github greenpau/caddy-security v1.4.0

latest release: v1.4.1
2 hours ago

caddy-security v1.4.0

Released October 5, 2026.

caddy-security v1.4.0 adds optional cross-device portal login and typed custom
claims in authorization policies. It also incorporates go-authcrunch's fix for
unconditional ACL rules and upgrades Caddy to v2.11.7.

These notes cover caddy-security v1.3.0 → v1.4.0 and the bundled go-authcrunch
update from v1.3.8 → v1.3.11, including changes in v1.3.9 and v1.3.10.

caddy-security changes

  • Cross-device login configuration. Authentication portals now accept
    enable cross-device login and disable cross-device login. Users can request
    a QR code or activation link, authenticate on another device, and explicitly
    approve the requesting browser. The feature is disabled by default. The
    cookie cross-device session id name <name> directive customizes its browser
    binding cookie. Duplicate or conflicting settings and malformed directives
    are rejected. Resolves #506.
  • Typed custom ACL fields. Authorization policies can declare acl field
    aliases for literal top-level claim keys, including namespaced claims. Fields
    support type string and type string list, work with existing ACL rules and
    allow/deny shortcuts, and remain local to their policy. All field declarations
    are applied before rule compilation, so rules can precede declarations.
    Duplicate declarations, malformed blocks, and null JSON fields are rejected.
  • Unconditional user transforms. Removes the compatibility restriction on
    match any transforms with token refresh, portal OIDC providers, and System
    API keys. The updated AuthCrunch evaluator allows these transforms to apply
    their claims and challenge requirements correctly.
  • Caddy parser compatibility. Preserves quoted brace characters as literal
    values under Caddy v2.11.7 while retaining checks for incomplete configuration
    blocks.
  • Test reliability and resource controls. Adds live test reporting and
    limits for aggregate memory, runtime, subprocesses, output, and artifacts.
    Interrupted and failed runs retain their evidence. Browser tests handle
    navigation-related execution-context loss and release completed device
    contexts before starting later scenarios. Go package, workflow guard, and CI
    deadlines are aligned at 60, 70, and 75 minutes respectively.
  • Integration coverage. Adds Caddyfile adaptation, unit, real TLS, and Chrome
    coverage for custom ACL fields and cross-device login, including OAuth/SAML,
    MFA, refresh, cancellation, expiry, concurrent redemption, and restart behavior.

go-authcrunch changes included in this release

  • Cross-device authentication runtime and UI. Adds QR/link activation,
    browser polling, fresh authentication, and explicit account/code approval for
    local/MFA, OAuth, and SAML login. Each device receives independently issued
    credentials. Requests require HTTPS, enforce browser/origin/portal binding,
    expire after five minutes, and can be redeemed only once. Redemption
    revalidates identity, policy, and the approving refresh session where applicable;
    logout, replay, cancellation, and failed issuance are covered.
  • Typed claim evaluation. Adds shared parsers and typed APIs for custom ACL
    fields across authorization guardians and cached identities. Referenced
    claims with invalid types reject ACL evaluation before any rule can grant
    access. Literal claim bindings preserve existing roles, request metadata, and
    caller-owned claim data. Addresses
    go-authcrunch #30.
  • Unconditional ACL fix. match any and default allow/deny rules now execute
    when normalized identity data omits exp. This fixes skipped default-deny
    rules and incorrectly rejected default-allow decisions while preserving token
    expiration validation and request restrictions.
  • Test infrastructure improvements. Adds bounded test workflows and live
    reporting, isolates large persistence-capacity tests in child processes, and
    tolerates normal Linux process exits during memory sampling. Dependency
    updates include ProtonMail/go-crypto, etree, circl, and go-json.

Dependency updates

Component Previous v1.4.0
go-authcrunch v1.3.8 v1.3.11
Caddy v2.11.4 v2.11.7
CertMagic v0.25.4 v0.25.6
tested v1.0.2 v1.1.0

Upgrade notes

  • Enable cross-device login explicitly in each intended portal and serve the
    complete portal namespace over HTTPS. Custom login templates need the
    conditional cross-device action to expose the feature.
  • Pending cross-device requests are held in memory and are discarded on reload
    or restart, including deployments using persistent state. Multiple instances
    need request affinity for each pending interaction. Existing persistent-state
    deployments continue to require a full stop/start instead of overlapping reload.
  • Review ACL rule ordering: a later acl default deny overrides an earlier
    non-stopping allow. Use an explicit allow stop when a successful rule should
    finalize the decision. The upstream fix makes this ordering apply consistently.
  • Custom claim keys are literal top-level keys; dots and slashes do not traverse
    nested objects. Aliases do not rewrite JWTs or become canonical role claims.

Full changes: caddy-security v1.3.0…v1.4.0
and go-authcrunch v1.3.8…v1.3.11.

Changelog

  • a8f81c7 authenticate: add optional cross-device portal login
  • fe9a179 authorize: add typed custom ACL fields with go-authcrunch v1.3.10

go-authcrunch changes

github.com/greenpau/go-authcrunch was updated from v1.3.8 to v1.3.11.

Compare: greenpau/go-authcrunch@v1.3.8...v1.3.11

  • acl: support typed policy-local claim fields (a549a9c)
  • ops: released v1.3.9 (334d002)
  • breakfix: increase CI timeout budgets for authentication tests (102f415)
  • ops: released v1.3.10 (b635472)
  • @alexvisser has signed the CLA in greenpau/go-authcrunch#116 (2069a14)
  • acl: evaluate unconditional rules without requiring expiration claims (dced816)
  • authn: add optional cross-device portal login (6f9889e)
  • breakfix: bound test resource usage and refresh dependencies (703de08)
  • breakfix: upgrade tested to v1.1.0 and isolate capacity tests (18b36b4)
  • breakfix: tolerate exited Linux processes in the test resource guard (c71274f)
  • ops: released v1.3.11 (a6767a8)

Don't miss a new caddy-security release

NewReleases is sending notifications on new releases.