Add --port
This commit is contained in:
@@ -36,9 +36,14 @@ Options take **one hyphen with a single letter** and **two with a full word**:
|
||||
Every option can also be set from the environment as `SEND_MAX_SIZE` and so on.
|
||||
`./send --help` lists them all.
|
||||
|
||||
`--port` is a convenience over `--listen`: it replaces only the port, so
|
||||
`./send -p 9000` listens on `127.0.0.1:9000` and `--listen 0.0.0.0 -p 9000`
|
||||
listens on all interfaces.
|
||||
|
||||
| Option | Default | Meaning |
|
||||
|---|---|---|
|
||||
| `-l`, `--listen` | `127.0.0.1:8080` | address to listen on |
|
||||
| `-p`, `--port` | — | port to listen on, replacing the one in `--listen` |
|
||||
| `-d`, `--data` | `./data` | data directory |
|
||||
| `-b`, `--base-url` | `/` | path prefix when mounted under a subdirectory |
|
||||
| `-u`, `--public-url` | — | absolute base URL used in generated links |
|
||||
@@ -76,6 +81,23 @@ as `Authorization: Bearer <token>`, or paste it into the form's token field.
|
||||
and on `SIGHUP`. It must stay mode `0600` — the server refuses to start
|
||||
otherwise, since it holds credential material.
|
||||
|
||||
### Remembering a token
|
||||
|
||||
Tick **Remember this token on this device** and the server sets a cookie, so the
|
||||
token only has to be pasted once. The upload page then says who you are and
|
||||
shows your real limits; **Forget** clears it, as does unticking the box on your
|
||||
next upload. It works with JavaScript disabled, because the browser sends the
|
||||
cookie either way.
|
||||
|
||||
The cookie is `HttpOnly`, which means the page's own script cannot read it — the
|
||||
server resolves the identity and renders it instead. That is deliberately
|
||||
unlike `localStorage`, where any script injected into the origin could read the
|
||||
token straight out and walk away with it. It is also `SameSite=Strict`, so no
|
||||
other site can make your browser upload or delete anything with it attached.
|
||||
|
||||
Callers sending `Authorization: Bearer` are never given a cookie; an API client
|
||||
keeps its own credentials.
|
||||
|
||||
## Uploading
|
||||
|
||||
From the browser, just use the page. It works with JavaScript disabled; with it
|
||||
@@ -119,6 +141,7 @@ file is accepted.
|
||||
| `GET /d/{id}` | the file, as an attachment; supports resuming |
|
||||
| `GET /i/{id}` | a page showing name, size, expiry and digest |
|
||||
| `POST /api/d/{id}/delete` | delete, with `token=` in the form or `Authorization: Bearer` |
|
||||
| `POST /api/forget` | clear a remembered token |
|
||||
|
||||
Deleting accepts the object's delete token, the token that uploaded it, or any
|
||||
admin token.
|
||||
@@ -172,6 +195,12 @@ Worth knowing if you are going to run this somewhere real.
|
||||
protection — so the upload handler maintains a per-read deadline instead.
|
||||
- **`X-Forwarded-For` is ignored** unless the peer is a configured
|
||||
`--trusted-proxy`, and then only to skip further trusted hops.
|
||||
- **A remembered token lives in an `HttpOnly`, `SameSite=Strict` cookie**, not
|
||||
in `localStorage`, so neither an injected script nor another website can get
|
||||
at it. `Secure` is set whenever the service knows it is being served over
|
||||
HTTPS — from `--public-url`, from a TLS connection, or from a trusted proxy's
|
||||
`X-Forwarded-Proto`. On browsers old enough to ignore `SameSite` entirely
|
||||
(pre-2017) the cookie would be CSRF-exposed; nothing here defends that case.
|
||||
- Rate limiting is per client address, with a separate bound on uploads in
|
||||
flight. Both are in memory and reset on restart.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user