From 8b65d1109b634eb04dc1b330c7e120129750a8dc Mon Sep 17 00:00:00 2001 From: SandObserver <260779319+SandObserver@users.noreply.github.com> Date: Wed, 30 Sep 2026 21:22:03 -0400 Subject: [PATCH] Document Allowed Addresses and the address check without a password --- src/content/docs/docs/security.md | 6 ++++++ src/content/docs/docs/settings-reference.md | 1 + src/content/docs/docs/troubleshooting.md | 11 +++++++++++ 3 files changed, 18 insertions(+) diff --git a/src/content/docs/docs/security.md b/src/content/docs/docs/security.md index ae189a3..c557c41 100644 --- a/src/content/docs/docs/security.md +++ b/src/content/docs/docs/security.md @@ -28,6 +28,12 @@ Run it on a trusted network, or behind a reverse proxy that terminates TLS and a Authentication is only in force once a password is stored. Until then, the endpoint that sets one accepts the first caller. See [First setup](/docs/first-setup/). +### Addresses without a password + +While no password is set, Stackyard answers only on IP addresses, `localhost`, single-label names, names under `.local`, `.home.arpa`, `.internal` and `.localhost`, and the names in **Allowed Addresses**. Any other address gets a 403. This stops a web page on another site from pointing its own name at your server (DNS rebinding) and changing your settings. + +The first page load after install or upgrade sets the list. A host name is trusted and saved. An IP address or local name saves an empty list. With a password set, every address works and the list is not checked. + ## Secrets Stored secrets are stripped from the config before it reaches the browser. A populated field reports as set without returning its value, in config responses and in exports alike. diff --git a/src/content/docs/docs/settings-reference.md b/src/content/docs/docs/settings-reference.md index a5fd980..b20b97f 100644 --- a/src/content/docs/docs/settings-reference.md +++ b/src/content/docs/docs/settings-reference.md @@ -40,6 +40,7 @@ If every app suddenly shows as unhealthy, the socket proxy address is the usual | --- | --- | | Password Protection | Sets or changes the dashboard password. Between 8 and 1024 characters. Leave blank to keep the existing one. Changing the password, or turning protection off, asks for the current password. | | Sign out all devices | Ends every session everywhere, including the one you are using. Use it if you think a session may be compromised. | +| Allowed Addresses | Host names Stackyard answers on while no password is set, separated by commas. IP addresses and local names such as `nas` or `nas.local` always work and need no entry. The first address used to open Stackyard is added for you. See [Security](/docs/security/#addresses-without-a-password). | Locked out? See [password recovery](/docs/troubleshooting/#i-forgot-the-password-and-i-am-locked-out). diff --git a/src/content/docs/docs/troubleshooting.md b/src/content/docs/docs/troubleshooting.md index d58e808..0894f8f 100644 --- a/src/content/docs/docs/troubleshooting.md +++ b/src/content/docs/docs/troubleshooting.md @@ -60,6 +60,15 @@ To fix it, on the server: The container log shows `config file cannot be used; sign-in and saving are refused until it is fixed`, with the reason and the copy's name. +### Stackyard does not answer on this address + +No password is set, and the address in your browser is not an IP address, a local name, or an entry in **Allowed Addresses**. Stackyard refuses it so a web page on another site cannot reach your settings. See [Security](/docs/security/#addresses-without-a-password). + +1. Open Stackyard by its IP address, or by an address you already allowed. +2. In **General**, add the address to **Allowed Addresses** and save. +3. Or set a password. With a password, every address works. +4. Choose **Check again**. + ### My dashboard is empty after a restart Confirm both volumes are mounted. Without `./data` nothing persists. @@ -248,6 +257,8 @@ Messages shown in the admin, and what each one means. | `The password was changed elsewhere. Reload the page and try again.` | The password changed on another device while this save ran. Nothing was saved. | | `Too many attempts. Try again later.` | 5 wrong passwords from this IP in 15 minutes. Wait, then try again. See [above](#one-persons-failed-logins-lock-everyone-out). | | `Stackyard cannot use its settings file` | The config file is damaged or cannot be read. Sign-in and saving are off until it is fixed. See [above](#stackyard-cannot-read-its-settings-file). | +| `Stackyard does not answer on this address` | No password is set and this address is not allowed. See [above](#stackyard-does-not-answer-on-this-address). | +| `Keep ... in Allowed Addresses, or this page stops working.` | The save would drop the address this page is open on while no password is set. Remove it from another address. | | `Enter the credential again for: ...` | The request a secret belonged to changed, so the secret was cleared. Re-enter and save. | | `Nothing at that address answered.` | The socket proxy address is unreachable from inside the container. Usually a proxy published on the host's loopback. | | `That name is resolved by Docker, which answers only for containers on a shared network.` | The socket proxy service name is not on a network Stackyard shares. |