diff options
| author | grm <grm@eyesin.space> | 2026-09-18 13:47:49 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-18 13:47:49 +0300 |
| commit | 3eeaa6d9a33f9294ade64c8ff26144fba86a379e (patch) | |
| tree | 1c4bf44884ea59f7e3d9ca12008846f08bf72d16 /.env.example | |
| parent | 254733b0566830a46e5a44c2d3127f57bfaceb65 (diff) | |
| download | blogspace-3eeaa6d9a33f9294ade64c8ff26144fba86a379e.tar.gz blogspace-3eeaa6d9a33f9294ade64c8ff26144fba86a379e.tar.bz2 blogspace-3eeaa6d9a33f9294ade64c8ff26144fba86a379e.zip | |
Security: Add HTTPS and TRUST_PROXY settings
The app only ever speaks plain HTTP, so it could not know the site was
served over TLS: generated links were http:// (the /webadmin bounce
from a blog host sent the login page over http), the session cookie
was never Secure and nothing sent HSTS. HTTPS=true fixes all three;
ClearSessionCookie now uses the same attributes as the set, since a
browser only replaces a cookie whose Secure flag matches.
TRUST_PROXY=true makes the client address the last X-Forwarded-For
entry — the one our proxy appended — so throttling and the log see
real addresses instead of the proxy's; earlier entries are whatever
the client sent and are ignored. Production startup warns when HTTPS
is off.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to '.env.example')
| -rw-r--r-- | .env.example | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/.env.example b/.env.example index ee6d25f..5d6908d 100644 --- a/.env.example +++ b/.env.example @@ -9,5 +9,9 @@ SUPERADMIN_USERNAME=admin SUPERADMIN_PASSWORD=change-me POSTGRES_PASSWORD=change-me-too MAX_UPLOAD_MB=10 +# The proxy in front terminates TLS: https:// links, Secure cookie, HSTS. +HTTPS=true +# The proxy sets X-Forwarded-For; use it for the client address (rate limits, log). +TRUST_PROXY=true # Only when running the dashboard on a non-standard port (dev): appended to generated blog links. #PUBLIC_PORT=8080 |
