Jump to content

Yet another server test to defeat.... :-)


Recommended Posts

Posted

Yes we can remove that script tag.

  • Like 1
pir8radio
Posted

Yes we can remove that script tag.

 

Cool,  thanks for even considering it!   I suspect emby will head down the Content Security Policy road one day anyway, this will help when you do..  Inline scripts are the easiest way to get into a website, the CSP will block all inline scripts to secure the page, and that's all we are trying to do here.. 

pir8radio
Posted (edited)

I've added a CSP to the test version here:

https://emby.media/community/index.php?/topic/61079-3603-db-changes/

 

Thanks.

 

wow, that's risky buddy..    :)   Great now I'm going to have to download the new beta... lol  I was holding off a bit, because I didn't want to be stuck in a particular database scheme if you were changing it again.   I'm scared......... But I guess I'll make the move.   What is still not working in that beta?

Edited by pir8radio
  • Like 1
Posted

Just try it standalone and there's nothing to worry about.

pir8radio
Posted

Just try it standalone and there's nothing to worry about.

 

Can i run the stand alone side by side without them screwing with each others DB?   I would like to run it looking at the same media so i can compare db speeds...  

Posted

When I added CSP to my domain it really did a number on emby loading. But I look forward to it being implement Ed by professionals.

Posted

I'm probably going to just remove it because it will just be unnecessary troubleshooting coming our way.

pir8radio
Posted (edited)

I'm probably going to just remove it because it will just be unnecessary troubleshooting coming our way.

 

Yea, I would wait to go full on CSP built into emby.    But you can still get rid of that one inline script lol      Let us fine tune the CSP in our proxy then move toward implementing it later.

Edited by pir8radio
pir8radio
Posted

Another thing you need to add to your CSP's is mb3admin  

 

I'm starting to get complaints from end users that their client is asking them to register emby.   This is because the clients cant "phone home" to emby to confirm the servers device count and what not.      Ill add this to mine and test..  I'll add a CSP forum post to cover everything.   We can test and hopefully one day hand off to luke a working and painless CSP. 

Posted

Also some clients get on the regular 'a stream unavailable' message

pir8radio
Posted

Also some clients get on the regular 'a stream unavailable' message

i have not seen this.  what clients?  

Posted

i have not seen this.  what clients?  

2 different clients on latest chrome.

 

 

I personally never run into any real emby problems, and i typically check on all the clients i have available (nvidia shield with emby app, kodi, chrome mobilephone, chrome pc).  Since i am fairly new to all of this i adopted the following methodology when i change something on my reverse proxy, by now i have a fairly complex HAproxy on Pfsense config, not sure if someone would benefit from it.

mb.doman.org            ->      haproxy (passes both domain to the backend, each domain can pass different configurations)    ->      same backend
mbtest.domain.org  
  • 4 weeks later...
Posted

@@pir8radio

 

May i ask what your setup is?

 

do you run a firewall and if so which ?

 

For me its

 

wan -> pfsense + haproxy package -> emby server

pir8radio
Posted (edited)

@@pir8radio

 

May i ask what your setup is?

 

do you run a firewall and if so which ?

 

For me its

 

wan -> pfsense + haproxy package -> emby server

 

WAN--Cloudflare------Firewall--nginx--emby        The firewall defaults to block all except TCP 80 & 443  

Edited by pir8radio
pir8radio
Posted

Which Firewall are you using

 

It's always good to keep that info private.. lol     :ph34r:

  • Like 1
Posted

Would you mind sending me a pm so I can copy your setup :D

Posted

i have similar to pir8radio.

 

wan - cloudflare - IPS - Firewall - nginx - servers

Posted

This is awesome information. I just tested my server and I got an F, lol. Looks like I will be digging into this tonight.

  • 4 weeks later...
Posted

WAN--Cloudflare------Firewall--nginx--emby        The firewall defaults to block all except TCP 80 & 443  

 

Hey, may i ask what cloudflare settings you use, i.e. flexible full or full strict, or do you just use it as a dns ?

pir8radio
Posted

Hey, may i ask what cloudflare settings you use, i.e. flexible full or full strict, or do you just use it as a dns ?

 

you mean under crypto?  Full.  Had to go with full because of how I hide my origin server..   :)

Posted

you mean under crypto? Full. Had to go with full because of how I hide my origin server.. :)

OK, thanks.

Posted

Made it to an A+ also, without loss of connectivity..

.5bcf37e0a9128_aplusbfhmedia.png

  • Like 1
  • 1 year later...
jachin99
Posted

Are you all making changes directly to the web app, or are you all using proxies?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...