github 2GT-Media-Group-LLC/mikrotik-manager v0.24.36-beta

pre-release3 hours ago

v0.24.36-beta: forced first password change, Change Guard that never promises what it can't do, honest restores

Follow-up to the outside code review (P1-3, P1-12, P2-5, P2-6, P1-10,
P2-36, C8).

Default password

  • The seeded admin/admin (and any install still on it) must set a new
    password at first login. Until then the session can only reach the
    change-password endpoints; sockets and the terminal refuse it.
  • The login page shows the default credentials only until they change
    (GET /api/auth/login-hints).

Change Guard

  • A change confirmed past a lockout warning, flagged by the prediction,
    or that could not be analysed now requires auto-revert: if the device
    can't arm it, or Change Guard is off, the change is refused before
    anything is applied (422 guard_required). Bulk runs with Change Guard
    on fail such devices instead of running them unprotected.
  • New POST /devices/:id/change-guard/check; the lockout and bond-delete
    dialogs show the device's real readiness and block "Apply anyway"
    when it can't auto-revert.
  • The capability probe also saves (and removes) a throwaway restore
    point, not only a scheduler.
  • Disarm uses fresh connections, treats a failed read as a failure, and
    re-reads to prove the scheduler is gone. If it can't, the guard is
    recorded as 'uncertain', the response gives revert_may_fire_at, and
    the device stays locked until the revert would have fired. The lock
    is also held while a left-armed revert is still due.

Restore and rollback

  • Run under Change Guard, sign in with the SSH key when one is deployed,
    upload to a unique filename and delete it afterwards.
  • RouterOS /import always exits 0, so its output is parsed: applied,
    nothing_applied or partial, with the line and reason. Failures return
    422 and the UI shows the message (the Backups page used to show none).

Tested on the TEST switch (guarded add/remove, refusal with the guard
off, real and no-op restores, rollback); config verified unchanged.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com


Container image: ghcr.io/2gt-media-group-llc/mikrotik-manager:0.24.36-beta

Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/

Don't miss a new mikrotik-manager release

NewReleases is sending notifications on new releases.