Skip to content

History / Feature Guide WAF

Revisions

  • docs: v1.13.2 forward-auth identity headers, WAF path template, redaction Claude-Session: https://claude.ai/code/session_01QthZYq4kNzWvzsW5NigKDW

    @fuomag9 fuomag9 committed Sep 27, 2026
  • docs: v1.13.0 withdrawn; version notes name v1.13.1

    @fuomag9 fuomag9 committed Sep 26, 2026
  • docs: sign-in usernames in v1.13.1; version notes now name v1.13.0

    @fuomag9 fuomag9 committed Sep 26, 2026
  • docs: security hardening, sealed instance sync and key pinning (#296) - new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS, TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES syncKeyId/syncPublicKey; compose pass-through note - secret rotation, admin env credentials, password policy, sessions - forward auth ports, portal rate limits, header stripping - instance sync sealing, key pinning, instance editing, CA keys - WAF directive rules, redaction, quick templates; placeholders - REST endpoints, troubleshooting entries, upgrade checklist - documentation IP ranges in Geo Blocking examples Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b

    @fuomag9 fuomag9 committed Sep 26, 2026
  • docs: L4 reserved ports; WAF anomaly scoring and sensitive-file rule

    @fuomag9 fuomag9 committed Sep 26, 2026
  • Document WAF request body limits Covers the new Max body size / Buffered in memory / Over-limit action fields, the 12.5 MiB CRS default that breaks large uploads, and the 1 GiB Coraza ceiling. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhSZwRD583v8FMJuYF6UPL

    @fuomag9 fuomag9 committed Aug 28, 2026
  • docs: update wiki with latest features - WAF Events: document period filters (All/24h/7d/30d/Custom), stats bar, and redesigned inline detail panel with Summary/Request/Response/Raw Audit tabs - Analytics: document optional ClickHouse via clickhouse compose profile, disabled banner behavior, combining with geoipupdate profile - User Management: add Create User flow and POST /api/v1/users endpoint - Forward Auth: add Excluded Paths section with Navidrome example - Geo Blocking: document LAN Only (RFC1918) preset button - mTLS RBAC: add Scoped mTLS Paths section (protected vs excluded paths) - Cloudflare DNS: simplify to redirect to DNS Provider Configuration page - Installation Guide: document clickhouse compose profile as default analytics Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

    @fuomag9 fuomag9 committed May 6, 2026
  • update wiki

    @fuomag9 fuomag9 committed Mar 12, 2026