Added some security considerations

This commit is contained in:
emeric
2021-05-27 14:02:55 +02:00
parent 8e9f02edad
commit 66de92fbb1
2 changed files with 10 additions and 2 deletions
+2 -2
View File
@@ -173,9 +173,9 @@ server {
location / { location / {
proxy_set_header Client-IP $remote_addr;
proxy_set_header Host $host; proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Proto $scheme;
proxy_pass http://localhost:5082/; proxy_pass http://localhost:5082/;
+8
View File
@@ -77,6 +77,14 @@ $setmulti(albumartistssort,%_albumartists_sort%)
* Previous track: <kbd>Ctrl</kbd> + <kbd>Left</kbd> * Previous track: <kbd>Ctrl</kbd> + <kbd>Left</kbd>
* Next track: <kbd>Ctrl</kbd> + <kbd>Right</kbd> * Next track: <kbd>Ctrl</kbd> + <kbd>Right</kbd>
## Security considerations
_Wt_ (the web framework used) has some [built-in security mesures](https://www.webtoolkit.eu/wt/features#security), but _LMS_ also has some too:
* to mitigate brute force login attempts, _LMS_ uses an internal login throttler based on the client IP address. The `Client-IP` or `X-Forwarded-For` headers are used to determined the real IP adress, so make sure to properly configure your reverse proxy to filter or even erase the values (see example in [INSTALL.md](INSTALL.md)).
* all passwords are stored hashed and salted using [bcrypt](https://fr.wikipedia.org/wiki/Bcrypt)
* all the resources relative to the music collection (tracks, covers, etc.) are private to a session
## Keyboard shortcuts
## Installation ## Installation
See [INSTALL.md](INSTALL.md) file. See [INSTALL.md](INSTALL.md) file.