Repository navigation
v1.0.0
Changelog
- 94c1350499fd49a469a87342c25f6cd17dc54623 Add encrypted PDF sharing backed by DarkStorage
- 05b9ceff69aab05980521d333d58eb4243f974ab Add encrypted PDF sharing backed by DarkStorage
- c9ff3bf3a8af4cb51be411dbb75ca79fdad953e0 Add landing page and Kubernetes deployment
- e080cf1735b1d3fd61a3f6bfbd4521b83eb7ba58 Harden platform and add device enrollment and named secret variables
- 8cc413307200c5c0db53d84b37b6c6adba87f670 Harden secret and document memory lifetimes with guarded buffers
- fd259df0ba9f0d0d3cf4d9ec5ebe3524b61a63cf Harden secret and document memory lifetimes with guarded buffers
- 4261f63b588dd18608c992495720a35c62b6288c Merge branch 'prod-readiness-2026-09-26' into prod-readiness-components
- 8918e7e318ce32b44f0accf831ea98f9871fd86b Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
- e194b4c7ddbfebdec05971cd56ffa1e476dee427 Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
- 8c1a204ebb1789b9361b60c79f4de45e66fe4001 Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
- cb8d81af1ecd446b85d8fbdaf2a56e51697594f9 Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
- 917bc42ab873b29bef6ac8df0249c68c6e2043f7 Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
- 4efa813c4d8682e9d71b582f5e140d46b13ff4a7 Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
- 10f723feb7b4dc466a4bbcd5045ed82c4d3bbbc8 Merge branch 'site/wiring-audit' into site/web-refresh
- 2cee976b4c0e40a0092034746fd3ae18cc8d75f4 Merge feat/cli-sso-login into release from main 64b23ff
- 2b4c53646331febf40d58543a472f7720715c063 Merge pull request #2 from afterdarksys/fix/cli-distribution
- 224b77892a9be231ef2a4f6584952d79c0bce8e0 Merge pull request #3 from afterdarksys/docs/cli-v1.0.0-notes
- bfd7f76434ec1cfcad8f24535773ac411f66b80c Merge pull request #4 from afterdarksys/fix/cli-default-output
- 8874962987f3f001f50bc4348ccf519b88a3b5b9 Merge release/cli-sso-login: CLI SSO login (production 2cee976)
- ad954730e06a223261fa7796389e255828c96fa0 Merge remote-tracking branch 'origin/prod-readiness-2026-09-26' into prod-readiness-web
- 9a9b6eb4450061d6f8f286725ca4ca3c0abdf3c6 Merge remote-tracking branch 'origin/prod-readiness-2026-09-26' into prod-readiness-web
- 16d558822d5fea9415801f13a6e6487e23163991 Merge remote-tracking branch 'origin/prod-readiness-2026-09-26' into prod-readiness-web
- f5272f2b3e018d42eeeef0d069d14edba3f826b9 Merge remote-tracking branch 'origin/prod-readiness-components' into integration-trial
- b39f5cfe23b588fa34f2a383aaf2cdeea37d0880 Merge remote-tracking branch 'origin/prod-readiness-web' into integration-trial
- 0c062063f9edfafe6a6dc279eafacf833acf14b0 Record verified integration revisions and deployment handoff
- 9eeb4b53769ac2957391ff58eeefd5df2c474c66 Record verified integration revisions and deployment handoff
- 9c8c2a382eab482027acf4ecd93eb2a5a9bd9ffd Record verified memory-hardening release revisions
- ec6e60c54ad826f02f36aeed820181e9e9f4b11d Record verified memory-hardening release revisions
- 360297bb845a257fa2255aed7ed14c93bfae5b1d Redesign website and console with themes and software documentation
- a488bd379ca917f12bc5e5af1a30d940d3002261 Redesign website and console with themes and software documentation
- 29bf307f8947af1e1f828318a4ea20ed99170cb6 build(deps): replace hashicorp/vault/shamir with an in-tree copy
- 8e6b73094a45f07b5254940ea0deb881f4cfc5e5 build(deps): update google.golang.org/grpc to 1.83.2
- a2a0e92150aed3942aa5a53a44b4fcd66fa28e25 build: Add Dockerfile and tidy dependencies
- 793587521754180da3608adafce14ad02f2f1c11 build: add .dockerignore for the API image
- f498d16a9ec1964ccc97a2b8b41d967e3bc76ac0 build: replace stale deploy scripts with build-only image scripts
- c1b499272672842306e8bd3eb10a9ae88e344efb chore(cli): remove the unreachable cli/cmd/secrets package
- 336d7e528fd62db0c37d588bdf264c1a080b791b chore(deploy): align k8s manifests with the image contract, drop dead ones
- 2aee99642968fbe86c17e92dc37581e87a3450d4 chore(web): drop the unused OIDC build argument and API origin from CSP
- a6f02e57e96c6e7d228c688651df6a4ef65d6239 crypto: PKCS#11 login outside the secure-memory lock, with a timeout
- b5463f6887822f34fcbaafa4837e84018b3be73b crypto: PKCS#11 login timeout is fatal and abandons the session
- 58083d492b68f0b0bd3c2acef439e90837ad89d7 deploy plan: isolated renderer, DarkStorage release branch, SNAT note
- 4d795130784f71a154ad4d79ebe50dc0962756ea deploy plan: renderer latency measured in the final container
- c90311850fbff5deb291207ea544d5d40242d513 deploy plan: separate renderer uids, liveness, TRUSTED_PROXIES, ptrace_scope
- 8d57be803c741170d714c4b0e81068dbc06f6ea6 deploy/2026-09-28: prod run list, DB preflight/backup, local rehearsal
- 3e050bd6176e1bb93679fff46855bcaf38302f2f deploy/2026-09-28: prod run list, DB preflight/backup, local rehearsal
- 25cefbe775fcca3849532df007f4b7ea99baec10 deploy/2026-09-28: read-only check that the API's Vault token can write the SSO secret path
- 6a4abcaba9517d010d413c0de8bfea13099c230a deploy/2026-09-28: read-only check that the API's Vault token can write the SSO secret path
- ab13c89f07b2599238510e020a9b95097b35460d deploy: Vault check probes a minted tenant token; root is a warning
- 73bfb88357fc4fe0c840bcd7a4a65ebf6aa2823c deploy: protected documents deployment plan and operator files
- c01e6fb9876685bba70d49a0c5f780a34d3a08d2 deploy: run list for the CLI SSO release 2cee976 on apps (run 2026-10-04)
- 69d60e628eacd0d28e81ad00eaa5a1d28b40200c deps: bump x/crypto, go-pkcs12, go-ntlmssp and lego to fixed versions
- 4050e3f6d8cd7a4d8c7e9b220f723d7b031cffa5 docker: build the api-server package, not main.go alone
- 7f12caf091d7fbd5c099ad93ed5461473bf26ee1 docs(cli): install/release docs; API keys via ss login or POST /api/v1/api-keys
- 0914759c5e598ba931d471b5deeb8a5930dc3b14 docs(cli): state what ct, discover --import and import actually do
- c5e8d298a6ac1e77abed22562f464acf943fcf59 docs(cli): v1.0.0 release notes are final
- 7ac7bd5dd5b8d9370b497cedb7702f7cad77f4bd docs(planning): Phase 5 complete — mark ADM-01..09 and DIAG-01..05 done
- c652bf6ffe496425a1c67611b4c5d82adf167300 docs(planning): Phase 6 complete — milestone v1.1 DONE
- 8a7a5b47cd984c80c71332b6b2171fc298183bdf docs(planning): mark Phase 4 Extraction Sources complete
- 8b1bc1b25ab070575e0c3f712c8d1b535830185c docs(web): bootstrap the first owner with its IdP subject
- 5dd6e30aed19ae42349672d441c095bb6965da5c docs(web): document the session design and the production run command
- 6101fff1c2a13b8fbb54f1cad15c9e239d81fe0e docs(web): name TRUSTED_PROXIES as the API setting for the web subnet
- 428e11c5d632832b5d40d807758c3de9eb52f20c docs(web): point the build step at scripts/build-web-image.sh
- 5ed2f334069982280b020a3b9ebb25fda93b8597 documents: alert after consecutive renderer timeouts, report it in /health
- 2cadb74537ac95ffff99db2392de949dc338687e documents: fair shares, rate limit, atomic audit, per-route deadlines
- 9b8ea1dff4ae39280e17e79455193e045e1b9b16 documents: re-encode renderer PNGs; socket must be a socket of the renderer uid
- 8a45e16c1d1966c175a636bad7c6dd208cbaec29 documents: revoke and its audit row commit in one transaction
- 9df7e891d5528e3d2fc2326a9943c9b64dab0bf0 documents: tile the watermark diagonally across the whole page
- fe471aebd163e70c4371adfa1d24efaf74c3ab04 feat(api): ADM-01..09 admin API endpoints
- 26334e3e61fca91f94655a800fc1fa8a185100dc feat(api): DIAG-01..03 diagnostics endpoints
- b919a5ca31fbebac7bfe9b2b27f93b38b2ccfada feat(api): INJ-06 server-side webhook push
