Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Offical apps | Community apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Feature Requests
  3. Security.txt in APP Konfigurator

Security.txt in APP Konfigurator

Scheduled Pinned Locked Moved Feature Requests
9 Posts 5 Posters 5.5k Views 5 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    S
    savity
    wrote on last edited by savity
    #1

    Hi Everyone,

    since security.txt is a https://www.rfc-editor.org/rfc/rfc9116 is there a way to get this done for my APPs?
    We are able to modify robots.txt but it would be awesome to do this for security.txt
    BR Savity

    1 Reply Last reply
    6
    • nebulonN
      nebulonN
      nebulon
      Staff
      wrote on last edited by
      #2

      Not sure I fully understand the RFC there, but this sounds more like the app itself should ship such a file so researchers discovering a security issue can contact the app authors to let them know?

      1 Reply Last reply
      2
      • S
        S
        savity
        wrote on last edited by
        #3

        The goal is to provide a way for individuals and teams to report any vulnerabilities found on the website or in the application. For example, this can be set up similarly to the following pages:

        https://www.brz.gv.at/security.txt
        https://www.bsi.bund.de/security.txt

        This approach allows for flexibility in addressing vulnerabilities; they do not always need to be limited to the application side alone.

        1 Reply Last reply
        0
        • nebulonN
          nebulonN
          nebulon
          Staff
          wrote on last edited by
          #4

          I guess we can add this in the app configure section if there is some interest.
          Some more context is at https://securitytxt.org/

          M 1 Reply Last reply
          7
          • J
            J
            johannesjom
            wrote on last edited by
            #5

            That would be a very cool feature!

            1 Reply Last reply
            1
            • nebulonN nebulon

              I guess we can add this in the app configure section if there is some interest.
              Some more context is at https://securitytxt.org/

              M
              M
              msbt
              App Dev
              wrote last edited by
              #6

              @nebulon was that ever implemented or considered? In case of a LAMP app, would it be wise to just create the directory on the server and put the file there like it was suggested here

              Happy Hosting & Web Development

              1 Reply Last reply
              1
              • nebulonN
                nebulonN
                nebulon
                Staff
                wrote last edited by
                #7

                no work was done here, it is still not clear to me if really the platform should provide this, as any security report would mostly be towards the app developers, not the one running the app I would assume.

                For a lamp app instance or also a surfer website, one can just put a file called security.txt there or am I missing something?

                1 Reply Last reply
                0
                • girishG
                  girishG
                  girish
                  Staff
                  wrote last edited by
                  #8

                  I added this a while ago for cloudron.io itself since we get almost one issue everyday from bounty hackers...

                  https://www.cloudron.io/security.html and https://www.cloudron.io/.well-known/security.txt . The security.txt is not top level but in well-known afaik. Let me know if this is wrong!

                  .well-known is not overwritten by the platform so you can just add it to the app itself (and thus part of your version control).

                  M 1 Reply Last reply
                  1
                  • girishG girish

                    I added this a while ago for cloudron.io itself since we get almost one issue everyday from bounty hackers...

                    https://www.cloudron.io/security.html and https://www.cloudron.io/.well-known/security.txt . The security.txt is not top level but in well-known afaik. Let me know if this is wrong!

                    .well-known is not overwritten by the platform so you can just add it to the app itself (and thus part of your version control).

                    M
                    M
                    msbt
                    App Dev
                    wrote last edited by
                    #9

                    @girish thanks, yeah that's what I've done, I was just not sure if you would consider that best practice of if it gets overridden at some point by some other setting in the platform-code 😉

                    Happy Hosting & Web Development

                    1 Reply Last reply
                    0

                    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                    With your input, this post could be even better 💗

                    Register Login
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Don't have an account? Register

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • Bookmarks
                    • Search