Security
-
The network map showed the whole fleet to users restricted to specific sites. Opening Topology listed every device in the installation — names, addresses, models, RouterOS versions and current CPU and memory load — regardless of the viewer's site access, and its site picker was filled with the names of sites the user cannot otherwise see. Picking any of those sites drew that site's map, read and overwrote its saved layout, and made the manager reach out to the devices on it. Topology now shows only the devices and sites you may see, and asking for a site outside them is refused. This affects only installations that use per-site restrictions; if every user is unrestricted, nothing changed for you. Present since per-site access shipped in v1.33.0.
-
"Apply to → all sites" on a backup schedule re-scheduled the entire installation. The Apply to option in the backup-schedule dialog took its device list straight from the whole fleet without checking the caller's site access: a restricted administrator or operator choosing "every device across all sites" changed the backup interval, start time and retention of every device in the installation, and naming a single site worked just as well for sites they have no access to. Existing schedules elsewhere were overwritten without warning, including ones inherited from a site policy. Both options now only touch devices within your own sites. Unrestricted users keep the fleet-wide behaviour they have today. Present since per-site access shipped in v1.33.0.
-
Command history showed runs against devices outside a user's sites. The history table on the Mass Commands page listed every command ever run in the installation, by any user, and opening one showed the devices it targeted and their full output — including devices at sites the user has no access to. Asking for one specific device's history was not checked either. Running commands was always restricted correctly; only the record of it was not. History now lists only runs that touched devices you may see, and within a run shows only those devices' results. Present since per-site access shipped in v1.33.0.