Comment on VoidAuth Release v1.6.0 - Optimization and 1k Stars Celebration 🎉
notquitenothing@sh.itjust.works 5 days agoI think technically you might actually not need https termination anymore, it was required when the session cookies were set secure manually but now they should be set automatically if the request protocol was https. You can give it a try just using http or self-signed certs, if you do let me know if it works!
You should be aware though that if you are not using https your password and other secrets will be transmitted unencrypted on that layer, so make sure that your setup is secured/encrypted in some other way like wireguard/Cloudflare tunneling.
irmadlad@lemmy.world 5 days ago
Most definitely using https. I’ll give it a go and see what shakes out. Thanks for the help. I’ll report back.