Session revocation, API-SSL, pinning, key rotation, per-site roles (v0.24.46)
Outside review follow-up, Phase 2 items P2-1, P1-4, I5, P2-29 and P1-7.
Sessions
- Every request re-checks the account: deleted, demoted or password-changed
accounts lose their sessions at once; logout revokes the token server-side. - Sockets and terminals re-check the session too.
Encrypted management (API-SSL)
- New devices try API-SSL first and fall back to the plain API.
- Security page shows a notice only while devices are still on the plain API,
with per-device and "switch all" actions that enable API-SSL (self-signed
cert if needed) and switch only after a successful login over it.
Certificate and host key pinning
- TLS certificates and SSH host keys are pinned on first use and verified
before login; a change stops polling, alerts, and offers "trust new".
Encryption key rotation
- Rotate from Settings -> General; old keys kept until everything is
re-encrypted (database values and backup files). - A generated key is only saved once startup confirms no data needs another
key, and encryption is refused if the key has been lost. - ENCRYPTION_KEY_PREVIOUS for keys set in .env.
Per-site roles
- Accounts can be limited to sites with admin/operator/viewer per site.
- Device, client, event, backup, topology, metrics and live-update access
follow the device's site; fleet-wide features are refused. - A site selection left in the browser by another account is dropped at
sign-in and on a site_forbidden reply; /api/auth/* ignores the site header. - Tag device counts only include the account's sites.
Docs: security.md, configuration.md, sites.md, devices.md, alerting.md.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.24.46-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.24.46-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/