Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/content/docs/docs/installation/docker.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ All optional.
]} />

<SettingList title="Sessions and logs" items={[
{ name: '`SESSION_MAX_AGE_DAYS`', text: 'Idle session lifetime. Default `0.5`, 12 hours.' },
{ name: '`SESSION_MAX_AGE_DAYS`', text: 'Idle session lifetime. Default `0.5`, 12 hours. A session in use ends 30 days after sign-in, or after this lifetime if longer.' },
{ name: '`PASSWORD_HASH_MEMORY`', text: 'Memory per password hash: `8mib` to `128mib`. Default `16mib`.' },
{ name: '`LOG_LEVEL`', text: '`debug`, `info`, `warn` or `error`. Default `info`. The General setting overrides it.' },
]} />
Expand Down
2 changes: 2 additions & 0 deletions src/content/docs/docs/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,8 @@ Run it on a trusted network, or behind a reverse proxy that terminates TLS and a
- Passwords are hashed with scrypt and a per-password salt, stored in PHC string format.
- Session tokens are HMAC-signed and verified with a constant-time comparison.
- Sessions expire after an idle lifetime, 12 hours by default. A session in use is reissued past the halfway mark.
- A session ends 30 days after sign-in even while in use, or after the idle lifetime if that is longer.
- Signing out ends the session on the server. A copy of its cookie stops working too.
- Login is rate-limited to 5 attempts per IP per 15 minutes. Counters are in memory, so a restart clears them and they are not shared across replicas. Run a single instance behind any proxy.
- Changing the password rotates the session secret, signing out every other device. Sign out all devices does the same without changing the password.
- Changing the password, or turning protection off, needs the current password as well as a session. Wrong attempts count toward the login limit of 5 per IP per 15 minutes.
Expand Down
Loading