Security
- In-memory storage: a device name could address another user's device. With the default
memory://storage, a device name such as../bob/laptoplet any signed-in user delete, overwrite or take over the key of another user's device. SQL storage was not affected. Upgrade if you usememory://. - The same identifier at two providers was one person. With more than one sign-in provider, signing in through one provider with the identifier of somebody from another gave access to their devices. A sign-in is now refused when its identifier has devices of another provider. Renaming a provider now locks out its users - keep the
name. - Providers named like another provider. An OIDC or GitLab provider named
basicorsimplemade its users look like built-in users (an IdP user named likeadminUsernamebecame admin), and two OIDC providers sharing a name could skip theaccessClaimcheck. The server now refuses to start with such a configuration. - OIDC authorization codes are bound to the browser with PKCE when the provider offers it, so a leaked code cannot be redeemed by somebody else. Failed callbacks no longer panic.
- Basic auth no longer accepts credentials in the URL.
- Logs: the storage URI is logged without its password, statements logged at debug level no longer carry their values (preshared keys), and Postgres passwords with spaces no longer end up in error messages.
- WireGuard keys ending in
|are refused.
Upgrade notes
- The server refuses to start when an
oidcorgitlabprovider is namedbasicorsimple, or when two providers share a name. Rename them; the message says which. - A Postgres
storageURI without a port now works (it defaults to 5432).
Full Changelog: v1.2.0...v1.2.1