Skip to content

Releases: DerKezorm/nextrmnl

nextrmnl 0.3.0

Choose a tag to compare

@DerKezorm DerKezorm released this 26 Sep 05:53

Read-only API keys, so a dashboard can show what nextrmnl is doing, and the QR code of the second factor is back.

New

  • Read-only API keys for dashboards such as nexdeck. The operator creates them under Settings, Security, once the switch "Allow API keys" is on; it is off by default. A key starts with nxt_, is shown exactly once and stored only as a hash. It belongs to an operator account and stops working as soon as that account is no longer operator or the switch is turned off again.
  • Four read-only endpoints under /api/v1, reachable only with Authorization: Bearer <key>: status (version, live sessions, sessions and failures today), sessions (who is connected to what), history (the last sessions and how they ended) and connections (each connection and whether it answers, checked at most once a minute). No sender addresses leave through this way, and a key can neither open a terminal nor change anything.

Fixed

  • The QR code for enrolling a second factor showed as a broken image. It is drawn again.
  • The About page links to nexbeat's project site.

Good to know

  • The update adds one table to the database on first start. Nothing else changes, and every API key stays useless until the switch is turned on.

Install

services:
  nextrmnl:
    image: ghcr.io/derkezorm/nextrmnl:0.3.0
    container_name: nextrmnl
    restart: unless-stopped
    ports:
      - "8460:8000"
    volumes:
      - ./data:/data
    environment:
      PUID: 1000
      PGID: 1000
      TZ: Europe/Berlin

nextrmnl 0.2.0

Choose a tag to compare

@DerKezorm DerKezorm released this 26 Sep 05:06

A second factor for every account, and a round of hardening after a security review of the whole code base. The project site is now at nextrmnl.nexapps.dev.

New

  • Second factor: a code from an authenticator app on top of the password (TOTP, RFC 6238). Enrol under Settings, Account with a QR code, confirm with the first code and your password, and keep the eight recovery codes for the day the phone is gone; each of them works once. Signing in then takes two steps: the password alone opens nothing, the vault key waits in memory for the code, at most five minutes and five tries.
  • Require it: the operator can demand a second factor from every password account. Accounts without one see only their account page until they have enrolled.
  • Reset by the operator: whoever locks themselves out gets the second factor reset under Settings, Accounts; that also ends the account's sessions and terminals.
  • Sign out everywhere for your own account, and Force sign-out of another account for the operator. Both end the browser sessions and every terminal that came with them.
  • Trusted proxies: NEXTRMNL_TRUSTED_PROXIES names the reverse proxies whose X-Forwarded-For is believed, so the sign-in brake and the session history see the real clients.
  • The authentik setup offers the known address again when you run it a second time; only the one-time token is asked for.

Hardened

  • X-Forwarded-For used to be believed from anyone, which let the sign-in brake be bypassed with invented addresses. It is now believed only from a trusted proxy, and the container no longer tells uvicorn to trust every forwarder.
  • Wrong codes count like wrong passwords, per account, and so does every password prompt while signed in: opening the vault, exporting it, changing the password, enrolling the second factor, linking an OIDC identity. Ten failures in a row lock the account for fifteen minutes.
  • A stored password now belongs to the host, port and user it was given for. The owner of a shared connection cannot redirect a member's stored password by changing the target, and the owner's start command never runs in a member's shell; members set their own under "my access".
  • A connection is opened to the address that was checked against the allowed targets, not to a second resolution of the name.
  • Only the owner or the operator can forget a host key, and only the operator accepts a changed one.
  • Terminals end with the sign-in they came with: on logout, on a password change, when the account is deleted or its second factor reset.
  • OIDC: linking an identity needs the password and happens over POST; an empty subject is refused; unlinking also clears the email address; changing the issuer forgets every stored subject; what a provider sends back is logged only at the deepest level.
  • A second factor whose seed cannot be read (a foreign secret.key) refuses the sign-in instead of letting it through.
  • Members can store passwords only for connections they can see, and the vault export leaves withdrawn shares out.
  • Backup manifests are validated before a restore, download headers carry no control characters, /api/docs is off unless NEXTRMNL_API_DOCS=1, there are at most 25 terminals per account, refused sign-ins at a target are braked, and the vault file import bounds the key derivation it accepts.
  • The Argon2 parameters are stored next to the vault key, and a password change rewraps the vault before it replaces the hash, so a failure halfway leaves the vault readable.

