you are viewing a single comment's thread
view the rest of the comments
[–] 5 points 5 months ago

there is just too much place in the codebase for vulnerabilities, and also, most projects like this are maintained by volunteers in their free time for free.

I guess if you set up an IP whitelist in the reverse proxy, or a client TLS certificate requirement, it's fine to open it to the internet, but otherwise no.

  • source
  • parent