github nilsteampassnet/TeamPass 3.2.2.6

4 hours ago

What's Changed

This is a maintenance release on the 3.2.2 line. It closes three access-control flaws: one-time item links (Secure Send) authorized the sender on key possession instead of current item access, the personal-items recovery dialog could act on another account, and deleting an item could also delete a second item of the user's choosing (GHSA-chpj-3vff-555v, GHSA-6rq2-hf9c-cxh2, GHSA-ghj3-wppx-w8j3). It also makes folder rights apply to item creation, so a read-only role can no longer add items. Secure Send gets a substantial rework: an explicit reveal confirmation, item snapshots, opt-in public address and opt-in TOTP sharing. The bug fixes cover installations upgraded from 2.x and 3.0.x, personal items after a key regeneration, accented search terms, the KeePass import and the Duo login. Upgrading is required for every installation.

This release changes the database schema. UPGRADE_MIN_DATE is raised, so every installation goes through the upgrade wizard once. The migration adds one column to the roles table and one setting. It rewrites no existing data.

🔒 Security fixes

  • Secure Send links could expose items the sender cannot access (GHSA-chpj-3vff-555v, PR #5393, @guerricv) - generating a one-time item link only checked that the sender held an encryption key on the item. Every user receives a key on every shared item through the background key distribution, so with one-time links enabled, any authenticated user could create a link for an item in a folder they cannot see, or for an item restricted to other users, and read its password, label, login, URL and description through that link. Personal items were not exposed. The sender's current access to the item is now checked when the link is created, again when it is revealed (before anything is decrypted and without consuming a view), and when the sender lists their links. Reported by @guerricv.

  • The personal-items recovery dialog could act on another account (GHSA-6rq2-hf9c-cxh2) - the action behind this dialog took its target account from a field of the request that no authorization check inspected. Any authenticated user could therefore use the "I no longer remember my previous password" option to blank the personal-item keys of another account, leaving those items unreadable for their owner, or queue their re-encryption. The action now always targets the signed-in user.

  • Deleting an item could also delete another item (GHSA-ghj3-wppx-w8j3) - the item delete checked the user's rights on the item id it received, but deleted every item matching that id or an item key sent in the same request. A user allowed to delete one item could send the key of a second item (keys appear in the item list of every folder the user can read, including read-only ones) and send it to the recycle bin too, with no log entry for it. The key is now used only to find the item when no id is sent, before the access check, and the deletion touches that single item.

  • A read-only role could create items in the folder (issue #5403, PR #5404, @guerricv) - item creation only checked that the folder was visible to the user, and read-only folders are visible. Creating an item, and choosing the destination of an item copy, now require the create right on the folder. The delete buttons are also hidden in folder lists, search results and the item card when the user has no delete right on the folder. The server-side delete checks were already in place and are unchanged.

  • Four insecure defaults corrected - a new installation seeded the per-account lockout threshold with 0, which disables it; it is now 10, and the administrator dashboard warns while an existing installation still has 0. The Security posture scan called Have I Been Pwned even when breach detection was disabled; the option is now hidden and ignored unless breach detection is on. Saving a new password only cleared the stored breach status when the Security posture page was enabled, so a replaced compromised password kept its badge; the status is now always cleared. The MFA-per-role selector, which is enforced at login, no longer carries a misleading "not yet implemented" note.

📨 Secure Send

  • Recipients confirm before the content is revealed (PR #5395, @guerricv) - opening a link no longer reveals anything by itself: the recipient confirms on the page, so a mail-security gateway or antivirus that follows links cannot consume a view. Views, failed passphrase attempts and an item's automatic-deletion budget are now reserved in one transaction, so concurrent requests cannot exceed a link's limits. The recipient page is sent with no-store, no-referrer and a restrictive Content Security Policy. An item set to delete itself after a number of views, or at a date, is deleted through a Secure Send link exactly as through the item viewer again: a reveal counts as a view, and the deletion is logged.

  • Item links share a snapshot of the item (PR #5396, @guerricv) - a new item link stores an encrypted copy of the label, login, URL, description and password as they were when the link was created. Later edits of the item do not change what the recipient sees, while deleting the item or the sender losing access still blocks the link. A description too long for the stored copy is shortened, and both the sender and the recipient are told; credentials are never shortened, and a set of credentials that does not fit is refused before anything is stored.

