Orlok

HTTPS and reverse proxy

Put Orlok behind a reverse proxy with TLS, as production installations should be.

Orlok works over plain HTTP on a local network, but installing the app on phones and receiving push notifications require HTTPS. Sign-in is rate limited per account and per address, so the login page can face the internet. In production, place a reverse proxy with TLS in front of the app and:

  • set ORLOK_PUBLIC_URL to the proxy's https:// address;
  • forward the X-Forwarded-Host and X-Forwarded-Proto headers, otherwise uploads are rejected by the cross-site request check.

Session cookies are marked Secure only when ORLOK_PUBLIC_URL uses https.