Reported against 2.2.1 by someone reading the source. Every finding held. **Sign-in had no ceiling.** Failures were logged with the caller's address and nothing more. Two counters now — one per address, one per account — because the two attacks look different: one source working through many accounts is caught by the first, many sources working on one account by the second, and behind a proxy only the second still means anything. The count is kept in the process that serves the request. PLANKA needs no Redis and the stock deployment is one container; run several and each keeps its own count, which multiplies the ceiling by their number. That trade is written where the limits are configured. **The second factor could be guessed at leisure.** Six digits, and a pending token that stayed valid for its full ten minutes however many codes were wrong. Wrong codes are now counted on the session row — in the database, so the count survives a restart and holds across every process — and when the budget is spent the session is destroyed. After that even the right code is refused and the login starts over from the password. **Avatars, background images and favicons** checked the token's signature and nothing else, so a revoked session, a deactivated account or a changed password all kept working there for as long as the signature lasted, which is a year by default. The five checks the API makes now live in one helper that both use, rather than the shortened copy that had drifted from it. **A link attachment's favicon** was fetched from wherever the URL pointed. Storing a link is harmless — it is a string the user typed — but fetching its icon is a request the server makes to an address the user chose, and whether an icon came back reported on what is reachable from inside the network. Server-side fetches now refuse private, loopback and link-local addresses, `169.254.169.254` among them. The attachment is still created: linking to an internal wiki is a legitimate thing to do, and it was the server's own request that had to stop. **The signing key.** Our own compose file ships `notsecretkey`, and it is printed in the documentation — so on any instance that copied it, anyone can sign a token for any account. PLANKA now says so on every start, and keeps saying it, along with a key that is missing or shorter than 32 characters. The placeholder carries the warning inline, where it is copied from. **The backup script** wrote password hashes, live sessions, TOTP secrets and SMTP credentials to an unencrypted archive. `BACKUP_PASSPHRASE` now encrypts it, and without one the script says what it just put on disk. It also says what it is — an example for the stock compose stack, not a backup concept — and names the window between the database dump and the file copy, which no ordering closes.
134 lines
4.9 KiB
YAML
134 lines
4.9 KiB
YAML
services:
|
|
planka:
|
|
image: ghcr.io/plankanban/planka:latest
|
|
restart: on-failure
|
|
volumes:
|
|
- data:/app/data
|
|
# - ./terms:/app/terms/custom
|
|
# Optionally override this to your user/group
|
|
# user: 1000:1000
|
|
# tmpfs:
|
|
# - /app/.tmp:mode=770,uid=1000,gid=1000
|
|
ports:
|
|
- 3000:1337
|
|
environment:
