-
1.1.1 Stable
released this
2026-10-05 22:37:18 +03:00 | 0 commits to main since this releaseRelease 1.1.1
Version 1.1.1 replaces HTTP Basic Authentication with session-based authentication and introduces several authentication, configuration, and web server security improvements.
Session-based authentication
HTTP Basic Authentication has been removed from the web interface.
The web interface now uses server-side sessions with a secure random session identifier stored in an
HttpOnlycookie.After a successful login, the browser receives a session cookie while the server stores the session state and tracks the user's last activity.
Passwords are no longer sent with every HTTP request as they were with HTTP Basic Authentication.
Inactivity timeout
Sessions now support a configurable sliding inactivity timeout.
Example:
web: auth: session_timeout: 30mEvery authenticated request refreshes the session's last activity time.
If no authenticated request is made within the configured period, the session expires and the user is redirected to the login page.
Restarting the application invalidates all existing sessions.
New login page
The web interface now provides a dedicated
/loginpage.Authentication is performed using the username and password configured in
config.yaml.A
/logoutendpoint has also been added for explicitly terminating the current session.Session cookie security
Session cookies use:
HttpOnly SameSite=Strict Path=/HTTPS deployments can additionally enable the
Securecookie flag:web: auth: cookie_secure: trueFor direct HTTP deployments it should remain:
cookie_secure: falseCSRF protection
Logout requests are now protected with a per-session CSRF token.
The CSRF token is generated using cryptographically secure random data and validated before the session can be terminated.
Login rate limiting
Login attempts can now be rate-limited by client IP.
Example configuration:
web: auth: login_max_attempts: 5 login_window: 5m login_lockout: 15mWith this configuration, five failed login attempts within five minutes temporarily block further login attempts from the same IP for fifteen minutes.
Successful authentication resets the failed-attempt counter.
Configuration changes
The previous configuration:
web: basic_auth: enabled: true username: admin password: change-mehas been replaced with:
web: auth: enabled: true username: admin password: change-me session_timeout: 30m cookie_secure: false login_max_attempts: 5 login_window: 5m login_lockout: 15mUsers upgrading from version 1.1.0 must update the
web.basic_authsection toweb.auth.Configuration loading fixes
Configuration loading has been made stricter and safer.
Existing configuration files are no longer initialized from compiled-in default values before YAML parsing.
This fixes an issue where missing, misspelled, or incorrectly structured authentication fields could silently fall back to credentials embedded in the application defaults.
For example, if the configured password is missing or invalid, the application now fails during startup instead of silently using the default password.
Unknown YAML fields are now rejected.
This makes configuration mistakes such as:
basic_auth:instead of:
auth:visible immediately during application startup.
Web server improvements
Web server startup now binds the HTTP listener synchronously.
As a result, errors such as an already occupied HTTP port are detected immediately and returned from application startup instead of only being logged asynchronously.
HTTP shutdown now uses graceful server shutdown with a timeout, allowing active requests to finish before the service stops.
Security improvements
Version 1.1.1 includes the following web authentication improvements:
- server-side sessions;
- cryptographically secure session identifiers;
- sliding inactivity timeout;
- session fixation protection;
HttpOnlysession cookies;SameSite=Strictcookies;- optional
Securecookies for HTTPS; - CSRF-protected logout;
- login rate limiting;
- temporary login lockout;
- strict YAML field validation;
- prevention of silent credential fallback.
Upgrade notes
When upgrading from 1.1.0 to 1.1.1, update the web authentication section in
config.yaml.Old:
web: basic_auth: enabled: true username: admin password: change-meNew:
web: auth: enabled: true username: admin password: change-me session_timeout: 30m cookie_secure: false login_max_attempts: 5 login_window: 5m login_lockout: 15mExisting HTTP Basic Auth browser credentials are no longer used.
Users must authenticate through the new login page after upgrading.
Downloads