Fixes from the security audit (the brute-force/rate-limiting angle matters more now that the password policy is min(6)/no-complexity, so IP-keyed throttles must not be spoofable): - bootstrap/app.php: trustProxies(at: '*') → trust only PRIVATE ranges in prod. Caddy reaches app:80 from the docker bridge (private IP) so it stays trusted, but a public/off-network source can no longer forge X-Forwarded-For to spoof request()->ip() and bypass the login/2FA/forgot throttles + the brute-force ban. - TerminalSession + HostCredential: replace $guarded=[] with an explicit $fillable allowlist; add $hidden=[secret,passphrase] to HostCredential so it never serializes its credential fields. - nginx /terminal/ws: access_log off — the single-use session token rode the query string into the access log. Verified: full suite 467 pass; all panel pages 200 with zero console errors; server terminal still connects + runs commands. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| cache | ||
| app.php | ||
| providers.php | ||