Skip to content

v1.8.7 — Document access fix & reverse-proxy setup

Choose a tag to compare

@edgarjc edgarjc released this 26 Sep 15:46
· 1 commit to main since this release
4231517

Security

  • Portal clients could download the signing certificate of any fully signed document in their workspace, including documents on projects they aren't assigned to. The certificate lists signers' names and emails, signing methods and the audit trail. They could also add "viewed" events to those documents' audit trails. Both routes now require the same project access as the rest of the document routes. Affects 1.3.1 through 1.8.6. Reported by @kta1kri. See GHSA-3jf5-3gm3-p9g6.

Fixes

  • Sign-in failed with "Invalid origin" from the second login on installs behind a domain or reverse proxy (Coolify, Cloudflare, Nginx). The shipped docker-compose.yml never passed WEB_URL into the container. It does now, and the container logs a warning at startup when WEB_URL is missing. (#70, #71)
  • The built-in PostgreSQL database could stop the container on first start with an empty data volume. (#71)
  • Copy buttons did nothing on installs served over plain HTTP. They now fall back to a method that works without HTTPS. (#69)

Upgrading

If you run Atrium behind a domain or reverse proxy, set WEB_URL to the address people open it at, e.g. WEB_URL=https://atrium.example.com. Compose users on an older copy of docker-compose.yml should also add WEB_URL: "${WEB_URL}" under the atrium service's environment. See Behind a reverse proxy.

Full changelog: v1.8.6...v1.8.7