Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Insecure login on LAN #560

Open
ManuXD32 opened this issue Nov 15, 2024 · 1 comment
Open

Insecure login on LAN #560

ManuXD32 opened this issue Nov 15, 2024 · 1 comment
Labels
bug Something isn't working

Comments

@ManuXD32
Copy link

Describe the bug
If you login on a machine, the account stays opened, so if you access the webui from another machine you can get to the web page without loging in again

To Reproduce

  1. Setup backrest on a server with port 0.0.0.0
  2. Login from machine 2
  3. Try to login from machine 3

Expected behavior
Ask for login on different machines

Screenshots
If applicable, add screenshots to help explain your problem.

Platform Info

  • OS and Architecture Ubuntu server 24.0.1
  • Backrest Version 1.6.1
@ManuXD32 ManuXD32 added the bug Something isn't working label Nov 15, 2024
@garethgeorge
Copy link
Owner

garethgeorge commented Nov 16, 2024

Backrest supports password authentication to address multiuser installs where other users of the system need to be restricted from accessing the UI.

Interestingly, if running multiple installs under different user accounts I think one would also have problems with each install trying to bind to port 8989. For now, on a multi user system backrest should always be used with authentication enabled and only on a single user account.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants