Skip to content

Releases: clementfavre/IISWeb

IISWeb 1.0.2

Choose a tag to compare

@clementfavre clementfavre released this 06 May 17:53

Highlights

  • Custom visual identity => warm peach background, plum accents, system fonts
    (Segoe UI / Cambria / Consolas), editorial page header
  • Two-factor authentication (TOTP, RFC 6238) with QR enrolment, recovery
    codes, and per-user enable/disable
  • Tamper-evident audit log => each row chained via SHA-256 hash, on-demand
    chain verification from the Audit page
  • Local user management => create user, change role, reset password, unlock
    account, disable MFA (admin override)

Fixes

  • MFA login loop on hosts where Kestrel alternated between IPv4 and IPv6
    loopback between requests. IP pinning now normalises ::ffff:127.0.0.1
    to 127.0.0.1
  • MFA => an expired ticket now redirects to the login page with a visible
    "verification session expired" message instead of a silent bounce

Upgrade

  • Drop-in over an existing 1.0.1 install. Schema migrates itself
    (TotpSecret, TotpEnabled, TotpRecoveryCodesJson on Users; PrevHash,
    RowHash on AuditLogs). Keep your App_Data\ and appsettings.Production.json.
  • Fresh install: App_Data\ and the SQLite database are created on first
    start. Seed the initial admin via IISWEB_INITIAL_ADMIN_USER /
    IISWEB_INITIAL_ADMIN_PASS env vars or run IISWeb.exe seed-admin

v1.0.1 - fix IIS hosting

Choose a tag to compare

@clementfavre clementfavre released this 03 May 07:53

Hotfix release

Fix

  • Bundle System.Security.Permissions so Microsoft.Web.Administration can read applicationHost.config when the app runs under IIS / ANCM. Without it, the pools list page returned Could not load file or assembly 'System.Security.Permissions' and showed an empty list
  • web.config: drop the redundant App_Data <hiddenSegments> entry that conflicted with IIS's machine-level config when deployed inside an existing site root (caused HTTP 500.19 / 0x800700b7).

Upgrade

  1. Stop the IISWeb App Pool
  2. Replace the binaries with the new asset
  3. Start the App Pool

IISWeb 1.0.0

Choose a tag to compare

@clementfavre clementfavre released this 03 May 07:25

First public release 🍾

What's in

  • Start / stop / recycle IIS Application Pools from a mobile-friendly UI
  • Cookie auth, CSRF, account lockout, IP allow-list, audit log (SQLite)
  • Cards / list view + search

Install

  1. Install the .NET 10 Hosting Bundle on the server
  2. Unzip the asset to C:\inetpub\IISWeb\
  3. Follow the README for IIS site setup and seed-admin

Full Changelog: https://github.com/D0LBA3B/IISWeb/commits/v1.0.0