Skip to content

Ebbwell 0.3.0 — local accounts

Choose a tag to compare

@Maxren2 Maxren2 released this 28 Sep 06:15
· 17 commits to main since this release

Local accounts with a network-restricted sign-in policy

Single sign-on (OpenID Connect) is now optional. You can also use local accounts (username + password), and you decide where passwords are accepted with LOCAL_LOGIN:

LOCAL_LOGIN Password sign-in
disabled (default) nowhere, single sign-on only
local-network only from LOCAL_NETWORKS, never through the public domain
everywhere anywhere (not recommended)
  • Fails closed. The connecting address and every forwarded client address must be local; any public or unparseable address means "outside". Passwords are never accepted over plain HTTP from outside.
  • No password form where passwords aren't allowed. The public domain goes straight to single sign-on.
  • Administration: create accounts with one-time temporary passwords (forced change at first sign-in), reset passwords, grant admin rights (also via OIDC_ADMIN_GROUPS), disable or delete accounts. The last admin can't be removed, and admins never see cycle data. A connection diagnostic shows how Ebbwell classifies your current connection.
  • Hardening: per-account lockout (10 failures → 15 min), per-device rate limit, login CSRF protection, timing-safe handling of unknown usernames.
  • Setup and recovery: bootstrap admin via ADMIN_USERNAME / ADMIN_PASSWORD. Recovery CLI: docker exec <container> node server/cli.ts reset-password <user>.
  • Plain-HTTP LAN access (http://nas-ip:port) works with a separate non-Secure session cookie.

Upgrade note: existing AUTH_MODE=oidc configurations keep working unchanged.

Image: ghcr.io/maxren2/ebbwell:0.3.0. See docs/DEPLOY.md §2.