inspiredby: admin mode, editor passes, link lookups
Why: Damien wanted to review visitor submissions, hide bad claims and swap photos from the site itself, and to let visitors start a suggestion by pasting a link.
Same service and port (inspiredby-web, 8440). This adds a second write path to the site and a server-side fetch of visitor-supplied URLs, so here is what a maintainer needs to know.
1. Who gets admin mode
There is no login page. Editors are: a direct LAN connection to http://192.168.1.136:8440; a browser holding an ib_editor cookie (a 90-day "editor pass" issued by a 10-minute link from the LAN admin page); or a Spotify account listed in INSPIREDBY_EDITOR_SPOTIFY_IDS in ~/inspiredby/.env or in the admins table.
- Lesson: the first version trusted the visitor IP passed on by Nginx Proxy Manager. NPM accepts
X-Real-IPfrom private ranges and ~265 CDN ranges (CloudFront/Cloudflare), so it can be forged. For about 10 minutes, a forged header could have claimed home-network access. The logs show no admin requests through the proxy in that window, and no write could have succeeded because the tables didn't exist yet. Proxied IPs are no longer used for access decisions at all. - All cookies share
INSPIREDBY_SECRET. The editor cookie must carry an explicit marker, or a visitor's Spotify cookie value could be replayed as an editor cookie (caught before shipping).
2. What admin mode writes
Only the editor tables (hidden_claims, reviews, admins, photos) and "editor" observations for approved suggestions, all via same-origin POSTs. Manual photos are converted with /usr/bin/ffmpeg into ~/inspiredby/media/photos/.
3. Server-side link lookups
/api/fromurl makes the server fetch a URL a visitor pasted. To stop it being used to probe the LAN (SSRF), only http(s) on ports 80/443 to public addresses is allowed, every redirect hop is re-checked, responses are capped at 2 MB / 10 s, and it's rate-limited (12/min per client). I tested LAN, loopback, link-local, hex-encoded and odd-port URLs, and all were refused.
Net effect: editing from the site without a login page, a second carefully fenced write path, and server-side fetches that can't reach the home network.
← Back to Admin Hub