CluPilotCloud/routes
nexxo 1f42c05648 feat(security): admin console can be pinned to non-public hostnames
The Proxmox fleet and the operator console must never be publicly reachable. The
primary control is the reverse proxy, but nginx here is a catch-all
(server_name _), so /admin was served on EVERY hostname — a proxy
misconfiguration would expose it. ADMIN_HOSTS pins it; any other host gets 404
(not 403: a public domain must not disclose that a console exists).

Prepended to the  group instead of the admin route group on purpose: route
middleware is reordered by Laravel's priority list, which runs  first — a
guest would then be redirected to /login and learn the console is there. Covered
by a test for exactly that case. Empty ADMIN_HOSTS = unrestricted, so nobody is
locked out by upgrading.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-25 20:45:54 +02:00
..
channels.php fix(admin): self-heal legacy is_admin into Owner (no RBAC bypass); validate datacenter country server-side 2026-07-25 18:19:24 +02:00
console.php feat(engine): orchestrator core (state machine + tick + lock) 2026-07-25 09:54:52 +02:00
web.php feat(security): admin console can be pinned to non-public hostnames 2026-07-25 20:45:54 +02:00