Skip to content

v2.77.1: embedded apps no longer loop on sign-in, backups no longer freeze AppCrane, and one browser can't rate-limit everyone

Choose a tag to compare

@gitayg gitayg released this 15 Sep 02:11

Embedded apps

  • Fixed a sign-in loop that made an embedded app flicker between the sign-in page and the app. It happened when the browser still held an old AppCrane sign-in whose session had expired, or when the user had no access to the app. The sign-in page now checks the saved sign-in with the server before sending you back to the app: an expired sign-in shows the sign-in form, and a user without access sees "You don't have access" instead of a redirect. If the page is sent back and forth more than three times in 30 seconds, it stops and offers "Sign in again".
  • If signing in through the popup fails (the identity provider refuses, there is no account, or the attempt expires), the popup now shows a short reason with a Close button, and the embedded app stops waiting at once and offers "Try again". The Sign in button stays available while it waits, so closing the popup and clicking again works.

Backups

  • Backups no longer freeze AppCrane on hosts with slow disks. On a slow disk, a database write during a backup could block AppCrane for about two seconds at a time, so hosted apps' sign-in stopped answering while a backup ran. That wait is now deferred until the backup finishes.

Rate limits

  • Behind Caddy, every request looked like it came from the same address, so all users shared one rate limit and five wrong passwords anywhere blocked sign-in for everyone for a minute. AppCrane now uses each client's real address from Caddy's forwarding header, and trusts that header only from the local machine. The TRUST_PROXY setting can list other trusted proxies.
  • Sign-in checks for hosted apps have their own limit, so a busy app page no longer uses up the API limit.