Skip to content

IT-Vault 2.4.0 — short signing links, and NAS templates

Choose a tag to compare

@shatheitguy shatheitguy released this 19 Sep 11:45
· 12 commits to main since this release

Acknowledgement links stopped being blocked by mail security.

A signing link was a couple of hundred characters of base64 in a query string — the shape of a phishing link, and gateways treat it accordingly. One install's Trend Micro rewrote it into a click-time proxy and then refused it: the mail arrived, the link didn't.

Links are now a short code in the path:

before:  https://host/sign?token=eyJhIjp7ImFzc2V0X2lkIjoi…   234 characters
now:     https://host/s/gnkdst2j                              33 characters

The code is stored rather than carried, which fixes something the old form gave away for free: that token was plain base64, so anyone who decoded it — and every gateway that rewrote it, and every log that recorded it — could read the asset name straight out of the URL.

Everything about the flow holds: single use, one live link per asset, seven days. Links already in inboxes keep working — the old ?token= form is still accepted until it expires. Superseded codes are kept rather than deleted, because only a row that still exists can say why it's dead: "a newer one was issued, use the most recent email" is the difference between finding the right mail and ringing IT.

The email footer had the same problem, smaller

A gateway rewrites every link it can see. In an HTML part that's invisible — the reader sees the anchor text. In the plain-text part the reader sees the rewrite itself: 200 characters of clicktime proxy, twice, under every message. The text footer now names the project and the author; the links live in the HTML part where they belong.

Install it on a NAS without reading a compose file

  • unraid/it-vault.xml — a Community Applications template: ports, the three data paths, the database fields with passwords masked, and an overview that says up front that IT-Vault brings no database of its own.
  • truenas/docker-compose.yaml — for TrueNAS Apps → Custom App → Install via YAML. This one does bring MariaDB, because on a NAS "install the database first" is where people stop.

tests/test_nas_templates.py keeps both honest against the code rather than against each other: every variable they set is one app.py reads, every path they mount is one it writes, and both name the same published image.

Upgrading

Pull the matching image; the SignLinks table is created on start.