github freifunkMUC/wg-access-server v1.2.1

5 hours ago

Security

  • In-memory storage: a device name could address another user's device. With the default memory:// storage, a device name such as ../bob/laptop let any signed-in user delete, overwrite or take over the key of another user's device. SQL storage was not affected. Upgrade if you use memory://.
  • The same identifier at two providers was one person. With more than one sign-in provider, signing in through one provider with the identifier of somebody from another gave access to their devices. A sign-in is now refused when its identifier has devices of another provider. Renaming a provider now locks out its users - keep the name.
  • Providers named like another provider. An OIDC or GitLab provider named basic or simple made its users look like built-in users (an IdP user named like adminUsername became admin), and two OIDC providers sharing a name could skip the accessClaim check. The server now refuses to start with such a configuration.
  • OIDC authorization codes are bound to the browser with PKCE when the provider offers it, so a leaked code cannot be redeemed by somebody else. Failed callbacks no longer panic.
  • Basic auth no longer accepts credentials in the URL.
  • Logs: the storage URI is logged without its password, statements logged at debug level no longer carry their values (preshared keys), and Postgres passwords with spaces no longer end up in error messages.
  • WireGuard keys ending in | are refused.

Upgrade notes

  • The server refuses to start when an oidc or gitlab provider is named basic or simple, or when two providers share a name. Rename them; the message says which.
  • A Postgres storage URI without a port now works (it defaults to 5432).

Full Changelog: v1.2.0...v1.2.1

Don't miss a new wg-access-server release

NewReleases is sending notifications on new releases.