fix(security): WebSocket auth gate + audit-driven hardening sweep

This commit is contained in:
maziggy
2026-06-02 10:02:17 +02:00
parent 9c8df1744d
commit b7d7c82501
32 changed files with 1420 additions and 234 deletions
+19
View File
@@ -36,3 +36,22 @@ LOG_TO_FILE=true
# also store the value separately (otherwise an encrypted backup cannot be
# restored after key loss).
# MFA_ENCRYPTION_KEY=
# External library folders (GHSA-r2qv follow-up) — colon-separated list of
# host paths that users are permitted to register as external library
# folders via Settings → Library → "Add external folder".
#
# Empty (the default) means the external-folder feature is DISABLED:
# attempts to register one return HTTP 400. Set this to one or more
# absolute paths to opt in. Paths that fall inside Bambuddy's own
# DATA_DIR / LOG_DIR / static dir are always rejected regardless of
# this value.
#
# Example for a single NAS mount:
# BAMBUDDY_EXTERNAL_ROOTS=/mnt/nas/3d-prints
# Example for two roots:
# BAMBUDDY_EXTERNAL_ROOTS=/mnt/nas/3d-prints:/srv/library
#
# In Docker, also bind-mount the host path into the container at the same
# location (see docker-compose.yml for the matching volume snippet).
# BAMBUDDY_EXTERNAL_ROOTS=