-
Notifications
You must be signed in to change notification settings - Fork 359
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
终端鉴权优化 #394
Comments
我不清楚您是如何认为我们没有做终端鉴权的 Lines 66 to 70 in 189f623
后端需要通过 token 验证才可以进入 web 终端,其次,我在文档中有注明使用 login 作为启动命令,这样相当于可以多套一层 linux 的用户认证 在未登录的情况下,访问 yourdomain.com/#/termainal 也有前端的路由守卫,跳转至 #/login nginx-ui/app/src/routes/index.ts Line 307 in 189f623
|
我没有完整的阅读文档,忽略了Linux默认的用户名和密码进行验证。 |
因为 demo 为了展示,所以直接用的 bash 作为启动命令 |
后续会增加设置,禁用 WebTerminal,以及二步验证等 |
https://yourdomain.com/#/terminal
没有终端相关的鉴权,存在被滥用的风险。
注:包括demo站点!
The text was updated successfully, but these errors were encountered: