Getting started

Configuration

What the installer wrote for you, what to check once your site is live, and how to turn on spam protection for your login and registration forms.

Your configuration file

The installer writes a small configuration file holding your database connection details and a randomly generated security token. The token authenticates internal system callbacks — treat it like a password: never share it, and never commit it to a public code repository.

This file lives inside Zender's own application folders, which both shipped web-server configurations already block from direct browser access. Don't move or copy it anywhere inside your public-facing document root.

Site settings

The site name, description, purchase code, and protocol you entered on the installer form all become editable settings — you're not stuck with what you typed during installation. Change any of them later from the admin dashboard's system settings screens (Admin → Overview → System).

Timezone and currency

Two different things are called "timezone" in Zender, and it's worth telling them apart:

  • The timezone and country you chose on the installer form describe the admin account created at install time — not the system as a whole.
  • Separately, the system ships with site-wide defaults used for new accounts and date handling: Asia/Manila and the Philippines, out of the box.

Currency works the same way — the system ships defaulting to US Dollars. Update the timezone, country, and currency defaults from Admin → Overview → System to match your own deployment rather than leaving the shipped defaults in place.

Setting up reCAPTCHA

Zender can protect your login, registration, and password-reset forms with Google's reCAPTCHA v2 (the "I'm not a robot" checkbox), turned on from Admin → Overview → System.

  1. In Google's reCAPTCHA admin console, register a new site: give it a label, choose reCAPTCHA v2 ("I'm not a robot" checkbox), and add your domain.
  2. Copy the site key and secret key it gives you.
  3. Paste both into Admin → Overview → System, and set reCAPTCHA to Enable.
Turn this on only after you've pasted in both keys. If reCAPTCHA is enabled but either key is missing, login, registration, and password reset all stop working for every account on your site — not just new sign-ups — until you fix the keys or switch reCAPTCHA back off.