The startup warning says the token is all that guards the web UI #106
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Every start logs WARN 'web ui is reachable off this machine; the token is all that guards it' (main.rs, binds_publicly). In the container ipx has to bind 0.0.0.0 for Docker's port mapping, so it fires on every start of a correct setup, and it is out of date: signing in takes an account's password or the admin token, and through the tunnel Cloudflare Access with a verified JWT from the trusted proxy (access_team, access_aud, trusted_proxies). It is the only WARN in a healthy production log, so every health check has to discount it. Wanted: say what actually guards it (accounts and token; Cloudflare Access when configured), at info when a trusted proxy or Access is set up.
Fixed in
ef5bdb4: the line names what guards the web UI (an account's password or the admin token, or Cloudflare Access through a trusted proxy) and is info when Access is configured, a warning otherwise. Production now logs it at INFO. Released in 0.9.1.