Skip to content

Bind to HOST_BINDING instead of every interface - #101

Open
amedipiran wants to merge 1 commit into
PhialsBasement:mainfrom
amedipiran:fix/host-binding
Open

amedipiran wants to merge 1 commit into
PhialsBasement:mainfrom
amedipiran:fix/host-binding

Conversation

@amedipiran

Copy link
Copy Markdown

.env.example documents HOST_BINDING and EXTERNAL_PORT, but main.py ignored both and hardcoded 0.0.0.0:5000.

Combined with LOCAL_MODE=true, which disables authentication and grants admin access to every visitor, that puts an admin UI on the local network with no way to opt out. I hit this while setting up a local instance: I had HOST_BINDING=127.0.0.1 in .env, and the server was still reachable from another machine on the LAN with full admin rights.

This reads both variables and defaults to 127.0.0.1, so a local install is private unless asked otherwise. Docker users who rely on 0.0.0.0 set HOST_BINDING=0.0.0.0, which docker-compose.yml can pass through.

Happy to default to 0.0.0.0 instead and just honour the variable, if you would rather not change existing behaviour for people who expect network access. But the combination of "binds everywhere" and "no authentication" seemed worth defaulting to the safe side.

🤖 Generated with Claude Code

.env.example documents HOST_BINDING and EXTERNAL_PORT, but main.py ignored
both and hardcoded 0.0.0.0:5000. With LOCAL_MODE=true, which disables
authentication and grants admin access to every visitor, that exposes an
admin UI to the whole local network with no opt-out.

Defaults to 127.0.0.1 so a local install is private unless asked otherwise.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant