Security Audit Fixes: Session fixation prevention, SameSite cookies, audit log redaction, backup integrity, Docker hardening, error sanitization, rate limiting, trusted proxies, and config hardening

This commit is contained in:
backup 2026-09-03 23:55:25 -05:00
commit b587fb87a9
18 changed files with 987 additions and 87 deletions

33
.env.example Normal file
View file

@ -0,0 +1,33 @@
# Environment variables for Traefik GUI
# See README.md for detailed setup instructions
# Required - Session signing secret (32+ characters, random)
# Generate with: openssl rand -hex 32
GUI_SESSION_SECRET=CHANGE_THIS_TO_A_32_CHARACTER_RANDOM_SECRET
# Required - Admin password (minimum 12 characters for production)
# This is hashed on startup; change to your preferred password
GUI_ADMIN_PASSWORD=changeme
# Frontend CORS origin (must match the URL you'll use to access the GUI)
GUI_CORS_ORIGIN=http://localhost:5173
# Server address
GUI_ADDR=:8080
# Development mode: set to "true" for local dev (enables dev-mode cookie behavior), "false" for production
GUI_DEV_MODE=false
# Traefik API URL (read-only; leave empty or set to http://localhost:8080/api for mock mode)
# Set to a real Traefik instance URL to enable read-only API features
TRAEFIK_API_URL=http://localhost:8080/api
# SQLite database path (relative to binary location; defaults to ./data/traefik-gui.db)
GUI_DB_PATH=./data/traefik-gui.db
# Config directory for Traefik dynamic config (must be under configs/)
GUI_CONFIG_DIR=./configs/dynamic
# Trusted proxies for X-Forwarded-For header parsing (comma-separated IPs or CIDR ranges, e.g., "10.0.0.0/8,192.168.1.1")
# Set to "*" to trust all proxies (use only behind known reverse proxies)
GUI_TRUSTED_PROXIES=