docs: v1.13.0 withdrawn; version notes name v1.13.1
docs: sign-in usernames in v1.13.1; version notes now name v1.13.0
docs: security hardening, sealed instance sync and key pinning (#296)
- new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS,
TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES
syncKeyId/syncPublicKey; compose pass-through note
- secret rotation, admin env credentials, password policy, sessions
- forward auth ports, portal rate limits, header stripping
- instance sync sealing, key pinning, instance editing, CA keys
- WAF directive rules, redaction, quick templates; placeholders
- REST endpoints, troubleshooting entries, upgrade checklist
- documentation IP ranges in Geo Blocking examples
Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b
forward-auth: document generic forward-auth provider with split browser vs API auth (#188)
Add wiki pages for forward auth, user management, and mTLS RBAC
New pages:
- Feature-Guide-Forward-Auth.md — built-in IdP, groups, per-host access
- Feature-Guide-User-Management.md — roles, admin page, groups, OAuth users
- Feature-Guide-mTLS-RBAC.md — roles, cert trust, path-based access rules
Updated pages:
- Home.md — add links to new feature guides
- Feature-Guide-Proxy-Hosts.md — add forward auth, location rules, mTLS RBAC
- Security-Configuration.md — add user roles section
- OAuth-Authentication-Setup.md — add forward auth integration section
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
docs: add geo blocking guide and update navigation
- Create Feature-Guide-Geo-Blocking.md with full setup and rule documentation
- Add geo blocking section to Feature-Guide-Proxy-Hosts.md
- Link new guide from Home.md navigation
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
made test credentials more coherent