Correctness fixes from the review: wireless security, uptime, logs, lockout model (v0.24.49)
Outside review follow-up: P2-12, P2-25, P2-33, P2-31, P2-18, P2-7.
- P2-12: on the legacy wireless package an SSID with a passphrase gets its own
WPA2 security profile (mtm-), created first; if that fails nothing
is created. Passphrase edits go through the same profile; shared profiles
are never changed; WPA3 is refused rather than downgraded. The guest wizard
tags its SSIDs and refuses to take over an unrelated SSID with the same name. - P2-25: availability counts every outage overlapping the window, clipped to
it, ongoing ones up to now (device page, fleet summary, scheduled report). - P2-33: terminal sessions are audited with the client address behind nginx;
docs state that shell input isn't recorded. - P2-31: SSH key deployment requires a working API login first, since the API
is the only way to remove a key again. - P2-18: short log timestamps use the device's own date (zone or offset), with
rollback for just-before-midnight and year-less December lines; log alerts
come from lines the poll stored, from the last 15 minutes; the per-device
hard 30-day event delete is gone (the retention sweep applies). - P2-7: lockout prediction follows a VLAN interface's parent port, bonds
holding the address or under its VLAN, the route to an off-subnet manager,
and access ports carrying a tagged management VLAN; picks the manager's own
session out of conntrack by source port (or says it can't); port VLAN edits
are simulated with the writer's own planner.
Docs: change-guard.md, devices.md, ssh-keys.md, alerting.md.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.24.49-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.24.49-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/