Skip to content

docs(security): exposing TeamWork safely — Tailscale vs ngrok, and who can open your files - #76

Merged
praxagent merged 1 commit into
mainfrom
docs/exposure
Sep 28, 2026
Merged

praxagent merged 1 commit into
mainfrom
docs/exposure

Conversation

@praxagent

Copy link
Copy Markdown
Owner

New docs/security/exposure.md and a corrected README auth note.

  • File links work on any address. Agents post relative links (/api/workspace/…/download), so they resolve against whatever address TeamWork was opened at: tailnet, localhost or tunnel.
  • Without INTERNAL_API_KEY, a public tunnel publishes everything. Every workspace file (through the file API, not only chat links), the chat, the terminal and the live browser. A random ngrok URL is obscurity, not access control.
  • tailscale serve is recommended. A public tunnel requires the key. With it set, chat images still embed (the session cookie is SameSite=Strict and same-origin), and a copied link needs a login.
  • README fix: it said the internal API has no authentication; with the key set, /api and websockets do require it (checked in internal_auth.py: 401 for HTTP, a close code for websockets).

…who can open your files

A public tunnel (ngrok, tailscale funnel) in front of TeamWork without
INTERNAL_API_KEY publishes every workspace file, the chat, the shared terminal
and the live browser to the internet; a random tunnel URL is obscurity, not
access control. New docs/security/exposure.md: tailscale serve recommended,
the key required before any public exposure, and what it means for chat file
links (relative, so they work on any address; they carry the SameSite=Strict
session cookie, so images still embed; a copied link needs a login).

The README's auth note said the internal API has no authentication; with
INTERNAL_API_KEY set, /api and the websockets do require it.
@praxagent
praxagent merged commit 737947a into main Sep 28, 2026
2 checks passed
@praxagent
praxagent deleted the docs/exposure branch September 28, 2026 05:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant