Single sign-on grows up: OIDC can be set up from Settings -> Security,
logging out can end the session at the identity provider, sign-in can be
SSO-only, and providers can end Muximux sessions through back-channel
logout. Docker discovery gains a muximux.app.url label for apps behind
your own reverse proxy. Proxied apps that fetch from Web Workers, such as
Dispatcharr's live stream player, work again, and ${VAR} secrets are no
longer written to config.yaml in plain text. Two upgrade notes: OIDC
with an invalid redirect_url now refuses to start, and auto-import only
creates gateway sites for containers that ask for one (see below).
Added
- OIDC in Settings. Single sign-on can be set up and changed in
Settings -> Security, with a connection test and copyable callback and
back-channel URLs. The client secret is never shown, and values that
come from environment variables stay in the environment. (#480) - OIDC sign-out at the identity provider. With
auth.oidc.provider_logout
on, logging out of Muximux also ends the session at the provider through
its end-session endpoint, with a configurable return address. (#480) - SSO-only sign-in.
auth.oidc.auto_redirectskips the login page and
auth.oidc.disable_local_loginrefuses username/password sign-in. (#480) - OIDC back-channel logout at
/api/auth/oidc/backchannel-logout:
signing out at the provider ends the user's Muximux sessions. (#480) muximux.app.urlDocker label -- open a discovered app at a fixed
URL, such as its public name behind your own reverse proxy, without the
built-in gateway. The app stays tracked and its health check follows the
container as its IP changes. (#479)
Fixed
${VAR}references inconfig.yamlsurvive saving from Settings.
They were written back as their expanded values, putting secrets kept in
the environment into the file in plain text.- No false "client_secret is stored in plaintext" warning at startup
whenauth.oidc.client_secretis written as${VAR}. The check looked
at the already-expanded value, so it fired for every configured secret. - Auto-import no longer publishes every container on a gateway
subdomain whenserver.tls.domainis set. Only containers with
muximux.app.gateway.domainget a gateway site; the derived default
only pre-fills the import modal. If you relied on those
derived subdomains, addmuximux.app.gateway.domain=<name>.<your domain>
to those containers before upgrading -- otherwise the sites are removed
on the first refresh and the apps point at their container URLs. - Auto-import updates keep per-app settings. A label change or
container IP change under theupdate/syncmodes replaced the whole
app, dropping health check, auth bypass, access, scale, pinned and proxy
headers. Only label-managed fields change now. muximux.app.pathis applied to discovered app URLs, and a relative
muximux.app.healthsuch as/api/v3/healthis resolved against the
container. Both were parsed but never used.muximux.gateway.skip_tls_verifyis no longer reported as an unknown
label.- Requests made from Web Workers in a proxied app now reach that app.
The runtime interceptor only ran in the app's pages, so a worker's
fetch, XHR, WebSocket orimportScriptswent to the Muximux origin
without the/proxy/<slug>prefix. Dispatcharr's built-in player hit
this: mpegts.js loads/proxy/ts/stream/<uuid>from ablob:worker,
Muximux readtsas an app slug and answered 404, and the player retried
forever. Workers now run a small prelude that applies the same routing --
prepended by the proxy to worker scripts, and injected intoblob:
workers by the page interceptor. - Detaching a Docker-tracked app now sticks. Detach under Settings ->
Discovery is a server-side change, but the open Settings dialog kept its
own copy of the app with the olddocker_key, and saving wrote that key
back -- the app was tracked again and its URL stayed locked. Saves now
never create or restore tracking (only Discover, auto-import and Re-link
do), and the dialog unlocks the app's URL as soon as it is detached.
(#479) - Custom SVG icons that open with a comment or an SVG DOCTYPE upload.
Illustrator and older tools write a comment or<!DOCTYPE svg ...>
ahead of the root element, and the upload sniff rejected those files as
an unsupported type. HTML in an SVG label is still refused. - Changing the sign-in method in Settings no longer leaves the dialog
showing unsaved changes, and the confirmation now appears next to the
Update Method button. Errors in the Security tab show the server's
message without an "API error: 400" prefix.
Changed
- Upgrade note: with OIDC enabled,
auth.oidc.redirect_urlmust now be
empty or an absolute http(s) URL. Otherwise Muximux refuses to start with
a clear error.redirect_urlis not checked while OIDC is disabled. (#480) - A failed or cancelled OIDC sign-in now returns to the login page with a
message instead of a plain "Authentication failed" page. (#480) - Dependencies: OpenTelemetry modules moved to the 1.45 and 0.21 trains
(GHSA-8wmf-6v46-5gfg, GHSA-w34q-cm8f-9c5x; reached only through the
embedded Caddy and not called by Muximux); Svelte 5.57.2, Vite 8.3.3,
marked18.1.0 and Paraglide 2.26; plus routine frontend and GitHub
Actions updates. - The release workflow uploads the SBOM once instead of twice.