The Proxmox fleet and the operator console must never be publicly reachable. The primary control is the reverse proxy, but nginx here is a catch-all (server_name _), so /admin was served on EVERY hostname — a proxy misconfiguration would expose it. ADMIN_HOSTS pins it; any other host gets 404 (not 403: a public domain must not disclose that a console exists). Prepended to the group instead of the admin route group on purpose: route middleware is reordered by Laravel's priority list, which runs first — a guest would then be redirected to /login and learn the console is there. Covered by a test for exactly that case. Empty ADMIN_HOSTS = unrestricted, so nobody is locked out by upgrading. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| AdminConsoleTest.php | ||
| AdminHostRestrictionTest.php | ||
| AdminSettingsTest.php | ||
| DatacenterTest.php | ||
| HostManagementTest.php | ||
| MaintenanceTest.php | ||
| ProvisioningActionsTest.php | ||
| RbacTest.php | ||