Good to know

  • The update adds columns to the database on first start; a backup is taken before. All browser sessions end with the update, sign in again.
  • Behind a reverse proxy set NEXTRMNL_TRUSTED_PROXIES to its address or network. Without it every request counts as coming from the proxy: safe, but all clients share one sign-in brake.
  • Accounts that sign in through OpenID Connect bring the provider's second factor; nextrmnl asks them for no code of its own.

Install

services:
  nextrmnl:
    image: ghcr.io/derkezorm/nextrmnl:0.2.0
    container_name: nextrmnl
    restart: unless-stopped
    ports:
      - "8460:8000"
    volumes:
      - ./data:/data
    environment:
      PUID: 1000
      PGID: 1000
      TZ: Europe/Berlin

nextrmnl 0.1.0

Choose a tag to compare

@DerKezorm DerKezorm released this 25 Sep 20:57

The first release of nextrmnl: SSH and SFTP in the browser, self-hosted, for the machines in your own network.

New

  • Terminal in the browser (xterm.js) over a WebSocket to the nextrmnl server, which speaks SSH to your machines. Tabs for open sessions, full screen, jump hosts, a command to run after sign-in, keepalives.
  • SFTP next to the terminal: browse, upload with drag and drop, download, rename, create folders, delete (whole folders too, after a warning), all through the same SSH connection.
  • Copy and paste like PuTTY: selecting copies; Ctrl+Shift+C, Ctrl+Insert and Ctrl+C with a selection copy; Ctrl+V, Ctrl+Shift+V, Shift+Insert and a right click paste. Several lines are shown before they run.
  • Accounts: the first account is the operator, others come by invitation link or through OpenID Connect. Connections can be shared; sharing passes name, address and settings, never access. Every member signs in with their own user and key.
  • A vault per account for private keys and stored passwords, sealed with a key that only the account's password unwraps. Not the operator, not a backup, not a database dump can read it. Generate Ed25519 or RSA keys or paste existing ones; download the vault as an encrypted file and restore it here or on another nextrmnl.
  • Host keys are compared on every connection. Unknown hosts are shown with their fingerprint before you trust them; a changed key is refused until you say otherwise.
  • Allowed targets: by default nextrmnl only connects into private networks (10/8, 172.16/12, 192.168/16, 100.64/10, loopback, link-local). The operator can add networks and names, or open it up.
  • OpenID Connect with any provider that offers discovery. For authentik there is a one-button setup that creates the provider, application, signing key and mappings with a one-time API token, or a blueprint file to do it without a token. Existing accounts link themselves to their identity at the provider; new accounts through the provider only when the operator allows it.
  • Public address under Settings, Sign-in, for installations behind a reverse proxy: invitation links, the OIDC return address and the WebSocket origin check follow it. NEXTRMNL_PUBLIC_URL still works as the default.
  • Backups: consistent copies on a schedule and before every schema change, downloads as an AES encrypted ZIP that 7-Zip opens without nextrmnl, restore with a preview and an automatic restart.
  • A log with four levels (the deep ones switch themselves off), a request id in every line and in every error message, downloadable. Never with terminal content, keystrokes, passwords, keys or tokens.
  • German and English; another language is one JSON file.

Good to know

  • Passwords are hashed with Argon2id, ten failed sign-ins lock the account for fifteen minutes, every changing request needs a header the browser only sends from nextrmnl itself, responses carry a Content Security Policy.
  • Put nextrmnl behind a reverse proxy with TLS before you use it from anywhere but your own desk. Pasting with a right click needs HTTPS anyway.
  • Two-factor sign-in is not part of this release.

Install

services:
  nextrmnl:
    image: ghcr.io/derkezorm/nextrmnl:0.1.0
    container_name: nextrmnl
    restart: unless-stopped
    ports:
      - "8460:8000"
    volumes:
      - ./data:/data
    environment:
      PUID: 1000
      PGID: 1000
      TZ: Europe/Berlin