3. Baota Panel: Remove the Site-Wide Gate (Recommended)
The trial must be public, but dozens of workspace pages sit behind the gate; whitelisting them one by one is impractical.Recommended: make the whole site public and keep passwords only for admin pages.
- → → shipstrade.com.cn → Settings → Configuration Files
- server
auth_basic& auth_basic_user_filetwo lines,user_file, then delete these two lines or add #comments - server server_nameSecurity Hardening RulesPHP location PHP
# ===== PHP location =====
location = /ship-accounts.json { deny all; } # Account data (incl. plaintext passwords): download prohibited
location = /shared-notices.json { deny all; } # Notice data: direct download prohibited
location ~ ^/uploads/.*\.php$ { deny all; } # PHP webshell- server
}before) paste the content below,replace the path with the actual path copied in Step 2
# ===== Encrypt admin pages only (rest of site public) =====
location = /hq-admin.html { auth_basic "Restricted"; auth_basic_user_file /www/server/panel/vhost/nginx/.htpasswd; }
location = /orders-admin.html { auth_basic "Restricted"; auth_basic_user_file /www/server/panel/vhost/nginx/.htpasswd; }
location = /site-config-admin.html { auth_basic "Restricted"; auth_basic_user_file /www/server/panel/vhost/nginx/.htpasswd; }
location = /ship-mgmt-dept.html { auth_basic "Restricted"; auth_basic_user_file /www/server/panel/vhost/nginx/.htpasswd; }
location = /ship-setup.html { auth_basic "Restricted"; auth_basic_user_file /www/server/panel/vhost/nginx/.htpasswd; }- nginx → → Nginx
⚠ If you still want to keep the site-wide gate: you can also use location = /login.html { auth_basic off; }to allow pages one by one, but with 60+ workspace pages something will be missed and visitors will still hit 401 — strongly not recommended.
🔒 Why hardening is mandatory:Verified in testing: upload.phpPHPship-accounts.jsonit stores all ship names + plaintext passwords; without protection they will leak once the gate is removed;notices-api.phpthe publish API has no validation, so anyone could post notices. The three hardening rules take 5 minutes; skipping them leaves the site exposed.
4. Verify After Upload (Use an Incognito Window)
⚠ Your own browser has saved the gate password, so pages won't prompt 401 and you can't test the real visitor experience. Use Chrome/EdgeWiFi
- an incognito window
https://shipstrade.com.cn/trial.html→ enter ship name + email → activate - The page shows ship name + password + 7-day validity
- Click "🔐 Login to Workspace Now" → login pageShip name auto-filled
- Enter password → click "⛵ Board" → enter the workspace (no more 401, no more silent failure)
- Click through several role pages, folders and notices to confirm they work
✓ Acceptance: no 401 popups, no errors; failed logins show clear messages like "wrong password / ship name not registered".