• 1.1.1 b1cd985720

    1.1.1 Stable

    astelm released this 2026-10-05 22:37:18 +03:00 | 0 commits to main since this release

    Release 1.1.1

    Version 1.1.1 replaces HTTP Basic Authentication with session-based authentication and introduces several authentication, configuration, and web server security improvements.

    Session-based authentication

    HTTP Basic Authentication has been removed from the web interface.

    The web interface now uses server-side sessions with a secure random session identifier stored in an HttpOnly cookie.

    After a successful login, the browser receives a session cookie while the server stores the session state and tracks the user's last activity.

    Passwords are no longer sent with every HTTP request as they were with HTTP Basic Authentication.

    Inactivity timeout

    Sessions now support a configurable sliding inactivity timeout.

    Example:

    web:
      auth:
        session_timeout: 30m
    

    Every authenticated request refreshes the session's last activity time.

    If no authenticated request is made within the configured period, the session expires and the user is redirected to the login page.

    Restarting the application invalidates all existing sessions.

    New login page

    The web interface now provides a dedicated /login page.

    Authentication is performed using the username and password configured in config.yaml.

    A /logout endpoint has also been added for explicitly terminating the current session.

    Session cookie security

    Session cookies use:

    HttpOnly
    SameSite=Strict
    Path=/
    

    HTTPS deployments can additionally enable the Secure cookie flag:

    web:
      auth:
        cookie_secure: true
    

    For direct HTTP deployments it should remain:

    cookie_secure: false
    

    CSRF protection

    Logout requests are now protected with a per-session CSRF token.

    The CSRF token is generated using cryptographically secure random data and validated before the session can be terminated.

    Login rate limiting

    Login attempts can now be rate-limited by client IP.

    Example configuration:

    web:
      auth:
        login_max_attempts: 5
        login_window: 5m
        login_lockout: 15m
    

    With this configuration, five failed login attempts within five minutes temporarily block further login attempts from the same IP for fifteen minutes.

    Successful authentication resets the failed-attempt counter.

    Configuration changes

    The previous configuration:

    web:
      basic_auth:
        enabled: true
        username: admin
        password: change-me
    

    has been replaced with:

    web:
      auth:
        enabled: true
        username: admin
        password: change-me
        session_timeout: 30m
        cookie_secure: false
        login_max_attempts: 5
        login_window: 5m
        login_lockout: 15m
    

    Users upgrading from version 1.1.0 must update the web.basic_auth section to web.auth.

    Configuration loading fixes

    Configuration loading has been made stricter and safer.

    Existing configuration files are no longer initialized from compiled-in default values before YAML parsing.

    This fixes an issue where missing, misspelled, or incorrectly structured authentication fields could silently fall back to credentials embedded in the application defaults.

    For example, if the configured password is missing or invalid, the application now fails during startup instead of silently using the default password.

    Unknown YAML fields are now rejected.

    This makes configuration mistakes such as:

    basic_auth:
    

    instead of:

    auth:
    

    visible immediately during application startup.

    Web server improvements

    Web server startup now binds the HTTP listener synchronously.

    As a result, errors such as an already occupied HTTP port are detected immediately and returned from application startup instead of only being logged asynchronously.

    HTTP shutdown now uses graceful server shutdown with a timeout, allowing active requests to finish before the service stops.

    Security improvements

    Version 1.1.1 includes the following web authentication improvements:

    • server-side sessions;
    • cryptographically secure session identifiers;
    • sliding inactivity timeout;
    • session fixation protection;
    • HttpOnly session cookies;
    • SameSite=Strict cookies;
    • optional Secure cookies for HTTPS;
    • CSRF-protected logout;
    • login rate limiting;
    • temporary login lockout;
    • strict YAML field validation;
    • prevention of silent credential fallback.

    Upgrade notes

    When upgrading from 1.1.0 to 1.1.1, update the web authentication section in config.yaml.

    Old:

    web:
      basic_auth:
        enabled: true
        username: admin
        password: change-me
    

    New:

    web:
      auth:
        enabled: true
        username: admin
        password: change-me
        session_timeout: 30m
        cookie_secure: false
        login_max_attempts: 5
        login_window: 5m
        login_lockout: 15m
    

    Existing HTTP Basic Auth browser credentials are no longer used.

    Users must authenticate through the new login page after upgrading.

    Downloads