doc: inspector security warning for changing host to a public IP#23640
doc: inspector security warning for changing host to a public IP#23640ChALkeR wants to merge 3 commits intonodejs:masterfrom
Conversation
c48bfaa to
e552d34
Compare
doc/api/cli.md
Outdated
There was a problem hiding this comment.
It might be worthwhile linking to this page that talks about things in more detail: https://nodejs.org/en/docs/guides/debugging-getting-started/#security-implications
There was a problem hiding this comment.
Nit: Specifically typo
doc/api/cli.md
Outdated
There was a problem hiding this comment.
"anyone of the outside" isn't grammatically correct - perhaps "as it allows other hosts to connect to the inspector"
There was a problem hiding this comment.
Done, with s/other/third-party/.
doc/api/cli.md
Outdated
There was a problem hiding this comment.
s/IP/host/ - use the same word in both places
e552d34 to
9897f34
Compare
doc/api/cli.md
Outdated
There was a problem hiding this comment.
security warning about providing a different `host` , or something similar to the added text in the other file? That would give people an indication about the circumstances in which there are security concerns upfront
There was a problem hiding this comment.
Changed to
See the security warning below regarding the
hostparameter usage.
and
See the security warning regarding the
hostparameter usage.
in two files.
Thanks!
9897f34 to
825dbdb
Compare
doc/api/cli.md
Outdated
| #### Warning: binding inspector to a public IP:port combination is insecure | ||
|
|
||
| Binding the inspector to a public IP (including `0.0.0.0`) with an open port is | ||
| insecure, as it allows third-party hosts to connect to the inspector and perform |
There was a problem hiding this comment.
Wouldn't external hosts be better than third-party here? We don't even have a second party here.
doc/api/cli.md
Outdated
There was a problem hiding this comment.
Nit: Specifically typo
|
Landed in 90be286 |
Refs: nodejs#23444 Refs: nodejs#21774 PR-URL: nodejs#23640 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Gireesh Punathil <gpunathi@in.ibm.com> Reviewed-By: Colin Ihrig <cjihrig@gmail.com> Reviewed-By: Sam Roberts <vieuxtech@gmail.com> Reviewed-By: Sakthipriyan Vairamani <thechargingvolcano@gmail.com> Reviewed-By: Eugene Ostroukhov <eostroukhov@google.com>
Refs: #23444 Refs: #21774 PR-URL: #23640 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Gireesh Punathil <gpunathi@in.ibm.com> Reviewed-By: Colin Ihrig <cjihrig@gmail.com> Reviewed-By: Sam Roberts <vieuxtech@gmail.com> Reviewed-By: Sakthipriyan Vairamani <thechargingvolcano@gmail.com> Reviewed-By: Eugene Ostroukhov <eostroukhov@google.com>
Refs: #23444 Refs: #21774 PR-URL: #23640 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Gireesh Punathil <gpunathi@in.ibm.com> Reviewed-By: Colin Ihrig <cjihrig@gmail.com> Reviewed-By: Sam Roberts <vieuxtech@gmail.com> Reviewed-By: Sakthipriyan Vairamani <thechargingvolcano@gmail.com> Reviewed-By: Eugene Ostroukhov <eostroukhov@google.com>
Refs: #23444 Refs: #21774 PR-URL: #23640 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Gireesh Punathil <gpunathi@in.ibm.com> Reviewed-By: Colin Ihrig <cjihrig@gmail.com> Reviewed-By: Sam Roberts <vieuxtech@gmail.com> Reviewed-By: Sakthipriyan Vairamani <thechargingvolcano@gmail.com> Reviewed-By: Eugene Ostroukhov <eostroukhov@google.com>
Refs: #23444 Refs: #21774 PR-URL: #23640 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Gireesh Punathil <gpunathi@in.ibm.com> Reviewed-By: Colin Ihrig <cjihrig@gmail.com> Reviewed-By: Sam Roberts <vieuxtech@gmail.com> Reviewed-By: Sakthipriyan Vairamani <thechargingvolcano@gmail.com> Reviewed-By: Eugene Ostroukhov <eostroukhov@google.com>
This is the documentation part of #23444.
Checklist
make -j4 test(UNIX), orvcbuild test(Windows) passes/cc @nodejs/documentation @nodejs/security-wg