- 4f11e57b6969e987edc1fe039363bd9a979d1100 feat(api): partial, conditional updates for secrets, JKS and YubiKeys
- b316368c599556757fa07c79dae3c5ee48d1517f feat(api-server): bootstrap-user command for the first owner
- 970a50cb039de980f65fcfe0b6da68d269c8486d feat(api-server): purge expired CLI auth rows every 15 minutes (L5)
- 071e0bedeb9bcb99c3a98e3fe175517915447612 feat(auth): CLI SSO login with PKCE codes and rotating refresh tokens
- 14d13fd25416f3fc27d790442ebab85ff8b550e6 feat(cli): ADM-01..09 ss admin subcommands
- b7ba9e3f49d35b466b813a8bfdb174eaefc72d36 feat(cli): DIAG-04..05 ss doctor and ss trace
- 1e87e1278e277c0f44d0c2cbf74405b5c980e97d feat(cli): EXT-01..07 extraction source importers
- 8e3cb137bef31d984898496c70e03d9e05d69c74 feat(cli): INJ-01..05 inject subcommand (ssh/env/file/pipe/http)
- a9ad82adcf749a8c0db27d1a7a0bc0c1a5a625ba feat(cli):
ss loginbrowser SSO, auth status/print-access-token, logout - e1316c523f4cc3edac8e6923569a3fb9b5e8c175 feat(db): OPS-03 secret TTL expiry background job
- a86d36d3c82e986bd6cdf642b8e0446a4ae47b1b feat(k8s): OPS-05 NetworkPolicy for pod isolation
- a98ad605fa0abac7cb5721e11290359acb69f19f feat(metrics): OPS-01 Prometheus metrics endpoint + OPS-02 trace ID propagation
- 3906052df0a01e488faee85d143c02c55d10ca26 feat(rotation): OPS-04 secret rotation engine
- d7d81cf799e06ec4ed75df304ef27bceb558a44c feat(sdk): TokenProvider and
ss loginCLI credentials - a177af3b0d717ba62186f5bb8a580a802904fd36 feat(sdk,cli): partial, conditional secret updates; redact reflected keys
- f8b006bacb264661758e16b2a5df8f2dcddb7afb feat(sharing): share with a same-tenant user by email
- a1527aab5f8ca7f9b168581461a70b7fb7853539 feat(web): friendly messages for /auth/callback?error=
- fcfdbea859b51c3623c4fa24b7e33f3abb1b4ad2 feat(web): manage stored API tokens on /api-tokens
- 9b73282529335f92c963b27ef31304855e49eaea feat(web): return to an allowlisted page after sign-in
- f47bb1171d94d916cb108206d68ebf2bc7204d6a feat(web): server-side session cookie and same-origin API proxy
- 2225f82293d1ca08cfbfa99f7f3e0f63b5cb56a9 feat: API enhancements and Docker build improvements
- 5259a2d35c075e515c04f47a805a20519eb18756 feat: Add CLI intelligence, SAML/OIDC types, Terraform provider, Ansible plugin, and ssd daemon
- f559dbcc036077fcc4b78d7f6927f59abd7edd96 feat: Add JKS keystore support with raw upload and managed entry modes
- 226f7463cc2295cda0cc89f0263c2e7bb5b361b0 feat: Add comprehensive database migrations for architecture overhaul
- bef571302e7f60a351445f49e9aee0dbec839013 feat: Add cryptocurrency wallet support with Vault integration
- c9058de51ecd4e94837842a34d8332891d7fe916 feat: Add production-ready TPM 2.0 database persistence
- c4f6236f69ee0fced787b1394e36bba322f2a08d feat: Add sharing routes, database methods, and SDK enhancements
- b16da2bed6378fb56b9d24a2507689a957219f78 feat: Billing, pricing page, and missing docs (import/discover/ct/daemon)
- 8b8aae284b270f2cf2ae39b7a024cc2a965acf44 feat: Complete API implementation - all 160 endpoints now live
- 8a5be4c7e91be865c6b26dcfda274b617ede096e feat: Complete crypto abstraction layer with multi-backend support
- ffa6b2ced0d866a07b1085bdc874426251a2282e feat: Complete web frontend — types, APIs, secret actions, missing pages
- 91263af6c5147b861e7dc8002027ab07a517c9d1 feat: Enable gRPC server on port 50051
- f1c493d60e091b0489d35ff919b722dd2cb5073a feat: Full secrets management overhaul — 10 types, versioning, sharing, CLI path access
- 48be7d71a9118c65751d4fe0e8b34a3d6e076d8d feat: Implement OCI KMS client and hybrid backend manager
- 1fcfdf683edf112d65cdf38cd511f005bdbde640 feat: Implement authentication enhancements (device flow, OIDC, ACL)
- 1322eab980cef56b38bba456df42f0e9549cab5e feat: Implement full GPG/PGP key support
