Jump to content

block user authentication with Cloudflare Zone lockdown


horstepipe

Recommended Posts

horstepipe

Hey

I'm using Cloudflare's Zone Lockdown feature to make the login page of my emby server inaccessible by locking this url:

embydomain.com/web/login.html*

As all my users run Kodi and are logged in anyway, this is (hopefully) an easy way to prevent bruteforce attacks on the login page.

 

So what I'm wondering about is that authentication in Kodi is still possible with this rule active. So in Kodi I still see the login screen, can enter username and password and login.

This seems to be true because Kodi uses another method to authenticate.

Anybody can assist me telling me what url to block to don't make Kodi devices able to authenticate, either?

Edited by horstepipe
Link to comment
Share on other sites

Jdiesel

Why not just block *embydomain.com* for all undesirable regions? Is there any specific reason for just blocking the login page versus the entire domain?

Link to comment
Share on other sites

horstepipe

Why not just block *embydomain.com* for all undesirable regions? Is there any specific reason for just blocking the login page versus the entire domain?

I'm also blocking all countries except mine for the whole domain, yes.

But it feels more save to make the login page completely inaccessible (even from my region)

Link to comment
Share on other sites

horstepipe

okay got it:

embydomain.com/emby/Users/AuthenticateByName*

I'll report back if it breaks something else :-)

Edited by horstepipe
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...