Repository navigation
Conversation
auzcoder
force-pushed
the
fix/auth-rate-limit-and-permissions
branch
from
September 28, 2026 19:51
00bbcdf to
48f6676
Compare
- Add in-memory sliding window rate limiter for auth token endpoints with CI/test bypass and successful request exclusion - Add user_permission meta column migration and Objection model configuration - Support scoping allowed proxy hosts per user when in 'Created Items Only' visibility mode - Restrict advanced nginx configuration editing on hosts to admin users only - Fix user permissions route ID parsing and omit id from permission update payloads - Add allowed proxy hosts selector in permissions modal and display permissions summary badges in users table
auzcoder
force-pushed
the
fix/auth-rate-limit-and-permissions
branch
from
September 28, 2026 20:16
48f6676 to
8888455
Compare
|
Docker Image for build 3 is available on DockerHub: Note Ensure you backup your NPM instance before testing this image! Especially if there are database changes. Warning Changes and additions to DNS Providers require verification by at least 2 members of the community! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This pull request introduces authentication endpoint rate limiting, adds granular proxy host permission scoping for non-admin users, and hardens security around advanced Nginx configurations.
Key Changes:
Authentication Rate Limiting (�ackend/lib/express/rate-limit.js, �ackend/routes/tokens.js):
Scoped Proxy Host Permissions (�ackend/migrations/20260906220000_user_permission_meta.js, �ackend/lib/access.js, �ackend/internal/proxy-host.js, rontend/src/modals/PermissionsModal.tsx):
Security Hardening on Host Advanced Configs (�ackend/internal/*.js, rontend/src/modals/*Modal.tsx):
Bugfix on User Permission Updates (�ackend/internal/user.js, �ackend/routes/users.js):
UI & Usability Enhancements (rontend/src/pages/Users/Table.tsx, rontend/src/components/Form/LocationsFields.tsx, rontend/src/modals/ProxyHostModal.tsx):
Testing