From f620ec614c39c41004b9d3509042dfd5f17e63cd Mon Sep 17 00:00:00 2001 From: Michael SCHAL Date: Sat, 18 Apr 2026 07:25:38 +0200 Subject: [PATCH] security: require auth on MongoDB and Redis Enable mongod --auth with root credentials from MONGO_USER/PASSWORD, and redis-server --requirepass from REDIS_PASSWORD. App connection strings now embed credentials. All secrets are required (no fallback) so misconfiguration fails fast at compose time. Co-Authored-By: Claude Haiku 4.5 --- .env.example | 25 +++++++++++++++---------- .env.unraid | 41 ++++++++++++++++++++--------------------- docker-compose.yml | 17 ++++++++++++----- 3 files changed, 47 insertions(+), 36 deletions(-) diff --git a/.env.example b/.env.example index 11757ab..3da7a6d 100644 --- a/.env.example +++ b/.env.example @@ -1,24 +1,29 @@ # Backend Configuration NODE_ENV=development PORT=5000 -API_URL=http://localhost:5000 -# MongoDB Configuration -MONGODB_URI=mongodb://mongo:27017/podcastic -MONGODB_USER=podcastic -MONGODB_PASSWORD=podcastic_dev +# CORS — comma-separated list of allowed origins (e.g. https://podcastic.example.com,https://app.example.com) +# Leave empty in dev to allow all origins +CORS_ORIGIN= -# Redis Configuration -REDIS_URL=redis://redis:6379 +# MongoDB Configuration (REQUIRED — no defaults) +MONGO_USER=podcastic +MONGO_PASSWORD=replace_with_strong_password +# Used by the app — credentials must match MONGO_USER/MONGO_PASSWORD above +MONGODB_URI=mongodb://podcastic:replace_with_strong_password@mongodb:27017/podcastic?authSource=admin -# JWT Configuration -JWT_SECRET=your_super_secret_jwt_key_change_in_production +# Redis Configuration (REQUIRED — no defaults) +REDIS_PASSWORD=replace_with_strong_password +REDIS_URL=redis://:replace_with_strong_password@redis:6379 + +# JWT Configuration (REQUIRED — min 32 chars, no defaults accepted) +# Generate: openssl rand -base64 32 +JWT_SECRET= JWT_EXPIRES_IN=7d JWT_REFRESH_EXPIRES_IN=30d # Podcast API (PodcastIndex) - OPTIONAL but recommended for search feature # Get free API keys at: https://podcastindex-api.com/ -# These enable podcast discovery and search functionality PODCAST_INDEX_API_KEY= PODCAST_INDEX_API_SECRET= diff --git a/.env.unraid b/.env.unraid index 8a8a12b..4d5a5af 100644 --- a/.env.unraid +++ b/.env.unraid @@ -1,26 +1,35 @@ # ========================================== # Podcastic - Unraid Configuration # ========================================== -# All services in single container on port 3579 # Application Environment NODE_ENV=production # ========================================== -# DATABASE & CACHE (Internal - Don't change) +# DATABASE & CACHE — REQUIRED, set strong passwords # ========================================== -MONGODB_URI=mongodb://127.0.0.1:27017/podcastic -REDIS_URL=redis://127.0.0.1:6379 +# Generate strong passwords: openssl rand -base64 24 +MONGO_USER=podcastic +MONGO_PASSWORD=CHANGE_ME_strong_random_password +REDIS_PASSWORD=CHANGE_ME_strong_random_password + +# These are derived from the credentials above (do not edit unless you know what you're doing) +MONGODB_URI=mongodb://podcastic:CHANGE_ME_strong_random_password@mongodb:27017/podcastic?authSource=admin +REDIS_URL=redis://:CHANGE_ME_strong_random_password@redis:6379 # ========================================== -# SECURITY - CHANGE THESE! +# SECURITY — REQUIRED # ========================================== -# JWT Secret - Use strong random string +# JWT Secret — minimum 32 chars, must