mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
chore: release 0.9.0 — security hardening + warn-don't-block network policy
Release 0.9.0 covering the merged security/reliability PRs (#106 deps/ supply-chain, #107 auth/network, #108 test stability, #110 tmux cwd) plus: - Network policy: a non-loopback bind without CODEMAN_PASSWORD now STARTS with a loud warning (3 ways to secure) instead of refusing to start. Loopback stays the safe default. --allow-unauthenticated-network just acknowledges (terser note). (src/web/server.ts start()) - Post-install security note explaining the loopback default + safe exposure. - New docs/security-architecture.md documenting the full model (binding, auth pipeline, tunnel req.ip caveat, file-serving, supply-chain, isolation, recommended setups). CLAUDE.md Security section + gotcha updated. - Updated auth-security test: asserts warn-and-start (not throw). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -460,3 +460,16 @@ if (process.env.CI || process.env.CODEMAN_NO_AUTOSTART) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// ----------------------------------------------------------------------------
|
||||
// Security note — printed on every install path
|
||||
// ----------------------------------------------------------------------------
|
||||
|
||||
console.log(colors.bold('Security:'));
|
||||
console.log(colors.dim(' Codeman binds ') + colors.cyan('127.0.0.1') + colors.dim(' (this machine only) — no password needed by default.'));
|
||||
console.log(colors.dim(' To reach it from another device, do ONE of:'));
|
||||
console.log(colors.dim(' • ') + colors.cyan('tailscale serve') + colors.dim(' / ') + colors.cyan('cloudflared tunnel') + colors.dim(' (recommended), or'));
|
||||
console.log(colors.dim(' • ') + colors.cyan('codeman web --host 0.0.0.0') + colors.dim(' AND set ') + colors.cyan('CODEMAN_PASSWORD'));
|
||||
console.log(colors.dim(' A non-loopback bind without a password still starts, but warns loudly.'));
|
||||
console.log(colors.dim(' Details: docs/security-architecture.md'));
|
||||
console.log('');
|
||||
|
||||
Reference in New Issue
Block a user