Security Audit Fixes: Session fixation prevention, SameSite cookies, audit log redaction, backup integrity, Docker hardening, error sanitization, rate limiting, trusted proxies, and config hardening

This commit is contained in:
backup 2026-09-03 23:55:25 -05:00
commit b587fb87a9
18 changed files with 987 additions and 87 deletions

View file

@ -4,6 +4,48 @@ Web-based GUI for managing Traefik v3.7.
See ARCHITECTURE.md for design.
---
## ⚠️ Security Notice
**Never commit the SQLite database file** (`data/traefik-gui.db`). It contains session data, CSRF tokens, and potentially sensitive configuration snapshots. The `.gitignore` excludes `*.db` and `data/` by default.
---
## Setup for Testers
1. **Copy the environment example:**
```bash
cp .env.example .env
```
Then edit `.env` and replace placeholder values with your own secrets:
- `GUI_SESSION_SECRET`: Must be at least 32 random characters
- `GUI_ADMIN_PASSWORD`: Minimum 12 characters for production
- Adjust `GUI_CORS_ORIGIN` if accessing from a different origin
2. **Start the backend:**
```bash
cd backend
go run ./cmd/traefik-gui --dev --session-secret $(grep GUI_SESSION_SECRET .env | cut -d= -f2-) --addr :8080
```
Or via Docker Compose:
```bash
docker compose up
```
3. **Start the frontend (separate terminal):**
```bash
cd frontend
npm install && npm run dev
```
4. **Open http://localhost:5173 (Vite) → login with admin/changeme** (or the password you set via `GUI_ADMIN_PASSWORD`)
5. **API health check:**
```
http://localhost:8080/api/health
```
## Quick Start
```bash