From 3eeaa6d9a33f9294ade64c8ff26144fba86a379e Mon Sep 17 00:00:00 2001 From: grm Date: Fri, 18 Sep 2026 13:47:49 +0300 Subject: Security: Add HTTPS and TRUST_PROXY settings MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The app only ever speaks plain HTTP, so it could not know the site was served over TLS: generated links were http:// (the /webadmin bounce from a blog host sent the login page over http), the session cookie was never Secure and nothing sent HSTS. HTTPS=true fixes all three; ClearSessionCookie now uses the same attributes as the set, since a browser only replaces a cookie whose Secure flag matches. TRUST_PROXY=true makes the client address the last X-Forwarded-For entry — the one our proxy appended — so throttling and the log see real addresses instead of the proxy's; earlier entries are whatever the client sent and are ignored. Production startup warns when HTTPS is off. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A --- cmd/blogspace/main.go | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) (limited to 'cmd') diff --git a/cmd/blogspace/main.go b/cmd/blogspace/main.go index 20e6ffe..26689bc 100644 --- a/cmd/blogspace/main.go +++ b/cmd/blogspace/main.go @@ -172,7 +172,10 @@ func serve(ctx context.Context, cfg *config.Config, st *store.Store) error { } errc := make(chan error, 1) go func() { errc <- srv.ListenAndServe() }() - log.Printf("listening on %s — dashboard at %s, blogs at http://.%s (dev=%v)", cfg.Addr, cfg.RootURL(), cfg.HostWithPort(), cfg.Dev) + if !cfg.Dev && !cfg.HTTPS { + log.Printf("warning: HTTPS is off — the session cookie is not Secure and links are http://; set HTTPS=true behind a TLS proxy") + } + log.Printf("listening on %s — dashboard at %s, blogs at %s://.%s (dev=%v)", cfg.Addr, cfg.RootURL(), cfg.Scheme(), cfg.HostWithPort(), cfg.Dev) select { case err := <-errc: return err -- cgit v1.2.3