github basnijholt/compose-farm v1.22.0

4 hours ago

Security

This release hardens the web UI. Thanks to a security researcher for the private report. Upgrading is recommended and needs no configuration changes.

  • Cross-origin protection (always on): state-changing requests and WebSocket connections (host shell, container exec, terminals) from other websites are now rejected. Previously, any website opened in a browser on the same network could drive the web UI, including opening a shell on your hosts. (#212)
  • Shell injection via service names fixed: service names passed to cf up/stop/pull/restart/logs/ps --service and to the web UI's per-service actions are now shell-quoted, and the web route rejects names outside the Compose service-name charset. (#213)
  • XSS fixes in the web UI: container names, images, host names, error messages, and command palette entries are now HTML-escaped, both server-side and in the browser. (#214)

Features

  • Optional web UI login: set CF_WEB_PASSWORD (and optionally CF_WEB_USERNAME, default admin) to require HTTP Basic auth for every page, API call, and WebSocket. Without it, behavior is unchanged. cf web prints the active mode on startup, and docker-compose.yml passes the variables through. See Web UI → Authentication. (#212)

Note: without a password, the web UI is intended for trusted networks. If its port is reachable directly (e.g. http://192.168.1.10:8000) rather than only through a reverse proxy with an exact Host rule, set CF_WEB_PASSWORD to also protect against DNS rebinding.

Other changes

  • Hosts sharing an address are treated as one machine in discovery (#207)
  • Traefik regeneration OS errors are reported as warnings (#193)
  • Refreshed README logo, animated docs scene, app icon, and social preview (#208–#211)
  • Dependency updates (#203, #204)

Full Changelog: v1.21.5...v1.22.0

Don't miss a new compose-farm release

NewReleases is sending notifications on new releases.