Skip to content

Commit ee299ee

Browse files
ADFA-5043: add comment about server side security
1 parent 120a6d5 commit ee299ee

1 file changed

Lines changed: 5 additions & 4 deletions

File tree

‎static/dashboard/routes.ts‎

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -569,10 +569,11 @@ apiRouter.delete('/credentials/:service', (req: Request, res: Response): void =>
569569
}
570570
});
571571

572-
// ADFA-5043: hand the app a service session cookie so it can inject it into the WebView and land the
573-
// user already authenticated as the box admin (Calibre-Web / Kolibri). The login runs server-side with
574-
// the stored credentials — the password never leaves the box. no-store so the session cookie is never
575-
// cached by the proxy or the client.
572+
// ADFA-5043: server-side login with the stored creds -> session cookie for the app to inject into the
573+
// WebView (auto-login as box admin: Calibre-Web / Kolibri). Password never leaves the box; no-store so
574+
// the cookie isn't cached; service not installed/ready -> 503 (app then opens the card without a cookie).
575+
// Mints an admin cookie, so it relies on /k2go-api staying localhost-only (nginx deny all in
576+
// dash-node-nginx.conf) — never expose /k2go-api to the LAN.
576577
apiRouter.get('/auth/:service/session', async (req: Request, res: Response): Promise<void> => {
577578
res.set('Cache-Control', 'no-store');
578579
const service = String(req.params.service);

0 commit comments

Comments
 (0)