Software Alternatives & Reviews

qBittorrent API is accessible regardless of username/password. Huge security concern.

authentik Caddy
  1. authentik is an open-source identity provider focused on flexibility and versatility.
    Pricing:
    • Open Source
    However, this app is able to authenticate and control qBit regardless of the webui username and password supplied; all it needs is the URL (qbittorrent.example.com) and it has full access. This is a huge security concern as this is a public facing service, and anyone with this url would be able to interact with my qBit instance, regardless of the fact that I'm protecting it with an authentication system.

    #Identity And Access Management #Identity Provider #SSO 41 social mentions

  2. 2
    The HTTP/2 Web Server with Automatic HTTPS
    Pricing:
    • Open Source
    I have a reverse proxy that points to the qBittorrent webui via a subdomain (qbittorrent.example.com, handled by a webserver not qBit). I'm using an app that takes this URL plus the webui credentials to interact with the qBittorrent API, so I can manage my torrents and media library all via this single app (nzb360).

    #Web Servers #HTTP/2 Web Server #Web And Application Servers 226 social mentions

Discuss: qBittorrent API is accessible regardless of username/password. Huge security concern.

Log in or Post with