Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: server binding 0.0.0.0 for useLocalIp only #2778

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

darkthread
Copy link

PR Type

What kind of change does this PR introduce?

Set the binding host to 0.0.0.0 only the user sets useLocalIp = true. Otherwise, users may mistakenly assume that the website can only be accessed locally, when in fact it is anonymously accessible throughout the entire LAN, which could create a security vulnerability.

[X] Bugfix
[ ] Feature
[ ] Refactoring (no functional changes, no api changes)
[ ] Documentation content changes
[ ] Other: <!-- Please describe: -->

What is the current behavior?

Live server is always binding to 0.0.0.0 (include localhost IP and all network adapter IP)

Issue Number: N/A

What is the new behavior?

When user set useLocalIp = true, live server bind to host 0.0.0.0, otherwise it bind to the setting from Config.getHost.

Does this PR introduce a breaking change?

[X] Yes
[ ] No

According to the existing documentation, users would understand that without setting "useLocalIp", access is limited to the local machine. However, the current situation opens up unused external access, and this change should not affect existing usage.

Other information

Copy link

@alencodes alencodes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

clean code.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants