v1.8.0 adds an animated wizard gopher to the login page.
Animated wizard on the login page
The login page shows a cel-shaded wizard gopher that follows the pointer and performs a staff strike when it is activated or the login form is submitted (#690 by @jonasgwozdz). On submit the native POST waits for 1.4 seconds of animation progress and then replays once with its original submitter and CSRF field. A four-second safety deadline releases the login if rendering stalls, and hidden, removed, paused or failed avatars release it at the next timer check, so the animation cannot block authentication. Reduced motion and unavailable WebGL 2 submit immediately, and the application logo stays as the fallback without JavaScript. The avatar reads no credentials. Three.js 0.186.1 is vendored and served locally under the existing CSP.
Tests and CI
@CybotTM added the companion's browser checks to CI and changed the E2E login helper to wait for the resulting navigation instead of sleeping a fixed 500 ms, which the delayed submit had broken (#690). The repository also carries an OpenSSF Best Practices answer file (#692).
Full changelog: v1.7.0...v1.8.0
Container image
ghcr.io/netresearch/ldap-manager:1.8.0
ghcr.io/netresearch/ldap-manager:1.8
ghcr.io/netresearch/ldap-manager:1
Verify your download
Per-asset signatures are bundled. Verify any single file:
cosign verify-blob \
--bundle ldap-manager-linux-amd64.sigstore.json \
--certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
ldap-manager-linux-amd64Verify checksums against the signed manifest:
cosign verify-blob \
--bundle checksums.txt.sigstore.json \
--certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
checksums.txt
sha256sum -c checksums.txt --ignore-missingVerify build provenance. Releases are built by a reusable
workflow, so the signing identity is that workflow rather than
this repository -- --signer-workflow is required and
verification fails without it:
gh attestation verify <artifact> \
--repo netresearch/ldap-manager \
--signer-workflow netresearch/.github/.github/workflows/release-go-app.ymlVerify container image:
cosign verify ghcr.io/netresearch/ldap-manager:1.8.0 \
--certificate-identity-regexp "^https://github\.com/netresearch/\.github/\.github/workflows/release-go-app\.yml@" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"
gh attestation verify oci://ghcr.io/netresearch/ldap-manager:1.8.0 \
--repo netresearch/ldap-manager \
--signer-workflow netresearch/.github/.github/workflows/release-go-app.yml