Ebbwell 0.3.0 — local accounts
Local accounts with a network-restricted sign-in policy
Single sign-on (OpenID Connect) is now optional. You can also use local accounts (username + password), and you decide where passwords are accepted with LOCAL_LOGIN:
LOCAL_LOGIN |
Password sign-in |
|---|---|
disabled (default) |
nowhere, single sign-on only |
local-network |
only from LOCAL_NETWORKS, never through the public domain |
everywhere |
anywhere (not recommended) |
- Fails closed. The connecting address and every forwarded client address must be local; any public or unparseable address means "outside". Passwords are never accepted over plain HTTP from outside.
- No password form where passwords aren't allowed. The public domain goes straight to single sign-on.
- Administration: create accounts with one-time temporary passwords (forced change at first sign-in), reset passwords, grant admin rights (also via
OIDC_ADMIN_GROUPS), disable or delete accounts. The last admin can't be removed, and admins never see cycle data. A connection diagnostic shows how Ebbwell classifies your current connection. - Hardening: per-account lockout (10 failures → 15 min), per-device rate limit, login CSRF protection, timing-safe handling of unknown usernames.
- Setup and recovery: bootstrap admin via
ADMIN_USERNAME/ADMIN_PASSWORD. Recovery CLI:docker exec <container> node server/cli.ts reset-password <user>. - Plain-HTTP LAN access (
http://nas-ip:port) works with a separate non-Secure session cookie.
Upgrade note: existing AUTH_MODE=oidc configurations keep working unchanged.
Image: ghcr.io/maxren2/ebbwell:0.3.0. See docs/DEPLOY.md §2.