Windows:
choco install mkcertmacOS:
brew install mkcertLinux:
# See HTTPS_MKCERT_GUIDE.md for detailed instructionsWindows:
setup-https-mkcert.batLinux/Mac:
bash setup-https-mkcert.shdocker-compose -f docker-compose.yml -f docker-compose.https.yml up -dhttps://localhost
https://192.168.1.100 (your actual IP)
β No certificate warnings! β Works with IP addresses! β Secure HTTPS!
- β Installs local Certificate Authority (trusted by your browser)
- β Generates SSL certificates for localhost + your IP
- β Creates nginx reverse proxy configuration
- β Creates docker-compose.https.yml
- β
Updates .env with secure HTTPS settings:
WTF_CSRF_SSL_STRICT=trueSESSION_COOKIE_SECURE=trueCSRF_COOKIE_SECURE=true
- β CSRF cookies work correctly with IP addresses
- β Strict security settings enabled
- β No more "CSRF token missing or invalid" errors
- β All traffic encrypted
- β Trusted certificates (no warnings)
- β Modern TLS 1.2/1.3
- β One command setup
- β Valid for 10 years
- β No renewal needed
To access from your phone, tablet, or other computers without warnings:
-
Find CA location:
mkcert -CAROOT
-
Copy
rootCA.pemto device -
Install certificate on device:
- iOS: Settings β Profile β Install
- Android: Settings β Security β Install certificate
- See HTTPS_MKCERT_GUIDE.md for details
-
Access from device:
https://192.168.1.100
After running the setup:
TimeTracker/
βββ nginx/
β βββ conf.d/
β β βββ https.conf # nginx HTTPS config
β βββ ssl/
β βββ cert.pem # SSL certificate (gitignored)
β βββ key.pem # Private key (gitignored)
βββ docker-compose.yml # Base configuration
βββ docker-compose.https.yml # HTTPS override (auto-generated)
βββ setup-https-mkcert.sh # Linux/Mac setup script
βββ setup-https-mkcert.bat # Windows setup script
βββ .env # Updated with HTTPS settings
- Navigate to
https://localhost - Click padlock icon in browser
- View certificate β Should show "mkcert" with no warnings
- Open DevTools (F12) β Application β Cookies
- Verify
sessionandXSRF-TOKENcookies haveSecureflag
- Login
- Create a project
- Log time
- Should work without any CSRF errors β
To return to HTTP:
# Stop HTTPS setup
docker-compose -f docker-compose.yml -f docker-compose.https.yml down
# Start normally
docker-compose up -d# Reinstall CA
mkcert -install
# Restart browser completely# Check if port is in use
netstat -ano | findstr :443 # Windows
lsof -i :443 # Linux/Mac
# Check logs
docker-compose logs nginx# Regenerate with correct IP
mkcert -key-file nginx/ssl/key.pem -cert-file nginx/ssl/cert.pem \
localhost 127.0.0.1 ::1 YOUR_ACTUAL_IP *.local
# Restart
docker-compose restart nginxFor detailed instructions, see:
- HTTPS_MKCERT_GUIDE.md - Complete mkcert guide
- CSRF_IP_ACCESS_FIX.md - CSRF troubleshooting
One command to HTTPS:
bash setup-https-mkcert.sh
docker-compose -f docker-compose.yml -f docker-compose.https.yml up -dResult:
β
Secure HTTPS
β
No certificate warnings
β
Works with IP addresses
β
CSRF cookies work perfectly
β
Production-grade security settings
Enjoy secure TimeTracker! π