diff --git a/src/security.rst b/src/security.rst index 35ab766..b141fb7 100644 --- a/src/security.rst +++ b/src/security.rst @@ -12,7 +12,30 @@ ActivityWatch is only as secure as your system Some things we can't protect against. Examples are malware running on the same host and anything that can access the database file. -As an example, ActivityWatch is not secure on systems with multiple users (due to there being no API authentication). +As an example, ActivityWatch is not secure on systems with multiple users, since the API is unauthenticated by default (see `API authentication`_ below). + + +API authentication +------------------ + +By default, the ActivityWatch API requires no authentication: any process that can reach the server (normally only processes on the same machine, since it listens on ``localhost``) can read, write, and delete all data. + +``aw-server-rust`` supports **opt-in** API key authentication. To enable it, set an API key under the ``[auth]`` section of the server's ``config.toml`` (see `directories ` for its location) and restart the server: + +.. code-block:: toml + + [auth] + api_key = "your-secret-key-here" + +When an API key is set, every request to ``/api/*`` (except ``GET /api/0/info``) must include the header ``Authorization: Bearer ``, otherwise the server responds with ``401 Unauthorized``. An empty ``api_key`` leaves authentication disabled. + +Things to keep in mind: + +- Authentication is disabled by default on desktop, so existing setups keep working unchanged. +- It is only supported by ``aw-server-rust``. ``aw-server`` (Python) does not support it. +- Every client must send the key. ``aw-sync`` reads it from the server config automatically, and ``aw-client-rust`` accepts one via ``AwClient::new_with_api_key``, but other clients and watchers may not support it yet and will fail with ``401`` once it's enabled. +- The key protects the API, not the data at rest: anything that can read the config file or the database file can still access your data. +- Authentication does not make it safe to expose the server on a network. The API is served over plain HTTP, so see `remote-server` before doing so. Deleting sensitive data