  • Current TOTP code on request (PR #5406, @guerricv) - for an item with TOTP enabled, the sender can tick Include the current TOTP code. The option is unchecked by default and is not offered to read-only accounts. The recipient receives a code generated by the server when the content is revealed, plus the next code when the current one is about to expire. The TOTP secret itself is never sent to the browser. An item whose TOTP secret cannot be used is reported instead of producing wrong codes.

  • Public sharing address (PR #5397, @guerricv) - the public sharing address setting now accepts a full HTTPS URL, a hostname, or the historical short prefix, keeps any configured port and path, and is validated on save. The sender form shows the address a link will use. Use public address is unchecked by default and the server applies the same default, so a link uses the main TeamPass address unless the sender selects the public one. Only public links check the request's host, so internal links keep working behind reverse proxies and DNS aliases. The unused endpoint that could change an existing link's lifetime and view count is removed.

  • Sender form (PRs #5398, #5399, @guerricv) - double-clicking can no longer generate two links, and the copy button can no longer copy a link that no longer matches the form. The modal follows the AdminLTE form layout, with accessible labels and dark-mode support. English and French messages are complete, and anonymous recipients see the instance's default language.

✨ New features

  • Login page branding from a dedicated folder - images placed in public/assets/custom/ can be used as the login logo and the new Custom login background by entering their file name (PNG, JPG, GIF or WebP). The folder ships with a README and an .htaccess that disables script execution, and the file integrity check ignores images placed directly in it. The custom logo is also no longer capped at 100 pixels wide.

  • LDAP configuration check - the LDAP settings page gains a Configuration check panel that detects settings no user can log in with, such as an attribute name entered as the user object filter or a full DN entered as the additional user DN, and proposes the corrected value. The page's test button now runs the actual login code and reports each step. Before, it ran its own copy of the search and could answer "User is successfully authenticated" while nobody could log in.

  • TOTP secrets in the CSV export - the CSV export gains a totp column, filled only for items with TOTP enabled. The standard profile (SHA-1, 6 digits, 30 seconds) is written as the bare secret, and any other profile as an otpauth:// URI so that importers do not generate wrong codes.

  • Per-role switch for the Security posture Fix shortcuts - Show the Security posture Fix shortcuts in the role settings hides the "Fix the most urgent" button, the per-item wrench and the reminder banner's Fix link for that role. The shortcuts now only point to items the user may edit. Editing rights are unchanged.

🛠️ Improvements

  • Clear error when the configuration cannot be read (issue #5380) - when the web server cannot read app/config/, typically after copying a release with rsync as root, TeamPass now shows a permission error instead of sending the administrator to the installer, and the upgrade wizard explains a missing settings.php instead of failing with a bare HTTP 500. The installer refuses a database that a TeamPass instance has already used, which would otherwise leave its data behind a new encryption key. The Docker documentation now covers the volume layout, file ownership and a tested procedure to recover a lost configuration.

  • The password show button in the item form is a toggle - it used to work only while held down, which was impossible with a keyboard or a touch screen. The choice is remembered in the browser, and the field is masked by default. Spell checking and autocorrection are disabled on the revealed password.

  • Background tasks on Windows - the scheduler and the task launcher used a Unix shell command that cmd.exe cannot run, and each task opened a console window. They now start without a window on Windows; Linux is unchanged.

  • Scheduled backup reports (PR #5384, @guerricv) - the backup report e-mails use a table layout that puts the result first, in every shipped language.

  • Documentation - the security hardening guide is rewritten as a production checklist, and a new Security posture page replaces the breach detection page (its old address still works).

🐛 Bug fixes

  • 3.0.x accounts could not log in after upgrading (issue #5389) - TeamPass 3.0.x hashed the password, and encrypted the private key with it, after HTML-escaping it. A password containing &, ", ', <, > or an accented letter therefore never matched after the upgrade. The login, the LDAP "previous password" dialog and the personal-items recovery now also try the escaped form, and the account is re-hashed with the real password.

