Uploaded image for project: 'James Server'
  1. James Server
  2. JAMES-3690

Allow to restrict the host webadmin is listening on

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 3.7.0
    • webadmin
    • None

    Description

      By default the WebAdmin server is activated, listens on all addresses without JWT security activated by default. This of course represents an open door for unaware users, failing to setup decent firewalling.

      There is a `host` option, set to localhost by default, that can provide a false sens of safety - however this is not applied.

      The proposal here is:

      • To use the host option to limit interfaces the webadmin server listens on
      • Ship a sample configuration listening on localhost thus preventing external use
      • Ship 0.0.0.0 for docker as port exposure is required (we can expect the admin to know what he is doing)

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              btellier Benoit Tellier
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 10m
                  10m