• radar@programming.dev
    link
    fedilink
    English
    arrow-up
    29
    ·
    2 days ago

    Reverse proxy doesn’t really get you much security. If there is an application level issue a reverse proxy will not help

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      23 hours ago

      well, at least you are not depending on the application to do TLS properly, and you may be able to set up some access restrictions that your clients may support

    • whimsy@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      Hmmm, I’m a bit rusty on this but can’t one put an auth gate in front of the application, handled by the reverse proxy?

      • radar@programming.dev
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        You can, that would actually give you security. Not sure how many people do that. I assumed a straight reverse proxy without any auth

        • PeriodicallyPedantic@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          I think that’s one of the major reasons to use pangolin over something like nginx - built in auth and support for oidc.

          Of course, the native jellyfin apps don’t like the auth layer so idk if it helps if you’re trying to install it on your dad’s tv