Skip to content

Tool settings

Turn WordPress debug mode, password protection, Set-Cookie stripping, and ionCube on or off, clear the server cache, restart PHP, and preview a site.

The Tools tab holds the switches and actions you reach for when something needs a quick fix: debug mode, password protection, cache clearing, a PHP restart, and a site preview on the temporary domain. Open the site, then Tools.

Open it

  1. Open a site and pick the environment in the top bar.
  2. Choose Tools.

Every change on this tab runs as a job, and the dashboard shows the progress.

Switch a setting on or off

Four settings are switches:

  • WordPress debug mode: turn WordPress debugging on while you track down a problem, and off again when you are done.
  • Password protection: ask visitors for a password before they can see the site. It is off until you turn it on, and Avaloi stores only a hash of the password. It suits staging and multidev environments you share with a client. It does not affect Git, which signs in with SSH keys or access tokens. See Staging privacy.
  • Strip Set-Cookie: Avaloi never caches a response that sets a cookie. If a plugin sets a cookie on every page and you want those pages cached, turn this on to strip the Set-Cookie header from cached responses. See Edge cache and CDN.
  • ionCube Loader: turn on the loader when a plugin or theme is encoded with ionCube and needs it.

Click Enable or Disable on the card. Each change is one job. The cards show no status label: an Enable button means the tool is off, and Disable (with Modify where there is a setting) means it is on. Every action button on Tools has the same size.

Redirects, IP deny, and APM

Three more cards switch a whole feature off or on without losing anything:

  • Redirects: stops every redirect rule at once and keeps the rules saved. The rules are on the Redirects page in the sidebar. See Redirects.
  • IP deny: stops blocking the addresses on your list and keeps the list saved. The list is the IP deny tab at the top of Tools. IP deny works on the live environment. See IP deny.
  • APM: Enable asks how long APM runs. Disabling stops collection, and the data already collected stays for 7 days. The APM page in the sidebar uses the same switch. See APM.

One rule for all three: while a tool is off, its sidebar item (or, for IP deny, its tab at the top of Tools) is hidden for that environment, and it comes back as soon as you turn the tool on. A bookmark to a page that is off still opens it, with a sentence that it is off and an Enable button.

Only members who may manage the edge (redirects and IP deny) or change the environment (APM) see Enable and Disable. Everyone else sees the state.

One click WordPress login

The One click WordPress login card switches the Log in to WP Admin button on or off for this environment. Each click of that button makes a link that works once for 60 seconds. Turn it off when every WordPress sign-in should go through the WordPress login form with a password, for example for a security plugin's two-factor check.

While it is off, the button leaves the Info tab and the WordPress users list, Avaloi makes no login links, links made before stop working, and Visit WP login still opens the WordPress login page. It works the same on live, because it changes no code. It has no sidebar item. Members who may run tools see Enable and Disable. See WP Admin login.

Clear the server cache

Clear the server cache after a change that did not show up on the site. The action runs as a job. You can also clear it from a site's row in the Sites list, or on many sites at once.

To clear the edge cache and the server cache together, use Clear cache on the Caching tab.

Restart PHP

Restart PHP when the site hangs or a PHP setting needs a fresh start. The restart runs as a job. The Sites list row menu has the same action.

Force HTTPS

Force HTTPS sends visitors from HTTP to HTTPS. Choose Modify and pick a mode:

  • All domains: every domain of the environment redirects to HTTPS, including the temporary domain.
  • Primary domain only: the primary domain redirects to HTTPS, and your other domains go to the primary domain. The temporary domain is left alone, so it keeps working for checks and previews.
  • Disabled: visitors can still open the site over HTTP.

The HTTPS redirect runs at Cloudflare. In "Primary domain only" mode, the move from your other domains to the primary runs on your site's web server, so it does not use up the shared Cloudflare rules.

Geolocation

Geolocation passes each visitor's country, and city when Cloudflare knows it, to PHP. Plugins read them from $_SERVER:

  • GEOIP_COUNTRY_CODE and HTTP_X_AVALOI_COUNTRY: the two letter country code, such as US.
  • GEOIP_CITY and HTTP_X_AVALOI_CITY: the city name.
  • GEOIP_REGION and HTTP_X_AVALOI_REGION_CODE: the region code, such as CA. HTTP_X_AVALOI_REGION holds the region name.
  • GEOIP_POSTAL_CODE and HTTP_X_AVALOI_POSTAL_CODE: the postal code. GEOIP_LATITUDE, GEOIP_LONGITUDE, and HTTP_X_AVALOI_TIMEZONE hold the rest.

A value Cloudflare does not know is empty, so treat an empty value as unknown. Names with accents arrive as UTF-8 text.

The country always comes from Cloudflare. The city, region, and the other details come only when the Cloudflare setting Add visitor location headers is on for the avaloi.com zone. Avaloi cannot turn it on for you. If it is off, the Geolocation card shows a note with these steps: in the Cloudflare dashboard open the avaloi.com zone, then Rules, then Settings (Managed Transforms), and turn on Add visitor location headers. Use the city as a hint and not as proof of where a person is, because it is an estimate from the visitor's IP address.

Cached pages are shared by every country, so a plugin that changes a whole page by country should exclude that page from the cache on the Caching tab, or change the page in the browser.

Site preview

Site preview lets you test the site on its temporary domain before you change DNS records or the database. Choose Enable, pick how long it stays on (one hour to seven days), and copy the preview link from the card. Preview turns itself off after that time.

While preview is on, WordPress uses the temporary domain as its address for requests to that domain, and links in the page point to it. Nothing in the database changes. Search engines are told not to index the preview, and password protection, when it is on, applies to the preview too.

Early Hints

Early Hints lets the browser start loading your stylesheets before the page arrives. With it on, your site sends a Link preload header for the stylesheets your home page uses, and Cloudflare answers with a 103 Early Hints response. Cloudflare's Early Hints setting is shared by every Avaloi site and stays on; this switch decides whether your site sends the hints.

What runs where

Every change on these four cards is one job. It writes the setting at Cloudflare and on your site's server. If the server needs an update or Cloudflare could not confirm a setting, the Tools tab shows a note under the cards.

Limits

  • Site preview stays on for one hour to seven days, then turns itself off.

Quick answers

I turned on debug mode. Where do the errors go? Read error.log on the Logs tab.

Clearing the cache did not change the page I see. The edge cache may still hold it. Use Clear cache on the Caching tab to purge both, or purge the one URL.

Why would I strip Set-Cookie? A page that sets a cookie is never cached. Stripping the header lets Avaloi cache those pages. Leave it off if the cookie matters to your visitors.

How do I know a preview is on? The Site Preview card says "Active until" and shows the link. Responses on the temporary domain carry x-avaloi-preview: active.

My plugin does not see the country. Check that the Geolocation card offers Disable (so it is on) and that the page did not come from the cache. The city can be empty when Cloudflare does not know it.

API

  • PATCH /v1/environments/{id}/tools/settings
  • POST /v1/environments/{id}/tools/cache/clear
  • POST /v1/environments/{id}/tools/php/restart
  • PUT /v1/environments/{id}/tools/site-preview
  • PUT /v1/environments/{id}/tools/auto-login
  • GET /v1/environments/{id}/edge/settings
  • PUT /v1/environments/{id}/edge/settings

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.