[{"data":1,"prerenderedAt":98},["ShallowReactive",2],{"\u002Fdocs\u002Fsecurity":3,"docs-nav":78},{"id":4,"title":5,"body":6,"description":70,"extension":71,"meta":72,"navigation":73,"path":74,"seo":75,"stem":76,"__hash__":77},"docs\u002Fdocs\u002F4.security.md","Security",{"type":7,"value":8,"toc":61},"minimark",[9,14,23,27,30,34,37,41,44,47,51],[10,11,13],"h2",{"id":12},"the-password-gate","The password gate",[15,16,17,18,22],"p",{},"Setting ",[19,20,21],"code",{},"REDRIVE_PASSWORD"," turns on cookie-based auth with rate-limited login. Leave it unset and there's no login at all — Redrive assumes it's talking only to you, on localhost.",[10,24,26],{"id":25},"the-unprotected-banner","The unprotected banner",[15,28,29],{},"Bind beyond loopback without a password, and Redrive logs a warning and shows a banner in the UI for the rest of the session. That's a reasonable setup for a trusted internal lab. Anywhere else, it's a real exposure — set the password.",[10,31,33],{"id":32},"broker-credentials-at-rest","Broker credentials at rest",[15,35,36],{},"Broker credentials are encrypted with ASP.NET Core Data Protection. On Windows, the encryption keys are DPAPI-protected, tied to the machine and user account. On Linux and macOS, the keys sit on disk beside the database. That's enough to stop a casual read or a copied database file from being useful on its own — it is not enough to stop someone who already has full access to your data directory.",[10,38,40],{"id":39},"message-payloads","Message payloads",[15,42,43],{},"Message payloads never touch your management credential. Peek, redrive, publish, discard, and purge all move over AMQP using your AMQP credential; Redrive adds no transport-level protection of its own beyond what that connection already gives you. Browsing queues and reading stats work fine with a monitoring-tagged, read-only management account.",[15,45,46],{},"Queue delete and binding changes (adding or removing a binding) are the exception — those go through the management API, not AMQP, so they fail against a read-only management credential. Give the account configure rights if you want to do those from Redrive.",[10,48,50],{"id":49},"a-note-on-dns-rebinding","A note on DNS rebinding",[15,52,53,54,57,58,60],{},"An unprotected instance bound to localhost is still reachable from a malicious website through DNS rebinding: a page you visit in your browser can trick it into talking to ",[19,55,56],{},"localhost:5100"," as if it were the site's own server. If that's in your threat model, set ",[19,59,21],{}," even for a local-only install. A Host-header allowlist to close this by default is on the roadmap.",{"title":62,"searchDepth":63,"depth":63,"links":64},"",2,[65,66,67,68,69],{"id":12,"depth":63,"text":13},{"id":25,"depth":63,"text":26},{"id":32,"depth":63,"text":33},{"id":39,"depth":63,"text":40},{"id":49,"depth":63,"text":50},"What Redrive protects, what it doesn't, and what that means for how you run it.","md",{},true,"\u002Fdocs\u002Fsecurity",{"title":5,"description":70},"docs\u002F4.security","SUVdJKo9sFv_cp3Hw3Pr1cLiYSGz2iseyqTcfcjSql4",[79],{"title":80,"path":81,"stem":82,"children":83,"page":97},"Docs","\u002Fdocs","docs",[84,88,92,96],{"title":85,"path":86,"stem":87},"Install","\u002Fdocs\u002Finstall","docs\u002F1.install",{"title":89,"path":90,"stem":91},"Configuration","\u002Fdocs\u002Fconfiguration","docs\u002F2.configuration",{"title":93,"path":94,"stem":95},"Deployment","\u002Fdocs\u002Fdeployment","docs\u002F3.deployment",{"title":5,"path":74,"stem":76},false,1786954328908]