github jhaals/yopass 15.0.0

3 hours ago

OIDC email verification

This major release makes verified email addresses the default for OIDC login. Providers such as [Google](https://developers.google.com/identity/openid-connect/reference) and [Auth0](https://auth0.com/docs/get-started/apis/scopes/openid-connect-scopes) already support email verification claims. If your provider returns email_verified: true for your users, no configuration changes are needed.

Yopass now checks this value before allowing a new login. This adds protection when access depends on a user’s email address or domain. Logins are rejected if the verification claim is false or missing.

Using Microsoft Entra ID? Its standard [UserInfo endpoint](https://learn.microsoft.com/en-us/entra/identity-platform/userinfo) does not return email_verified. For Entra and other providers that omit this claim, you can retain compatibility by setting:

OIDC_REQUIRE_VERIFIED_EMAIL=false

Or use --oidc-require-verified-email=false.

Use this setting when your provider controls email addresses and application access appropriately. Email-domain restrictions still apply. Deployments without OIDC and clients using API tokens are unaffected.

What’s new

  • Safer sharing when the key is sent separately. Links without a decryption key now wait for the recipient to submit a key before retrieving the secret. This helps prevent email security scanners from consuming one-time messages by clicking “Reveal Secure Message.” Correcting the key in the URL also preserves an already-downloaded message. (#4017)
  • Clearer feedback for incorrect keys. The “Decrypt secret” button now gives a subtle shake when decryption fails, so repeated attempts are easier to notice. Submitting the same key retries decryption locally without downloading the message again. Errors are announced to screen readers, and the animation respects reduced-motion preferences. (#4018)
  • Choose your form defaults. Administrators can choose whether “Read receipt” and “One-time download” start checked on text and file forms. Users can still change these options unless one-time downloads are enforced. (#4015)
  • A fresh look. Updated logos and browser icons, with better support for dark mode and custom branding. (#4016)

Security and reliability

  • Added configurable request and file-transfer deadlines to help protect the server from slow clients.
  • Invalid configured OIDC session keys now prevent startup.
  • Fixed client IP detection behind trusted proxies to avoid trusting spoofed forwarded addresses.

Check your transfer timeouts

The default deadline is 5 minutes for streaming file uploads and downloads and 30 seconds for ordinary requests. These limits cover the whole transfer.

For large files or slower connections, adjust FILE_TRANSFER_TIMEOUT and REQUEST_TIMEOUT, using values such as 10m or 60s.

If you use a reverse proxy or load balancer, align its upload and response timeouts with your Yopass settings. Increasing Yopass’s deadline alone will not help if the proxy cuts the transfer short. Check both sides when choosing limits for your deployment.

Don't miss a new yopass release

NewReleases is sending notifications on new releases.