mirror of
https://github.com/YunoHost/package_linter.git
synced 2024-09-03 20:06:12 +02:00
mention the reverse proxy bypass
This commit is contained in:
parent
832dc3d55b
commit
8b38cf0924
1 changed files with 5 additions and 4 deletions
|
@ -1550,10 +1550,11 @@ class Configurations(TestSuite):
|
|||
and not line.strip().startswith(comment)
|
||||
):
|
||||
yield Info(
|
||||
f"{filename}:{number}: Binding to '0.0.0.0' or '::' can result in "
|
||||
"a security issue as the SSO can be bypassed by knowing a public "
|
||||
"IP (typically an IPv6) and the app port. Please be sure that this "
|
||||
"behavior is intentional. Maybe use '127.0.0.1' or '::1' instead."
|
||||
f"{filename}:{number}: Binding to '0.0.0.0' or '::' can result "
|
||||
"in a security issue as the reverse proxy and the SSO can be "
|
||||
"bypassed by knowing a public IP (typically an IPv6) and the "
|
||||
"app port. lease be sure that this behavior is intentional. "
|
||||
"Maybe use '127.0.0.1' or '::1' instead."
|
||||
)
|
||||
|
||||
#############################################
|
||||
|
|
Loading…
Reference in a new issue