github mescon/Muximux v3.5.0

5 hours ago

Single sign-on grows up: OIDC can be set up from Settings -> Security,
logging out can end the session at the identity provider, sign-in can be
SSO-only, and providers can end Muximux sessions through back-channel
logout. Docker discovery gains a muximux.app.url label for apps behind
your own reverse proxy. Proxied apps that fetch from Web Workers, such as
Dispatcharr's live stream player, work again, and ${VAR} secrets are no
longer written to config.yaml in plain text. Two upgrade notes: OIDC
with an invalid redirect_url now refuses to start, and auto-import only
creates gateway sites for containers that ask for one (see below).

Added

  • OIDC in Settings. Single sign-on can be set up and changed in
    Settings -> Security, with a connection test and copyable callback and
    back-channel URLs. The client secret is never shown, and values that
    come from environment variables stay in the environment. (#480)
  • OIDC sign-out at the identity provider. With auth.oidc.provider_logout
    on, logging out of Muximux also ends the session at the provider through
    its end-session endpoint, with a configurable return address. (#480)
  • SSO-only sign-in. auth.oidc.auto_redirect skips the login page and
    auth.oidc.disable_local_login refuses username/password sign-in. (#480)
  • OIDC back-channel logout at /api/auth/oidc/backchannel-logout:
    signing out at the provider ends the user's Muximux sessions. (#480)
  • muximux.app.url Docker label -- open a discovered app at a fixed
    URL, such as its public name behind your own reverse proxy, without the
    built-in gateway. The app stays tracked and its health check follows the
    container as its IP changes. (#479)

Fixed

  • ${VAR} references in config.yaml survive saving from Settings.
    They were written back as their expanded values, putting secrets kept in
    the environment into the file in plain text.
  • No false "client_secret is stored in plaintext" warning at startup
    when auth.oidc.client_secret is written as ${VAR}. The check looked
    at the already-expanded value, so it fired for every configured secret.
  • Auto-import no longer publishes every container on a gateway
    subdomain
    when server.tls.domain is set. Only containers with
    muximux.app.gateway.domain get a gateway site; the derived default
    only pre-fills the import modal. If you relied on those
    derived subdomains, add muximux.app.gateway.domain=<name>.<your domain>
    to those containers before upgrading -- otherwise the sites are removed
    on the first refresh and the apps point at their container URLs.
  • Auto-import updates keep per-app settings. A label change or
    container IP change under the update/sync modes replaced the whole
    app, dropping health check, auth bypass, access, scale, pinned and proxy
    headers. Only label-managed fields change now.
  • muximux.app.path is applied to discovered app URLs, and a relative
    muximux.app.health such as /api/v3/health is resolved against the
    container. Both were parsed but never used.
  • muximux.gateway.skip_tls_verify is no longer reported as an unknown
    label.
  • Requests made from Web Workers in a proxied app now reach that app.
    The runtime interceptor only ran in the app's pages, so a worker's
    fetch, XHR, WebSocket or importScripts went to the Muximux origin
    without the /proxy/<slug> prefix. Dispatcharr's built-in player hit
    this: mpegts.js loads /proxy/ts/stream/<uuid> from a blob: worker,
    Muximux read ts as an app slug and answered 404, and the player retried
    forever. Workers now run a small prelude that applies the same routing --
    prepended by the proxy to worker scripts, and injected into blob:
    workers by the page interceptor.
  • Detaching a Docker-tracked app now sticks. Detach under Settings ->
    Discovery is a server-side change, but the open Settings dialog kept its
    own copy of the app with the old docker_key, and saving wrote that key
    back -- the app was tracked again and its URL stayed locked. Saves now
    never create or restore tracking (only Discover, auto-import and Re-link
    do), and the dialog unlocks the app's URL as soon as it is detached.
    (#479)
  • Custom SVG icons that open with a comment or an SVG DOCTYPE upload.
    Illustrator and older tools write a comment or <!DOCTYPE svg ...>
    ahead of the root element, and the upload sniff rejected those files as
    an unsupported type. HTML in an SVG label is still refused.
  • Changing the sign-in method in Settings no longer leaves the dialog
    showing unsaved changes, and the confirmation now appears next to the
    Update Method button. Errors in the Security tab show the server's
    message without an "API error: 400" prefix.

Changed

  • Upgrade note: with OIDC enabled, auth.oidc.redirect_url must now be
    empty or an absolute http(s) URL. Otherwise Muximux refuses to start with
    a clear error. redirect_url is not checked while OIDC is disabled. (#480)
  • A failed or cancelled OIDC sign-in now returns to the login page with a
    message instead of a plain "Authentication failed" page. (#480)
  • Dependencies: OpenTelemetry modules moved to the 1.45 and 0.21 trains
    (GHSA-8wmf-6v46-5gfg, GHSA-w34q-cm8f-9c5x; reached only through the
    embedded Caddy and not called by Muximux); Svelte 5.57.2, Vite 8.3.3,
    marked 18.1.0 and Paraglide 2.26; plus routine frontend and GitHub
    Actions updates.
  • The release workflow uploads the SBOM once instead of twice.

Don't miss a new Muximux release

NewReleases is sending notifications on new releases.