  • Personal-items recovery re-keyed nothing (issue #5392) - after a key regeneration, the recovery task completed every step without re-keying anything. It now re-encrypts the user's personal items from their previous key. Attachments of personal items are also re-keyed correctly after a regeneration. In the LDAP previous-password card, "I don't remember" now gives up only the items that cannot be recovered, instead of every personal item.

  • Saving a personal item could remove its owner's access (issue #5407, PR #5408, @ais-yasas) - when a shared item had been moved into someone's personal folder, saving it deleted the owner's key whenever the owner was not the item's creator. The item then showed "Sharekey not yet generated" and its password could not be replaced. The owner is now the owner of the personal folder, never the creator.

  • 2.x personal items could no longer be migrated (PR #5391, @ais-yasas) - since 3.1.4.40, opening a personal item still encrypted with a 2.x personal salt key hid the page content and showed nothing, because the dialog it relies on had been removed. The dialog is back. The migration also no longer overwrites an item it cannot decrypt with an empty password, and accepts the forms TeamPass 2.x used to protect the salt key.

  • Accented search terms and entity-encoded results (PR #5405, @guerricv) - searching for an accented word did not find labels saved from the item form, which stores "é" as &eacute;, and search results showed such values as Eligibilit&eacute;. Search now matches both spellings and results display the characters. The item card also showed an escaped login such as O&#039;Brien, and the copy button copied it that way.

  • KeePass import crashed on an entry without a title - the import stopped on such an entry. Passwords containing & were also stored as &amp;; they are now imported as written.

  • Duo required a second click (issue #5401) - when Duo was the user's only MFA method, the first click validated the password and showed an empty Duo panel. A single click now reaches the Duo prompt.

  • DataTables warning on the failed-connections log (PR #5383, @guerricv) - changing the channel after opening System → Failed connections raised a "Requested unknown parameter 'actions'" warning.

  • The browser extension FQDN looked saved when it was not - when no FQDN was stored, the Browser extension tab prefilled the field with the host derived from the TeamPass URL, but saved nothing until it was edited, so the Licence tab and the extension received an empty value. The suggestion is now a placeholder, and the Licence tab says that no FQDN is saved.

  • Docker quick start failed at the first pull (issue #5402) - the example .env pinned a tag never published on Docker Hub. It now defaults to latest.

⬆️ Upgrade notes

  • Schema. The upgrade adds an allow_security_posture_fix column to the roles table (default 1, shortcuts shown) and seeds the custom_login_background setting (empty, shipped wallpaper). UPGRADE_MIN_DATE is raised, so every installation goes through the upgrade wizard once; the Docker entrypoint runs the migration on start.
  • Account lockout. Existing installations keep their threshold. If it is 0, the administrator dashboard now warns that failed logins never lock an account: set Maximum login attempts before account lockout in Settings → Options → Security & authentication.
  • Read-only roles. Users whose role gives only read access on a folder can no longer create items there, or copy items into it. Review the folder rights of users who relied on the previous behaviour.
  • Existing Secure Send links. Recipients now press a confirmation button to reveal the content. Policy changes apply to existing links: enabling Require a passphrase makes links without one unavailable, and disabling secure notes makes existing note links unavailable. A note can no longer be revealed once its sender is disabled or deleted.
  • Public sharing address. If you set a short prefix, new links now always use HTTPS and keep the main URL's port and path, and a dotted value such as share.dmz is treated as a complete hostname. Check the public route after upgrading, or enter an explicit URL such as https://share.example.com. Links already sent keep working while their hostname does not change.
  • Custom branding on Docker. Mount individual files into public/assets/custom/ rather than the folder itself: mounting the folder hides its shipped README and .htaccess, which the integrity check then reports as missing.
  • Upgrading by copying files. Use rsync with --no-owner --no-group, as now documented: running it as root otherwise hands app/config/, storage/ and secrets/ back to root.
  • Back up your database before upgrading, as always.

Full Changelog: 3.2.2.5...3.2.2.6

Important

  • Requires at least PHP 8.2

Languages

Please join Teampass v3 translation project on Poeditor and translate it for your language.

Installation

Follow instructions from Documentation.

Upgrade

Follow instructions from Documentation.

Ideas and comments

Are welcome ... please use Discussions.

Don't miss a new TeamPass release

NewReleases is sending notifications on new releases.