docs: v1.13.0 withdrawn; version notes name v1.13.1
docs: sign-in usernames in v1.13.1; version notes now name v1.13.0
docs: security hardening, sealed instance sync and key pinning (#296)
- new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS,
TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES
syncKeyId/syncPublicKey; compose pass-through note
- secret rotation, admin env credentials, password policy, sessions
- forward auth ports, portal rate limits, header stripping
- instance sync sealing, key pinning, instance editing, CA keys
- WAF directive rules, redaction, quick templates; placeholders
- REST endpoints, troubleshooting entries, upgrade checklist
- documentation IP ranges in Geo Blocking examples
Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b
Add troubleshooting docs for HKDF/secret decryption errors (#263)
- Troubleshooting: new "Secret Decryption Issues" section covering the
"[secret] HKDF decryption failed" error, which data is encrypted with
SESSION_SECRET, and recovery options (re-enter the token, restore the
previous SESSION_SECRET, LEGACY_KEY_CUTOFF_DATE for legacy-format
secrets only).
- Environment Variables Reference: document LEGACY_KEY_CUTOFF_DATE and
warn that changing SESSION_SECRET invalidates stored encrypted values.
docs: document OAuth self-registration
Co-Authored-By: Claude <noreply@anthropic.com>
Fix broken TOC anchors and duplicate Excluded Paths section
Correct TOC entries pointing at renamed/missing headings across several
pages, add sections that were missing from their TOCs, and merge the two
conflicting Excluded Paths sections in the Forward Auth guide into one
accurate description (protected-paths precedence, glob wildcard matching).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zWmkyJGH9VspzwwH8yMz9
Update wiki for multi-provider DNS, Better Auth, forward auth excluded paths
- Add DNS-Provider-Configuration page covering all 12 supported DNS providers
- Replace Cloudflare-only DNS page with redirect to new multi-provider page
- Update all cross-references from Cloudflare DNS to DNS Provider Configuration
- Add excluded paths section to Forward Auth guide
- Fix Contributing page: NextAuth.js → Better Auth in tech stack
- Add dns-providers and oauth-providers to REST API endpoint table
- Fix outdated OAuth callback URL format in Troubleshooting
- Update Environment Variables: Cloudflare settings → DNS Provider settings
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Update docs for 1.0-RC: Better Auth migration, new OAuth callback URLs
- OAuth callback URL changed from /api/auth/callback/oauth2 to
/api/auth/oauth2/callback/{provider-id}
- Document UI-based OAuth provider management (Settings → OAuth Providers)
- Update rate limiting docs: Better Auth built-in (AUTH_RATE_LIMIT_*)
replaces legacy LOGIN_* vars for auth endpoints
- Add AUTH_TRUST_HOST env var documentation
- Update account unlinking docs (now supported via Profile page)
- Add upgrade notice for users migrating from < 1.0-RC
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Document ClickHouse analytics migration
- Add ClickHouse Analytics section to Environment Variables Reference
with CLICKHOUSE_PASSWORD (required), CLICKHOUSE_URL, CLICKHOUSE_USER,
CLICKHOUSE_DB
- Update environment variable checklists with CLICKHOUSE_PASSWORD
- Update Feature Guide Analytics with ClickHouse architecture, data
retention, and storage table
- Add CLICKHOUSE_PASSWORD to Installation Guide required variables
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
docs: update wiki for current features, remove ACME scanning references
- Certificate-Management: remove issuer/expiry scanning docs (feature removed)
- Environment-Variables-Reference: remove CADDY_CERTS_DIR section
- Home: add links to new Analytics and REST API guides
- New: Feature-Guide-Analytics (traffic charts, geo map, user agents)
- New: Feature-Guide-REST-API (endpoints, tokens, OpenAPI docs, examples)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
made test credentials more coherent
updated docs with instances sync and 1.0