SamWaf v1.3.19
Release date: 2026-02-24
✨ Features
- Display bound host information inside certificate folders
- Rule engine now supports enable/disable toggle per rule
- Added email notification channel. Thanks to @zisain
- Added ServerChan notification support. Thanks to @Tea-NT
- Added customizable authentication prefix for password and CAPTCHA verification. Thanks to @wenjiamian
- Tasks now support custom schedule modification. Thanks to @wjw479
- Added support for Let’s Encrypt free IP certificates, including automatic renewal. Thanks to @nankaine
- Added support for custom backend request header forwarding. Thanks to @GiriNeko
- Added toggle for request header desensitization. Thanks to 3757***
- Custom block page now supports different interception handling modes. Thanks to @LockiJiang
- CC protection now supports returning HTTP 444 (connection close). Thanks to @echs-top
- Added Two-Factor Authentication (2FA) with customizable issuer display
- Custom
X-Forwarded-Forheader now supports modifying chained IP values. Thanks to @GiriNeko - Added support for ZeroSSL domain certificate issuance. Thanks to @dabaibai
- Tunnel now supports selection between IPv4 / IPv6. Thanks to 王**
- Rule list now includes rule code identifier
- Email notification subscription now supports custom recipient address
- Frontend configuration selections are now automatically saved
- Added Enterprise WeCom (WeChat Work) notification channel. Thanks to @Drqf
- Added rule effect testing interface
- Added additional custom rule functions
- Added support for writing access logs to Nginx, Apache, or custom log files. Thanks to @Neillll
- Added support for the latest Ip2region version with upload capability. Thanks to @echs-top
- Added support for custom response headers. Thanks to @echs-top
🐛 Bug Fixes
- Fixed conflict when backend system also used
Authorizationheader in account/password authentication. Thanks to @xihefeng - Fixed issue where certificate bindings were not cleared when copying a site. Thanks to @a1403951401
- Fixed port occupation issue after HTTP/3 restart. Thanks to @echs-top
- Fixed dark mode UI issues. Thanks to @lifetin
- Fixed white-screen issue when enabling real IP parsing and receiving multiple IPs in
X-Forwarded-For. Thanks to @rzorzo - Fixed HTTP not automatically redirecting to HTTPS under wildcard reverse proxy configuration. Thanks to @CHD073
- Fixed notification frequency message merge issue
- Fixed potential resource release issue in backend health check. Thanks to @yypts and @EvianTian
⚡ Optimizations
- Website selection now supports input filtering
- Improved IP extraction configuration UI
- When custom
X-Forwarded-Forvalue is not empty, the specified value is prioritized. Thanks to @GiriNeko - Improved notification subscription interface. Thanks to @zisain
- For non-standard 443 ports, HTTP → HTTPS redirection requires redirect service to be enabled
- Unified IP extraction source logic. Thanks to @SONGjiemo
🔒 Security
- Hidden SamWaf fingerprint characteristics in the management console. Thanks to @wenjiamian