You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Yeah, I can be convinced. I was working on the "really, there should be a firewall and middleware" model, but it's easy enough to run that way (--host=0.0.0.0) if you know what you're doing.
What about 127.0.0.1 for a (safer) default, but no warning if you explicitly set it otherwise; assume the user knows what they're doing and why?
There is likely no problem with gaining control of the server host via otto, but the datastore is writable to anyone.
Perhaps we should serve on 127.0.0.1 by default, and until we implement permission control print a warning when not serving to localhost.
The text was updated successfully, but these errors were encountered: