github dedicatedcode/reitti v5.6.1

2 hours ago

Reitti v5.6.1 Release Notes

Hey everyone, Daniel here! 👋

⚠️ This is a security release. Please update as soon as possible.

Normally I'd open with a shiny feature, but this release is different. Several security issues were found and fixed, and I want to be upfront about what they were, because a few of them are serious if your reitti instance is reachable by people you don't trust. There is no new functionality in v5.6.1, only fixes.

Most of them came out of a deep security review of v5.6.0 by @claudiusbirdwhistle, whose pull requests are bundled into this release. The forged remember-me cookie was reported at almost the same time, and independently, through a private security advisory by @W3Max. Both arrived at the same conclusion. Thank you both, and welcome to the project.

Security Fixes

  • Forged remember-me cookies (#1284, reported by @claudiusbirdwhistle and independently through a private advisory by @W3Max, reworked in #1303 and #1304). The key used to sign remember-me cookies was a hardcoded constant in the source code. Since accounts created via SSO/OIDC are stored without a local password, anyone who knew a username could craft a valid remember-me cookie for that account, no password required. The signing key is now generated individually per installation and kept in the database, and remember-me is no longer available to accounts without a local password.
  • Unauthenticated setup page (#1286, reported by @claudiusbirdwhistle, reworked in #1305 and #1307). On instances where an admin account existed without a password, including admins created via OIDC, anyone with network access could set that password through /setup and take over the admin account. The setup page now only ever applies to the local bootstrap admin, and only while it has no password.
  • SSO account takeover through identity confusion (#1284, reported by @claudiusbirdwhistle, reworked in #1304). When an OIDC identity logged in with a username that matched an existing account, reitti linked them together. This only affects you if you connect reitti to a new OIDC provider, or if your provider allows different users to use the same preferred_username value. If neither applies to you, you were never at risk. Reitti now refuses the login instead of re-linking.
  • API tokens worked against the web UI (#1284, reported by @claudiusbirdwhistle). API tokens, which often end up in tracker configs and URLs, were accepted on parts of the web UI, including settings endpoints. Tokens are now only valid for /api/ paths, and the web UI always requires a real login.
  • Session cookie hardening (#1284, reported by @claudiusbirdwhistle). The session cookie now sets SameSite=Lax and HttpOnly, which blocks cross-site requests from riding along on your session.

What You Should Do

Update as soon as you can. If you cannot update right now, these measures reduce the risk in the meantime:

  • Do not expose reitti to untrusted networks. Put it behind a VPN, a reverse proxy with its own authentication, or firewall rules. All of the issues above require network access to your instance.
  • Block /setup at your reverse proxy if you want to be extra safe until you can update.
  • If you use OIDC/SSO, make sure your identity provider only authenticates trusted users, with no open self-registration.
  • Make sure every local admin account has a password set.

What Changes After the Update

  • All remember-me sessions are invalidated once, so you will have to log in again. Sorry for the inconvenience, but that is the fix working as intended.
  • The GPSLogger configuration download moved from the integrations settings page to the API: /api/v2/gpslogger/reitti.properties (#1303). If you saved the old URL somewhere, you will need to update it.
  • API tokens now only authenticate /api/ endpoints. If you used a token against one of the undocumented endpoints outside of /api/, that will no longer work. If you rely on such data for an integration, please open a feature request so it can be exposed through an official API endpoint.

Other Changes

  • Fresh translations from Hosted Weblate (#1266, submitted by @weblate). A big thank you to all translators!

Thank You

This release is mostly the result of other people reading my code more carefully than I did.

  • @claudiusbirdwhistle reviewed v5.6.0 and opened the security pull requests behind this release, #1284 and #1286. This is also their first contribution to reitti, so a warm welcome to the project.
  • @W3Max reported the forgeable remember-me cookie privately through a GitHub security advisory for the same vulnerability, which is why remember-me is now rejected outright for accounts without a local password.

Help Spread the Word

Word of mouth is what keeps reitti growing. If you know someone looking for a private Google Timeline alternative, a way to geotag their Immich library, or an open Street View to contribute to, mention reitti. I would much rather spend my time writing code than posting on social media, so every mention helps more than you know.

If you want to support the project financially, there are now two ways to do it:

Patreon
Ko-fi


Full Changelog: v5.6.0...v5.6.1

Getting Started

The latest docker-compose.yml is available in the GitHub release assets. Pull the new image, restart, done. No configuration changes are needed, the remember-me signing key is generated automatically and stored per installation. Expect to log in once again, since existing remember-me cookies are invalidated by design.

  • GitHub: Report issues & view source
  • RSS: Stay updated by adding .atom to the end of our releases URL
  • Discuss: Join the conversation on Lemmy
  • IRC: #reitti on libera.chat

If you have any questions, feel free to add them to the release discussion.

Thank you all for being part of this journey. Happy tracking!

Daniel

Don't miss a new reitti release

NewReleases is sending notifications on new releases.