docs: consistent Configuration callouts + reflect app hardening on Security page - #138
Merged
Merged
Conversation
Add the CORS_ALLOWED_ORIGINS environment variable to the Installation env table (Maintainerr/Maintainerr#3407). The bundled UI is same-origin with the API and does not need it; it is only for a separate front end. The Security & Authentication page lives in the current docs (/next/security/), but API.md and Configuration.md linked to it with an absolute /security, which resolves to the site root where the page does not exist yet, so the build flagged both as broken. Switch them to version-relative links (./Security.md) so they resolve within whichever version is viewed. docusaurus build now reports no broken links.
Configuration page: use one consistent callout style - a single info box for the security note and uniform notes everywhere else, dropping the green tips that made the page a patchwork of colors. Move the Base URL note from the top of the page to the Radarr/Sonarr section where that field is entered. Security page: reflect the appliance hardening in Maintainerr/Maintainerr#3407 - cross-origin reads are blocked by default (CORS_ALLOWED_ORIGINS to opt in a separate front end), submitted settings are schema-validated, and container file permissions are least-privilege.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two documentation cleanups.
Configuration page: consistent callouts. The page used a patchwork of note (blue), tip (green), and info (teal) callouts, with the same kind of information wearing different colors as you scrolled. Now it uses one info box for the security note and uniform notes for everything else; the green tips are gone. No information is removed. The
Base URLnote also moves from the top of the page down to the Radarr/Sonarr section where that field is actually entered (and the example now usesradarr, a service that has a Base URL field).Security page: reflect the app hardening in Maintainerr/Maintainerr#3407. Cross-origin reads are blocked by default (with
CORS_ALLOWED_ORIGINSto opt in a separate front end), submitted settings are schema-validated, and container file permissions are least-privilege.docusaurus buildreports no broken links.Note: this is stacked on #137 (so the
./Security.mdlinks resolve). Merge #137 first; then this retargets tomaincleanly.