changed. |
server.json, serve.log | The running page's process, port and token, and its log. |
None of them holds a secret's value.
Commands#
Run with node $HOME\.toller\app\src\cli.ts <command>:
| Command | What it does |
|---|---|
run | One round now, and what it found: counts by kind, never a secret's value. |
findings | What's on the page now, by area: kind, where, and why. |
start | On duty: a round every hour, and its page up. Castellan's Start. |
stop | Off duty: no rounds. The page stays up. Castellan's Stop. |
open | Makes sure its page is up, without changing duty. |
shutdown | Ends its page's process. |
status | On duty or not. --json prints what Castellan reads. |
uninstall | Removes it and its sign-in task. --purge removes its data too; --dry-run says what it would do. |
It starts at sign-in from the scheduled task \Toller\Home page.
Local API#
At http://toller.localhost:21818/, answering only this PC:
| Address | What it answers |
|---|---|
GET /api/ping | Its version and duty, with busy (a round under way) and toLookAt (findings not marked seen). |
Its buttons, Seen and the fixes among them, need the token from its own page.
Related articles
Is this page right?
If something on it is wrong or out of date, tell us and we'll fix the page.
Still stuck? Write to support@castellan-software.com and mention article 1703. Every version of Toller, and what changed in it, is in its release notes.