Skip to content

v2.55.6

Choose a tag to compare

@aebrer aebrer released this 11 Aug 23:51
· 31 commits to master since this release
6a06b2b

Make dashboard remote auth resilient and expiry-aware

Remote dashboard authentication now handles concurrent Tailscale lookups reliably, and device pairings have configurable expiry with advance warnings.

What changed

  • Resilient Tailscale identity lookup. Remote requests now use peer-specific tailscale whois resolution. Concurrent requests for the same peer share one in-flight lookup without caching completed results.
  • Clear fail-closed errors. Clean unknown peers remain denied with 403, while command, timeout, parse, and schema failures are reported as distinct authentication-subsystem failures without exposing peer addresses, identities, or raw command output.
  • Configurable pairing duration. New pairings last 180 days by default. Settings accepts 1–3650 days for future pairings without changing existing devices' recorded expiry dates.
  • Advance expiry warnings. Remote devices receive a warning during the final 10% of their original pairing period, at most once per UTC day across tabs, reconnects, and dashboard restarts.
  • Long-lived tab checks. Startup, foreground, reconnect, and scheduled authentication checks share the same warning path, with bounded retry and browser/server clock-skew handling.
  • Device expiry visibility. Settings shows each paired device's recorded expiry date alongside unpair controls.
  • Backward-compatible storage. Existing pairing files migrate without changing recorded expiries, while updated state remains atomically written with restrictive permissions.
  • Regression coverage and documentation. Resolver concurrency, failure handling, settings, warning boundaries, persistence, HTTP behavior, timers, and UI behavior are covered; dashboard documentation reflects the new authentication flow.

Implemented in PR 455.