docs: add documentation regarding the safety of query-string token usage
This commit is contained in:
@@ -136,4 +136,9 @@ The script ensures .NET 10 and Ollama are installed, builds the client self-cont
|
|||||||
## Notes
|
## Notes
|
||||||
|
|
||||||
- Request and response bodies are streamed through the tunnel, which is important for Ollama streaming responses.
|
- Request and response bodies are streamed through the tunnel, which is important for Ollama streaming responses.
|
||||||
- Use HTTPS or a private network/VPN when exposing this outside a trusted network. The token is simple shared-secret protection, not a full access-control system.
|
|
||||||
|
## Security notes
|
||||||
|
|
||||||
|
- Use HTTPS or a private network/VPN when exposing this outside a trusted network.
|
||||||
|
- **Tokens in URLs** (`/token/<token>/...` and `?token=...`) are logged by web servers (Apache, Nginx, Kestrel), reverse proxies, and browsers (history). Malicious MITM proxies can also read them. Prefer header-based auth (`X-Reverse-Llama-Token` or `Authorization: Bearer`) when your client supports it.
|
||||||
|
- The token is simple shared-secret protection, not a full access-control system.
|
||||||
|
|||||||
@@ -47,6 +47,9 @@ internal static class TokenAuthentication
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Path-token auth: useful for clients that cannot send headers.
|
||||||
|
// SECURITY: the token appears in the URL and will be logged by
|
||||||
|
// web servers, proxies, and browsers. Prefer header auth when possible.
|
||||||
if (allowPathToken
|
if (allowPathToken
|
||||||
&& TryGetPathToken(request.Path, out var pathToken, out _))
|
&& TryGetPathToken(request.Path, out var pathToken, out _))
|
||||||
{
|
{
|
||||||
@@ -57,6 +60,9 @@ internal static class TokenAuthentication
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Query-string auth: needed for clients that cannot send headers
|
||||||
|
// (e.g. browser address bar, status page).
|
||||||
|
// SECURITY: same URL-logging risks as path-token auth above.
|
||||||
if (allowQueryToken
|
if (allowQueryToken
|
||||||
&& request.Query.TryGetValue("token", out var queryValues))
|
&& request.Query.TryGetValue("token", out var queryValues))
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user