- 7a3ce5227c622d4ef1e8fc2646891065c18d14f3 feat: Implement intelligence features, LDAP, transformations, and enterprise auth
- 3cd845501b87cb617186ed92a80f5749e2475501 feat: Phase 3 complete — 7 new key types
- 7b6ab2eae0e9527a12f5908269e9779a17492fef feat: Separate Docker compatibility workarounds by version
- dcef3c770b7f4cabfe82e652ab1e55c02fa0a50e feat: TOTP authenticator support + comprehensive security audit
- a4d8e33b7c6a54cc474de3f8080ed5d9eacb9933 feat: enable TOTP and add YubiKey OTP credential support
- cea9ab34fc4dcff4b15d15f87c7fcc34f40c3e62 feat: harden secret handling and add secure key operations
- 51822a28946e49aa436017f1546e0b537222c248 fix(agents): reject grant aliases that differ only by case
- 57ffc0e06c1ab40c31e91d45de32e28c67fde19d fix(ansible): never disable TLS verification or send the key in cleartext
- 50a465bf2dcc764e04482717c6059b222931dfbd fix(api): OpenSSL import accepts PKCS#8 keys; SSH RSA size bounded
- 81ab9c863ac48ce22dff71d6e1e7a0947dcb3059 fix(api): edits keep stored disk and code-signing secret fields
- 20eab58a82ff3f3f77a79e5fd002b63117ef9d51 fix(api): honour X-Forwarded-For only from configured proxies
- 53d67f1ca2a5f3a6d0595565a29c5f5b470706aa fix(api): quotas count live certificates and API keys; settings PUT reports 501
- 7ac3f80d08f95a310a09fdebf1294ef5f4267b77 fix(api): stop serving /metrics on the public API port
- a49746c0e3e522041c28a0eb8ace2cbcbcf8aae3 fix(api): validate imported OpenSSL keys fully, merge social secrets, count live quota items
- f89b3d840129d9618454a7ccdfed3bc7ee9fda4b fix(audit): accept resource_id and user_id query filters
- 7395a2af04fc82095de07ac69af38565e5a3929d fix(auth): CLI access tokens die with their refresh family (L1)
- 1891f87f93d87c16b5bfce8ce372dbbffd71cc04 fix(auth): Implement working Authentik SSO with client-side JWT authentication
- c2cfd454c4c01cbf57c6a080526174ff095b4d17 fix(auth): accept only typed access tokens
- 561386c5317468e536c9baa0533725c5cda43164 fix(auth): derive session JWT permissions from user roles
- 6d6226c38101f4c44a64bbd0d7d95b0965fc82af fix(auth): make OIDC default tenant configurable via DEFAULT_TENANT_ID
- fa3eed146f6ee24668e54a95a19824617fecca5d fix(auth): make session logout actually revoke the JWT
- f721702c17a62771f4ff36bf23ec5335d9a11cf1 fix(auth): refresh rotation cannot exhaust the DB pool (M1)
- 58c89ae3dcdc90afdad12f5635413b452d402ca0 fix(auth): require export:read for private key material
- 00f19c28058bf6bb029d86869cd30c971e5d8792 fix(billing): apply a paid tier only to subscriptions being paid
- 91916d50a38824758eb0673e20c9ce2d6af87485 fix(billing): apply the subscription as Stripe reports it, not the event
- 08700c5e517bc26217622b6866d55b12f2d6811e fix(billing): check the subscription's tenant before binding; pay before upgrading
- daee65a10c7461f3330382d9b318318b75b95005 fix(billing): checkout for tenant admins only, bound by tenant reference
- 5a369aeee27c7382b0a90eedde57abeee2f67f70 fix(billing): handle failed and recovered invoice payments
- f6ef1ce48751ec6ddcc2930490caba0b207de0f3 fix(billing): refuse Stripe webhooks when no webhook secret is set
- a8968b8c9bf765da49c459edd915450ee37ac12c fix(billing): update tenants.plan on Stripe subscription changes
- 378c176aa14cd92921f44883e4ef90f95039991b fix(bootstrap): never promote a subject-bound user by email alone
- 77d316a89caf395fd3e1a893f1b3f76933f23650 fix(bootstrap): refuse unbound users with passkeys or a non-OIDC origin
- 14e99cac03d4abf0de1202f6d9fb0f7e748d16cf fix(certificates): encode PFX downloads with modern PKCS#12 algorithms
- bd85df0a796281a3e7430e836f0a8314284f67b2 fix(certificates): store enrolled certificates under their own ID
- d01e27f33632a797b1efd03bc7ad783211d37b1a fix(certificates): take the PFX export password in a POST body
