Skip to content

v0.3.1

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 26 Sep 06:55
· 25 commits to main since this release
2d33a8d

A security release. It fixes
GHSA-3cgw-73cr-r8c6,
and every installation running 0.1.0 through 0.3.0 should upgrade.

Security

  • A session could be issued without a verified second-factor code. A session
    is now issued only in answer to a code verified in the same request.
  • Failed second-factor attempts did not reliably lead to a lockout. The
    failed-attempt count was cleared as soon as the password was correct, before
    the second factor had been checked. It is now cleared only when a sign-in
    completes.
  • The demo seed no longer has a default password. db:seed gave every demo
    account a password printed in the README, including the accounts it marks as
    requiring two-factor authentication. It now takes SEED_PASSWORD, or
    generates a password for the run and prints it once. On an installation that
    was seeded without SEED_PASSWORD, re-run the seed with it set, or change
    those accounts' passwords.

Removed

  • POST /auth/mfa/complete-enrolment. An account that has to enrol while it
    signs in now receives its session from POST /auth/mfa/activate, in a new
    session field beside the recovery codes: the code that switches the factor
    on is the one that finishes the sign-in. An account that is already enrolled
    signs in through POST /auth/mfa/verify, as before. The web console is
    updated; the mobile app never called the endpoint.