|
|
- BASE_URL=http://localhost:3000
|
|
- DATABASE_URL=postgresql://postgres@postgres/planka
|
|
|
|
# Optionally store the database password in secrets:
|
|
# - DATABASE_URL=postgresql://postgres:$${DATABASE_PASSWORD}@postgres/planka
|
|
# - DATABASE_PASSWORD__FILE=/run/secrets/database_password
|
|
# And add the following to the service:
|
|
# secrets:
|
|
# - database_password
|
|
|
|
# REPLACE THIS. Every access token is signed with it, so leaving the
|
|
# published example value means anyone can mint a token for any account
|
|
# on this instance. Generate one with: openssl rand -hex 32
|
|
# PLANKA warns about this on every start until you change it.
|
|
- SECRET_KEY=notsecretkey
|
|
# Optionally store in secrets - then SECRET_KEY should not be set
|
|
# - SECRET_KEY__FILE=/run/secrets/secret_key
|
|
|
|
# - LOG_LEVEL=warn
|
|
|
|
# - TRUST_PROXY=true
|
|
# - MAX_UPLOAD_FILE_SIZE=
|
|
# - TOKEN_EXPIRES_IN=365 # In days
|
|
|
|
# - STORAGE_LIMIT=
|
|
# - ACTIVE_USERS_LIMIT=
|
|
|
|
# related: https://github.com/knex/knex/issues/2354
|
|
# As knex does not pass query parameters from the connection string,
|
|
# we have to use environment variables in order to pass the desired values, e.g.
|
|
# - PGSSLMODE=<value>
|
|
|
|
# Configure knex to accept SSL certificates
|
|
# - KNEX_REJECT_UNAUTHORIZED_SSL_CERTIFICATE=false
|
|
|
|
# The default application language used as a fallback when a user's language is not set.
|
|
# This language is also used for per-board notifications.
|
|
# - DEFAULT_LANGUAGE=en-US
|
|
|
|
# Do not comment out DEFAULT_ADMIN_EMAIL if you want to prevent this user from being edited/deleted
|
|
# - DEFAULT_ADMIN_EMAIL=demo@demo.demo
|
|
# - DEFAULT_ADMIN_PASSWORD=demo
|
|
# Optionally store in secrets - then DEFAULT_ADMIN_PASSWORD should not be set
|
|
# - DEFAULT_ADMIN_PASSWORD__FILE=/run/secrets/default_admin_password
|
|
# - DEFAULT_ADMIN_NAME=Demo Demo
|
|
# - DEFAULT_ADMIN_USERNAME=demo
|
|
|
|
# Set to true to show more detailed authentication error messages.
|
|
# It should not be enabled without a rate limiter for security reasons.
|
|
# - SHOW_DETAILED_AUTH_ERRORS=false
|
|
|
|
# All outgoing HTTP requests (SMTP, webhooks, Apprise notifications, favicon fetching, etc.)
|
|
# will be sent through this proxy if set.
|
|
# If commented out, an internal Squid proxy will be started inside the container,
|
|
# which you can control via OUTGOING_BLOCKED_* and OUTGOING_ALLOWED_* below.
|
|
# - OUTGOING_PROXY=http://proxy:3128
|
|
|
|
# Set to true to expose the Swagger specification at /swagger.json
|
|
# - SWAGGER_EXPOSED=false
|
|
|
|
# - S3_ENDPOINT=
|
|
# - S3_REGION=
|
|
# - S3_ACCESS_KEY_ID=
|
|
# - S3_SECRET_ACCESS_KEY=
|
|
# Optionally store in secrets - then S3_SECRET_ACCESS_KEY should not be set
|
|
# - S3_SECRET_ACCESS_KEY__FILE=/run/secrets/s3_secret_access_key
|
|
# - S3_BUCKET=
|
|
# - S3_FORCE_PATH_STYLE=true
|
|
# - S3_REQUEST_CHECKSUM_CALCULATION=
|
|
|
|
# Email Notifications (https://nodemailer.com/smtp/)
|
|
# These values override and disable configuration in the UI if set.
|
|
# - SMTP_HOST=
|
|
# - SMTP_PORT=587
|
|
# - SMTP_NAME=
|
|
# - SMTP_SECURE=true
|
|
# - SMTP_TLS_REJECT_UNAUTHORIZED=false
|
|
# - SMTP_USER=
|
|
# - SMTP_PASSWORD=
|
|
# Optionally store in secrets - then SMTP_PASSWORD should not be set
|
|
# - SMTP_PASSWORD__FILE=/run/secrets/smtp_password
|
|
# - SMTP_FROM="Demo Demo" <demo@demo.demo>
|
|
|
|
# Using Gravatar directly exposes user IPs and hashed emails to a third party (GDPR risk).
|
|
# Use a proxy you control for privacy, or leave commented out or empty to disable.
|
|
# - GRAVATAR_BASE_URL=https://www.gravatar.com/avatar/
|
|
|
|
# --------------------------------------------------------------------
|
|
# Outgoing traffic control (internal Squid proxy)
|
|
# --------------------------------------------------------------------
|
|
|
|
# These IPs/hostnames will always be blocked (highest priority)
|
|
# - OUTGOING_BLOCKED_IPS=
|
|
# - OUTGOING_BLOCKED_HOSTS=localhost,postgres
|
|
|
|
# Only these IPs/hostnames will be reachable
|
|
# - OUTGOING_ALLOWED_IPS=
|
|
# - OUTGOING_ALLOWED_HOSTS=
|
|
depends_on:
|
|
postgres:
|
|
condition: service_healthy
|
|
|
|
postgres:
|
|
image: postgres:16-alpine
|
|
restart: on-failure
|
|
volumes:
|
|
- db-data:/var/lib/postgresql/data
|
|
environment:
|
|
- POSTGRES_DB=planka
|
|
- POSTGRES_HOST_AUTH_METHOD=trust
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U postgres -d planka"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 5
|
|
|
|
volumes:
|
|
data:
|
|
db-data:
|