- ec3ed50c0e775124e4dcc2376dde1012f545c66c fix(cli): config permission gate only for key use; symlinks; ~/.adkm 0700
- ea454a8a12406c19ee94eeb1f1aea03f91b88855 fix(cli): ct monitor/import/watch and discover --import fail instead of faking
- fa51137088f4fcc50d992762da8c891076ca6d76 fix(cli): export to stdout is always complete JSON
- d5aa6a2dfc03abf3223bd84ca80eee3a36d31e9c fix(cli): follow a symlink for private writes only if you own link and target
- c923bff5f52b4baf595792250f5a741de74f3586 fix(cli): harden release gates and installer staging (security review)
- e8ea1adf70fcec4397a9c6c28016c5ada7e8e5fc fix(cli): logout attempts both revocations and joins errors (L3)
- 4682816bd180a36ba1b330f0dbfa623729c899fe fix(cli): path-based ss secret follows the {meta,data} response
- 6af4e24bb30fc185079b79a71f7417eec6b7eab8 fix(cli): plain --data on secrets update is an error, not a silent replace
- 93371dfead16be1f2f32173de4d2917c8f8488e4 fix(cli): point importers at routes that exist and fail on errors
- ab4813799e45f5bbc99f62c6d97c137a9c6f9c8b fix(cli): publish ss to afterdarksys; checksum-verifying installer at /install
- a215befe54f72db95a7e2f5bdcaf4541fa98c96f fix(cli): readable default output instead of Go pointer dumps
- c7bc6eb50491cdff5d03a8a5c1d58dba7677289a fix(cli): real login, 0600 config, documented env vars
- aa9b3fc7c696c4070c232f2a1e9da6ac4ec84954 fix(cli): release.sh uses normal git credentials for the source repo
- 5bd5a305f86994d04a2e25fd03d9f76d7d5f64ce fix(cli): save a new SSO session under the credentials lock
- 9c7a882c112bb6abfe72ec892576af57e80e849d fix(cli): secret history decodes the bare array; export keeps values literal
- 3d1f196ae17b5cc5ddd61efe690b03b29289963d fix(cli): ss discover verifies TLS instead of skipping verification
- a66f70a68465ccd34f760b1dd364c1ad83776acf fix(cli): tokens and secrets update commands work against the API
- 29ef476f76d2e687c0713730f7feee020753de9c fix(compose): local stack that actually starts
- 195b766184efbf4bbd9e87e33edfbbd54bc12f80 fix(credentials): encode JSONB tags as JSON
- c89b712a0a6d944703fbdd08f3549198a29895c7 fix(credentials): fail closed on updates and record real history
- 25e39560163ebe4d3a4707d182d5b540098a0d26 fix(crypto): stop WipeString from crashing the API on short secrets
- 434db3acdffbaa0fb41b6ddbf3454a106ea3d4b6 fix(database): select explicit tenant columns
- 1e8fef1972c634e3098588d6c664161354e0e348 fix(diagnostics): rate-limit the public token validator
- 29d5d9853caee405536d177caa1886263e775dcb fix(export): fail closed and export secrets and certificates
- 33249fd529e0e37956df0fb3bea9246e151a62ee fix(export): include secrets in /export/json
- b63aa4fff3eb05135e0125dc57ab7409137c31cf fix(gpg): honour expires_in_days on key generation
- 8f043b39fe27ebf29d4939505e8f03972ca1b818 fix(grpc): validate tokens with the HTTP API's rules
- 1cd8f5784a6c6e4d43be55acba1787132c78a419 fix(handlers): write Vault last in updates and restore it on failure
- c71953de4c1e569a50f24967c66aed4613ca8079 fix(handlers): write credentials under the tenant Vault KV prefix
- e1ce2d1f949d37b9a3c61dee58d230b26e2e948f fix(k8s): keep /metrics off the internet, narrow scrape access, PG16 warning
- 5771bb5b9f578347e623201823f1d0b975e567f3 fix(mcp-server): enforce the tools.json schemas and test the live tool surface
- 9510b9979c9e02a3078bd319d0de3feb978bbd71 fix(migrations): apply 033-037 at API startup on pre-ledger installs
- d5f5a3c5253b79685ba91cdacc6776ce21315769 fix(migrations): create the feature tables handlers use on every install
- c6df9085ccd0c77788536caacdd2904ebb7e6602 fix(migrations): lock legacy tables before checking they are empty
- 1880461635168a82aaa5df80b531d0ebbcdcfd1e fix(migrations): make steady-state starts lock-free and bound lock waits
