[{"data":1,"prerenderedAt":120},["ShallowReactive",2],{"\u002Fdocs\u002Fsecurity":3,"docs-nav":88},{"id":4,"title":5,"body":6,"description":80,"extension":81,"meta":82,"navigation":83,"path":84,"seo":85,"stem":86,"__hash__":87},"docs\u002Fdocs\u002F8.security.md","Security",{"type":7,"value":8,"toc":71},"minimark",[9,19,24,32,36,39,43,46,50,57,61],[10,11,12,13,18],"p",{},"This page covers what Redrive protects on its own and what it leaves to your broker account. Every broker operation runs as the connection's account, and which permission each one needs is listed in ",[14,15,17],"a",{"href":16},"\u002Fdocs\u002Fgetting-started","Getting started",".",[20,21,23],"h2",{"id":22},"the-password-gate","The password gate",[10,25,26,27,31],{},"Setting ",[28,29,30],"code",{},"REDRIVE_PASSWORD"," turns on cookie-based auth in front of the whole app, with login attempts rate limited to five per minute from one address. Leave it unset and there's no login at all: Redrive assumes it's talking only to you, on localhost.",[20,33,35],{"id":34},"the-unprotected-banner","The unprotected banner",[10,37,38],{},"Bind beyond loopback without a password, and Redrive logs a warning and shows a banner in the UI for the rest of the session. That's a reasonable state for a trusted internal lab. Anywhere else it's a real exposure: set the password.",[20,40,42],{"id":41},"broker-credentials-at-rest","Broker credentials at rest",[10,44,45],{},"Broker credentials are encrypted with ASP.NET Core Data Protection. On Windows, the encryption keys are DPAPI-protected, tied to the machine and user account. On Linux and macOS, the keys sit on disk beside the database. That's enough to stop a casual read, and a copied database file is useless on its own. It isn't enough to stop someone who already has full access to your data directory.",[20,47,49],{"id":48},"message-payloads","Message payloads",[10,51,52,53,18],{},"Message payloads move over AMQP as the connection's account, and Redrive adds no transport protection of its own beyond what that connection already gives you. Which operations travel over AMQP and which go through the management API is mapped in ",[14,54,56],{"href":55},"\u002Fdocs\u002Fqueues","Queues & messages",[20,58,60],{"id":59},"dns-rebinding","DNS rebinding",[10,62,63,64,67,68,70],{},"An unprotected instance bound to localhost is still reachable from a malicious website through DNS rebinding. A page open in your browser can trick the browser into sending requests to ",[28,65,66],{},"localhost:5100"," as if they were going to the site's own server. If that's in your threat model, set ",[28,69,30],{}," even for a local-only install. A Host-header allowlist to close this by default is on the roadmap.",{"title":72,"searchDepth":73,"depth":73,"links":74},"",2,[75,76,77,78,79],{"id":22,"depth":73,"text":23},{"id":34,"depth":73,"text":35},{"id":41,"depth":73,"text":42},{"id":48,"depth":73,"text":49},{"id":59,"depth":73,"text":60},"What Redrive protects, what it doesn't, and what that means for how you run it.","md",{},true,"\u002Fdocs\u002Fsecurity",{"title":5,"description":80},"docs\u002F8.security","AGe5xoO_5x5gRNUR1D_EBn8ackb5z6GzSUdbuyk2snI",[89],{"title":90,"path":91,"stem":92,"children":93,"page":119},"Docs","\u002Fdocs","docs",[94,98,100,102,106,110,114,118],{"title":95,"path":96,"stem":97},"Install","\u002Fdocs\u002Finstall","docs\u002F1.install",{"title":17,"path":16,"stem":99},"docs\u002F2.getting-started",{"title":56,"path":55,"stem":101},"docs\u002F3.queues",{"title":103,"path":104,"stem":105},"Redriving","\u002Fdocs\u002Fredriving","docs\u002F4.redriving",{"title":107,"path":108,"stem":109},"Publishing & topology","\u002Fdocs\u002Fpublishing","docs\u002F5.publishing",{"title":111,"path":112,"stem":113},"Configuration","\u002Fdocs\u002Fconfiguration","docs\u002F6.configuration",{"title":115,"path":116,"stem":117},"Deployment","\u002Fdocs\u002Fdeployment","docs\u002F7.deployment",{"title":5,"path":84,"stem":86},false,1787116432400]