Quellcode durchsuchen

docs: note the form password cookie is not marked Secure

The session cookie the password gate issues has no Secure attribute. That is
deliberate - the form is meant to work over plain HTTP on a LAN with no
certificate - but it means the cookie would still travel over plain HTTP
even when an HTTPS reverse proxy sits in front of the webserver. Documented
as a real deployment constraint to plan around rather than something the
form handles automatically.
fszontagh vor 1 Monat
Ursprung
Commit
fa5ff68a65
1 geänderte Dateien mit 7 neuen und 0 gelöschten Zeilen
  1. 7 0
      docs/nodes.md

+ 7 - 0
docs/nodes.md

@@ -397,6 +397,13 @@ decryption involved. It is a gate against a link being forwarded somewhere it
 shouldn't go, not a secret and not a security boundary. Do not rely on it to
 keep a form private from someone who already has access to the workspace.
 
+The session cookie itself is also not marked `Secure`. That is deliberate -
+this is meant to work for a plain-HTTP LAN deployment with no certificate at
+all - but it means the cookie would be sent over plain HTTP even when an
+HTTPS reverse proxy sits in front of the webserver. Deploying behind such a
+proxy is a real constraint to plan around, not something this form handles
+for you.
+
 ### No captcha
 
 There is no captcha and no rate limiting on the form endpoint beyond the