Skip to content

Conversation

@darkthread
Copy link

PR Type

What kind of change does this PR introduce?

Set the binding host to 0.0.0.0 only the user sets useLocalIp = true. Otherwise, users may mistakenly assume that the website can only be accessed locally, when in fact it is anonymously accessible throughout the entire LAN, which could create a security vulnerability.

[X] Bugfix
[ ] Feature
[ ] Refactoring (no functional changes, no api changes)
[ ] Documentation content changes
[ ] Other: <!-- Please describe: -->

What is the current behavior?

Live server is always binding to 0.0.0.0 (include localhost IP and all network adapter IP)

Issue Number: N/A

What is the new behavior?

When user set useLocalIp = true, live server bind to host 0.0.0.0, otherwise it bind to the setting from Config.getHost.

Does this PR introduce a breaking change?

[X] Yes
[ ] No

According to the existing documentation, users would understand that without setting "useLocalIp", access is limited to the local machine. However, the current situation opens up unused external access, and this change should not affect existing usage.

Other information

Copy link

@alencodes alencodes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

clean code.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants