From 3eeaa6d9a33f9294ade64c8ff26144fba86a379e Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:47:49 +0300 Subject: Security: Add HTTPS and TRUST_PROXY settings MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The app only ever speaks plain HTTP, so it could not know the site was served over TLS: generated links were http:// (the /webadmin bounce from a blog host sent the login page over http), the session cookie was never Secure and nothing sent HSTS. HTTPS=true fixes all three; ClearSessionCookie now uses the same attributes as the set, since a browser only replaces a cookie whose Secure flag matches. TRUST_PROXY=true makes the client address the last X-Forwarded-For entry — the one our proxy appended — so throttling and the log see real addresses instead of the proxy's; earlier entries are whatever the client sent and are ignored. Production startup warns when HTTPS is off. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- .env.example | 4 ++++ 1 file changed, 4 insertions(+) (limited to '.env.example') diff --git a/.env.example b/.env.example index ee6d25f..5d6908d 100644 --- a/.env.example +++ b/.env.example @@ -9,5 +9,9 @@ SUPERADMIN_USERNAME=admin SUPERADMIN_PASSWORD=change-me POSTGRES_PASSWORD=change-me-too MAX_UPLOAD_MB=10 +# The proxy in front terminates TLS: https:// links, Secure cookie, HSTS. +HTTPS=true +# The proxy sets X-Forwarded-For; use it for the client address (rate limits, log). +TRUST_PROXY=true # Only when running the dashboard on a non-standard port (dev): appended to generated blog links. #PUBLIC_PORT=8080 -- cgit v1.2.3