diff --git a/RPC-Setup-XMLRPC.md b/RPC-Setup-XMLRPC.md index 16ef212..cbecaac 100644 --- a/RPC-Setup-XMLRPC.md +++ b/RPC-Setup-XMLRPC.md @@ -94,6 +94,17 @@ http { Do not forget, that on http://localhost:8008/RPC2 you will not see anything (through in rtorrent.error_log you will see something as `upstream prematurely closed connection while reading response header from upstream, client: 192.168.93.104, server: ngnix-rtorrent, request: "GET /RPC2 HTTP/1.1", upstream: "scgi://127.0.0.1:5000", host: "192.168.93.242:8008"`. It is xmlrpc, not web service. You can test it by xmlrpc (see later)) +**SECURITY NOTE**: use some basic auth, client certificate, SSO or any authentication method. Exemple for basic auth: + +``` + location /RPC2 { + auth_basic "Restricted area"; + auth_basic_user_file /etc/nginx/auth/seedbox_auth; + scgi_pass 127.0.0.1:5000; + include scgi_params; + } +``` + ## Other notes If any of your downloads have non-ascii characters in the filenames, you must also set the following in rtorrent.rc to force rtorrent to use the UTF-8 encoding. The XMLRPC standard requires UTF-8 replies, and rtorrent presently has no facilities to convert between encodings so it might generate invalid replies otherwise.