IT-Vault 2.4.0 — short signing links, and NAS templates
Acknowledgement links stopped being blocked by mail security.
A signing link was a couple of hundred characters of base64 in a query string — the shape of a phishing link, and gateways treat it accordingly. One install's Trend Micro rewrote it into a click-time proxy and then refused it: the mail arrived, the link didn't.
Links are now a short code in the path:
before: https://host/sign?token=eyJhIjp7ImFzc2V0X2lkIjoi… 234 characters
now: https://host/s/gnkdst2j 33 characters
The code is stored rather than carried, which fixes something the old form gave away for free: that token was plain base64, so anyone who decoded it — and every gateway that rewrote it, and every log that recorded it — could read the asset name straight out of the URL.
Everything about the flow holds: single use, one live link per asset, seven days. Links already in inboxes keep working — the old ?token= form is still accepted until it expires. Superseded codes are kept rather than deleted, because only a row that still exists can say why it's dead: "a newer one was issued, use the most recent email" is the difference between finding the right mail and ringing IT.
The email footer had the same problem, smaller
A gateway rewrites every link it can see. In an HTML part that's invisible — the reader sees the anchor text. In the plain-text part the reader sees the rewrite itself: 200 characters of clicktime proxy, twice, under every message. The text footer now names the project and the author; the links live in the HTML part where they belong.
Install it on a NAS without reading a compose file
unraid/it-vault.xml— a Community Applications template: ports, the three data paths, the database fields with passwords masked, and an overview that says up front that IT-Vault brings no database of its own.truenas/docker-compose.yaml— for TrueNAS Apps → Custom App → Install via YAML. This one does bring MariaDB, because on a NAS "install the database first" is where people stop.
tests/test_nas_templates.py keeps both honest against the code rather than against each other: every variable they set is one app.py reads, every path they mount is one it writes, and both name the same published image.
Upgrading
Pull the matching image; the SignLinks table is created on start.