Security

You can modify the following security settings for Synology Unified Controller at Control Panel > Security > Security:

  • Logout timer (minutes): Users will be automatically logged out from Synology Unified Controller if they are inactive for the time period specified here. Enter any value from 1 to 65535.
  • Enhance browser compatibility by skipping IP checking: If you access Synology Unified Controller through an HTTP proxy and encounter random logouts, you can enable this option to skip IP checking.
  • Improve protection against cross-site request forgery attacks: This option enhances the system's protection against cross-site scripting attacks. This option will take effect the next time you log in.
  • Improve security with HTTP Content Security Policy (CSP) header: This option enhances the system's security against cross-site scripting (XSS) attacks by allowing only data from trusted sources and restricting inline script execution.
  • Do not allow Synology Unified Controller to be embedded with iFrame: You can enable this option to restrict other websites from embedding Synology Unified Controller into other web pages with iFrame, thus preventing certain types of attacks from malicious websites. Specific websites can be allowed to embed Synology Unified Controller with iFrame by clicking the button Allowed websites.
  • Show notification on Synology Unified Controller desktop when the current IP changes: When the IP of a currently connected user changes, send desktop notification to that user.