Security Audit Fixes: Session fixation prevention, SameSite cookies, audit log redaction, backup integrity, Docker hardening, error sanitization, rate limiting, trusted proxies, and config hardening
This commit is contained in:
parent
7fc90524b5
commit
b587fb87a9
18 changed files with 987 additions and 87 deletions
42
README.md
42
README.md
|
|
@ -4,6 +4,48 @@ Web-based GUI for managing Traefik v3.7.
|
|||
|
||||
See ARCHITECTURE.md for design.
|
||||
|
||||
---
|
||||
|
||||
## ⚠️ Security Notice
|
||||
|
||||
**Never commit the SQLite database file** (`data/traefik-gui.db`). It contains session data, CSRF tokens, and potentially sensitive configuration snapshots. The `.gitignore` excludes `*.db` and `data/` by default.
|
||||
|
||||
---
|
||||
|
||||
## Setup for Testers
|
||||
|
||||
1. **Copy the environment example:**
|
||||
```bash
|
||||
cp .env.example .env
|
||||
```
|
||||
Then edit `.env` and replace placeholder values with your own secrets:
|
||||
- `GUI_SESSION_SECRET`: Must be at least 32 random characters
|
||||
- `GUI_ADMIN_PASSWORD`: Minimum 12 characters for production
|
||||
- Adjust `GUI_CORS_ORIGIN` if accessing from a different origin
|
||||
|
||||
2. **Start the backend:**
|
||||
```bash
|
||||
cd backend
|
||||
go run ./cmd/traefik-gui --dev --session-secret $(grep GUI_SESSION_SECRET .env | cut -d= -f2-) --addr :8080
|
||||
```
|
||||
Or via Docker Compose:
|
||||
```bash
|
||||
docker compose up
|
||||
```
|
||||
|
||||
3. **Start the frontend (separate terminal):**
|
||||
```bash
|
||||
cd frontend
|
||||
npm install && npm run dev
|
||||
```
|
||||
|
||||
4. **Open http://localhost:5173 (Vite) → login with admin/changeme** (or the password you set via `GUI_ADMIN_PASSWORD`)
|
||||
|
||||
5. **API health check:**
|
||||
```
|
||||
http://localhost:8080/api/health
|
||||
```
|
||||
|
||||
## Quick Start
|
||||
|
||||
```bash
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue