Skip to content

v0.2.2 — security: license keys can't be forged

Choose a tag to compare

@joshmaster2165 joshmaster2165 released this 30 Sep 20:00
· 100 commits to main since this release

Security release: upgrade from 0.2.0 and 0.2.1.

  • Security: license keys signed with someone else's key are refused by every release build. Until now, a server started with NODE_ENV set to anything but production also trusted a signing key named by CT_LICENSE_PUBLIC_KEY (meant for tests), so a self-signed key could turn Enterprise on. Release builds (the image and the npm package) no longer contain that path at all, and CI checks each image refuses a forged key. Upgrade from 0.2.0 and 0.2.1.
  • Trials end on their end date. The 14-day grace period is for paid licenses while they renew; a trial now has none. Tested on a running server: at a trial's end, every Enterprise feature stops without a restart, passwords work again, and agents' traffic carries on.
  • The Enterprise license files name Agent Control Tower as the licensor.
  • The license site at license.agentcontroltower.app has a new look, to match the website.

Install: docker run -p 4000:4000 -v ct-data:/data ghcr.io/joshmaster2165/controltower:0.2.2 · Helm: helm install controltower oci://ghcr.io/joshmaster2165/charts/controltower --version 0.2.2