Important
This release includes a security fix for Host header handling.
The issue only affects setups where requests can reach solidtime with arbitrary Host headers, for example when a reverse proxy forwards unvalidated Host headers or when no reverse proxy is used.
solidtime Cloud and our recommended Traefik setup are not affected.
Affected self-hosted installations should upgrade as soon as possible.
Caution
Make sure your APP_URL is set correctly before updating, otherwise the solidtime instance will not work properly
What's Changed
- Add trusted host validation middleware to prevent Host header poisoning. Thanks to @tonghuaroot for the security report
- Fixed invoice tax rate by @korridor in #1184
For self-hosting
This release adds host validation based on APP_URL.
By default, solidtime now only accepts requests for the hostname configured in APP_URL and its subdomains. Requests for other hostnames are rejected with HTTP 400.
If your instance is intentionally reachable through additional hostnames, configure the new TRUSTED_HOSTS environment variable:
APP_URL=https://solidtime.example.com
TRUSTED_HOSTS=solidtime.internal,solidtime.tailnet-name.ts.netWildcard subdomains are supported:
TRUSTED_HOSTS=*.example.comNo database migrations are included in this release.
Full Changelog: v0.18.0...v0.19.0