github avandeputte/haproxy-manager v1.91.0
1.91.0

latest releases: v1.95.0, v1.95.0-beta.1, v1.94.0...
one month ago

A comprehensive code review turned up defects across the stack. This release fixes all of them, each pinned by a test. No new features — a hardening and correctness pass.

Security

  • A password change now signs stolen sessions out. Changing the login rotates the session-signing secret, so a cookie captured beforehand stops working immediately instead of lasting the session lifetime — previously it could be traded for the node's API key and secret.
  • The config backup carries no secrets. DNS-provider credentials, ACME EAB keys and the single sign-on client secret are stripped alongside the password hashes that already were; a restore onto the same node fills them back from what is stored, a restore elsewhere asks for them again. The file is genuinely safe to copy around now.
  • A corrupt config.json can no longer reopen setup to whoever reaches the port, and a writer refuses to overwrite an unreadable file rather than lose the only copy.
  • Mesh sync keeps this node's "Verify TLS" for a peer instead of taking the sender's own setting, so it can no longer quietly undo the protection an admin turned on.
  • Operator fields can't inject configuration. Server address/port, condition values, health-check URIs and rule parameters are stripped of control characters at render, so a newline in a field meant to hold one value cannot smuggle a second HAProxy directive.
  • The two-factor counter and recovery codes are consumed under one lock (no replay race); acme.sh DNS credentials can no longer set process-hijacking environment variables; the OIDC callback enforces the ID token's nonce.

Correctness

  • The management UI's own certificate is now found by Issue and Renew (it lived in the node-local section and was invisible to both).
  • After a rolled-back or failed reload, the node reads dirty and asks to re-apply, instead of falsely reporting the new config as live.
  • A failover no longer blanks Home Assistant dashboards: the demoted node stops deleting the cluster entities the new active node just published.
  • The traffic and watchdog pages no longer throw intermittent 500s under load (state is now locked on both the reader and writer side), and the History page no longer blocks saves while it diffs.

Interface

  • A slow response (loading stats, issuing a certificate, renewing) can no longer land on and wipe whatever page you navigated to in the meantime; background refresh loops stop when you leave the page and no longer wipe a settings form mid-edit.
  • Editing a service no longer silently resets an ssl health check; a few mislabeled buttons and a delete prompt are corrected.

Upgrading: everyone's UI session ends once (sign in again), and because the backup format now omits secrets, a cross-node restore prompts for DNS credentials again. Nothing else changes.

Packages are attached below; the container image is at ghcr.io/avandeputte/haproxy-manager:1.91.0.

Don't miss a new haproxy-manager release

NewReleases is sending notifications on new releases.