Auth hardening from the review (S1-S9) and large-config backups (v0.24.50)
Outside review P3 security items S1-S9 (S10 shipped in 0.24.44):
- S1: TOTP setup keeps the new secret pending until confirmed; the active
authenticator keeps working through an abandoned re-setup. - S2: SSO logins are bound to the starting browser by an HttpOnly cookie and
refused at the callback if SSO was turned off meanwhile. - S3: allowed email domains admit only verified emails; with group mappings
configured the role is recomputed each sign-in (default role when no group
maps), never demoting the last admin. - S4: the SSO callback returns a single-use, 60 s code exchanged by POST from
the same browser, instead of the session JWT in the URL fragment. - S5: rate limiting counts and expires in one Lua call (repairing keys left
without expiry), on a non-queuing connection; the memory fallback keeps each
bucket's own window. - S6: passwords are capped at 72 bytes (bcrypt's limit).
- S7: alert channel secrets and webhook signing secrets are stored encrypted,
sealed at startup if saved before, opened only to send, and covered by key
rotation and the encryption status. - S8: a JWT_SECRET set in the environment retires older secrets after 24 h
and removes them from secrets.json. - S9: the own-session log filter also requires the manager's own address,
learned from /user/active, so others using the same account are kept.
Backups (Discussion #85, trackersoft): exports time out after 60 s without
output (10 min overall) instead of 30 s total; a key backup falls back to the
password only when the key is refused at login, reporting the real error
otherwise; backup/restore requests get 11 minutes in the client and nginx,
and failures show their reason.
Docs: configuration.md, sso-oidc.md, alerting.md, api.md, backups.md.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.24.50-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.24.50-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/