- docs/hosting.md: LAN vs internet; binding 4533 to 127.0.0.1 behind an
HTTPS proxy (Caddy example, no buffering, long read timeouts for SSE and
streams); the Client IP detection hop count (default 1, so 0 with no
proxy or clients can forge X-Forwarded-For); the public address that
password-reset links need; finding the setup token.
- docs/security.md: sessions, API keys, rate limits, headers and CSP; why
CSRF rests on SameSite=Strict plus JSON-only cookie writes; the Subsonic
password column, including the known issue that admin reset-password
writes the login password there (#5026); why Android allows plain HTTP;
the CI publish gate.
- README: keeps the LAN-first port mapping with a pointer for internet
hosts, scopes "plain http:// is fine" to trusted networks, explains the
setup token in first-run step 1, and links both docs.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>