Security Audit Fixes: Session fixation prevention, SameSite cookies, audit log redaction, backup integrity, Docker hardening, error sanitization, rate limiting, trusted proxies, and config hardening
This commit is contained in:
parent
7fc90524b5
commit
b587fb87a9
18 changed files with 987 additions and 87 deletions
33
.env.example
Normal file
33
.env.example
Normal file
|
|
@ -0,0 +1,33 @@
|
|||
# Environment variables for Traefik GUI
|
||||
# See README.md for detailed setup instructions
|
||||
|
||||
# Required - Session signing secret (32+ characters, random)
|
||||
# Generate with: openssl rand -hex 32
|
||||
GUI_SESSION_SECRET=CHANGE_THIS_TO_A_32_CHARACTER_RANDOM_SECRET
|
||||
|
||||
# Required - Admin password (minimum 12 characters for production)
|
||||
# This is hashed on startup; change to your preferred password
|
||||
GUI_ADMIN_PASSWORD=changeme
|
||||
|
||||
# Frontend CORS origin (must match the URL you'll use to access the GUI)
|
||||
GUI_CORS_ORIGIN=http://localhost:5173
|
||||
|
||||
# Server address
|
||||
GUI_ADDR=:8080
|
||||
|
||||
# Development mode: set to "true" for local dev (enables dev-mode cookie behavior), "false" for production
|
||||
GUI_DEV_MODE=false
|
||||
|
||||
# Traefik API URL (read-only; leave empty or set to http://localhost:8080/api for mock mode)
|
||||
# Set to a real Traefik instance URL to enable read-only API features
|
||||
TRAEFIK_API_URL=http://localhost:8080/api
|
||||
|
||||
# SQLite database path (relative to binary location; defaults to ./data/traefik-gui.db)
|
||||
GUI_DB_PATH=./data/traefik-gui.db
|
||||
|
||||
# Config directory for Traefik dynamic config (must be under configs/)
|
||||
GUI_CONFIG_DIR=./configs/dynamic
|
||||
|
||||
# Trusted proxies for X-Forwarded-For header parsing (comma-separated IPs or CIDR ranges, e.g., "10.0.0.0/8,192.168.1.1")
|
||||
# Set to "*" to trust all proxies (use only behind known reverse proxies)
|
||||
GUI_TRUSTED_PROXIES=
|
||||
Loading…
Add table
Add a link
Reference in a new issue