docs: v1.13.0 withdrawn; version notes name v1.13.1
docs: sign-in usernames in v1.13.1; version notes now name v1.13.0
docs: security hardening, sealed instance sync and key pinning (#296)
- new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS,
TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES
syncKeyId/syncPublicKey; compose pass-through note
- secret rotation, admin env credentials, password policy, sessions
- forward auth ports, portal rate limits, header stripping
- instance sync sealing, key pinning, instance editing, CA keys
- WAF directive rules, redaction, quick templates; placeholders
- REST endpoints, troubleshooting entries, upgrade checklist
- documentation IP ranges in Geo Blocking examples
Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b
Fix broken TOC anchors and duplicate Excluded Paths section
Correct TOC entries pointing at renamed/missing headings across several
pages, add sections that were missing from their TOCs, and merge the two
conflicting Excluded Paths sections in the Forward Auth guide into one
accurate description (protected-paths precedence, glob wildcard matching).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zWmkyJGH9VspzwwH8yMz9
updated docs with instances sync and 1.0