Repository navigation
Added
TRUSTED_PROXIES: behind a reverse proxy or Cloudflare Tunnel, the real client address is taken fromCF-Connecting-IP/X-Forwarded-For– for the login rate limit and logs. Before, failed logins of one client blocked everyone behind the same proxy. The headers are only trusted from the configured proxies.- Reachability checks keep a 30-day history, shown as uptime bars (24 hours / 7 days) on the Reachability page.
- Expected status per check (e.g.
200,2xx,200-399): only these codes count as reachable. Checks can now be edited (address and expected status).
Security
- Cross-site request forgery: write requests to the API are only accepted from dnsdeck's own origin. Before, a page on a sibling subdomain of the same domain could, for example, create a webhook and thereby read webhook secrets, despite the
SameSite=Strictcookie. - Login rate limit: attempts are counted before the password check, so parallel requests can no longer exceed the limit of 10 attempts per minute.
- Changing
APP_PASSWORDnow signs out all existing sessions. After updating, everyone has to sign in once again.
Install or update
Image: ghcr.io/mrcdlm/dnsdeck:0.5.0 (linux/amd64, linux/arm64)
Set DNSDECK_VERSION=0.5.0 in .env, then run:
docker compose pull && docker compose up -dNew here? Start with the quick start.
Full Changelog: v0.4.0...v0.5.0