|
|
|
|
|
by rekoil
1012 days ago
|
|
No what I'm talking about here is the unauthenticated JSON-based configuration API that hosts itself on port 2019 on localhost of the machine that runs Caddy. This is unrelated to sites hosted using HTTP. I was clumsily using the term "HTTP" to refer to the fact that this configuration mechanism is based on HTTP-communication. |
|
Seems counter to their objective of having secure defaults.
[0] https://caddyserver.com/docs/api#post-stop