Skip to content

v0.5.1 — self-hosted dashboard password

Choose a tag to compare

@ahmetvural79 ahmetvural79 released this 06 Oct 18:18
· 3 commits to main since this release

Security

  • VITRUS_PASSWORD — set it and the self-hosted dashboard, its read API and the replay settings ask for it (HTTP Basic, any user name). The tracker and ingest stay public, because your visitors' browsers call them. Until now these were open to anyone who could reach the port; vitrus start now says so when the variable is unset. Upgrade and set it if your server is reachable from outside.
  • Ingest bodies over 64 KB are refused with 413 (Bun's default limit was 128 MB).

Docs

  • README rebuilt around screenshots of the hosted dashboard on a demo workspace (sample data).