Repository navigation
Bind to HOST_BINDING instead of every interface - #101
Open
amedipiran wants to merge 1 commit into
Open
amedipiran wants to merge 1 commit into
amedipiran wants to merge 1 commit into
Conversation
.env.example documents HOST_BINDING and EXTERNAL_PORT, but main.py ignored both and hardcoded 0.0.0.0:5000. With LOCAL_MODE=true, which disables authentication and grants admin access to every visitor, that exposes an admin UI to the whole local network with no opt-out. Defaults to 127.0.0.1 so a local install is private unless asked otherwise.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
.env.exampledocumentsHOST_BINDINGandEXTERNAL_PORT, butmain.pyignored both and hardcoded0.0.0.0:5000.Combined with
LOCAL_MODE=true, which disables authentication and grants admin access to every visitor, that puts an admin UI on the local network with no way to opt out. I hit this while setting up a local instance: I hadHOST_BINDING=127.0.0.1in.env, and the server was still reachable from another machine on the LAN with full admin rights.This reads both variables and defaults to
127.0.0.1, so a local install is private unless asked otherwise. Docker users who rely on0.0.0.0setHOST_BINDING=0.0.0.0, whichdocker-compose.ymlcan pass through.Happy to default to
0.0.0.0instead and just honour the variable, if you would rather not change existing behaviour for people who expect network access. But the combination of "binds everywhere" and "no authentication" seemed worth defaulting to the safe side.🤖 Generated with Claude Code