v0.3.1
Pre-release
Pre-release
A security release. It fixes
GHSA-3cgw-73cr-r8c6,
and every installation running 0.1.0 through 0.3.0 should upgrade.
Security
- A session could be issued without a verified second-factor code. A session
is now issued only in answer to a code verified in the same request. - Failed second-factor attempts did not reliably lead to a lockout. The
failed-attempt count was cleared as soon as the password was correct, before
the second factor had been checked. It is now cleared only when a sign-in
completes. - The demo seed no longer has a default password.
db:seedgave every demo
account a password printed in the README, including the accounts it marks as
requiring two-factor authentication. It now takesSEED_PASSWORD, or
generates a password for the run and prints it once. On an installation that
was seeded withoutSEED_PASSWORD, re-run the seed with it set, or change
those accounts' passwords.
Removed
POST /auth/mfa/complete-enrolment. An account that has to enrol while it
signs in now receives its session fromPOST /auth/mfa/activate, in a new
sessionfield beside the recovery codes: the code that switches the factor
on is the one that finishes the sign-in. An account that is already enrolled
signs in throughPOST /auth/mfa/verify, as before. The web console is
updated; the mobile app never called the endpoint.