v0.24.35-beta: security hardening from an outside code review
Fixes found in an independent review of 0.24.32, checked against the
code and tested on the local stack.
Login and roles
- Ignore the JWT_SECRET that .env.example used to ship with (and any
"changeme" value); blank both secrets in .env.example so they are
generated. A warning is logged when a placeholder is ignored. - Only accept full session tokens: the short-lived two-factor token is
no longer treated as a login. requireWrite allows admin and operator
only. - Admin-only credential presets are enforced in bulk add too; a missing
role is treated as least privilege. - Non-admins must re-enter the device password to change its address,
so a saved password is only sent to the address it was saved for. - Deploy-SSH-key-to-all is admin-only; check-update, check-routerboard,
device test, wireless scan and adoption address check need write.
Device secrets
- Viewers and read-only tokens get Wi-Fi keys, WireGuard keys, SNMP
communities and hotspot passwords masked. Slack/Discord webhook URLs
are masked for everyone. - RouterOS v6 exports use hide-sensitive unless secrets are opted in;
older v6 Config History snapshots are admin-only.
Robustness
- RouterOS API replies: unsigned length decoding, reserved control bytes
rejected, size caps, prototype-free attribute objects; a bad reply
drops that connection instead of crashing the backend. - VLAN ranges are clamped to 1-4094.
- Scheduler gate keys outlive their interval, so daily and hourly tasks
no longer run every ten minutes.
Other
- Flux query values are escaped with fluxString.
- Alert channels refuse loopback, link-local and this stack's services,
time out after 10s, never echo response bodies, and won't carry a
saved token to a changed server. - audit_log.username widened; failed audit inserts are logged.
- Client MACs are URL-encoded; key-rotation docs corrected.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container image: ghcr.io/2gt-media-group-llc/mikrotik-manager:0.24.35-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/