aboutsummaryrefslogtreecommitdiffstats
path: root/AGENTS.md
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 13:47:49 +0300
committergrm <grm@eyesin.space>2026-09-18 13:47:49 +0300
commit3eeaa6d9a33f9294ade64c8ff26144fba86a379e (patch)
tree1c4bf44884ea59f7e3d9ca12008846f08bf72d16 /AGENTS.md
parent254733b0566830a46e5a44c2d3127f57bfaceb65 (diff)
downloadblogspace-3eeaa6d9a33f9294ade64c8ff26144fba86a379e.tar.gz
blogspace-3eeaa6d9a33f9294ade64c8ff26144fba86a379e.tar.bz2
blogspace-3eeaa6d9a33f9294ade64c8ff26144fba86a379e.zip
Security: Add HTTPS and TRUST_PROXY settings
The app only ever speaks plain HTTP, so it could not know the site was served over TLS: generated links were http:// (the /webadmin bounce from a blog host sent the login page over http), the session cookie was never Secure and nothing sent HSTS. HTTPS=true fixes all three; ClearSessionCookie now uses the same attributes as the set, since a browser only replaces a cookie whose Secure flag matches. TRUST_PROXY=true makes the client address the last X-Forwarded-For entry — the one our proxy appended — so throttling and the log see real addresses instead of the proxy's; earlier entries are whatever the client sent and are ignored. Production startup warns when HTTPS is off. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'AGENTS.md')
-rw-r--r--AGENTS.md5
1 files changed, 4 insertions, 1 deletions
diff --git a/AGENTS.md b/AGENTS.md
index 406c621..4f5e893 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -45,6 +45,8 @@ table and deployment notes.
and `HttpOnly`, management POSTs need the HMAC `_csrf` token, and the
base-domain blog is only editable by the superadmin.
- App runs plain HTTP behind a reverse proxy; auth is a JWT cookie.
+ `HTTPS=true` tells it the proxy has TLS (https links, `Secure` cookie,
+ HSTS); `TRUST_PROXY=true` that `X-Forwarded-For`'s last entry is the client.
- Stdlib `net/http` ServeMux with method+pattern routes. No router library.
## Layout
@@ -138,7 +140,8 @@ internal/web/ server.go (host router, middleware, render helpers)
minute each), answered with 429 by `s.throttle` and a log line; failed
logins are logged with the username and address, and the login body is
capped at `maxLoginBody` (64 KB) since it is the one POST outside
- `guardPOST`. Flood
+ `guardPOST`. `s.clientIP` is the peer address, or the last
+ `X-Forwarded-For` hop with `TRUST_PROXY` (earlier entries are forgeable). Flood
control for everything else stays at the reverse proxy (`limit_req`).
- **Templates**: each page file is parsed together with its layout
(`layouts/dashboard.html` or `layouts/blog.html` for `blog/*`) and all