Using NasDash

Authentication and Roles

Administrator, readers, public mode, sessions, and allowlists.

NasDash has an administrator and readers. The administrator configures the instance and accesses sensitive data. A reader receives a server-side filtered configuration.

Access Model

  • Administrator: settings, secrets, mutations, and authorized actions.
  • Private Reader: login required, access based on their allowlist.
  • Public Reader: instance viewable without login if public mode is enabled, with filtered data.

Allowlists can restrict categories, locations, Docker hosts, devices, and other resources. Always test with a real reader account: hiding a button in the interface is not an authorization validation.

Environment Secrets

Initial passwords and the JWT key are described in Environment Variables. Replace all example values before network exposure.

NASDASH_JWT_SECRET Rotation

Changing the JWT key invalidates sessions. Plan the rotation and keep the new value stable.