Encrypt cookies
This commit is contained in:
@@ -23,6 +23,12 @@ When you put it behind a reverse proxy that terminates TLS, set `--public-url`,
|
||||
and make sure the proxy neither buffers request bodies nor imposes its own
|
||||
upload limit.
|
||||
|
||||
The data directory holds the uploads, `tokens.json`, and `session.key`, which
|
||||
seals the login cookie so that it carries a session rather than the token
|
||||
itself. The last two are credential material, written `0600`. Deleting
|
||||
`session.key` logs every browser session out and costs nothing else; a new one
|
||||
is generated on the next start.
|
||||
|
||||
## Options
|
||||
|
||||
**Read `./uncensored-send --help` rather than this file.**
|
||||
|
||||
Reference in New Issue
Block a user