hooram / ownphotos

Self hosted alternative to Google Photos
MIT License
2.77k stars 233 forks source link

Lack of SSL (HTTPS) make it completely insecure #117

Closed Expro closed 5 years ago

Expro commented 5 years ago

Hi,

Currently, Ownphotos work only via HTTP, thus giving away passwords and transferred content to anyone listening. Considering that it may provide access to a lot of sensitive informations (faces, names, locations in time...) and work as gateway to Nextcloud via provided credentials, giving away access to even more sensitive data, it makes entire projects unusable in anything other than demo envinronments, which is damn shame, as otherwise it is very high quality tool.

Please provide support for HTTPS with custom pair of certificate + private key.

Regards, Expro

StefanAbl commented 5 years ago

Couldn't HTTPS Encryption be achieved using a reverse proxy like nginx. Though I strongly agree it should be using HTTPS and a self sign cert out of the box.

guysoft commented 5 years ago

Indeed, use nginx-proxy https://github.com/jwilder/nginx-proxy got that setup here