Security
This release hardens the web UI. Thanks to a security researcher for the private report. Upgrading is recommended and needs no configuration changes.
- Cross-origin protection (always on): state-changing requests and WebSocket connections (host shell, container exec, terminals) from other websites are now rejected. Previously, any website opened in a browser on the same network could drive the web UI, including opening a shell on your hosts. (#212)
- Shell injection via service names fixed: service names passed to
cf up/stop/pull/restart/logs/ps --serviceand to the web UI's per-service actions are now shell-quoted, and the web route rejects names outside the Compose service-name charset. (#213) - XSS fixes in the web UI: container names, images, host names, error messages, and command palette entries are now HTML-escaped, both server-side and in the browser. (#214)
Features
- Optional web UI login: set
CF_WEB_PASSWORD(and optionallyCF_WEB_USERNAME, defaultadmin) to require HTTP Basic auth for every page, API call, and WebSocket. Without it, behavior is unchanged.cf webprints the active mode on startup, anddocker-compose.ymlpasses the variables through. See Web UI → Authentication. (#212)
Note: without a password, the web UI is intended for trusted networks. If its port is reachable directly (e.g.
http://192.168.1.10:8000) rather than only through a reverse proxy with an exactHostrule, setCF_WEB_PASSWORDto also protect against DNS rebinding.
Other changes
- Hosts sharing an address are treated as one machine in discovery (#207)
- Traefik regeneration OS errors are reported as warnings (#193)
- Refreshed README logo, animated docs scene, app icon, and social preview (#208–#211)
- Dependency updates (#203, #204)
Full Changelog: v1.21.5...v1.22.0