v0.2.2 — security: license keys can't be forged
Security release: upgrade from 0.2.0 and 0.2.1.
- Security: license keys signed with someone else's key are refused by every release build. Until now, a server started with
NODE_ENVset to anything butproductionalso trusted a signing key named byCT_LICENSE_PUBLIC_KEY(meant for tests), so a self-signed key could turn Enterprise on. Release builds (the image and the npm package) no longer contain that path at all, and CI checks each image refuses a forged key. Upgrade from 0.2.0 and 0.2.1. - Trials end on their end date. The 14-day grace period is for paid licenses while they renew; a trial now has none. Tested on a running server: at a trial's end, every Enterprise feature stops without a restart, passwords work again, and agents' traffic carries on.
- The Enterprise license files name Agent Control Tower as the licensor.
- The license site at license.agentcontroltower.app has a new look, to match the website.
Install: docker run -p 4000:4000 -v ct-data:/data ghcr.io/joshmaster2165/controltower:0.2.2 · Helm: helm install controltower oci://ghcr.io/joshmaster2165/charts/controltower --version 0.2.2