github greenpau/caddy-security v1.3.0

4 hours ago

caddy-security v1.3.0

This release adds an option to keep users signed in across Caddy restarts, makes
it possible to protect applications with direct OAuth sign-in, and gives
administrators more control over GitHub access rules, password hashing, and log
noise. It also fixes login return URLs and includes security improvements from
the underlying AuthCrunch library.

  • Keep login state across restarts. The new optional state block saves
    authentication state to a private directory. With the same storage, public
    address, and compatible configuration, completed sessions can survive a Caddy
    restart, so users do not have to sign in again just because the service
    restarted. This includes generated signing keys, refresh sessions, and OpenID
    Connect sessions and grants. Logout and token-reuse protections also survive
    restarts. Session expiration still applies, and unfinished sign-ins must start
    again. Persistence remains disabled unless you configure it.

  • Sign in through an external provider without a separate portal. An
    authorization policy can now use an OAuth identity provider directly. Users
    visiting a protected application are sent to the provider to sign in and then
    returned to the application. You can configure this without creating an
    authentication portal, local user database, or JWT signing keys. The policy
    manages the application's session and logout, and checks its access rules on
    each request. This mode suits applications that need provider sign-in without
    the portal's profile pages, local MFA, or user transforms. Sessions have a
    fixed lifetime; they do not automatically renew through the provider.

  • Control GitHub access using account IDs and organizations. Portal user
    transforms can now match a GitHub account's numeric ID or organization
    membership, using exact matches or regular expressions. An ID-based rule
    continues to identify the same person if they rename their GitHub account.
    You can combine an ID and an organization requirement in one rule before
    assigning a role. Organization matching requires user_org_filters on the
    GitHub provider and uses the public memberships returned by its lookup;
    private memberships are not discovered by this feature.

  • Generate Argon2id password hashes. The local password generator now
    supports Argon2id, with configurable memory, iteration, and parallelism
    settings. Run
    authcrunch security local generate password hash --algorithm argon2
    to enter a password privately and receive a ready-to-use Caddyfile password
    directive. This release also adds integration coverage for importing Argon2id
    hashes and using them through browser, JSON, and Basic login. Bcrypt remains
    the default, existing passwords are not automatically converted, and API keys
    continue to use bcrypt.

  • Reduce repetitive authentication logs. A new logging block inside
    security lets you suppress selected AuthCrunch diagnostic messages using
    exact text, partial text, prefixes, suffixes, or regular expressions. This
    helps reduce expected noise, such as selected missing-token diagnostics,
    while keeping other messages visible. Filtering affects logging only;
    access decisions stay the same. These rules do not filter Caddy's independent
    authentication-middleware logger or access logs.

  • Return users to the correct application after login. The HTTP/3 login
    redirect fix preserves the application's full return address instead of
    sometimes reducing it to a path. This matters when the login portal and
    application use different hostnames. Regression coverage checks browser login
    over HTTP/1.1, HTTP/2, and HTTP/3, including paths and query strings.

  • Security and reliability improvements. The AuthCrunch dependency moves
    from v1.3.4 to v1.3.8. Its changes add stricter validation and size limits for
    OAuth provider responses, improve handling of malformed identity data, harden
    redirect construction, and escape untrusted content in registration emails
    and portal status messages. Portal HTML pages now block framing to protect
    against clickjacking. Management APIs reject oversized requests, and malformed
    SSO certificates or keys produce startup errors instead of crashes. Password
    configuration errors also avoid echoing credential values.

When upgrading, account for these configuration and deployment changes:

  • Persistence requires a stop/start deployment. Once persistent state is
    enabled, stop Caddy completely before starting its replacement. Overlapping
    reloads are rejected, and only one running instance may own the directory.
    Use a private directory on a durable local Unix filesystem; Windows,
    network filesystems, and sharing the directory between active replicas are
    unsupported. Local user databases must also be file-backed. First enabling
    persistence does not import existing in-memory sessions, so plan for users to
    sign in again. Later security-configuration changes can also require a fresh
    login.

  • Existing Caddyfile authorize syntax stays the same. It now adapts to a
    dedicated authorization handler that correctly preserves OAuth redirects,
    callbacks, logout responses, and denials. If you deploy previously generated
    JSON, regenerate it from your Caddyfile before adopting direct OAuth. The
    legacy JSON authentication provider remains available for existing uses.

  • Keep declarations in one global security block. Duplicate blocks now
    fail validation instead of silently replacing earlier configuration.

  • Open the portal as a page rather than inside an iframe. The new framing
    protection blocks embedded portal pages, including login and account flows.

  • Choose direct OAuth access rules deliberately. Allowing the default
    authp/user role permits every account accepted by the configured provider.
    Use narrower identity or provider-role rules when only selected people should
    have access, and ensure the OAuth callback and logout paths reach the same
    authorization policy as the application.

Changelog

  • 3d753e3 app: persist runtime state across Caddy restarts
  • c24371f authenticate: support GitHub ID and organization transforms
  • f3f92a4 authorize: complete direct OAuth policy integration
  • 941449b breakfix: preserve HTTP/3 login return URLs with go-authcrunch v1.3.6
  • 95ca7a3 caddyfile: add AuthCrunch logging skip configuration
  • 7730553 fix: parse redirect test HTML without regular expressions
  • 987088e local: add Argon2id password generation and adoption coverage
  • 907d05a skills: adopt routed authoring and audit repository skill contracts

go-authcrunch changes

github.com/greenpau/go-authcrunch was updated from v1.3.4 to v1.3.8.

Compare: greenpau/go-authcrunch@v1.3.4...v1.3.8

  • breakfix: preserve authorization return URLs over HTTP/3 (3a9f9ec)
  • ops: released v1.3.5 (6ee75f1)
  • security: harden local authorization redirect prefix checks (c8e9a51)
  • security: bound OAuth token endpoint responses (4fd49d0)
  • security: bound generic OAuth UserInfo responses (30525d3)
  • security: harden Discord guild enrichment responses (2ae8115)
  • security: harden Google group enrichment responses (a8922c1)
  • security: constrain GitHub follow-up requests (14b2c68)
  • security: validate verified Cognito extension claims (ed10495)
  • security: prevent sandbox toast message XSS (5947059)
  • security: bound authentication admin API requests (6e3bdf6)
  • security: prevent portal UI framing (b3ab3a7)
  • security: bound shared HTTP client responses (3942aa1)
  • security: reject malformed SSO key material (b54787d)
  • security: protect persisted configuration secrets (aceff80)
  • security: escape registration email HTML (8021473)
  • security: reject forwarded prefix authority injection (61e8606)
  • skills: adopt authoring contracts and audit repository guidance (498fc5c)
  • tests: handle Chrome navigation races in profile session E2E (0f1a5bd)
  • ops: released v1.3.6 (0e1a3b7)
  • acl: move code generation into assets/scripts (8931436)
  • authn: add GitHub ID and organization transform matchers (4ecc8ca)
  • breakfix: keep temporary checkouts out of release lint checks (b83fc9f)
  • ops: released v1.3.8 (4fabdf9)

Don't miss a new caddy-security release

NewReleases is sending notifications on new releases.