• radar@programming.dev
    link
    fedilink
    English
    arrow-up
    29
    ·
    2 days ago

    Reverse proxy doesn’t really get you much security. If there is an application level issue a reverse proxy will not help

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      18 hours ago

      well, at least you are not depending on the application to do TLS properly, and you may be able to set up some access restrictions that your clients may support

    • whimsy@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      Hmmm, I’m a bit rusty on this but can’t one put an auth gate in front of the application, handled by the reverse proxy?

      • radar@programming.dev
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        You can, that would actually give you security. Not sure how many people do that. I assumed a straight reverse proxy without any auth