Fold for Craft CMS

Configuration

Every setting lives under Fold → Settings, and can also be set in config/fold.php like any Craft plugin. None of them is required: a fresh install has a working locator — free map, free geocoder — before anybody opens the settings screen.

Two are worth changing before launch: Default country, which biases every search, and — on a busy site — Geocoding provider.

Map

SettingConfig keyDefaultWhat it does
Map providermapDriverleafletleaflet, google (Pro) or mapbox (Pro)
Tile URLleafletTileUrlOpenStreetMap's tilesLeaflet's tile URL template
AttributionleafletAttributionOpenStreetMap creditShown on the map. OpenStreetMap's tiles require it.
Google Maps API keygoogleApiKey—The browser key that draws a Google map. Public; restrict it by HTTP referrer.
Mapbox access tokenmapboxAccessToken—Used by the Mapbox map and the Mapbox geocoder. Must be a public pk. token — an sk. token is rejected, because this one is sent to the browser.
—leafletJsUrl, leafletCssUrlthe bundled copyLoad Leaflet from somewhere else. Config file only.
—leafletClusterJsUrl, leafletClusterCssUrl, leafletClusterDefaultCssUrlthe bundled copyLoad Leaflet.markercluster (and its two stylesheets — the second is the default bubble styling) from somewhere else. Config file only; only used when clustering is on.

Geocoding

SettingConfig keyDefaultWhat it does
Geocoding providergeocoderDrivernominatimnominatim, google (Pro), mapbox (Pro) or none
Google Geocoding API keygoogleGeocodingApiKey—The server key used for Google geocoding; never sent to a browser. Restrict it by IP. Blank falls back to the map key.
Look up coordinates automaticallyautoGeocodeOnQueue a lookup when a location's address changes
Cache lookups forgeocodeCacheDuration2592000 (30 days)Seconds. 0 turns the cache off.
User agentgeocoderUserAgentbuilt from the siteSent to Nominatim, which blocks requests without one

Searching

SettingConfig keyDefaultWhat it does
Distance unitdistanceUnitmimi or km, everywhere Fold shows a distance
Default radiusdefaultRadius25Used when a search does not give one
Radius optionsradiusOptions[5, 10, 25, 50, 100]What the built-in radius select offers. With one option, the select is hidden.
Results per searchdefaultLimit25Page size when a search does not give one
Maximum resultsmaxLimit200Ceiling on limit, however large a public request asks for
Searches per visitor per minutesearchRateLimit30Per IP address. Over it, the JSON endpoint answers 429, and front-end searches stop sending new terms to the geocoder. 0 turns it off — for a site that rate-limits at its CDN.
Ask for the visitor's locationrequestBrowserLocationOffPrompt for the browser's position as soon as the map loads
Cluster markersclusterMarkersOnPro, Leaflet maps only. Overlapping pins are grouped into numbered bubbles with the bundled Leaflet.markercluster, which is only loaded when this is on. Google and Mapbox maps ignore it and show every pin.
Record searcheslogSearchesOffPro. Keep a log of searches; see Search and radius
Keep searches forsearchLogRetentionDays90Pro. Days a search log row is kept; older rows are deleted by Craft's garbage collection. 0 keeps them forever.
Publish exact stock countsexposeStockLevelsOffPro + Commerce. Adds availableStock to stock searches on the JSON endpoint; off, only inStock is published. See Commerce stock.

Defaults

SettingConfig keyDefaultWhat it does
Default countrydefaultCountryCodeUSBiases search geocoding, and is the starting country for new addresses (a group can override the latter)
Map centredefaultLat, defaultLng39.8283, -98.5795Where the map sits before there are results — the middle of the continental US
ZoomdefaultZoom4The zoom that goes with it

config/fold.php

<?php

return [
    'mapDriver' => 'google',
    'geocoderDriver' => 'google',
    'googleApiKey' => '$GOOGLE_MAPS_BROWSER_KEY',     // referrer-restricted
    'googleGeocodingApiKey' => '$GOOGLE_GEOCODING_KEY', // IP-restricted

    'distanceUnit' => 'km',
    'defaultRadius' => 40,
    'radiusOptions' => [10, 25, 40, 80],
    'defaultCountryCode' => 'GB',
    'defaultLat' => 54.0,
    'defaultLng' => -2.5,
    'defaultZoom' => 5,
];

The three key settings — googleApiKey, googleGeocodingApiKey and mapboxAccessToken — resolve environment variables, so '$GOOGLE_MAPS_BROWSER_KEY' (here, or typed into the settings screen) reads the value from .env and keeps the key itself out of project files. App::env() works too.

Settings in config/fold.php win over the control panel, and can be set per environment in the usual way — Nominatim and no logging in development, a paid provider in production.

Keys and the page source

The map key is necessarily public: a browser cannot draw a Google or Mapbox map without it. Fold writes only the key the chosen map provider needs into the page, so a Mapbox token never appears on a site that renders Google maps. Restrict the Google map key to your domains (HTTP referrers) in the Google Cloud console, and a Mapbox token to your URLs in the Mapbox account.

Geocoding requests come from your server, not a browser, and a key restricted to HTTP referrers will refuse them. That is why Google has two settings: give Google Geocoding API key its own key, restricted to your server's IP, and it is never written into a page. Left blank, geocoding falls back to the map key, which then has to be unrestricted — and an unrestricted key in page source is somebody else's free Geocoding API.