diff --git a/config-example.json b/config-example.json index cd2d0fa..a48a64b 100644 --- a/config-example.json +++ b/config-example.json @@ -1,6 +1,8 @@ { "Host": ":8080", "Expvar": true, + "User": "Username", + "Password": "123456", "Apps": [ { "ApplicationDisabled": false, diff --git a/config.go b/config.go index c8a3274..78cd0e9 100644 --- a/config.go +++ b/config.go @@ -8,9 +8,11 @@ import "errors" // The config file type ConfigFile struct { - Host string // The host, eg: :8080 will start on 0.0.0.0:8080 - Expvar bool - Apps []*App + Host string // The host, eg: :8080 will start on 0.0.0.0:8080 + Expvar bool + User string + Password string + Apps []*App } // Error for App not found diff --git a/router.go b/router.go index 52f2b40..b80ca91 100644 --- a/router.go +++ b/router.go @@ -8,7 +8,9 @@ import ( _ "expvar" "net/http" "os" + "strings" + "github.com/goji/httpauth" "github.com/gorilla/handlers" "github.com/gorilla/mux" ) @@ -19,7 +21,11 @@ func NewRouter() *mux.Router { router := mux.NewRouter().StrictSlash(true) if Conf.Expvar { - router.Handle("/debug/vars", http.DefaultServeMux) + if len(strings.TrimSpace(Conf.User)) == 0 || len(strings.TrimSpace(Conf.Password)) == 0 { + panic("Your are exporting debug variables and you are not defining an User and a Password") + } + + router.Handle("/debug/vars", httpauth.SimpleBasicAuth(Conf.User, Conf.Password)(http.DefaultServeMux)) } for _, route := range routes {