diff --git a/src/api/rest.rst b/src/api/rest.rst index 5693938..d89b9c3 100644 --- a/src/api/rest.rst +++ b/src/api/rest.rst @@ -24,7 +24,7 @@ REST Security ------------- .. note:: - Our current security consists only of not allowing non-localhost connections, this is likely to be the case for quite a while. + By default, the server only listens on localhost and the API requires no authentication. aw-server-rust supports opt-in API key authentication: when enabled, requests must include an ``Authorization: Bearer `` header. See :doc:`../security` for details. Clients might in the future be able to have read-only or append-only access to buckets, providing additional security and preventing compromised clients from being able to cause a severe security breach. All clients will probably also encrypt data in transit. diff --git a/src/configuration.rst b/src/configuration.rst index 022b2a1..1c7fafd 100644 --- a/src/configuration.rst +++ b/src/configuration.rst @@ -13,17 +13,26 @@ Configuration options for the server, client, and default watchers are listed be aw-server-python ---------------- -- ``host`` Hostname to start the server on. Currently only ``localhost`` or ``127.0.0.1`` are supported. +These settings go under the ``[server]`` section of ``aw-server/aw-server.toml``. + +- ``host`` Address to bind the server to. The default is ``localhost``. Binding to any other address exposes the server to the network, see :doc:`remote-server`. - ``port`` Port number to start the server on. -- ``storage`` Type of storage for holding buckets and events. Supported types are ``peewee``, ``memory`` (useful in testing), or ``mongodb`` (MongoDB support will be removed in a future version). +- ``storage`` Type of storage for holding buckets and events. Supported types are ``peewee`` (the default), ``sqlite``, or ``memory`` (useful in testing). - ``cors_origins`` Comma-separated list of allowed origins for CORS (Cross-Origin Resource Sharing). Useful in testing and development to let other origins access the ActivityWatch API, such as aw-webui in development mode on port 27180. +- ``query_cache`` Whether to cache query results for finished past periods in memory. The default is ``true``. +- ``custom_static`` A table under ``[server.custom_static]`` mapping watcher names to directories containing their :doc:`custom visualizations `. aw-server-rust -------------- -- ``host`` Hostname to start the server on. Currently only ``localhost`` or ``127.0.0.1`` are supported. +These settings go at the top level of ``aw-server-rust/config.toml`` (there is no ``[server]`` section). + +- ``address`` Address to bind the server to. The default is ``127.0.0.1``. Binding to any other address exposes the server to the network, see :doc:`remote-server`. - ``port`` Port number to start the server on. - ``cors`` List of allowed origins for CORS (Cross-Origin Resource Sharing). Useful in testing and development to let other origins access the ActivityWatch API, such as aw-webui in development mode on port 27180. +- ``cors_regex`` List of regular expressions matching additional allowed CORS origins. +- ``custom_static`` A table mapping watcher names to directories containing their :doc:`custom visualizations `. +- ``api_key`` Under an ``[auth]`` section: an optional API key that clients must send to access the API. Authentication is disabled when it is unset, see :doc:`security`. aw-client --------- diff --git a/src/getting-started.rst b/src/getting-started.rst index 5acec25..66fb7a3 100644 --- a/src/getting-started.rst +++ b/src/getting-started.rst @@ -28,10 +28,7 @@ Installation .. group-tab:: Android - Install it from the `Play Store `_ or using the APK from the `aw-android releases page `_. - - .. note:: - Getting it to F-droid is a work-in-progress, see `this PR `_. + Install it from the `Play Store `_, `F-Droid `_, or using the APK from the `aw-android releases page `_. Usage diff --git a/src/remote-server.rst b/src/remote-server.rst index 3b4ce33..61da345 100644 --- a/src/remote-server.rst +++ b/src/remote-server.rst @@ -20,7 +20,7 @@ There are several reasons why we won't support and strongly discourage this: - It is **not secure**. - - There is no API security, so exposing the server on the network will let *anyone* on the network read, write, or delete **all data**. + - The API is unauthenticated by default, so exposing the server on the network will let *anyone* on the network read, write, or delete **all data**. aw-server-rust supports an opt-in API key (see :doc:`security`), but it is sent in plain text along with everything else. - There is no HTTPS support, so all data would be sent unencrypted. - We want ActivityWatch to be **user-first**: something people use of their own will, not something forced on them by others (bosses, colleagues). @@ -67,11 +67,17 @@ Opening the server to the network If you decide to not heed our warning, you can open the server to the network by setting the following :doc:`configuration`: -aw-server.toml:: +For aw-server-python, ``aw-server/aw-server.toml``:: [server] - address = "0.0.0.0" # or the IP address of your network interface of choice - cors_origins = "*" # or a list of allowed origins, e.g. "http://:5600" + host = "0.0.0.0" # or the IP address of your network interface of choice + cors_origins = "*" # or a comma-separated list of allowed origins, e.g. "http://:5600" + # leave other settings as-is + +For aw-server-rust, ``aw-server-rust/config.toml`` (top-level keys, no ``[server]`` section):: + + address = "0.0.0.0" # or the IP address of your network interface of choice + cors = ["http://:5600"] # exact allowed origins # leave other settings as-is To then redirect events from local watchers to that server, you can use the following client configuration: