v1.2.0 — Shared-Domain Sign-In & Origin Checks
Highlights
- One sign-in across two hosts of one domain. Set
SKRUN_SESSION_COOKIE_DOMAIN(example.com) and a dashboard on one host and the API on another share a single browser session; setSKRUN_PUBLIC_URLand every URL the server hands out — OAuthredirect_uri, device-login link, schemaservers— stops depending on aHostheader the caller chose. Both are validated at startup; a bad pair refuses to boot with a message naming what it got. - Cookie-authenticated changes are checked for cross-site origin, on every deployment. A
POST/PUT/PATCH/DELETEcarrying the session cookie must show a browser signal (Sec-Fetch-Site, a matchingOrigin) or a content type a cross-site form cannot produce —SameSite=Laxdoes not stop a forged form between two hosts of one domain. API keys anddev-tokenare untouched. - Expired run files are deleted on a schedule. Output directories and uploaded inputs no longer wait for their next read to expire: a sweep runs every five minutes and a restart clears what a previous process left.
FILES_RETENTION_S/INPUT_FILES_RETENTION_Sare now deletion bounds. /docsruns only code we control. The interactive API docs pin their renderer to one version and one integrity hash under a Content Security Policy, and no longer relay "Try it" requests or fonts through third-party hosts.- The CLI consent cookie is host-locked (
__Host-prefix), and a failed OAuth exchange no longer echoes the exception to the browser.
Breaking
- A non-browser client that authenticates with the session cookie and sends a form-style body (or no
Content-Type) on a change is refused with403. Add-H "Content-Type: application/json"— or use ansk_live_key. Clients usingAuthorizationare unaffected.
Migration
- Nothing to configure: both new variables are optional and unset means the previous behaviour.
- If you set
SKRUN_SESSION_COOKIE_DOMAINin production, the cookie is renamed__Secure-skrun_session: everyone signs in once more, once. Check what else lives under that DNS zone first —docs/self-hosting.mdsays what to look at. - The image's start script now states what a boot really requires: the database and storage settings always,
CORS_ORIGINunderNODE_ENV=production, no provider key ever.
Stats
- 1972 unit + integration tests pass (was 1907 at v1.1.0)
- 144 E2E in-memory, plus the live multi-provider suite
- OpenAPI 3.1 spec at 1.2.0
Install
npx @skrun-dev/cli@1.2.0 --version
# or
npm i -g @skrun-dev/cli@1.2.0Full changelog: CHANGELOG.md