Say what guards the web UI, and warn only without Cloudflare Access (#106)
Every start logged WARN "web ui is reachable off this machine; the token is all that guards it". A container has to bind 0.0.0.0 for its port to be published, so it fired on every start of production, and it was out of date: signing in takes an account's password or the admin token, and through the tunnel Cloudflare Access. It was the only warning in a healthy log. Now it names what guards it, at info when Access is configured and a warning otherwise. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -23,6 +23,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
|||||||
|
|
||||||
### Changed
|
### Changed
|
||||||
|
|
||||||
|
- The start-up line about the web UI being reachable off the machine says what guards it, and is a warning only when there is no Cloudflare Access in front of it.
|
||||||
- The feed list updates just the feed that changed, as a scan checks it or you read an item, instead of reloading the whole list.
|
- The feed list updates just the feed that changed, as a scan checks it or you read an item, instead of reloading the whole list.
|
||||||
- A scan fetches several feeds at once, so a refresh no longer waits on every site in turn.
|
- A scan fetches several feeds at once, so a refresh no longer waits on every site in turn.
|
||||||
- An open page reloads the feed list only when a scan has checked something, not every minute.
|
- An open page reloads the feed list only when a scan has checked something, not every minute.
|
||||||
|
|||||||
16
src/main.rs
16
src/main.rs
@@ -619,8 +619,22 @@ async fn start_web(
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Bound beyond localhost, as a container has to be for its port to be published. Worth a
|
||||||
|
// warning only when nothing but a password stands in front of it: it said "the token is all
|
||||||
|
// that guards it" on every start of production, behind Cloudflare Access, and was the only
|
||||||
|
// warning in a healthy log (#106).
|
||||||
if ctx.cfg().web.binds_publicly() {
|
if ctx.cfg().web.binds_publicly() {
|
||||||
tracing::warn!(bind, "web ui is reachable off this machine; the token is all that guards it");
|
if ctx.cfg().web.access().is_some() {
|
||||||
|
tracing::info!(
|
||||||
|
bind,
|
||||||
|
"web ui is reachable off this machine; signing in takes an account's password or the admin token, or Cloudflare Access through a trusted proxy"
|
||||||
|
);
|
||||||
|
} else {
|
||||||
|
tracing::warn!(
|
||||||
|
bind,
|
||||||
|
"web ui is reachable off this machine; an account's password or the admin token is all that guards it"
|
||||||
|
);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
let access = Arc::new(access::Keys::default());
|
let access = Arc::new(access::Keys::default());
|
||||||
|
|||||||
Reference in New Issue
Block a user