docs: v1.13.2 forward-auth identity headers, WAF path template, redaction
Claude-Session: https://claude.ai/code/session_01QthZYq4kNzWvzsW5NigKDW
0c841e1
docs: v1.13.0 withdrawn; version notes name v1.13.1
83bd139
docs: sign-in usernames in v1.13.1; version notes now name v1.13.0
c59eb10
docs: security hardening, sealed instance sync and key pinning (#296)
- new env vars (SESSION_SECRET_PREVIOUS, FORWARD_AUTH_ALLOWED_PORTS,
TRUSTED_CLIENT_IP_HEADER, INSTANCE_SYNC_TIMEOUT_MS) and INSTANCE_SLAVES
syncKeyId/syncPublicKey; compose pass-through note
- secret rotation, admin env credentials, password policy, sessions
- forward auth ports, portal rate limits, header stripping
- instance sync sealing, key pinning, instance editing, CA keys
- WAF directive rules, redaction, quick templates; placeholders
- REST endpoints, troubleshooting entries, upgrade checklist
- documentation IP ranges in Geo Blocking examples
Claude-Session: https://claude.ai/code/session_015yn7EDT9FJnxBqP6AFCN8b
527ccff
docs: L4 reserved ports; WAF anomaly scoring and sensitive-file rule
cf62ce4
forward-auth: document generic forward-auth provider with split browser vs API auth (#188)
8f2baa7
dns: document RFC2136 (BIND/TSIG) DNS-01 provider
2fcf4bf
Document DNS challenge propagation delay/timeout settings (#258)
71f125d
Add troubleshooting docs for HKDF/secret decryption errors (#263)
- Troubleshooting: new "Secret Decryption Issues" section covering the
"[secret] HKDF decryption failed" error, which data is encrypted with
SESSION_SECRET, and recovery options (re-enter the token, restore the
previous SESSION_SECRET, LEGACY_KEY_CUTOFF_DATE for legacy-format
secrets only).
- Environment Variables Reference: document LEGACY_KEY_CUTOFF_DATE and
warn that changing SESSION_SECRET invalidates stored encrypted values.
4119bf5
Document ClouDNS DNS provider and fill in missing provider rows/guides
Add ClouDNS (provider #20) to the supported providers table with a
setup guide covering API & Resellers users, sub-users, and IP
restrictions. Also add the previously missing deSEC, Dynu, acme-dns,
and Infomaniak table rows and setup guides so the table matches the
registry count.
4f62540
Document WAF request body limits
Covers the new Max body size / Buffered in memory / Over-limit action
fields, the 12.5 MiB CRS default that breaks large uploads, and the 1 GiB
Coraza ceiling.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhSZwRD583v8FMJuYF6UPL
5dee34e
docs: document OAuth self-registration
Co-Authored-By: Claude <noreply@anthropic.com>
bad5a1a
Fix broken TOC anchors and duplicate Excluded Paths section
Correct TOC entries pointing at renamed/missing headings across several
pages, add sections that were missing from their TOCs, and merge the two
conflicting Excluded Paths sections in the Forward Auth guide into one
accurate description (protected-paths precedence, glob wildcard matching).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zWmkyJGH9VspzwwH8yMz9
3d927ad
Fix duplicate First Login sections in Installation Guide
Merge the two disconnected First Login sections into one, move login
troubleshooting into the shared Troubleshooting section, and sync the
TOC with the page's actual headings.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zWmkyJGH9VspzwwH8yMz9
3937000
Update DNS-Provider-Configuration.md
b8d72d0
docs: update wiki with latest features
- WAF Events: document period filters (All/24h/7d/30d/Custom), stats bar,
and redesigned inline detail panel with Summary/Request/Response/Raw Audit tabs
- Analytics: document optional ClickHouse via clickhouse compose profile,
disabled banner behavior, combining with geoipupdate profile
- User Management: add Create User flow and POST /api/v1/users endpoint
- Forward Auth: add Excluded Paths section with Navidrome example
- Geo Blocking: document LAN Only (RFC1918) preset button
- mTLS RBAC: add Scoped mTLS Paths section (protected vs excluded paths)
- Cloudflare DNS: simplify to redirect to DNS Provider Configuration page
- Installation Guide: document clickhouse compose profile as default analytics
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
53eec2b
