docs: v1.13.0 withdrawn; version notes name v1.13.1
docs: sign-in usernames in v1.13.1; version notes now name v1.13.0
docs: security hardening, sealed instance sync and key pinning (#296)
- new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS,
TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES
syncKeyId/syncPublicKey; compose pass-through note
- secret rotation, admin env credentials, password policy, sessions
- forward auth ports, portal rate limits, header stripping
- instance sync sealing, key pinning, instance editing, CA keys
- WAF directive rules, redaction, quick templates; placeholders
- REST endpoints, troubleshooting entries, upgrade checklist
- documentation IP ranges in Geo Blocking examples
Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b
Add troubleshooting docs for HKDF/secret decryption errors (#263)
- Troubleshooting: new "Secret Decryption Issues" section covering the
"[secret] HKDF decryption failed" error, which data is encrypted with
SESSION_SECRET, and recovery options (re-enter the token, restore the
previous SESSION_SECRET, LEGACY_KEY_CUTOFF_DATE for legacy-format
secrets only).
- Environment Variables Reference: document LEGACY_KEY_CUTOFF_DATE and
warn that changing SESSION_SECRET invalidates stored encrypted values.
Update wiki for multi-provider DNS, Better Auth, forward auth excluded paths
- Add DNS-Provider-Configuration page covering all 12 supported DNS providers
- Replace Cloudflare-only DNS page with redirect to new multi-provider page
- Update all cross-references from Cloudflare DNS to DNS Provider Configuration
- Add excluded paths section to Forward Auth guide
- Fix Contributing page: NextAuth.js → Better Auth in tech stack
- Add dns-providers and oauth-providers to REST API endpoint table
- Fix outdated OAuth callback URL format in Troubleshooting
- Update Environment Variables: Cloudflare settings → DNS Provider settings
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
made test credentials more coherent
updated docs with instances sync and 1.0