caddy-security v1.4.0
Released October 5, 2026.
caddy-security v1.4.0 adds optional cross-device portal login and typed custom
claims in authorization policies. It also incorporates go-authcrunch's fix for
unconditional ACL rules and upgrades Caddy to v2.11.7.
These notes cover caddy-security v1.3.0 → v1.4.0 and the bundled go-authcrunch
update from v1.3.8 → v1.3.11, including changes in v1.3.9 and v1.3.10.
caddy-security changes
- Cross-device login configuration. Authentication portals now accept
enable cross-device loginanddisable cross-device login. Users can request
a QR code or activation link, authenticate on another device, and explicitly
approve the requesting browser. The feature is disabled by default. The
cookie cross-device session id name <name>directive customizes its browser
binding cookie. Duplicate or conflicting settings and malformed directives
are rejected. Resolves #506. - Typed custom ACL fields. Authorization policies can declare
acl field
aliases for literal top-level claim keys, including namespaced claims. Fields
supporttype stringandtype string list, work with existing ACL rules and
allow/deny shortcuts, and remain local to their policy. All field declarations
are applied before rule compilation, so rules can precede declarations.
Duplicate declarations, malformed blocks, and null JSON fields are rejected. - Unconditional user transforms. Removes the compatibility restriction on
match anytransforms with token refresh, portal OIDC providers, and System
API keys. The updated AuthCrunch evaluator allows these transforms to apply
their claims and challenge requirements correctly. - Caddy parser compatibility. Preserves quoted brace characters as literal
values under Caddy v2.11.7 while retaining checks for incomplete configuration
blocks. - Test reliability and resource controls. Adds live test reporting and
limits for aggregate memory, runtime, subprocesses, output, and artifacts.
Interrupted and failed runs retain their evidence. Browser tests handle
navigation-related execution-context loss and release completed device
contexts before starting later scenarios. Go package, workflow guard, and CI
deadlines are aligned at 60, 70, and 75 minutes respectively. - Integration coverage. Adds Caddyfile adaptation, unit, real TLS, and Chrome
coverage for custom ACL fields and cross-device login, including OAuth/SAML,
MFA, refresh, cancellation, expiry, concurrent redemption, and restart behavior.
go-authcrunch changes included in this release
- Cross-device authentication runtime and UI. Adds QR/link activation,
browser polling, fresh authentication, and explicit account/code approval for
local/MFA, OAuth, and SAML login. Each device receives independently issued
credentials. Requests require HTTPS, enforce browser/origin/portal binding,
expire after five minutes, and can be redeemed only once. Redemption
revalidates identity, policy, and the approving refresh session where applicable;
logout, replay, cancellation, and failed issuance are covered. - Typed claim evaluation. Adds shared parsers and typed APIs for custom ACL
fields across authorization guardians and cached identities. Referenced
claims with invalid types reject ACL evaluation before any rule can grant
access. Literal claim bindings preserve existing roles, request metadata, and
caller-owned claim data. Addresses
go-authcrunch #30. - Unconditional ACL fix.
match anyand default allow/deny rules now execute
when normalized identity data omitsexp. This fixes skipped default-deny
rules and incorrectly rejected default-allow decisions while preserving token
expiration validation and request restrictions. - Test infrastructure improvements. Adds bounded test workflows and live
reporting, isolates large persistence-capacity tests in child processes, and
tolerates normal Linux process exits during memory sampling. Dependency
updates include ProtonMail/go-crypto, etree, circl, and go-json.
Dependency updates
| Component | Previous | v1.4.0 |
|---|---|---|
| go-authcrunch | v1.3.8 | v1.3.11 |
| Caddy | v2.11.4 | v2.11.7 |
| CertMagic | v0.25.4 | v0.25.6 |
| tested | v1.0.2 | v1.1.0 |
Upgrade notes
- Enable cross-device login explicitly in each intended portal and serve the
complete portal namespace over HTTPS. Custom login templates need the
conditional cross-device action to expose the feature. - Pending cross-device requests are held in memory and are discarded on reload
or restart, including deployments using persistent state. Multiple instances
need request affinity for each pending interaction. Existing persistent-state
deployments continue to require a full stop/start instead of overlapping reload. - Review ACL rule ordering: a later
acl default denyoverrides an earlier
non-stopping allow. Use an explicitallow stopwhen a successful rule should
finalize the decision. The upstream fix makes this ordering apply consistently. - Custom claim keys are literal top-level keys; dots and slashes do not traverse
nested objects. Aliases do not rewrite JWTs or become canonical role claims.
Full changes: caddy-security v1.3.0…v1.4.0
and go-authcrunch v1.3.8…v1.3.11.
Changelog
- a8f81c7 authenticate: add optional cross-device portal login
- fe9a179 authorize: add typed custom ACL fields with go-authcrunch v1.3.10
go-authcrunch changes
github.com/greenpau/go-authcrunch was updated from v1.3.8 to v1.3.11.
Compare: greenpau/go-authcrunch@v1.3.8...v1.3.11
- acl: support typed policy-local claim fields (a549a9c)
- ops: released v1.3.9 (334d002)
- breakfix: increase CI timeout budgets for authentication tests (102f415)
- ops: released v1.3.10 (b635472)
- @alexvisser has signed the CLA in greenpau/go-authcrunch#116 (2069a14)
- acl: evaluate unconditional rules without requiring expiration claims (dced816)
- authn: add optional cross-device portal login (6f9889e)
- breakfix: bound test resource usage and refresh dependencies (703de08)
- breakfix: upgrade tested to v1.1.0 and isolate capacity tests (18b36b4)
- breakfix: tolerate exited Linux processes in the test resource guard (c71274f)
- ops: released v1.3.11 (a6767a8)