|
|
@@ -397,6 +397,13 @@ decryption involved. It is a gate against a link being forwarded somewhere it
|
|
|
shouldn't go, not a secret and not a security boundary. Do not rely on it to
|
|
|
keep a form private from someone who already has access to the workspace.
|
|
|
|
|
|
+The session cookie itself is also not marked `Secure`. That is deliberate -
|
|
|
+this is meant to work for a plain-HTTP LAN deployment with no certificate at
|
|
|
+all - but it means the cookie would be sent over plain HTTP even when an
|
|
|
+HTTPS reverse proxy sits in front of the webserver. Deploying behind such a
|
|
|
+proxy is a real constraint to plan around, not something this form handles
|
|
|
+for you.
|
|
|
+
|
|
|
### No captcha
|
|
|
|
|
|
There is no captcha and no rate limiting on the form endpoint beyond the
|