docs(security): exposing TeamWork safely — Tailscale vs ngrok, and who can open your files - #76
Merged
Merged
Conversation
…who can open your files A public tunnel (ngrok, tailscale funnel) in front of TeamWork without INTERNAL_API_KEY publishes every workspace file, the chat, the shared terminal and the live browser to the internet; a random tunnel URL is obscurity, not access control. New docs/security/exposure.md: tailscale serve recommended, the key required before any public exposure, and what it means for chat file links (relative, so they work on any address; they carry the SameSite=Strict session cookie, so images still embed; a copied link needs a login). The README's auth note said the internal API has no authentication; with INTERNAL_API_KEY set, /api and the websockets do require it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
New
docs/security/exposure.mdand a corrected README auth note./api/workspace/…/download), so they resolve against whatever address TeamWork was opened at: tailnet, localhost or tunnel.INTERNAL_API_KEY, a public tunnel publishes everything. Every workspace file (through the file API, not only chat links), the chat, the terminal and the live browser. A random ngrok URL is obscurity, not access control.tailscale serveis recommended. A public tunnel requires the key. With it set, chat images still embed (the session cookie isSameSite=Strictand same-origin), and a copied link needs a login./apiand websockets do require it (checked ininternal_auth.py: 401 for HTTP, a close code for websockets).