docs: v1.13.2 forward-auth identity headers, WAF path template, redaction
Claude-Session: https://claude.ai/code/session_01QthZYq4kNzWvzsW5NigKDW
docs: v1.13.0 withdrawn; version notes name v1.13.1
docs: sign-in usernames in v1.13.1; version notes now name v1.13.0
docs: security hardening, sealed instance sync and key pinning (#296)
- new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS,
TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES
syncKeyId/syncPublicKey; compose pass-through note
- secret rotation, admin env credentials, password policy, sessions
- forward auth ports, portal rate limits, header stripping
- instance sync sealing, key pinning, instance editing, CA keys
- WAF directive rules, redaction, quick templates; placeholders
- REST endpoints, troubleshooting entries, upgrade checklist
- documentation IP ranges in Geo Blocking examples
Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b
forward-auth: document generic forward-auth provider with split browser vs API auth (#188)
Fix broken TOC anchors and duplicate Excluded Paths section
Correct TOC entries pointing at renamed/missing headings across several
pages, add sections that were missing from their TOCs, and merge the two
conflicting Excluded Paths sections in the Forward Auth guide into one
accurate description (protected-paths precedence, glob wildcard matching).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zWmkyJGH9VspzwwH8yMz9
docs: update wiki with latest features
- WAF Events: document period filters (All/24h/7d/30d/Custom), stats bar,
and redesigned inline detail panel with Summary/Request/Response/Raw Audit tabs
- Analytics: document optional ClickHouse via clickhouse compose profile,
disabled banner behavior, combining with geoipupdate profile
- User Management: add Create User flow and POST /api/v1/users endpoint
- Forward Auth: add Excluded Paths section with Navidrome example
- Geo Blocking: document LAN Only (RFC1918) preset button
- mTLS RBAC: add Scoped mTLS Paths section (protected vs excluded paths)
- Cloudflare DNS: simplify to redirect to DNS Provider Configuration page
- Installation Guide: document clickhouse compose profile as default analytics
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Update wiki for multi-provider DNS, Better Auth, forward auth excluded paths
- Add DNS-Provider-Configuration page covering all 12 supported DNS providers
- Replace Cloudflare-only DNS page with redirect to new multi-provider page
- Update all cross-references from Cloudflare DNS to DNS Provider Configuration
- Add excluded paths section to Forward Auth guide
- Fix Contributing page: NextAuth.js → Better Auth in tech stack
- Add dns-providers and oauth-providers to REST API endpoint table
- Fix outdated OAuth callback URL format in Troubleshooting
- Update Environment Variables: Cloudflare settings → DNS Provider settings
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Add wiki pages for forward auth, user management, and mTLS RBAC
New pages:
- Feature-Guide-Forward-Auth.md — built-in IdP, groups, per-host access
- Feature-Guide-User-Management.md — roles, admin page, groups, OAuth users
- Feature-Guide-mTLS-RBAC.md — roles, cert trust, path-based access rules
Updated pages:
- Home.md — add links to new feature guides
- Feature-Guide-Proxy-Hosts.md — add forward auth, location rules, mTLS RBAC
- Security-Configuration.md — add user roles section
- OAuth-Authentication-Setup.md — add forward auth integration section
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>