caddy-security v1.3.0
This release adds an option to keep users signed in across Caddy restarts, makes
it possible to protect applications with direct OAuth sign-in, and gives
administrators more control over GitHub access rules, password hashing, and log
noise. It also fixes login return URLs and includes security improvements from
the underlying AuthCrunch library.
-
Keep login state across restarts. The new optional
stateblock saves
authentication state to a private directory. With the same storage, public
address, and compatible configuration, completed sessions can survive a Caddy
restart, so users do not have to sign in again just because the service
restarted. This includes generated signing keys, refresh sessions, and OpenID
Connect sessions and grants. Logout and token-reuse protections also survive
restarts. Session expiration still applies, and unfinished sign-ins must start
again. Persistence remains disabled unless you configure it. -
Sign in through an external provider without a separate portal. An
authorization policy can now use an OAuth identity provider directly. Users
visiting a protected application are sent to the provider to sign in and then
returned to the application. You can configure this without creating an
authentication portal, local user database, or JWT signing keys. The policy
manages the application's session and logout, and checks its access rules on
each request. This mode suits applications that need provider sign-in without
the portal's profile pages, local MFA, or user transforms. Sessions have a
fixed lifetime; they do not automatically renew through the provider. -
Control GitHub access using account IDs and organizations. Portal user
transforms can now match a GitHub account's numeric ID or organization
membership, using exact matches or regular expressions. An ID-based rule
continues to identify the same person if they rename their GitHub account.
You can combine an ID and an organization requirement in one rule before
assigning a role. Organization matching requiresuser_org_filterson the
GitHub provider and uses the public memberships returned by its lookup;
private memberships are not discovered by this feature. -
Generate Argon2id password hashes. The local password generator now
supports Argon2id, with configurable memory, iteration, and parallelism
settings. Run
authcrunch security local generate password hash --algorithm argon2
to enter a password privately and receive a ready-to-use Caddyfile password
directive. This release also adds integration coverage for importing Argon2id
hashes and using them through browser, JSON, and Basic login. Bcrypt remains
the default, existing passwords are not automatically converted, and API keys
continue to use bcrypt. -
Reduce repetitive authentication logs. A new
loggingblock inside
securitylets you suppress selected AuthCrunch diagnostic messages using
exact text, partial text, prefixes, suffixes, or regular expressions. This
helps reduce expected noise, such as selected missing-token diagnostics,
while keeping other messages visible. Filtering affects logging only;
access decisions stay the same. These rules do not filter Caddy's independent
authentication-middleware logger or access logs. -
Return users to the correct application after login. The HTTP/3 login
redirect fix preserves the application's full return address instead of
sometimes reducing it to a path. This matters when the login portal and
application use different hostnames. Regression coverage checks browser login
over HTTP/1.1, HTTP/2, and HTTP/3, including paths and query strings. -
Security and reliability improvements. The AuthCrunch dependency moves
from v1.3.4 to v1.3.8. Its changes add stricter validation and size limits for
OAuth provider responses, improve handling of malformed identity data, harden
redirect construction, and escape untrusted content in registration emails
and portal status messages. Portal HTML pages now block framing to protect
against clickjacking. Management APIs reject oversized requests, and malformed
SSO certificates or keys produce startup errors instead of crashes. Password
configuration errors also avoid echoing credential values.
When upgrading, account for these configuration and deployment changes:
-
Persistence requires a stop/start deployment. Once persistent state is
enabled, stop Caddy completely before starting its replacement. Overlapping
reloads are rejected, and only one running instance may own the directory.
Use a private directory on a durable local Unix filesystem; Windows,
network filesystems, and sharing the directory between active replicas are
unsupported. Local user databases must also be file-backed. First enabling
persistence does not import existing in-memory sessions, so plan for users to
sign in again. Later security-configuration changes can also require a fresh
login. -
Existing Caddyfile
authorizesyntax stays the same. It now adapts to a
dedicated authorization handler that correctly preserves OAuth redirects,
callbacks, logout responses, and denials. If you deploy previously generated
JSON, regenerate it from your Caddyfile before adopting direct OAuth. The
legacy JSON authentication provider remains available for existing uses. -
Keep declarations in one global
securityblock. Duplicate blocks now
fail validation instead of silently replacing earlier configuration. -
Open the portal as a page rather than inside an iframe. The new framing
protection blocks embedded portal pages, including login and account flows. -
Choose direct OAuth access rules deliberately. Allowing the default
authp/userrole permits every account accepted by the configured provider.
Use narrower identity or provider-role rules when only selected people should
have access, and ensure the OAuth callback and logout paths reach the same
authorization policy as the application.
Changelog
- 3d753e3 app: persist runtime state across Caddy restarts
- c24371f authenticate: support GitHub ID and organization transforms
- f3f92a4 authorize: complete direct OAuth policy integration
- 941449b breakfix: preserve HTTP/3 login return URLs with go-authcrunch v1.3.6
- 95ca7a3 caddyfile: add AuthCrunch logging skip configuration
- 7730553 fix: parse redirect test HTML without regular expressions
- 987088e local: add Argon2id password generation and adoption coverage
- 907d05a skills: adopt routed authoring and audit repository skill contracts
go-authcrunch changes
github.com/greenpau/go-authcrunch was updated from v1.3.4 to v1.3.8.
Compare: greenpau/go-authcrunch@v1.3.4...v1.3.8
- breakfix: preserve authorization return URLs over HTTP/3 (3a9f9ec)
- ops: released v1.3.5 (6ee75f1)
- security: harden local authorization redirect prefix checks (c8e9a51)
- security: bound OAuth token endpoint responses (4fd49d0)
- security: bound generic OAuth UserInfo responses (30525d3)
- security: harden Discord guild enrichment responses (2ae8115)
- security: harden Google group enrichment responses (a8922c1)
- security: constrain GitHub follow-up requests (14b2c68)
- security: validate verified Cognito extension claims (ed10495)
- security: prevent sandbox toast message XSS (5947059)
- security: bound authentication admin API requests (6e3bdf6)
- security: prevent portal UI framing (b3ab3a7)
- security: bound shared HTTP client responses (3942aa1)
- security: reject malformed SSO key material (b54787d)
- security: protect persisted configuration secrets (aceff80)
- security: escape registration email HTML (8021473)
- security: reject forwarded prefix authority injection (61e8606)
- skills: adopt authoring contracts and audit repository guidance (498fc5c)
- tests: handle Chrome navigation races in profile session E2E (0f1a5bd)
- ops: released v1.3.6 (0e1a3b7)
- acl: move code generation into assets/scripts (8931436)
- authn: add GitHub ID and organization transform matchers (4ecc8ca)
- breakfix: keep temporary checkouts out of release lint checks (b83fc9f)
- ops: released v1.3.8 (4fabdf9)