From d12de589a25b7d1fd4b23a1ed8fc3069d21cf252 Mon Sep 17 00:00:00 2001 From: kami Date: Fri, 31 Jul 2026 23:03:45 +0400 Subject: [PATCH] mavweb: default -addr to loopback, not all interfaces PR #47 added two state-changing routes (POST /chat, POST /routines) behind the -addr flag, which defaulted to ":9200" (all interfaces). Default now binds 127.0.0.1:9200; anyone who wants LAN/wider exposure still passes an explicit bind (as deploy/docker-compose.yml already does with "-addr :9201" inside the container, unaffected by this default change). Vikunja #317. --- cmd/mavweb/main.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/cmd/mavweb/main.go b/cmd/mavweb/main.go index 0d41585..cf6109d 100644 --- a/cmd/mavweb/main.go +++ b/cmd/mavweb/main.go @@ -314,7 +314,7 @@ func noCache(h http.Handler) http.Handler { } func main() { - addr := flag.String("addr", ":9200", "HTTP listen address") + addr := flag.String("addr", "127.0.0.1:9200", "HTTP listen address (loopback by default; pass e.g. \":9200\" or a LAN IP deliberately for wider exposure — POST /chat and /routines are state-changing)") voiceAddr := flag.String("voice", "127.0.0.1:9100", "voice server TCP addr (host:port)") // ntfyWS: the ntfy WebSocket subscribe URL the PWA connects to for in-app // nudge delivery, e.g. wss://ntfy.kvmx.ru/maven/ws?auth=. The