Security
Configure local login, session duration, session cleanup, Plex sign-in, and trusted reverse proxies.
Last updated
Was this helpful?
Configure local login, session duration, session cleanup, Plex sign-in, and trusted reverse proxies.
Use this page to control who can sign in and how CW handles sessions.
Set the local CW admin username used on the login page.
Set a new local CW password.
Leave this blank to keep the current password
Minimum length: 8
Repeat the new password exactly.
CW will not save if the password fields do not match.

Choose how long the login session lasts.
Enabled — keeps you signed in for the number of days you choose
Browser session only — signs you out when the browser fully closes
This only affects the CW web session.
It does not change provider tokens.
Set how long a remembered session stays valid.
Only used when Session caching is enabled
Range: 1 to 365

Plex sign-in is optional.
It adds Sign in with Plex to the login page.
Your local CW username and password stay as the fallback sign-in method.
Actions:
Link Plex account — link one Plex account for web sign-in
Unlink — remove Plex sign-in from the login page
Related: Plex SSO.
This section shows the browser session you are currently using to access CW. If your account has other active browser sessions, CW shows those separately so it is clear which session is current and which sessions are not.
Use Log out to end only the session for the browser you are using right now.

If the same account is signed in from other browsers or devices, CW shows a compact summary of those sessions here.
Use Log out other sessions to sign out every other active browser session while keeping your current browser signed in. This is useful when you want to remove stale, duplicate, or forgotten logins without signing yourself out.

Use this only when CW sits behind a reverse proxy and you want correct client IP handling for login protection and rate limiting.
Enter proxy IP addresses or CIDR ranges separated by ;.
Example:
Add the proxy server IPs here.
Do not add the IPs of end users connecting through the proxy.
Last updated
Was this helpful?
Was this helpful?
127.0.0.1;192.168.2.1;192.168.2.0/16