Releases: DerKezorm/nextrmnl
Releases · DerKezorm/nextrmnl
Release list
nextrmnl 0.3.0
Read-only API keys, so a dashboard can show what nextrmnl is doing, and the QR code of the second factor is back.
New
- Read-only API keys for dashboards such as nexdeck. The operator creates them under Settings, Security, once the switch "Allow API keys" is on; it is off by default. A key starts with
nxt_, is shown exactly once and stored only as a hash. It belongs to an operator account and stops working as soon as that account is no longer operator or the switch is turned off again. - Four read-only endpoints under
/api/v1, reachable only withAuthorization: Bearer <key>:status(version, live sessions, sessions and failures today),sessions(who is connected to what),history(the last sessions and how they ended) andconnections(each connection and whether it answers, checked at most once a minute). No sender addresses leave through this way, and a key can neither open a terminal nor change anything.
Fixed
- The QR code for enrolling a second factor showed as a broken image. It is drawn again.
- The About page links to nexbeat's project site.
Good to know
- The update adds one table to the database on first start. Nothing else changes, and every API key stays useless until the switch is turned on.
Install
services:
nextrmnl:
image: ghcr.io/derkezorm/nextrmnl:0.3.0
container_name: nextrmnl
restart: unless-stopped
ports:
- "8460:8000"
volumes:
- ./data:/data
environment:
PUID: 1000
PGID: 1000
TZ: Europe/Berlinnextrmnl 0.2.0
A second factor for every account, and a round of hardening after a security review of the whole code base. The project site is now at nextrmnl.nexapps.dev.
New
- Second factor: a code from an authenticator app on top of the password (TOTP, RFC 6238). Enrol under Settings, Account with a QR code, confirm with the first code and your password, and keep the eight recovery codes for the day the phone is gone; each of them works once. Signing in then takes two steps: the password alone opens nothing, the vault key waits in memory for the code, at most five minutes and five tries.
- Require it: the operator can demand a second factor from every password account. Accounts without one see only their account page until they have enrolled.
- Reset by the operator: whoever locks themselves out gets the second factor reset under Settings, Accounts; that also ends the account's sessions and terminals.
- Sign out everywhere for your own account, and Force sign-out of another account for the operator. Both end the browser sessions and every terminal that came with them.
- Trusted proxies:
NEXTRMNL_TRUSTED_PROXIESnames the reverse proxies whoseX-Forwarded-Foris believed, so the sign-in brake and the session history see the real clients. - The authentik setup offers the known address again when you run it a second time; only the one-time token is asked for.
Hardened
X-Forwarded-Forused to be believed from anyone, which let the sign-in brake be bypassed with invented addresses. It is now believed only from a trusted proxy, and the container no longer tells uvicorn to trust every forwarder.- Wrong codes count like wrong passwords, per account, and so does every password prompt while signed in: opening the vault, exporting it, changing the password, enrolling the second factor, linking an OIDC identity. Ten failures in a row lock the account for fifteen minutes.
- A stored password now belongs to the host, port and user it was given for. The owner of a shared connection cannot redirect a member's stored password by changing the target, and the owner's start command never runs in a member's shell; members set their own under "my access".
- A connection is opened to the address that was checked against the allowed targets, not to a second resolution of the name.
- Only the owner or the operator can forget a host key, and only the operator accepts a changed one.
- Terminals end with the sign-in they came with: on logout, on a password change, when the account is deleted or its second factor reset.
- OIDC: linking an identity needs the password and happens over POST; an empty subject is refused; unlinking also clears the email address; changing the issuer forgets every stored subject; what a provider sends back is logged only at the deepest level.
- A second factor whose seed cannot be read (a foreign
secret.key) refuses the sign-in instead of letting it through. - Members can store passwords only for connections they can see, and the vault export leaves withdrawn shares out.
