Create a minimal Flask application configured for Tor hosting. The key considerations are binding to localhost only and avoiding any external requests that could leak your IP:
# app.py - Flask app for Tor hidden service
from flask import Flask, request
import os
app = Flask(__name__)
# Security configuration
app.config['SECRET_KEY'] = os.urandom(32)
app.config['SESSION_COOKIE_HTTPONLY'] = True
app.config['SESSION_COOKIE_SAMESITE'] = 'Strict'
# Never trust proxy headers on Tor
app.config['PREFERRED_URL_SCHEME'] = 'http'
@app.route('/')
def index():
return 'Welcome to my .onion site'
@app.after_request
def security_headers(response):
response.headers['X-Content-Type-Options'] = 'nosniff'
response.headers['X-Frame-Options'] = 'SAMEORIGIN'
response.headers['Referrer-Policy'] = 'no-referrer'
# Remove server header
response.headers.pop('Server', None)
return response
if __name__ == '__main__':
app.run(host='127.0.0.1', port=5000)The after_request decorator adds security headers to every response and strips the Server header to prevent framework fingerprinting. Binding to 127.0.0.1 ensures the app only accepts connections from the local Tor daemon via the reverse proxy.