You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Single sign-on, a Terminal, a Packet Sniffer and a migration export
New
Sign in with an existing account. Single sign-on against any OpenID Connect provider - Entra
ID, Okta, Keycloak, Authentik. Add one under Settings -> Authentication -> Access Management -> SSO / OIDC, map a claim to a MikroDash role, and each enabled provider gets its own button on
the sign-in screen. You can upload an icon so the button carries your provider's mark.
The password form never goes away. Your local administrator is always a way back in, even if
the provider is down. A username that collides with an existing local account is refused rather
than merged, and somebody whose claims map to no role cannot sign in at all.
Roles follow your provider. The role is worked out on every sign-in, so moving someone
between groups moves their access here, and removing them removes it.
A Terminal page. The device's own console in the browser, with tab completion done by the
router, ? help, pasted blocks, and a prompt that says which menu you are in. Granted per device
and recorded in the Audit Trail line by line.
A Packet Sniffer page. Run the router's own capture, watch the packet table fill, and export
it as a pcap for Wireshark, with a progress bar for the download.
Tools is a category, not a page. Ping, Traceroute, Torch, Bandwidth Test and Packet Sniffer
are five pages in the sidebar now, with a new Admin category beside them.
Five cards on the Torch page: total rate, the busiest protocol and its share, the busiest
talker, and the flow count - so a torch run answers "what is using the line" without reading the
table.
A migration export for backups, off by default and set per device. A .backup restores onto
the same device; to rebuild on a different one you need the export, and an ordinary export has
every password masked. Switch this on and each backup keeps a second export with them included,
encrypted at rest, downloadable from the history as .rsc (secrets).
Thanks to @eltionb for raising it.
Changed
Backup exports are terse. Each command is one line instead of being wrapped across
continuations, so changing one rule shows as a one-line diff rather than a dozen. On the first
run after upgrading, each device stores a fresh backup and its next diff shows the whole
configuration as changed, once. Thanks to @eltionb.
Fixed
Right-click paste did not work on the Terminal page over plain HTTP.
Dropdowns, buttons and text boxes could render unstyled in some browsers, showing the browser's
own default rather than the theme.
Internal
The ID token is verified against the provider's key set with the standard library alone - no new
dependencies - with PKCE, a nonce, an algorithm allow-list and bounded key refetches.
Schema v30 adds the migration export's size to the backup history.