Skip to content

mantis server 0.3.0

Latest

Choose a tag to compare

@adamXbot adamXbot released this 03 Oct 06:39
716ec8c

Security release for the fixes in #108. Read the upgrade checklist in CHANGELOG.md before deploying.

Upgrade steps

  • Apply database migration 0008_fleet_lineage_self_origins (AUTO_MIGRATE=1 or pnpm db:migrate). It adds api_keys.owner_api_key_id and keys.self_origins; both are additive.
  • Re-point Uptime Kuma monitors at each key's new monitor_status_url. Status is now served at /status/<publicId>.<tag>; the old URL returns an empty 404.
  • If fleet devices attach their own alert destination at enrollment, list the approved pairs in MANTIS_ENROLL_DESTINATIONS; otherwise those requests get 403.
  • Regenerate css-background snippets, Windows device bundles and the Home Assistant receiver, and re-paste the Kandji script.
  • Upgrade the CLI to 0.3.0 with the server.

Changes

  • Enrollment-scoped keys mint plain tripwires only, attach only operator-approved destinations, and claim an external_id only inside their own fleet. A claim never returns a disabled or expired key.
  • The public trigger no longer drops requests by client IP before the key lookup; any path under a trigger URL fires the key.
  • Keys can declare their own site origins (self_origins) so own-site page views cannot mask a clone-site hit.
  • Alerts link the dashboard instead of the trigger URL; webhook and Home Assistant payloads gain dashboard_url.
  • Removing a destination aborts its queued deliveries. Destinations that point back at the instance are refused.
  • Admins can reveal and rotate a global webhook destination's signing secret.
  • More dashboard and API actions are written to the audit log; retention runs in cron mode.
  • Generated canaries: the css-background snippet decodes correctly, Windows tasks register with the right principal, boot and wake alarms retry.

New optional settings: MANTIS_ENROLL_DESTINATIONS, MANTIS_ENROLL_KEYS_PER_HOUR, DASHBOARD_BASE_URL. docker-compose.yml now pins TRUSTED_IP_HEADER=x-forwarded-for by default.

Companion releases: CLI 0.3.0 and edge 0.2.0.