Encrypt cookies

This commit is contained in:
2026-09-13 11:45:15 +02:00
parent 99bdadf248
commit cb34bae784
11 changed files with 344 additions and 34 deletions
+6
View File
@@ -23,6 +23,12 @@ When you put it behind a reverse proxy that terminates TLS, set `--public-url`,
and make sure the proxy neither buffers request bodies nor imposes its own
upload limit.
The data directory holds the uploads, `tokens.json`, and `session.key`, which
seals the login cookie so that it carries a session rather than the token
itself. The last two are credential material, written `0600`. Deleting
`session.key` logs every browser session out and costs nothing else; a new one
is generated on the next start.
## Options
**Read `./uncensored-send --help` rather than this file.**