github Cloud-City-Computing/c2 v0.13.0
Cloud Codex 0.13.0

one hour ago

The cookie-hardening release. Upgrading from 0.12.0 applies no migration and needs nothing run, and signed-in browsers stay signed in. A script that posts to /api with only a session cookie now needs an Origin header or the bearer header.

docker compose -f docker-compose-release.yml pull app
docker compose -f docker-compose-release.yml up -d

Run it

git clone https://github.com/Cloud-City-Computing/c2.git
cd c2
cp .env.example .env    # fill in DB and admin credentials and APP_URL; SMTP is optional
docker compose -f docker-compose-release.yml up -d
docker compose -f docker-compose-release.yml run --rm app npm run migrate -- --adopt-fresh-install

That pulls ghcr.io/cloud-city-computing/cloud-codex:0.13.0 and serves it on http://localhost:3000. The last line is a one-time step on a fresh install.

Security

  • Another host under your domain can no longer set Codex's sign-in cookies (GHSA-xq3x-556x-fr4q, medium).
    • A script on a sibling host could plant the OAuth state cookie or the session cookie, which allowed Google login CSRF and capturing a victim's GitHub token on the attacker's account.
    • On https these cookies are now __Host-oauth_state_<provider> and __Host-sessionToken, read only under those exact names.
    • The protection needs https. An instance served over plain http keeps the older names and stays exposed.
    • Existing sessions keep working and move to the new name on their next visit. LEGACY_SESSION_COOKIE=0 turns off the older name for an instance whose domain has hosts you do not control.
  • A write authenticated by the session cookie alone needs an accepted Origin. The app's own requests and server-to-server callers are unaffected.

Also in this release

  • A first boot no longer restarts the app while MySQL initialises (0.12.0's known gap): the MySQL healthcheck pings over TCP.
  • A clean boot log and browser console: no dotenv banner, running without SMTP reads as a setting, and no refused GitHub requests when no GitHub account is linked.
  • Fixed: signing in over plain http to an address other than localhost keeps its session.
  • Self-hosting docs match the code: SMTP is optional everywhere, every first-install snippet includes the adopt step and names APP_URL, and the settings table lists every variable (pinned by tests).

Known gaps

  • linux/amd64 only.
  • Documents edited only over the collaborative WebSocket have a stale html_content until an explicit save.

Full detail in CHANGELOG.md.

Don't miss a new c2 release

NewReleases is sending notifications on new releases.