From ef5bdb424420bda23113b75e09438c7f3f1ebad3 Mon Sep 17 00:00:00 2001 From: rays Date: Tue, 29 Sep 2026 20:46:43 +0000 Subject: [PATCH] Say what guards the web UI, and warn only without Cloudflare Access (#106) Every start logged WARN "web ui is reachable off this machine; the token is all that guards it". A container has to bind 0.0.0.0 for its port to be published, so it fired on every start of production, and it was out of date: signing in takes an account's password or the admin token, and through the tunnel Cloudflare Access. It was the only warning in a healthy log. Now it names what guards it, at info when Access is configured and a warning otherwise. Co-Authored-By: Claude Opus 5.5 --- CHANGELOG.md | 1 + src/main.rs | 16 +++++++++++++++- 2 files changed, 16 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index bf900ca..2e9f9d5 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -23,6 +23,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Changed +- The start-up line about the web UI being reachable off the machine says what guards it, and is a warning only when there is no Cloudflare Access in front of it. - The feed list updates just the feed that changed, as a scan checks it or you read an item, instead of reloading the whole list. - A scan fetches several feeds at once, so a refresh no longer waits on every site in turn. - An open page reloads the feed list only when a scan has checked something, not every minute. diff --git a/src/main.rs b/src/main.rs index d73303b..ee5d804 100644 --- a/src/main.rs +++ b/src/main.rs @@ -619,8 +619,22 @@ async fn start_web( ); } + // Bound beyond localhost, as a container has to be for its port to be published. Worth a + // warning only when nothing but a password stands in front of it: it said "the token is all + // that guards it" on every start of production, behind Cloudflare Access, and was the only + // warning in a healthy log (#106). if ctx.cfg().web.binds_publicly() { - tracing::warn!(bind, "web ui is reachable off this machine; the token is all that guards it"); + if ctx.cfg().web.access().is_some() { + tracing::info!( + bind, + "web ui is reachable off this machine; signing in takes an account's password or the admin token, or Cloudflare Access through a trusted proxy" + ); + } else { + tracing::warn!( + bind, + "web ui is reachable off this machine; an account's password or the admin token is all that guards it" + ); + } } let access = Arc::new(access::Keys::default());