Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/api/rest.rst
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ REST Security
-------------

.. note::
Our current security consists only of not allowing non-localhost connections, this is likely to be the case for quite a while.
By default, the server only listens on localhost and the API requires no authentication. aw-server-rust supports opt-in API key authentication: when enabled, requests must include an ``Authorization: Bearer <api_key>`` header. See :doc:`../security` for details.

Clients might in the future be able to have read-only or append-only access to buckets, providing additional security and preventing compromised clients from being able to cause a severe security breach.
All clients will probably also encrypt data in transit.
Expand Down
15 changes: 12 additions & 3 deletions src/configuration.rst
Original file line number Diff line number Diff line change
Expand Up @@ -13,17 +13,26 @@ Configuration options for the server, client, and default watchers are listed be
aw-server-python
----------------

- ``host`` Hostname to start the server on. Currently only ``localhost`` or ``127.0.0.1`` are supported.
These settings go under the ``[server]`` section of ``aw-server/aw-server.toml``.

- ``host`` Address to bind the server to. The default is ``localhost``. Binding to any other address exposes the server to the network, see :doc:`remote-server`.
- ``port`` Port number to start the server on.
- ``storage`` Type of storage for holding buckets and events. Supported types are ``peewee``, ``memory`` (useful in testing), or ``mongodb`` (MongoDB support will be removed in a future version).
- ``storage`` Type of storage for holding buckets and events. Supported types are ``peewee`` (the default), ``sqlite``, or ``memory`` (useful in testing).
- ``cors_origins`` Comma-separated list of allowed origins for CORS (Cross-Origin Resource Sharing). Useful in testing and development to let other origins access the ActivityWatch API, such as aw-webui in development mode on port 27180.
- ``query_cache`` Whether to cache query results for finished past periods in memory. The default is ``true``.
- ``custom_static`` A table under ``[server.custom_static]`` mapping watcher names to directories containing their :doc:`custom visualizations <watchers>`.

aw-server-rust
--------------

- ``host`` Hostname to start the server on. Currently only ``localhost`` or ``127.0.0.1`` are supported.
These settings go at the top level of ``aw-server-rust/config.toml`` (there is no ``[server]`` section).

- ``address`` Address to bind the server to. The default is ``127.0.0.1``. Binding to any other address exposes the server to the network, see :doc:`remote-server`.
- ``port`` Port number to start the server on.
- ``cors`` List of allowed origins for CORS (Cross-Origin Resource Sharing). Useful in testing and development to let other origins access the ActivityWatch API, such as aw-webui in development mode on port 27180.
- ``cors_regex`` List of regular expressions matching additional allowed CORS origins.
- ``custom_static`` A table mapping watcher names to directories containing their :doc:`custom visualizations <watchers>`.
- ``api_key`` Under an ``[auth]`` section: an optional API key that clients must send to access the API. Authentication is disabled when it is unset, see :doc:`security`.

aw-client
---------
Expand Down
5 changes: 1 addition & 4 deletions src/getting-started.rst
Original file line number Diff line number Diff line change
Expand Up @@ -28,10 +28,7 @@ Installation

.. group-tab:: Android

Install it from the `Play Store <https://play.google.com/store/apps/details?id=net.activitywatch.android>`_ or using the APK from the `aw-android releases page <https://github.com/ActivityWatch/aw-android/releases>`_.

.. note::
Getting it to F-droid is a work-in-progress, see `this PR <https://gitlab.com/fdroid/fdroiddata/-/merge_requests/5502>`_.
Install it from the `Play Store <https://play.google.com/store/apps/details?id=net.activitywatch.android>`_, `F-Droid <https://f-droid.org/packages/net.activitywatch.android/>`_, or using the APK from the `aw-android releases page <https://github.com/ActivityWatch/aw-android/releases>`_.


Usage
Expand Down
14 changes: 10 additions & 4 deletions src/remote-server.rst
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ There are several reasons why we won't support and strongly discourage this:

- It is **not secure**.

- There is no API security, so exposing the server on the network will let *anyone* on the network read, write, or delete **all data**.
- The API is unauthenticated by default, so exposing the server on the network will let *anyone* on the network read, write, or delete **all data**. aw-server-rust supports an opt-in API key (see :doc:`security`), but it is sent in plain text along with everything else.
- There is no HTTPS support, so all data would be sent unencrypted.

- We want ActivityWatch to be **user-first**: something people use of their own will, not something forced on them by others (bosses, colleagues).
Expand Down Expand Up @@ -67,11 +67,17 @@ Opening the server to the network

If you decide to not heed our warning, you can open the server to the network by setting the following :doc:`configuration`:

aw-server.toml::
For aw-server-python, ``aw-server/aw-server.toml``::

[server]
address = "0.0.0.0" # or the IP address of your network interface of choice
cors_origins = "*" # or a list of allowed origins, e.g. "http://<remote IP>:5600"
host = "0.0.0.0" # or the IP address of your network interface of choice
cors_origins = "*" # or a comma-separated list of allowed origins, e.g. "http://<remote IP>:5600"
# leave other settings as-is

For aw-server-rust, ``aw-server-rust/config.toml`` (top-level keys, no ``[server]`` section)::

address = "0.0.0.0" # or the IP address of your network interface of choice
cors = ["http://<remote IP>:5600"] # exact allowed origins
# leave other settings as-is

To then redirect events from local watchers to that server, you can use the following client configuration:
Expand Down
Loading