New
- Possible duplicate devices. When a machine gets a new RustDesk ID (UUID mismatch, reinstall, cloned image), the old and new entries are flagged: a badge and a "Duplicates" filter on Devices, and a callout on the device page with Open, Delete and "Not a duplicate". Matches on the same machine UUID, or the same hostname, user and platform; generic hostnames like
localhostare ignored. The admin API addspossible_duplicatesto device payloads (#91). - Your theme is saved to your account. Light or dark now sticks across tabs, browsers and devices, and My Account has an Appearance section with Dark, Light and Match system (#94).
Security
- Bundled CortenDesk Server 1.1.1: fixes a WebSocket handshake DoS (RUSTSEC-2023-0065), a protobuf recursion crash, and UDP reflection, and ignores forged client addresses on the WebSocket ports. See the server release.
- The built-in
/ws/idand/ws/relaybridge no longer passes a client-suppliedX-Real-IPto the ID server and relay. A forwarded address is trusted only from a private or loopback proxy. - Dependencies with published advisories updated, including Laravel, Livewire and league/commonmark, and the web client's build tools.
- The repository now runs CodeQL, Semgrep, gitleaks,
composer auditandnpm audit.
Notes
- Two migrations run on start: the theme preference, and dismissed duplicate pairs.
- Don't publish ports 21118/21119 unless you have RustDesk clients in WebSocket mode, and then only behind a proxy that sets
X-Real-IP. The console's web client doesn't need them; it goes through/ws/idand/ws/relayon port 8080. The examples in the README and wiki are updated.
docker pull marcpope/cortendesk:1.12.0
docker pull ghcr.io/marcpope/cortendesk:1.12.0