Skip to content

Configuration

All options live in config/imagepresets.php (publish it with php artisan vendor:publish --tag=imagepresets-config). Keys without an env variable are changed in the file.

KeyEnvDefaultDescription
route.prefixIMAGEPRESET_ROUTE_PREFIXimagepresetURL path of the endpoint, without leading slash
route.nameIMAGEPRESET_ROUTE_NAMEimagepresetRoute name used by the helper, facade and Blade directive
route.middlewareIMAGEPRESET_THROTTLE['throttle:2400,1']Middleware of the route. The env variable sets the single default entry; edit the array to add more
route.signedIMAGEPRESET_SIGNED_URLfalseGenerate signed URLs and add the signed middleware, see Signed URLs

The route is registered when the application boots, so changing route.* at runtime (e.g. in a service provider’s boot() after the package) has no effect on the route itself. The route has no web middleware: no session, no cookies, no CSRF.

KeyEnvDefaultDescription
diskIMAGEPRESET_DISKpublicFilesystem disk for generated images
pathIMAGEPRESET_PATH''Subdirectory inside the disk. Empty — the root of the disk
remote_redirectIMAGEPRESET_REMOTE_REDIRECTfalseOn a remote disk, redirect to temporaryUrl() instead of streaming the file through PHP
remote_redirect_ttlIMAGEPRESET_REMOTE_REDIRECT_TTL300Lifetime of the presigned URL, seconds
local_cache_dir—storage/app/imagepreset_glide_cacheWhere Glide writes the result before it is uploaded to a remote disk. Not used for local disks
source_dir—storage/app/imagepreset_sourcesWorking copies of source images and downloaded remote images
temp_dir—storage/app/imagepreset_tempGlide’s temporary directory

A disk counts as local when its driver in config/filesystems.php is local; anything else is remote. Details — Storage disks.

KeyEnvDefaultDescription
driverIMAGEPRESET_DRIVER, then IMAGE_DRIVERgdgd or imagick
quality—80Quality when the request has no q
format—webpOutput format when the request has no fm
default_fit_both—fillfit when both w and h are given and fit is not
default_fit_one—maxfit when only w or only h is given
verify_decodeIMAGEPRESET_VERIFY_DECODEfalseDecode every generated webp with GD and reject damaged output before it is cached, see Cache maintenance

driver reads IMAGEPRESET_DRIVER first and falls back to the project-wide IMAGE_DRIVER (also used by spatie/laravel-medialibrary and others). See Drivers & formats.

KeyDefaultDescription
allowed_sizes[[300, 200], [600, 400], [1200, 800]][w, h] pairs allowed when both are given
allowed_widths[100, 200, 300, 400, 600, 800, 1000, 1200, 1600]Widths allowed when only w is given
allowed_heights[100, 200, 300, 400, 600, 800]Heights allowed when only h is given
allowed_qualities[50, 60, 70, 80, 90, 100]Allowed q
allowed_fits['contain', 'crop', 'fill', 'fill-max', 'max', 'stretch']Allowed fit
allowed_formats['webp', 'jpg', 'png', 'gif']Allowed fm. avif is not in the default list
allowed_orientations['auto', '0', '90', '180', '270']Allowed or
blur_max100Maximum blur
sharp_max100Maximum sharp

allowed_sizes, allowed_widths, allowed_heights and allowed_qualities accept the wildcard ['*']. allowed_fits and allowed_formats don’t. Details — Allowlists & audit log.

KeyDefaultDescription
presets[] (examples commented out)Named parameter sets, see Named presets
KeyDefaultDescription
allowed_hosts[]Hosts allowed in a remote src, exact match. The host of APP_URL is always allowed
max_download_bytes20971520 (20 MB)Maximum size of a downloaded remote image
max_image_pixels150000000Maximum width × height of a source image, local or remote. 0 — no limit

Details — Image sources.

KeyDefaultDescription
svg.sanitizetrueSanitize SVG before caching
svg.remove_remote_referencestrueStrip external references; used only with enshrined/svg-sanitize
svg.rasterizefalseConvert SVG to raster when w, h or fm is given. Needs driver = imagick

Details — SVG.

KeyEnvDefaultDescription
cache_max_ageIMAGEPRESET_CACHE_MAX_AGE31536000max-age and s-maxage of served images, seconds

Details — HTTP caching & CDN.

KeyEnvDefaultDescription
backend_url_enabledIMAGEPRESET_BACKEND_URL_ENABLEDtruefalse — the helper, facade and Blade directive return src unchanged. The endpoint keeps working
trusted_bypassIMAGEPRESET_TRUSTED_BYPASSfalseLet backend-generated URLs skip the allowlists, see Trusted bypass
KeyEnvDefaultDescription
audit_log.enabledIMAGEPRESET_AUDIT_LOGfalseLog the parameters of every valid request to the default log channel
audit_log.only_newIMAGEPRESET_AUDIT_LOG_ONLY_NEWtrueLog only requests whose image is not cached yet

Details — Allowlists & audit log.

There is no config key for it, but it matters: while an image is generated the package holds Cache::lock('imagepreset:<file>', 30) and waits up to 15 seconds for it, so concurrent first requests for the same image generate it once. A request that can’t get the lock in 15 seconds gets 503.

The lock uses the default cache store. It must support atomic locks and be shared by every app server: Redis, Memcached, database or DynamoDB. The file store locks only within one server, array only within one process.