(cfg config.Config)
| 99 | } |
| 100 | |
| 101 | func logStartupBanner(cfg config.Config) { |
| 102 | log.Printf("vault: %s", cfg.VaultPath) |
| 103 | log.Printf("bind: %s", cfg.Bind) |
| 104 | authMode := "ZENNOTES_AUTH_TOKEN required" |
| 105 | if strings.TrimSpace(cfg.AuthToken) == "" { |
| 106 | authMode = "OPEN (no auth token set — anyone reachable can read/write)" |
| 107 | } |
| 108 | log.Printf("auth: %s", authMode) |
| 109 | tlsMode := "behind TLS proxy (cookies marked Secure, HSTS sent)" |
| 110 | if !cfg.BehindTLS { |
| 111 | tlsMode = "plain HTTP (set ZENNOTES_BEHIND_TLS=1 once a TLS proxy is in front)" |
| 112 | } |
| 113 | log.Printf("tls: %s", tlsMode) |
| 114 | if !bindIsLoopback(cfg.Bind) && !cfg.BehindTLS { |
| 115 | log.Printf("WARNING: bound to a non-loopback address without ZENNOTES_BEHIND_TLS=1.") |
| 116 | log.Printf("WARNING: put a TLS-terminating reverse proxy in front before exposing publicly.") |
| 117 | } |
| 118 | } |
| 119 | |
| 120 | func warnInsecureExposureLoop(ctx context.Context) { |
| 121 | t := time.NewTicker(15 * time.Minute) |
no test coverage detected