Security release for the fixes in #108. Read the upgrade checklist in CHANGELOG.md before deploying.
Upgrade steps
- Apply database migration
0008_fleet_lineage_self_origins(AUTO_MIGRATE=1orpnpm db:migrate). It addsapi_keys.owner_api_key_idandkeys.self_origins; both are additive. - Re-point Uptime Kuma monitors at each key's new
monitor_status_url. Status is now served at/status/<publicId>.<tag>; the old URL returns an empty 404. - If fleet devices attach their own alert destination at enrollment, list the approved pairs in
MANTIS_ENROLL_DESTINATIONS; otherwise those requests get403. - Regenerate css-background snippets, Windows device bundles and the Home Assistant receiver, and re-paste the Kandji script.
- Upgrade the CLI to 0.3.0 with the server.
Changes
- Enrollment-scoped keys mint plain tripwires only, attach only operator-approved destinations, and claim an
external_idonly inside their own fleet. A claim never returns a disabled or expired key. - The public trigger no longer drops requests by client IP before the key lookup; any path under a trigger URL fires the key.
- Keys can declare their own site origins (
self_origins) so own-site page views cannot mask a clone-site hit. - Alerts link the dashboard instead of the trigger URL; webhook and Home Assistant payloads gain
dashboard_url. - Removing a destination aborts its queued deliveries. Destinations that point back at the instance are refused.
- Admins can reveal and rotate a global webhook destination's signing secret.
- More dashboard and API actions are written to the audit log; retention runs in cron mode.
- Generated canaries: the css-background snippet decodes correctly, Windows tasks register with the right principal, boot and wake alarms retry.
New optional settings: MANTIS_ENROLL_DESTINATIONS, MANTIS_ENROLL_KEYS_PER_HOUR, DASHBOARD_BASE_URL. docker-compose.yml now pins TRUSTED_IP_HEADER=x-forwarded-for by default.
Companion releases: CLI 0.3.0 and edge 0.2.0.