Header-only control token, masked secrets, loopback default (v0.9.9)
Finishes the small items of the security audit in docs/prs/2026-07-08-PR#000: TODO 3, 4 and 7. The three mutating endpoints of BuildsApiController no longer accept the control token as a `token` query parameter — only the X-GitTally-Token header, which the bundled UI has always used. URLs end up in access logs, proxy logs, browser history and Referer headers, and the token never expires, so a historical log capture would yield a valid credential. `config:print` masks git.token as `***` on both the raw and the --full path and names the new --show-secrets flag in a leading YAML comment, so the output stays parseable when piped. The setup script points at --show-secrets where it used to steer the operator to the plain token. `server.bindAddress` now defaults to 127.0.0.1: neither the UI nor the API authenticates read access, so reaching GitTally should require the host's reverse proxy. Existing .gittally.yml files keep their explicit value; the managed nginx container needs `0.0.0.0` set deliberately, which is noted in the release notes, docs/configuration.md and docs/deployment.md. Released as v0.9.9, which also carries the previous two commits. Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -18,7 +18,12 @@ data class ServerConfig(
|
||||
val publicBaseUrl: String = "",
|
||||
/** HTTP port of the `server` subcommand; 18080 like the legacy artifact server. */
|
||||
val port: Int = 18080,
|
||||
val bindAddress: String = "0.0.0.0",
|
||||
/**
|
||||
* Loopback by default: the UI and the API are unauthenticated, so reaching them should
|
||||
* require the host's reverse proxy. Set `0.0.0.0` explicitly to expose all interfaces —
|
||||
* which the managed nginx container needs (see `docs/deployment.md`).
|
||||
*/
|
||||
val bindAddress: String = "127.0.0.1",
|
||||
/** Optional Impressum (legal disclosure) link shown in the web UI footer; empty hides the link. */
|
||||
val impressumUrl: String = "",
|
||||
val nginx: NginxConfig = NginxConfig(),
|
||||
|
||||
Reference in New Issue
Block a user