Require authentication and explicit certificate trust
Pre-release
Pre-release
·
15 commits
to main
since this release
What's Changed
- Require owner authentication across control APIs, WebSockets, diagnostics, documentation, and loopback endpoints; missing passwords lock access.
- Show the complete SHA-256 fingerprint before login and provide mt --fingerprint plus local mt --set-password recovery.
- Enforce stronger new passwords, upgrade password hashing, and fix accumulated login throttling with bounded concurrent password work.
- Bind preview credentials to their route, reject hostile browser origins, prevent owner credentials from reaching preview upstreams, and close WebSockets when their API key is revoked.
- Require HTTPS and certificate validation for Hub and native connectors; block credential-bearing redirects and restrict the tmux bridge to HTTPS loopback.
Release integrity
Native archives have matching platform-specific SPDX SBOM assets plus GitHub build-provenance and SBOM attestations. Installers and the built-in updater additionally verify a signed manifest and all packaged-file hashes.