Using NasDash
Authentication and Roles
Administrator, readers, public mode, sessions, and allowlists.
NasDash has an administrator and readers. The administrator configures the instance and accesses sensitive data. A reader receives a server-side filtered configuration.
Access Model
- Administrator: settings, secrets, mutations, and authorized actions.
- Private Reader: login required, access based on their allowlist.
- Public Reader: instance viewable without login if public mode is enabled, with filtered data.
Allowlists can restrict categories, locations, Docker hosts, devices, and other resources. Always test with a real reader account: hiding a button in the interface is not an authorization validation.
Environment Secrets
Initial passwords and the JWT key are described in Environment Variables. Replace all example values before network exposure.
NASDASH_JWT_SECRET Rotation
Changing the JWT key invalidates sessions. Plan the rotation and keep the new value stable.