- 22f5d6fa37275452e5c0caec3de026208fd77066 fix(oidc): bind the login state to the browser (login CSRF)
- cdedccd33f93244f99e71856ee5d9ac610a6a81b fix(oidc): discover provider endpoints before reading the client secret
- ca507b53ca371e9238f6241507f74e28343a68b3 fix(oidc): do not hold the JWKS cache lock across a download
- cbc4c551e42105744f8d6557d675f0e4129d71b5 fix(oidc): let existing users log in and link them safely to the IdP
- 09cee0dcc1a016f69aaa6ce03e74e185756e89e7 fix(oidc): redirect callback failures with fixed error codes
- 260bf99fff2a8136d7208c78e4a7546ffa394e17 fix(oidc): take provider endpoints from issuer discovery
- 78834554f531d8fa9bb3e49bc0e0b1f896581605 fix(oidc): verify nonce, pin algorithms and harden IdP HTTP calls
- b71b787baa9fefdd6316820c6f490d8722c6986c fix(passkeys): fresh login to add, usernameless login, clone refusal
- 6f5594d153d5f733cb1aedba5297f8b664f0335f fix(passkeys): keep email and client IP out of the passkey-added log line
- 2c85fecdbef31e36685b7eed8ef79f8e47809af9 fix(passkeys): register passkeys only for the signed-in user
- 0333382c193d059044899338b7880028cd03270d fix(scripting): remove cross-tenant access from Starlark builtins
- f02321cef14857227c1fa73c5d2d2d3d420887fa fix(sdk): kill ss on oversized output; refuse a mismatched APIURL (L6, L7)
- 47f13a85cadf25e592a33bac66a0254632819fba fix(sdk): match api-token and secret-update contracts, refuse cleartext API URLs
- 0e65246a13dfb5e22d8138fbd61b698ff95edf91 fix(sdk,cli): align credential commands with handler contracts
- 19591108f89188159719ea68b4bba73d166a0066 fix(sdk,cli): encode audit query, implement mock template
- bfa02aa10077e554f043be322396f1134f808e1e fix(sdk,cli): keep secrets in their container on update; work without HOME
- feafcc687c10f2aa3d72621598af0a638d31ec24 fix(sdk,mcpbridge): never follow redirects with the API credential
- 09dd0b6900995b3b845f700b36de78016d90656c fix(sec): SEC-01 verify OIDC tokens via JWKS signature verification
- ac6f3c62410152355232e9c3d83a1a880017d5b1 fix(sec): SEC-01 wire JWKS-verified ValidateToken into OIDCCallback handler
- 177266070e4a4bcd6b563719db0bbc09dbf550b3 fix(sec): SEC-02 implement SAML assertion validation with signature verification
- 76a17303fbc64db72d0e289ceaf1925d1805a174 fix(sec): SEC-03 fix Vault policy isolation and add path-prefix enforcement
- 80bdf770e32f00d665d5a4ca2e2e274458587d0e fix(sec): SEC-04 + SEC-05 JWT revocation list and gRPC auth interceptors
- 0661663d37f91e23cebef4d8dfbc4773381afadf fix(sec): SEC-04 wire JWT revocation into logout handler and auth middleware
- 32be1db739b3ced5ffbe1af69049e91cf5bc32e0 fix(sec): SEC-06 implement per-tenant CORS origin allowlist
- 3b64153954f2318ba7292bd7da0af5bb230fedd5 fix(sec): SEC-07 harden LDAP TLS and wire real client into LDAPSearch
- 1f4cc1ba76d4a94a1a2256059c6e630c54d85fcc fix(sec): SEC-08 add Vault AppRole auth and LifetimeWatcher token renewal
- 2efc6d39a50b2c34ba3db54e9966bbc7c0dcf25c fix(ssd): honest local monitor that fails closed
- ea7bb9e5a36114873cbeee79664b920739bc0ec8 fix(ssd): launchd files match the daemon
- 13bf23fd58f6a48af8b8d9d6896754261d6f2c16 fix(ssd): no hang on FIFOs, report unreadable keys, no webhook redirects
- 451a3918e45443ee07ca0653664d71807ccc7f9e fix(ssd): restore the Windows build
- eab24b86ca75c4ccd6771a841cd8748747b16fa6 fix(ssd): verify monitored TLS hosts instead of skipping verification
- 7de4ca5455fc8c2c6d42d1f47e42984463db3918 fix(sso): allow every mapped role as the SSO default role
- 0479505ba68ed4d4c2389178fca8dbe2b1984cf1 fix(sso): auto-create users only for IdP-verified emails
- ae841d768b25132aff306f14a491382c0c707210 fix(sso): keep OIDC client secrets in Vault, not PostgreSQL
- 36ccf78e31c401ebaf8cd2eada6a3aa541cd2b1b fix(stripe-setup): add missing go.sum and fix vet finding
