Skip to content

History / Feature Guide mTLS RBAC

Revisions

  • docs: v1.13.0 withdrawn; version notes name v1.13.1

    @fuomag9 fuomag9 committed Sep 26, 2026
  • docs: sign-in usernames in v1.13.1; version notes now name v1.13.0

    @fuomag9 fuomag9 committed Sep 26, 2026
  • docs: security hardening, sealed instance sync and key pinning (#296) - new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS, TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES syncKeyId/syncPublicKey; compose pass-through note - secret rotation, admin env credentials, password policy, sessions - forward auth ports, portal rate limits, header stripping - instance sync sealing, key pinning, instance editing, CA keys - WAF directive rules, redaction, quick templates; placeholders - REST endpoints, troubleshooting entries, upgrade checklist - documentation IP ranges in Geo Blocking examples Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b

    @fuomag9 fuomag9 committed Sep 26, 2026
  • docs: update wiki with latest features - WAF Events: document period filters (All/24h/7d/30d/Custom), stats bar, and redesigned inline detail panel with Summary/Request/Response/Raw Audit tabs - Analytics: document optional ClickHouse via clickhouse compose profile, disabled banner behavior, combining with geoipupdate profile - User Management: add Create User flow and POST /api/v1/users endpoint - Forward Auth: add Excluded Paths section with Navidrome example - Geo Blocking: document LAN Only (RFC1918) preset button - mTLS RBAC: add Scoped mTLS Paths section (protected vs excluded paths) - Cloudflare DNS: simplify to redirect to DNS Provider Configuration page - Installation Guide: document clickhouse compose profile as default analytics Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

    @fuomag9 fuomag9 committed May 6, 2026
  • Add wiki pages for forward auth, user management, and mTLS RBAC New pages: - Feature-Guide-Forward-Auth.md — built-in IdP, groups, per-host access - Feature-Guide-User-Management.md — roles, admin page, groups, OAuth users - Feature-Guide-mTLS-RBAC.md — roles, cert trust, path-based access rules Updated pages: - Home.md — add links to new feature guides - Feature-Guide-Proxy-Hosts.md — add forward auth, location rules, mTLS RBAC - Security-Configuration.md — add user roles section - OAuth-Authentication-Setup.md — add forward auth integration section Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

    @fuomag9 fuomag9 committed Apr 6, 2026