Update wiki for multi-provider DNS, Better Auth, forward auth excluded paths
- Add DNS-Provider-Configuration page covering all 12 supported DNS providers
- Replace Cloudflare-only DNS page with redirect to new multi-provider page
- Update all cross-references from Cloudflare DNS to DNS Provider Configuration
- Add excluded paths section to Forward Auth guide
- Fix Contributing page: NextAuth.js → Better Auth in tech stack
- Add dns-providers and oauth-providers to REST API endpoint table
- Fix outdated OAuth callback URL format in Troubleshooting
- Update Environment Variables: Cloudflare settings → DNS Provider settings
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
dc23485
Update docs for 1.0-RC: Better Auth migration, new OAuth callback URLs
- OAuth callback URL changed from /api/auth/callback/oauth2 to
/api/auth/oauth2/callback/{provider-id}
- Document UI-based OAuth provider management (Settings → OAuth Providers)
- Update rate limiting docs: Better Auth built-in (AUTH_RATE_LIMIT_*)
replaces legacy LOGIN_* vars for auth endpoints
- Add AUTH_TRUST_HOST env var documentation
- Update account unlinking docs (now supported via Profile page)
- Add upgrade notice for users migrating from < 1.0-RC
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
4e746d7
Document ClickHouse analytics migration
- Add ClickHouse Analytics section to Environment Variables Reference
with CLICKHOUSE_PASSWORD (required), CLICKHOUSE_URL, CLICKHOUSE_USER,
CLICKHOUSE_DB
- Update environment variable checklists with CLICKHOUSE_PASSWORD
- Update Feature Guide Analytics with ClickHouse architecture, data
retention, and storage table
- Add CLICKHOUSE_PASSWORD to Installation Guide required variables
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
ad61962
Add new API endpoints to REST API guide
Add groups, group members, mTLS roles, mTLS role certs, mTLS access
rules, forward auth access, forward auth sessions, and client cert
roles to the endpoint table. Update related documentation links.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
c5744c9
Resolve merge conflict: keep all new feature guide links
Include Forward Auth, User Management, mTLS RBAC (ours) and
Analytics, REST API (theirs).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
6e783a7
Add wiki pages for forward auth, user management, and mTLS RBAC
New pages:
- Feature-Guide-Forward-Auth.md — built-in IdP, groups, per-host access
- Feature-Guide-User-Management.md — roles, admin page, groups, OAuth users
- Feature-Guide-mTLS-RBAC.md — roles, cert trust, path-based access rules
Updated pages:
- Home.md — add links to new feature guides
- Feature-Guide-Proxy-Hosts.md — add forward auth, location rules, mTLS RBAC
- Security-Configuration.md — add user roles section
- OAuth-Authentication-Setup.md — add forward auth integration section
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
bfe74a3
docs: update wiki for current features, remove ACME scanning references
- Certificate-Management: remove issuer/expiry scanning docs (feature removed)
- Environment-Variables-Reference: remove CADDY_CERTS_DIR section
- Home: add links to new Analytics and REST API guides
- New: Feature-Guide-Analytics (traffic charts, geo map, user agents)
- New: Feature-Guide-REST-API (endpoints, tokens, OpenAPI docs, examples)
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
37a2faf
docs: add L4 proxy hosts guide and update tech stack to shadcn/ui
- New Feature-Guide-L4-Proxy-Hosts.md covering TCP/UDP proxying,
matcher types, TLS termination, load balancing, health checks,
geo blocking, port management, and troubleshooting
- Updated Contributing-Development.md: MUI → shadcn/ui + Tailwind CSS
- Updated Home.md navigation with L4 Proxy Hosts link
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
90207e9
docs: add geo blocking guide and update navigation
- Create Feature-Guide-Geo-Blocking.md with full setup and rule documentation
- Add geo blocking section to Feature-Guide-Proxy-Hosts.md
- Link new guide from Home.md navigation
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
868e111
made test credentials more coherent
a3495ea
updated docs with instances sync and 1.0
5fedf64