Files
WhatIDo/Caddyfile.example
T
dev 6844d659fc harden security and add public TLS scaffold
- require ADMIN_PASSWORD (no default), remove CORS
- close public DB port, move DB credentials to .env (DB_PASSWORD)
- fix HTML escaping, add helmet + sec headers (no CSP due to inline scripts)
- rate limit public routes by IP (express-rate-limit)
- validate restore data and confine file unlinking to uploads/
- block dangerous upload extensions, 30MB per-entry limit, SVG not served inline
- return 400 on unknown group_id in POST /api/entries
- add commented Caddy/Let's Encrypt reverse-proxy scaffold + Caddyfile.example
- update README
2026-09-07 11:27:04 +03:00

20 lines
1.0 KiB
Caddyfile
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Пример конфигурации Caddy для публичного развёртывания WhatIDo.
#
# Порядок включения:
# 1. Скопируйте этот файл в ./Caddyfile (cp Caddyfile.example Caddyfile)
# 2. Замените yourdomain.example на реальный домен/WWW, указывающий на сервер
# 3. В docker-compose.yml расскомментируйте сервис caddy (и тома caddy_data/caddy_config)
# и переведите блок ports сервиса app в expose (см. комментарии в compose)
# 4. docker compose up -d --build
#
# Caddy автоматически получит Let's Encrypt сертификат на 80/443 портах.
# Запрос к app идёт по HTTPS на внутренний порт 3443 (самоподписанный серт
# приложения, поэтому tls_insecure_skip_verify).
yourdomain.example {
reverse_proxy app:3443 {
transport http {
tls_insecure_skip_verify
}
}
}