be a strong random string # Generate: openssl rand -base64 32 -JWT_SECRET=change-this-to-random-secret-key-in-production +JWT_SECRET= JWT_EXPIRES_IN=7d JWT_REFRESH_EXPIRES_IN=30d +# CORS — comma-separated list of frontend origins (e.g. https://podcastic.your-domain.com) +# Leave empty only if frontend and backend share the same origin +CORS_ORIGIN= + # ========================================== # OPTIONAL: PodcastIndex API (Podcast Search) # ========================================== @@ -30,26 +39,16 @@ PODCAST_INDEX_API_KEY= PODCAST_INDEX_API_SECRET= # ========================================== -# PORTS (Single container) +# PORTS # ========================================== # Frontend: http://your-unraid-ip:3579 # API: http://your-unraid-ip:3579/api -# Health: http://your-unraid-ip:3579/health - -PORT=5000 # Internal backend port (don't change) - -# ========================================== -# Frontend Configuration -# ========================================== -VITE_API_URL=http://your-unraid-ip:3579/api -# Or use relative path: -# VITE_API_URL=/api +PORT=3579 # ========================================== # NOTES FOR UNRAID # ========================================== -# 1. Change JWT_SECRET to a random string -# 2. If accessing from WAN, update VITE_API_URL to your domain +# 1. Generate strong passwords with: openssl rand -base64 32 +# 2. Set CORS_ORIGIN to your public frontend URL if accessing from WAN # 3. Optionally add PodcastIndex API keys for search feature # 4. All data stored in /mnt/user/appdata/podcastic/ -# 5. Logs in /mnt/user/appdata/podcastic/logs/ diff --git a/docker-compose.yml b/docker-compose.yml index aede5f0..efe2a56 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -5,12 +5,17 @@ services: image: mongo:8 container_name: podcastic-mongodb restart: unless-stopped + command: ["--auth"] + environment: + MONGO_INITDB_ROOT_USERNAME: ${MONGO_USER:?MONGO_USER is required} + MONGO_INITDB_ROOT_PASSWORD: ${MONGO_PASSWORD:?MONGO_PASSWORD is required} + MONGO_INITDB_DATABASE: podcastic volumes: - mongodb_data:/data/db networks: - podcastic_net healthcheck: - test: ["CMD", "mongosh", "--eval", "db.adminCommand('ping')"] + test: ["CMD", "mongosh", "--quiet", "-u", "${MONGO_USER}", "-p", "${MONGO_PASSWORD}", "--authenticationDatabase", "admin", "--eval", "db.adminCommand('ping')"] interval: 10s timeout: 5s retries: 5 @@ -20,12 +25,13 @@ services: image: redis:7-alpine container_name: podcastic-redis restart: unless-stopped + command: ["redis-server", "--requirepass", "${REDIS_PASSWORD:?REDIS_PASSWORD is required}"] volumes: - redis_data:/data networks: - podcastic_net healthcheck: - test: ["CMD", "redis-cli", "ping"] + test: ["CMD", "redis-cli", "-a", "${REDIS_PASSWORD}", "ping"] interval: 10s timeout: 5s retries: 5 @@ -41,11 +47,12 @@ services: environment: NODE_ENV: production PORT: 3579 - MONGODB_URI: mongodb://mongodb:27017/podcastic - REDIS_URL: redis://redis:6379 - JWT_SECRET: ${JWT_SECRET:-change_me_in_production} + MONGODB_URI: mongodb://${MONGO_USER}:${MONGO_PASSWORD}@mongodb:27017/podcastic?authSource=admin + REDIS_URL: redis://:${REDIS_PASSWORD}@redis:6379 + JWT_SECRET: ${JWT_SECRET:?JWT_SECRET is required (min 32 chars, generate with: openssl rand -base64 32)} JWT_EXPIRES_IN: 7d JWT_REFRESH_EXPIRES_IN: 30d + CORS_ORIGIN: ${CORS_ORIGIN:-} PODCAST_INDEX_API_KEY: ${PODCAST_INDEX_API_KEY:-} PODCAST_INDEX_API_SECRET: ${PODCAST_INDEX_API_SECRET:-} depends_on: