Skip to content

Releases: Neotoxic-off/Stash

v0.1.5

Choose a tag to compare

@Neotoxic-off Neotoxic-off released this 17 May 03:29
Include object SHA256 in storage events

Add an optional Sha256 field to StorageEvent and update ObjectCreated/ObjectUpdated factories to accept an optional sha256 parameter. Update ObjectsController to pass the computed sha256 when broadcasting create/update events so notifications include the object's checksum for consumers to verify integrity. Timestamp behavior is preserved.

v0.1.4

Choose a tag to compare

@Neotoxic-off Neotoxic-off released this 17 May 01:26
Add protected layout, move pages, remove proxy

Introduce a new (protected)/layout.tsx that enforces auth by validating a stash_session cookie against an HMAC-SHA256 token derived from ADMIN_PASSWORD and redirects unauthenticated requests to /login. Move several route pages into the (protected) group (/, [bucket], events, keys) so they are guarded by the new layout. Remove the previous proxy middleware (web/src/proxy.ts) which performed similar session checks. Also: remove Navbar from the global root layout and render it in the protected layout instead, and tweak the login page min-height to use full screen (min-h-screen).

v0.1.3

Choose a tag to compare

@Neotoxic-off Neotoxic-off released this 17 May 00:59
Add admin login/logout and auth proxy

Introduces a simple session-based admin auth flow and middleware to protect the app.

- Adds POST /api/auth/login: validates the provided password against ADMIN_PASSWORD, sets an httpOnly `stash_session` cookie (HMAC-SHA256 hex of a fixed nonce) on success, returns 403 on invalid credentials and 500 if ADMIN_PASSWORD is not configured.
- Adds POST /api/auth/logout: clears the `stash_session` cookie.
- Adds a client-side login page at /login with form, loading/error states, and navigation on success.
- Adds a proxy middleware (web/src/proxy.ts) that redirects unauthenticated requests to /login, skips static assets and public routes (/login, /api/auth/login, /api/auth/logout), and treats missing ADMIN_PASSWORD as open access.
- Updates Navbar to include a logout button that calls the logout endpoint and navigates to the login page.

This provides basic admin protection for the app; session tokens are derived from the admin password using an HMAC-based scheme and stored in a cookie with Lax sameSite and a 7-day expiry.

v0.1.2

Choose a tag to compare

@Neotoxic-off Neotoxic-off released this 17 May 00:21
Support AWS Credential key ID as API key

Allow AWS-signed requests to authenticate by extracting the Credential key ID from Authorization headers and treating it as the access key. Updates ApiKeyMiddleware (C#) to parse Authorization for `Credential=KEYID/...` when no X-Access-Key or accessKey query param is present, and updates the Next.js forwardHeaders to populate x-access-key from the same Credential value so downstream authentication can succeed. Existing validation (empty/length check) remains unchanged.

v0.1.1

Choose a tag to compare

@Neotoxic-off Neotoxic-off released this 16 May 23:41
Add StorageDbContext and update .gitignore

Introduce StorageDbContext (EF Core) with DbSets for Bucket, StorageObject, AccessKey, MultipartUpload, MultipartPart, and PresignedToken. Configure primary keys for entities, add a unique index on (BucketName, Key) for StorageObject, and set MultipartPart.Id to ValueGeneratedOnAdd. Also tweak .gitignore to ignore /data/ (leading slash) and add .claude/settings.local.json.