Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@

# The base image's configuration, which copying its files doesn't carry over.
# check_base_env.sh below fails the build if this drifts from the base image.
ENV HOME=/config \

Check warning on line 19 in Dockerfile

View workflow job for this annotation

GitHub Actions / build

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "SELKIES_ENABLE_BASIC_AUTH") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
LANGUAGE=en_US.UTF-8 \
LANG=en_US.UTF-8 \
TERM=xterm \
Expand Down Expand Up @@ -54,6 +54,12 @@
RUN sh /tmp/check_base_env.sh /connecthub-base.env \
&& rm -f /tmp/check_base_env.sh /connecthub-base.env

# The base's "*" lets any page open the stream WebSocket. The session cookie only keeps
# out other *sites*, so a page on a sibling subdomain (other.example.com beside
# hub.example.com) could still connect and control the desktop. Empty is Selkies'
# same-origin default: the Origin's hostname must match the Host nginx forwards.
ENV SELKIES_ALLOWED_ORIGINS=

# Install FreeRDP 3, GPU drivers for VA-API, Python 3, and utilities
RUN apt-get update && apt-get install -y --no-install-recommends \
freerdp3-x11 \
Expand Down
10 changes: 10 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -203,6 +203,16 @@ The application will automatically recognize the authenticated user and grant ac

`FORWARD_AUTH_TRUSTED_PROXIES` is **required**: the header is only honoured when the request comes from one of these IPs/CIDRs (your proxy's address or Docker network). Otherwise anyone reaching the container port directly could forge the header. Also avoid publishing the container port publicly in this mode.

### Which pages may open the stream

Only ConnectHub's own page can open the remote desktop stream: Selkies checks that the browser's `Origin` matches the address you reached ConnectHub on, which keeps out pages on other sites, including other apps on sibling subdomains of the same domain. This works unchanged through a reverse proxy or tunnel, by LAN IP and on localhost. To allow another page (for example a portal that embeds ConnectHub from a different hostname), list its origin:

```yaml
SELKIES_ALLOWED_ORIGINS=https://portal.example.com
```

Avoid `*`, which lets any page connect if the browser sends your session cookie.

---

## Connection Types (RDP, VNC, SSH)
Expand Down
4 changes: 4 additions & 0 deletions docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,10 @@ services:
# Session cookie Secure flag: auto (follows https), true, false
- COOKIE_SECURE=${COOKIE_SECURE:-auto}

# Only ConnectHub's own page may open the stream. Add origins (comma-separated) only
# if another page must embed it, e.g. https://portal.example.com; avoid "*".
# - SELKIES_ALLOWED_ORIGINS=

# Optional custom session secret key (auto-generated if omitted)
- SECRET_KEY=${SECRET_KEY:-}

Expand Down
Loading