docs: v1.13.0 withdrawn; version notes name v1.13.1
docs: sign-in usernames in v1.13.1; version notes now name v1.13.0
docs: security hardening, sealed instance sync and key pinning (#296)
- new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS,
TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES
syncKeyId/syncPublicKey; compose pass-through note
- secret rotation, admin env credentials, password policy, sessions
- forward auth ports, portal rate limits, header stripping
- instance sync sealing, key pinning, instance editing, CA keys
- WAF directive rules, redaction, quick templates; placeholders
- REST endpoints, troubleshooting entries, upgrade checklist
- documentation IP ranges in Geo Blocking examples
Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b
Fix duplicate First Login sections in Installation Guide
Merge the two disconnected First Login sections into one, move login
troubleshooting into the shared Troubleshooting section, and sync the
TOC with the page's actual headings.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zWmkyJGH9VspzwwH8yMz9
docs: update wiki with latest features
- WAF Events: document period filters (All/24h/7d/30d/Custom), stats bar,
and redesigned inline detail panel with Summary/Request/Response/Raw Audit tabs
- Analytics: document optional ClickHouse via clickhouse compose profile,
disabled banner behavior, combining with geoipupdate profile
- User Management: add Create User flow and POST /api/v1/users endpoint
- Forward Auth: add Excluded Paths section with Navidrome example
- Geo Blocking: document LAN Only (RFC1918) preset button
- mTLS RBAC: add Scoped mTLS Paths section (protected vs excluded paths)
- Cloudflare DNS: simplify to redirect to DNS Provider Configuration page
- Installation Guide: document clickhouse compose profile as default analytics
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Update wiki for multi-provider DNS, Better Auth, forward auth excluded paths
- Add DNS-Provider-Configuration page covering all 12 supported DNS providers
- Replace Cloudflare-only DNS page with redirect to new multi-provider page
- Update all cross-references from Cloudflare DNS to DNS Provider Configuration
- Add excluded paths section to Forward Auth guide
- Fix Contributing page: NextAuth.js → Better Auth in tech stack
- Add dns-providers and oauth-providers to REST API endpoint table
- Fix outdated OAuth callback URL format in Troubleshooting
- Update Environment Variables: Cloudflare settings → DNS Provider settings
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Document ClickHouse analytics migration
- Add ClickHouse Analytics section to Environment Variables Reference
with CLICKHOUSE_PASSWORD (required), CLICKHOUSE_URL, CLICKHOUSE_USER,
CLICKHOUSE_DB
- Update environment variable checklists with CLICKHOUSE_PASSWORD
- Update Feature Guide Analytics with ClickHouse architecture, data
retention, and storage table
- Add CLICKHOUSE_PASSWORD to Installation Guide required variables
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
made test credentials more coherent