- 7094ca810c6632ebe06e093763bc7165ac4fb4f3 fix(web): Fix API authentication and implement missing credential pages
- 3d3f53d0ebd42bab8cac3314f6aae496ae3dd561 fix(web): answer 408 even when cancelling a stalled body never settles
- 1e5ccb0bbdc999a613274e6355ae1c0ce0540092 fix(web): assert verified email in the e2e IdP; document the prod choice
- 436c415e5449721ddc4bec1e982c283b72924b89 fix(web): bound request bodies while reading them
- 1ae3c0c8393d780161eefe39193ed5579c43fb34 fix(web): certificate-only download, confirm before revealing key material, report copy results
- 138280f999d4f6bdab4297830f0b5f2c443fd334 fix(web): checkout requires a signed-in admin on /pricing
- 586758bba416ced68de35e197a3fcb985a715989 fix(web): complete login through the API OIDC flow and revoke on logout
- 9bdd7677a5e00debb100adb03032d1e89e78882e fix(web): copy public/ into the standalone image
- 488512032b6205406e73d715949e9f48d2ac28e2 fix(web): credential forms send the API's fields through apiClient
- 17ce9275f221d8effa74fe66d9cb37550cec0ea2 fix(web): download PKCS#12 certificates with a POST body password
- e26a462ae630d3d8a0dc7956a4472100c60ae305 fix(web): forward one trusted client address to the API
- bfa7a29a9ef170527a6b29972c6615d641646d43 fix(web): keep password managers from filling API token value fields
- c8ca15966f80e4752148eb3f55fc985cb6d3ee91 fix(web): leave the callback document after storing the session
- 7c4fbb067538d32176565599326f49e8d9af4a17 fix(web): match callback error codes to the API's fixed set
- 541693d64e562dada1dce4fe2af706e500cdb76b fix(web): match list, certificate, GPG and sharing calls to the API contract
- 82b0ff18e303454c8dae79dc0af5321e0cd2c0bf fix(web): no silent or faked actions on experimental and contact pages
- 2586e9cac9bc6889ae68fe8ee2847fff0bde2685 fix(web): real dashboard counters and working quick actions
- 7121b8501856861d0d021f19627fb9a0280f677e fix(web): refuse encoded separators and any-case auth in proxy paths
- 5b24cd088b7d5a53a6e4c27de27c88653b4d2d8e fix(web): send every API call through the same-origin proxy
- 37529c6595a95f1abb7fb270eb8c9c4b2ae46fbf fix(web): show only API-backed sections on /settings
- 21288a256dc85a9bb8d7fce6b30493a2b730adeb fix(web): stop requiring the removed OIDC client ID to build the image
- 1c6dde11599a6d085f708c7c09d8ef0d87cc424d fix(web): stop shipping stale env files in the image
- d107baf778947c65e8fd81c3b8527a078f3c27ac fix(web): stop the secrets list crashing on responses without values
- 3fdb92b27b9d3ba7c2705abaa3dda33210a36c8a fix(web): time out slow request bodies after 30 seconds
- 5e5c21529bcfaeeaf8bc0e6f18d148e2e5a2bf4e fix(web): update next to 15.5.26 and sharp to 0.35.4
- 427c2489798e6ef69192d11b8691bd26154709f1 fix(web): validate forwarded client IPs with net.isIP; pin trusted proxies
- 028b9a84f8864ac0819e3d78ca8ad1efa7f93323 fix(web): wire the buttons that did nothing
- c67e32c95c0b75d0da73d47e2e6cdfd0dc81f2c9 fix(webauthn): reject passkey listing for callers without a user
- 5d52053f4db7ca4aaf80e96c5b380e1b0901d1f6 fix(wifi): default and validate security_protocol and band
- ae870892077da15e50cdd9359efe31f093fb318f fix: Resolve build errors and add OCI SDK dependencies
- 5eb152f1e5dca80594544eefea7ed99dc973ee0f fix: Resolve compilation errors in crypto layer
- 2c41ea6427947ae5d2589afeac9078e882c1faf1 fix: Update Dockerfile and deployment for non-root user compatibility
- ecd850291c6ca3d2fc924d9878f950e5cd5b9afb fix: replace opensc-pkcs11 with opensc in Alpine Dockerfile
- 5d450df0b8dba8a2a028d6d82e5f686be92b9564 fix: replace opensc-pkcs11 with opensc in builder stage too
- 592f58d48a6a7cf43d449d160a4af24b4e2adeb4 fix: security audit 2026-06-10 — close 9 critical and 12 high/medium findings
