github 2GT-Media-Group-LLC/mikrotik-manager v0.24.50-beta

latest release: v0.24.51-beta
pre-release4 hours ago

Auth hardening from the review (S1-S9) and large-config backups (v0.24.50)

Outside review P3 security items S1-S9 (S10 shipped in 0.24.44):

  • S1: TOTP setup keeps the new secret pending until confirmed; the active
    authenticator keeps working through an abandoned re-setup.
  • S2: SSO logins are bound to the starting browser by an HttpOnly cookie and
    refused at the callback if SSO was turned off meanwhile.
  • S3: allowed email domains admit only verified emails; with group mappings
    configured the role is recomputed each sign-in (default role when no group
    maps), never demoting the last admin.
  • S4: the SSO callback returns a single-use, 60 s code exchanged by POST from
    the same browser, instead of the session JWT in the URL fragment.
  • S5: rate limiting counts and expires in one Lua call (repairing keys left
    without expiry), on a non-queuing connection; the memory fallback keeps each
    bucket's own window.
  • S6: passwords are capped at 72 bytes (bcrypt's limit).
  • S7: alert channel secrets and webhook signing secrets are stored encrypted,
    sealed at startup if saved before, opened only to send, and covered by key
    rotation and the encryption status.
  • S8: a JWT_SECRET set in the environment retires older secrets after 24 h
    and removes them from secrets.json.
  • S9: the own-session log filter also requires the manager's own address,
    learned from /user/active, so others using the same account are kept.

Backups (Discussion #85, trackersoft): exports time out after 60 s without
output (10 min overall) instead of 30 s total; a key backup falls back to the
password only when the key is refused at login, reporting the real error
otherwise; backup/restore requests get 11 minutes in the client and nginx,
and failures show their reason.

Docs: configuration.md, sso-oidc.md, alerting.md, api.md, backups.md.

Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com


Container images (published once CI passes):

  • ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.24.50-beta
  • ghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.24.50-beta

Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/

Don't miss a new mikrotik-manager release

NewReleases is sending notifications on new releases.