Site-scoped device credentials, SSO-only sign-in, device-mode checks, CVE alerts (v0.30.0)
#228: Device Credentials is its own page under Operations. A credential
preset is fleet-wide or belongs to one site: fleet admins manage all of
them, site admins their own sites'. A site's preset is only offered and
accepted for devices in that site, and names are unique per site. The
add-device dialogs list only presets valid for the site the device
joins. Editing a device now applies the same preset rules as adding one;
it had let a site admin use an admin-only fleet-wide preset.
#226: PASSWORD_LOGIN=false makes sign-in SSO-only: the login page shows
the SSO button alone, and password sign-in, password changes and 2FA
setup are refused. It applies only while SSO is configured; setting it
back to true and restarting is the break-glass.
#227: an admin signed in through SSO, with no local password, can't turn
SSO off or point it at another provider.
#230: Config Health reads RouterOS device-mode and reports what blocks
the manager: the scheduler (Change Guard can't arm its undo) as a
warning, bandwidth-test, sniffer, hotspot and fetch as info, and a
flagged device.
#224: a cve_active alert rule (off by default) for RouterOS versions in
the fleet hit by a CVE that's exploited, critical or high; checked after
the daily feed refresh and when the rule is turned on, once per CVE and
version. Also a webhook event.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.30.0-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.30.0-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/