- 6d70b23eab176eb8622a7bf8dcb32dc51d5c6d70 fix: security audit — patch 8 critical and 13 high severity findings
- b008428f7492a5d5db6547810e3a1992b31dbaba fix: update totp.go to use current vault and middleware APIs
- 04c8d6770d63c2194d1ecc2d3f727a835a5c78d9 migrations: 044 makes an IdP subject unique per tenant
- 0c3d32f9b1c8fc5180afa69000eb68cdaa3bedc7 migrations: 045 adds the tenant sso_required policy
- 588e2d498a3296328b3a0a15d3540f55a784364f renderer: no network, unix socket, process-group kill, work-dir sweep
- 64b23ff7edd7f4038c4394225f701a79c9d84908 renderer: refuse root outside container mode; runbook notes
- d658fc07a91f798c5668605322f6590bb7105ebf renderer: single-use worker per request, full sweep between requests
- 535071e42110a92a93711c493f75f1d554bc7779 renderer: workers as uid 10003 without capabilities; supervisor is PID 1
- 6fd36512c8f65fa9c163feac4067159f15347085 securemem: 16 MiB budget when RLIMIT_MEMLOCK is unlimited
- 2d923b8f98218525143c7f9222b16b0dd46300b7 securemem: locked-page budget, exit 70 on dependency failure, /health
- 6bed360f2f5e692a48f9fecac97b096c8667be76 security: Enforce permissions on all previously open API routes
- 342240f2e7816f814d4ba9d3582f7650fd3f4faf style: Format authentik provider code
- 7868f6293aa662f60203a9b55b9e0b0b55514985 style: gofmt files touched on this branch
- 1d6057b2eabdb82ac6193cc3753a5550cc432f57 style: gofmt ssd and update tests
- 7bf4adfccabd11ad704ad93b92b03f38bc1047a5 test(ansible): exercise main()'s refusal of validate_certs=false and http
- 6c9876c48bdb905f89a70da4ef9a232223873bdc test(ansible): run main() on ansible-core 2.19+ and <= 2.18
- 4c5f5025a542037df0ffb5625324333ff8f720e4 test(api): UI wiring suite in the platform integration run
- f8e276eb309a79d85a597651aa81b3cceaed7263 test(api): negative import tests and social secret merge
- 3dfcae5bb2932c0cc7368820567e00b9721b61dd test(db): make the CLI auth PostgreSQL test rerunnable on one database
- 87c324185eab107135aeb30cf531a9fba63326a1 test(live): Vault dev token via environment; reserved TLD for URL check
- c9143bdeda5de0c2e70eaf816f3151f2ed0904e1 test(live): partial-update checks, real cleartext-URL assertion, host Vault option
- 2a0b85c35b4dd569f4b8e99dcff0dcad920bf88f test(web): bootstrap the first admin with bootstrap-user; check OIDC binding
- e3932bf7ffffadfd038cf79cd52380ef586e6c01 test(web): e2e views and edits a secret, stores a password, generates an SSH key, exports audit logs
- 94209f75ab279c911dee971442a97895ff2b0600 test(web): end-to-end login, secrets, variables, device approval, logout
- 600286ac5f61185ecfc828a22476c3063ad70453 test(web): member role, sharing, API tokens, callback errors, body caps in e2e
- c2fd35e61069a3c6b752dd645ebe2635b9e8b974 test(web): pricing sign-in path, member checkout 403, anonymous 401
- e1195d3f4afa8600f56496072eec3247afc10fe2 web: API directory and OpenAPI without private source links
- 952a0d203d4db5d7fdd80518964fa8a1ed9aac5e web: add Software section and link it from the site nav
- 80bdb1c678386d1ec4cdb8093bdbdf6d7ee603f3 web: add aikeys to Software with configuration and how-to docs
- b98a8b9fa412a742f3533c41891732767e3fa631 web: drop Vault backend references from public copy
- 2225bb8a41b78c74bb031e1f7efff9f25308c301 web: one documentation system under /docs
- 2835e8e1bfcd10dfd5659fb213d4b36b2700214b web: protected documents guide in the /docs system, key store wording
- 77afb4f6c86cb2dcf6dd6140a6cfa060ba00eb33 web: site checker covers redirects, themes and console errors; icon
Install
macOS / Linux (curl):
curl -fsSL https://secretserver.io/install | sh
The installer verifies the archive against ss_1.0.0_checksums.txt.
Homebrew:
brew install afterdarksys/tap/secretserver-cli
Direct download: See assets below; verify with
shasum -a 256 -c ss_1.0.0_checksums.txt --ignore-missing.