Files
dashcaddy/dashcaddy-api
Hermes e40cb35011
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
Add MONITORING_PUBLIC env var to gate monitoring endpoints behind auth
By default /api/v1/monitoring/stats and /api/v1/health-checks/status are
public (current behavior, dashboard needs them pre-login). Users deploying
DashCaddy on the open internet can now set:

  MONITORING_PUBLIC=false

...or add 'monitoring: { public: false }' to config.json to require auth.
This prevents anonymous disclosure of CPU/memory/disk data.

The check uses env var first, then config.json, then defaults to true
(preserves current behavior for existing users).
2026-06-10 20:13:53 -07:00
..
2026-06-10 20:06:09 -07:00
2026-06-10 20:06:09 -07:00
2026-03-05 02:26:12 -08:00
2026-03-05 02:26:12 -08:00
2026-03-29 18:46:02 -07:00
2026-03-29 18:46:02 -07:00
2026-03-05 02:26:12 -08:00
2026-03-05 02:26:12 -08:00