github goshs-labs/goshs v2.1.7

5 hours ago

What Changed in v2.1.7

This is a security-focused release resolving six advisories. Most close the same class of gap: the per-folder .goshs ACL was enforced on HTTP/WebDAV but not on every other protocol serving the webroot. It also adds folder uploads to the web UI, fixes an FTP crash and an SFTP path bug on Windows, and brings the usual dependency and CI maintenance.

🔒 Security

Per-folder .goshs ACL now enforced on every protocol: SFTP, FTP, TFTP and SMB share a new fail-closed enforcer, httpserver.ProtocolACL. These protocols cannot present a folder's basic-auth credential, so a folder protected by a .goshs auth entry is denied outright. Block-listed names and the .goshs file itself (which holds the bcrypt hashes) are always denied, and directory listings hide .goshs, blocked entries and auth-protected subdirectories.

  • SFTP ignores the .goshs ACL (GHSA-2m7f-jq4x-rcj7, High): SFTP handlers only checked the webroot boundary, so the single SFTP credential could read, write, list, rename or delete files inside folders that .goshs protects or blocks over HTTP. ProtocolACL is now wired into every SFTP read, write, list and command path, including the rename destination.
  • TFTP, FTP and SMB ignore the .goshs ACL (GHSA-q8gg-q2wc-w52g, Medium): the same gap in the other transfer protocols. Protected subtrees could be downloaded anonymously over TFTP, including the .goshs file with its bcrypt hash. The fixes:
    • TFTP checks the ACL on read and write requests.
    • FTP wraps its filesystem in an ACL layer that also filters listings.
    • SMB checks at handle creation and on the rename destination, and filters directory queries.
  • A directory named .goshs wipes inherited auth (GHSA-mhxc-hfx2-7w79, Medium): a .goshs directory (creatable via ?mkdir) made the ACL resolver return an empty ACL, silently removing inherited per-directory auth and block lists for the whole subtree. The resolver now fails closed: an unreadable or unparsable .goshs (including a dangling symlink) denies everything, and non-regular .goshs entries are ignored. ?mkdir and uploads refuse any .goshs path component.
  • Block list bypass on case-insensitive filesystems (GHSA-3x28-6v7h-gg87, Medium): incomplete fix of CVE-2026-66064. Block-list and never-serve checks compared names case-sensitively, so SECRET.txt slipped past a block on secret.txt on Windows/macOS. All enforcement points across HTTP, WebDAV, SFTP and listing filters now compare case-insensitively.
  • Concurrent requests bypass the brute-force lockout (GHSA-8f9w-966j-qhq9, Medium): verifyCredentials checked and updated the per-IP failure counter in two separate locked sections around the bcrypt compare. A burst of concurrent wrong-password requests all passed the check, and the counter ended at 1, so the 5-failure lockout never triggered. Each attempt is now counted in the same locked section as the check, before the password is verified, so each IP gets at most 5 guesses per lockout window no matter how many requests it sends at once.

✨ New Features

  • Folder upload in the web UI (#227): whole folders, including subdirectories, can now be dropped or selected for upload, and their structure is preserved on the server. Relative paths are sanitized: .. cannot escape the target directory, and .goshs components are refused.

🐛 Bug Fixes

  • FTP crashed on AUTH TLS without TLS (nil-pointer panic): when a client requested explicit TLS, the FTP driver handed back an empty TLS configuration and the server crashed. FTP now serves FTPS with the configured certificate (-s with -ss or -sk/-sc) and cleanly refuses AUTH TLS when TLS is not enabled.
  • SFTP paths doubled on Windows (#292): SFTP on Windows hosts prefixed the webroot twice, breaking directory navigation and transfers.

🛠️ Build, CI & Packaging

  • Docker builder image moved to Go 1.27 (golang:1.27-alpine); runtime alpine base image refreshed.
  • All github/codeql-action steps are pinned to the same release, and Dependabot now groups its bumps into a single PR, so split updates no longer break the CodeQL workflow.
  • README: security contributor acknowledgements updated.

⬆️ Dependencies

  • Go modules: golang.org/x/crypto 0.54.0 → 0.57.0, golang.org/x/net 0.57.0 → 0.59.0, golang.org/x/term 0.45.0 → 0.46.0, golang.org/x/text 0.41.0 → 0.42.0, github.com/fclairamb/ftpserverlib 0.32.3 → 0.32.4, github.com/miekg/dns 1.1.72 → 1.1.73, github.com/sirupsen/logrus 1.9.4 → 1.10.2, github.com/stretchr/testify 1.11.1 → 1.12.1, github.com/moby/moby/api 1.55.0 → 1.56.0.
  • GitHub Actions: github/codeql-action (init/autobuild/analyze/upload-sarif) 4.37.7 → 4.38.2, codecov/codecov-action 7.0.0 → 7.1.1, docker/setup-qemu-action 4.2.0 → 4.4.0, docker/setup-buildx-action 4.3.0 → 4.4.1, docker/build-push-action 7.3.0 → 7.4.0.
  • Docker: golang 1.26-alpine → 1.27-alpine, alpine base digest refresh.

Don't miss a new goshs release

NewReleases is sending notifications on new releases.