aboutsummaryrefslogtreecommitdiffstats
path: root/.env.example
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:47:49 +0300
committergrm <grm@eyesin.space>2026-09-18 13:47:49 +0300
commit3eeaa6d9a33f9294ade64c8ff26144fba86a379e (patch)
tree1c4bf44884ea59f7e3d9ca12008846f08bf72d16 /.env.example
parent254733b0566830a46e5a44c2d3127f57bfaceb65 (diff)
downloadblogspace-3eeaa6d9a33f9294ade64c8ff26144fba86a379e.tar.gz
blogspace-3eeaa6d9a33f9294ade64c8ff26144fba86a379e.tar.bz2
blogspace-3eeaa6d9a33f9294ade64c8ff26144fba86a379e.zip
Security: Add HTTPS and TRUST_PROXY settings
The app only ever speaks plain HTTP, so it could not know the site was served over TLS: generated links were http:// (the /webadmin bounce from a blog host sent the login page over http), the session cookie was never Secure and nothing sent HSTS. HTTPS=true fixes all three; ClearSessionCookie now uses the same attributes as the set, since a browser only replaces a cookie whose Secure flag matches. TRUST_PROXY=true makes the client address the last X-Forwarded-For entry — the one our proxy appended — so throttling and the log see real addresses instead of the proxy's; earlier entries are whatever the client sent and are ignored. Production startup warns when HTTPS is off. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to '.env.example')
-rw-r--r--.env.example4
1 files changed, 4 insertions, 0 deletions
diff --git a/.env.example b/.env.example
index ee6d25f..5d6908d 100644
--- a/.env.example
+++ b/.env.example
@@ -9,5 +9,9 @@ SUPERADMIN_USERNAME=admin
SUPERADMIN_PASSWORD=change-me
POSTGRES_PASSWORD=change-me-too
MAX_UPLOAD_MB=10
+# The proxy in front terminates TLS: https:// links, Secure cookie, HSTS.
+HTTPS=true
+# The proxy sets X-Forwarded-For; use it for the client address (rate limits, log).
+TRUST_PROXY=true
# Only when running the dashboard on a non-standard port (dev): appended to generated blog links.
#PUBLIC_PORT=8080