Skip to content

3.2.2.8

Latest

Choose a tag to compare

@nilsteampassnet nilsteampassnet released this 07 Oct 04:53
bdd7e1a

What's Changed

This is a maintenance release on the 3.2.2 line. It reworks the Restore missing sharekeys tool, which can now rebuild the encryption keys from the keys of any user who can still open the objects and checks every key against the data it must decrypt, and it fixes three Health page findings that could not be cleared whatever the administrator did. It also stops TeamPass from being reported as modified by the file integrity check after Composer was run on the server, which the installation guide used to recommend, and the Docker image now ships exactly the libraries of the release. There is no database change.

🛠️ Improvements

  • Restore missing sharekeys can use another user's keys - the tool rebuilt the reference key of the internal TP account from the administrator's own keys only, so every object the administrator could not open was left for a user to save again by hand. A new Open the objects with the keys of list selects any user who can still open them; their password is checked on the server, which opens their keys there for the duration of the repair. Neither the password nor any private key is stored or sent back to the browser, and the use of another user's keys is recorded in the system logs. The list shows how many shared item keys each user holds, and Show details names the users still holding a key on each object that cannot be repaired. See Tools.

  • Every key is checked against the data it must open - a sharekey only proves that a key was encrypted for a user, not that the object is still encrypted with it. When an item is saved and the background distribution of its new keys never completes, the other users, the TP account included, keep the previous key, and the repair used to copy that stale key to every user missing one. The repair now checks each key against the encrypted content: a TP reference key that no longer opens its object is replaced from the selected user's keys, and the other users' keys on that object, which came from the same incomplete distribution, are recreated from it. Content stored corrupted, which decrypts to unreadable data with every key, is never mistaken for a stale key: those objects are left untouched and reported. The background task no longer distributes a reference key that does not open its object, and its summary lists them. The repair also stops up front, with an explanation, when the TP account key itself cannot be opened on the server.

  • The "Fix items are empty after user OTP change" tool is removed - it rebuilt the TP keys from a reference user, but only overwrote the item keys that already existed, never created a missing one, ignored custom fields and attachments, generated a new key pair for the TP account when it could not open the current one, which made every existing TP key unusable, and sent the TP account password and the reference user's private key to the browser. Restore missing sharekeys with a reference user replaces it. Restore keys saved before an OTP repair stays, for the keys that tool saved.

  • The PHP libraries are shipped, never installed with Composer - every dependency is in app/vendor/, with its autoloader already generated, but the installation guide told administrators to run composer install after cloning or unzipping, and the Docker image rebuilt the folder with Composer. Each run rewrites Composer's own files (app/vendor/composer/autoload_real.php, InstalledVersions.php, installed.php), which Utilities → Health → File integrity then reports as critical modifications. The guides now say not to run Composer, and the Docker image uses the libraries of the release.

🐛 Bug fixes

  • Items with an empty password were reported as corrupted - an empty password is encrypted too, by the API and in personal folders, and decrypts to an empty value, which the Corrupted items scan of the Health page took for a decryption failure. Those items were counted as corrupted, shown in red in the item list when Highlight corrupted items in items list is enabled, and their users were asked to check the password. The scan now reads the decryption status, as the item card already did.

  • Inconsistent users could never go back to zero - the Health page counted every legacy encryption key still held by a user, including keys emptied by the I no longer remember my previous password option of the personal items recovery, which keep their version. The key migration ignores those empty keys, so such users were reported as inconsistent forever, and repair_phpseclib_migration.php --repair reset their migration at every run for nothing. Both now ignore empty keys.

  • Orphan sharekeys could never go back to zero - the Items integrity scan maintenance task removed the keys of deleted objects and accounts from the items table only, and the keys of deleted attachments and custom fields. The keys a deleted account left on attachments, custom fields, history entries and suggestions, and the keys of deleted history entries and suggestions, stayed forever, while the Health page counts all of them. The task now removes them too.

⬆️ Upgrade notes

  • No database change. UPGRADE_MIN_DATE is unchanged: replace the files, there is no upgrade wizard to run.
  • Do not run Composer after replacing the files. If you followed the former installation guide and the file integrity check reports autoload_real.php, InstalledVersions.php or installed.php as modified, replacing the files with this release's archive clears it; do not run composer install afterwards.
  • Docker. The image no longer runs Composer while it is built. A container built from this release reports no modified library file.
  • Run the repair after upgrading if the Health page reports missing or corrupted keys. Utilities → Tools → Restore missing sharekeys: Analyze first, then Repair, with your own keys or with the keys of a user who can still open the objects. The Items integrity scan task clears the orphan sharekeys at its next run.
  • The repair may now replace existing keys. It still never touches a key that opens its object. A key is only replaced when the object is proven to be encrypted with another one; the keys of the other users of such an object are then recreated by the background task, and those users cannot open it until the task has run. Check the Tasks page.
  • Back up your database before upgrading, as always.

Full Changelog: 3.2.2.7...3.2.2.8

Important

  • Requires at least PHP 8.2

Languages

Please join Teampass v3 translation project on Poeditor and translate it for your language.

Installation

Follow instructions from Documentation.

Upgrade

Follow instructions from Documentation.

Ideas and comments

Are welcome ... please use Discussions.

Download TeamPass