HTTPS and reverse proxy
Put Orlok behind a reverse proxy with TLS, as production installations should be.
Orlok works over plain HTTP on a local network, but installing the app on phones and receiving push notifications require HTTPS. Sign-in is rate limited per account and per address, so the login page can face the internet. In production, place a reverse proxy with TLS in front of the app and:
- set
ORLOK_PUBLIC_URLto the proxy'shttps://address; - forward the
X-Forwarded-HostandX-Forwarded-Protoheaders, otherwise uploads are rejected by the cross-site request check.
Session cookies are marked Secure only when ORLOK_PUBLIC_URL uses https.