Breaking Changes
- The new
AppOptions:PublicBaseUrlshould be set to this server's public URL (ControlR_AppOptions__PublicBaseUrlfor container deployments).- Links this server sends out (emailed password reset and confirmation, device access, and tenant invites) are built from it instead of the incoming request.
- The actions that produce those links are refused until it is set, and the Invite page cannot load its pending invitations.
- You will need to log out and back in if you have "Remember Me" enabled.
- A pre-existing auth cookie will lack the new permission claims.
- Failures from
/api/v1/*endpoints now answer with an RFC 9457application/problem+jsonbody. - Some of the routes and DTOs used in the
/api/v1/*endpoints have been changed.- There should be no more breaking changes to the
/api/v1/*endpoints after this release.
- There should be no more breaking changes to the
- Although roles were migrated to permission presets, user tags that mapped users to devices were removed.
- If you were using user tags to control access to devices, you will need to migrate to the new permissions system.
AllowAgentsToSelfBootstrapmoved out ofAppOptionsinto a newDeveloperOptionssection, so the environment variable is nowControlR_DeveloperOptions__AllowAgentsToSelfBootstrap.- The setting is for development and load testing only and defaults to
false. Anyone who never set it is unaffected.
- The setting is for development and load testing only and defaults to
Enhancements
- Added
Customers,Device Groups, andUser Groups. - Added Tenant and Server service accounts, including API-credential issuance with configurable expiration.
- Revoked and expired credentials can be deleted manually from the service accounts pages, and are
permanently removed by a background service afterAppOptions:ServiceAccountCredentialCleanupAfterDays
days (default 30; 0 disables automatic deletion).
- Revoked and expired credentials can be deleted manually from the service accounts pages, and are
- Replaced roles with a granular permissions system.
- You can now grant users and service accounts specific permissions, scoped to the whole tenant, a customer, a device group, or an individual device.
- Existing roles get migrated to permission presets, which are bundles of related permissions that can be applied at once.
- Added a Permissions page under Tenant Admin for managing who can do what.
- Added filters on the dashboard for customer and device group.
- Added any/all match mode for filtering by tags and device groups.
- Reworked how ungrouped/untagged device display is toggled.
- Authorization changes are now logged, with tenant and server views of the activity.
- Fine-grained permissions can now be applied to Personal Access Tokens.
- Personal access token management is now permission-gated (
personal-access-token.self.read/.self.write, granted via the new "Self Service" preset that every user receives).- Tokens that inherit the owner's full permissions can only be created by a direct login, not by another token.
- Added an Effective Permissions page that shows exactly what a user or service account can do.
- Added
Customerinput to the deploy page, allowing for the device to get added to a specific customer during agent installation. - Refactored
Deploypage for better usability (back button, pre-populated expiration for time-based keys, grid sizing). - Added
IControlrApiClientFactoryto theControlR.ApiClientlibrary. Register one factory and produceIControlrApiclients that target different ControlR servers, each with its own credentials.- Includes idle-target eviction, an optional tracked-target cap with least-recently-used eviction, and credential rotation via remove-and-recreate.
- Existing
AddControlrApiClientandControlrApiClientBuilderusage is unchanged.
ControlR.ApiClientcan now authenticate as a service account. SetServiceAccountApiKeyand requests carry the credential in thex-api-keyheader, authenticating as the service account instead of as a user.- Available on
AddControlrApiClient,ControlrApiClientBuilder, and each factory target. A personal access token or bearer token takes precedence when it is also configured.
- Available on
- Added
ControlrApiClientBuilder.GetAuthSession(), which exposes the interactive bearer session for the process-wide client.
Fixes
- The
ControlR.ApiClientbackground token-refresh no longer ends the session on transient failures. - The
ControlR.ApiClientinteractive session no longer keeps reporting itself as signed in after the server rejects its refresh token during an ordinary API call. - Disposing a
ControlR.ApiClientinteractive auth session now moves it to a new terminalDisposedstate and raisesStateChanged. - Interactive sign-in in
ControlR.ApiClientnow clears a personal access token or service account key if one was already configured on the session. - The dashboard's file operations no longer report success when the agent reports a failure.
- Emailed account links no longer take their address from the incoming request, which let a forged
X-Forwarded-Hostheader aim a genuine password-reset token at an attacker's site. Ref: #175- The same rule now covers every absolute URL the server hands out, including device access links and tenant invites.
- Fixed an issue where the Enter key did not work on Windows when using mobile input with physical input mode enabled.
Removals
None.
Internal
ControlR.ApiClientnow marks the internal installer-key and user logon-token methods
[Obsolete], each pointing at its/api/v1replacement and the difference the caller has to
handle. The UI already uses V1 for both, so nothing in the product calls these anymore.- The value-carrying MVC error shortcuts (
BadRequest(value),NotFound(value),Conflict(value),
Unauthorized(value),StatusCode(code, value)) are banned underApi/V1by RS0030, so a new V1
endpoint cannot reintroduce a bare-string error body. UseProblem()instead.