- Backup manifests are validated before a restore, download headers carry no control characters,
/api/docsis off unlessNEXTRMNL_API_DOCS=1, there are at most 25 terminals per account, refused sign-ins at a target are braked, and the vault file import bounds the key derivation it accepts. - The Argon2 parameters are stored next to the vault key, and a password change rewraps the vault before it replaces the hash, so a failure halfway leaves the vault readable.
Good to know
- The update adds columns to the database on first start; a backup is taken before. All browser sessions end with the update, sign in again.
- Behind a reverse proxy set
NEXTRMNL_TRUSTED_PROXIESto its address or network. Without it every request counts as coming from the proxy: safe, but all clients share one sign-in brake. - Accounts that sign in through OpenID Connect bring the provider's second factor; nextrmnl asks them for no code of its own.
Install
services:
nextrmnl:
image: ghcr.io/derkezorm/nextrmnl:0.2.0
container_name: nextrmnl
restart: unless-stopped
ports:
- "8460:8000"
volumes:
- ./data:/data
environment:
PUID: 1000
PGID: 1000
TZ: Europe/Berlinnextrmnl 0.1.0
The first release of nextrmnl: SSH and SFTP in the browser, self-hosted, for the machines in your own network.
New
- Terminal in the browser (xterm.js) over a WebSocket to the nextrmnl server, which speaks SSH to your machines. Tabs for open sessions, full screen, jump hosts, a command to run after sign-in, keepalives.
- SFTP next to the terminal: browse, upload with drag and drop, download, rename, create folders, delete (whole folders too, after a warning), all through the same SSH connection.
- Copy and paste like PuTTY: selecting copies; Ctrl+Shift+C, Ctrl+Insert and Ctrl+C with a selection copy; Ctrl+V, Ctrl+Shift+V, Shift+Insert and a right click paste. Several lines are shown before they run.
- Accounts: the first account is the operator, others come by invitation link or through OpenID Connect. Connections can be shared; sharing passes name, address and settings, never access. Every member signs in with their own user and key.
- A vault per account for private keys and stored passwords, sealed with a key that only the account's password unwraps. Not the operator, not a backup, not a database dump can read it. Generate Ed25519 or RSA keys or paste existing ones; download the vault as an encrypted file and restore it here or on another nextrmnl.
- Host keys are compared on every connection. Unknown hosts are shown with their fingerprint before you trust them; a changed key is refused until you say otherwise.
- Allowed targets: by default nextrmnl only connects into private networks (10/8, 172.16/12, 192.168/16, 100.64/10, loopback, link-local). The operator can add networks and names, or open it up.
- OpenID Connect with any provider that offers discovery. For authentik there is a one-button setup that creates the provider, application, signing key and mappings with a one-time API token, or a blueprint file to do it without a token. Existing accounts link themselves to their identity at the provider; new accounts through the provider only when the operator allows it.
- Public address under Settings, Sign-in, for installations behind a reverse proxy: invitation links, the OIDC return address and the WebSocket origin check follow it.
NEXTRMNL_PUBLIC_URLstill works as the default. - Backups: consistent copies on a schedule and before every schema change, downloads as an AES encrypted ZIP that 7-Zip opens without nextrmnl, restore with a preview and an automatic restart.
- A log with four levels (the deep ones switch themselves off), a request id in every line and in every error message, downloadable. Never with terminal content, keystrokes, passwords, keys or tokens.
- German and English; another language is one JSON file.
Good to know
- Passwords are hashed with Argon2id, ten failed sign-ins lock the account for fifteen minutes, every changing request needs a header the browser only sends from nextrmnl itself, responses carry a Content Security Policy.
- Put nextrmnl behind a reverse proxy with TLS before you use it from anywhere but your own desk. Pasting with a right click needs HTTPS anyway.
- Two-factor sign-in is not part of this release.
Install
services:
nextrmnl:
image: ghcr.io/derkezorm/nextrmnl:0.1.0
container_name: nextrmnl
restart: unless-stopped
ports:
- "8460:8000"
volumes:
- ./data:/data
environment:
PUID: 1000
PGID: 1000
TZ: Europe/Berlin