github 2GT-Media-Group-LLC/mikrotik-manager v0.24.35-beta

latest release: v0.24.36-beta
pre-release4 hours ago

v0.24.35-beta: security hardening from an outside code review

Fixes found in an independent review of 0.24.32, checked against the
code and tested on the local stack.

Login and roles

  • Ignore the JWT_SECRET that .env.example used to ship with (and any
    "changeme" value); blank both secrets in .env.example so they are
    generated. A warning is logged when a placeholder is ignored.
  • Only accept full session tokens: the short-lived two-factor token is
    no longer treated as a login. requireWrite allows admin and operator
    only.
  • Admin-only credential presets are enforced in bulk add too; a missing
    role is treated as least privilege.
  • Non-admins must re-enter the device password to change its address,
    so a saved password is only sent to the address it was saved for.
  • Deploy-SSH-key-to-all is admin-only; check-update, check-routerboard,
    device test, wireless scan and adoption address check need write.

Device secrets

  • Viewers and read-only tokens get Wi-Fi keys, WireGuard keys, SNMP
    communities and hotspot passwords masked. Slack/Discord webhook URLs
    are masked for everyone.
  • RouterOS v6 exports use hide-sensitive unless secrets are opted in;
    older v6 Config History snapshots are admin-only.

Robustness

  • RouterOS API replies: unsigned length decoding, reserved control bytes
    rejected, size caps, prototype-free attribute objects; a bad reply
    drops that connection instead of crashing the backend.
  • VLAN ranges are clamped to 1-4094.
  • Scheduler gate keys outlive their interval, so daily and hourly tasks
    no longer run every ten minutes.

Other

  • Flux query values are escaped with fluxString.
  • Alert channels refuse loopback, link-local and this stack's services,
    time out after 10s, never echo response bodies, and won't carry a
    saved token to a changed server.
  • audit_log.username widened; failed audit inserts are logged.
  • Client MACs are URL-encoded; key-rotation docs corrected.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com


Container image: ghcr.io/2gt-media-group-llc/mikrotik-manager:0.24.35-beta

Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/

Don't miss a new mikrotik-manager release

NewReleases is sending notifications on new releases.