84 KiB
Changelog
All notable changes to this project are documented here. Format loosely
follows Keep a Changelog; versions
correspond to git tags (vX.Y.Z). Entries here cover theta-env's own
orchestration code; see each submodule's own CHANGELOG.md
(proxy,
sso-manager-node)
for what changed inside the apps it composes.
[v1.25.0] - 2026-08-01
- Added OpenBao (Vault) container for secrets management and native UI proxying.
- Updated
sso-manager-nodeto v1.14.0 (Discovery and Vault integration). - Updated
proxyto v1.12.0.
Unreleased
[1.23.0] - 2026-07-31
Submodules bumped
jump-host — v1.13.0
Changed
- Title changed to "SSO Manager" — the jump-host web UI now presents itself as "SSO Manager" in the navbar and page title, matching its role as the unified access portal for both services and hosts.
sso-manager-node — v1.13.0
Changed
- Directory page cleaned up — removed the parent badge and slug display from the directory table; resource names now align with the badges above for a cleaner, more compact layout.
- Users list SSH key column fixed — users with multiple SSH keys no longer show multiple checkmarks; the column now shows a single checkmark indicating "has key" regardless of key count.
proxy — v1.11.0
Changed
- Permissions, Users, and Groups pages converted to table layouts — card grids replaced with striped tables for better scanability and alignment. Users page adds per-field validation error display alongside the summary message.
- Groups page auto-refreshes — adding or removing a group now triggers an explicit reload, ensuring the list stays in sync without manual refresh.
[1.22.0] - 2026-07-31
Submodules bumped
jump-host — v1.12.0
Added
- TUI host picker with colors: ANSI-colored terminal UI with box-drawing header, cyan/magenta/green title treatment, per-row coloring (cyan hostnames, blue IPs), environment badges (red PROD / dim DEV), green inverse selection highlight with "◄ SELECTED ►" indicator, yellow filter text, and a footer separator with quick-select hint.
sso-manager-node — v1.12.0
Changed
- Catalog page (
/) redesigned: Removed the portal banner; "My Access" section now has tabs separating Services and Hosts; icons support both Font Awesome classes and image URLs (http/https). - Profile page redesigned as a single card with tabs: Password reset is now a modal button; "My groups", "My Services", "Security & Usage Stats", and "Members of X's group" are now tabs on the main profile card instead of separate cards; metrics display fixed to properly load and show service usage data.
proxy — v1.10.0
Changed
- Permissions page: Converted from card grid to table/list layout with columns: Subject, Scope, Domain, Role, Actions.
- Users page: Converted from card grid to table/list layout; form validation now shows both a summary message AND per-field error messages with visual highlighting.
- Groups page: Added automatic refresh after adding/deleting groups to ensure new entries appear immediately.
[1.21.0] - 2026-07-31
Submodules bumped
Operational note — the SSO image now builds slapd from source. OpenLDAP's
nestgroupoverlay (nested groups) exists only on master; no 2.6.x release ships it.Dockerfile.openldaptherefore compiles OpenLDAP from a pinned commit, which makes the SSO image slower to build and pullspw-sha2from contrib. Two consequences worth knowing:
- Master ships LMDB 1.0.0, whose on-disk format is mutually unreadable with the 0.9.x in 2.6.x (
MDB_INVALID: File is not an LMDB file). Moving an existing/var/lib/ldaponto this image is aslapcat->slapaddreload, not a restart.- There is a
TODOto drop the whole from-source stage oncenestgroupships in a release. The entrypoint already probes fornestgroup.soand the app keys offapp_ldap__nestedGroupsServerSide, so that swap needs no other changes.
sso-manager-node — v1.11.0
Added
- End-user catalog at
/— the first ungated nav item; previously every nav entry was admin-only and a normal user had no signposted destination. Search/filter, per-kind icons, and a how to reach it block per card: the URL for a service, the SSH invocation for a host (using the jump-hostuid_-_slug@hostgrammar whendirectory.jumpHostis set). - Self-service access requests —
/api/access-requests(create, list own, list decidable, approve, deny, withdraw) with approve/deny queues on the catalog. Approving performs the LDAP group add, so LDAP stays the access-control truth. Requests target a resource's_accessgroup, never_admin. Replaces the "coming soon" stub. - Admin access visibility — an Access column on the directory table (member/group counts, flagging links whose LDAP group was deleted) and a "what can this user reach" lookup, the reverse question that previously had no UI at all.
- Nested LDAP groups.
groupOfNames.memberalready accepts a group DN, so nesting needs no schema — what it needs is resolution, which no released OpenLDAP performs. Server-side via the pinned-masternestgroupoverlay; client-side the app computes the closure itself (cycle-detected, depth-capped) against any other server.PUT/DELETE /api/group/:group/nested/:child,GET /api/group/:group/effective, and a Nested tab on each group card. app_super_adminis now seeded (it never was) and nested intoapp_sso_admin/app_sso_invite/app_sso_oauth_admin, so the privilege is real LDAP membership visible to SSSD and sudo rather than a special case in app code. Resource creation nestsapp_super_admin-><slug>_adminand<slug>_admin-><slug>_access.- Resource metadata
iconandtagline, collected on the admin form with a live icon preview.
Fixed
GET /api/discovery/mereturned onlyisPublicresources for every human caller — it readreq.user.groups, which does not exist (req.usercarriesmemberOf), so the empty list failed open. "My Services" was blank for everyone, andisDirectoryAdmin()was false even for real directory admins.- The portal's "Discover More Services" was dead for every non-admin — it called the admin-gated endpoint and swallowed the 403 into an empty array.
- Services reported no address —
/mehad reimplementedgetMyAccesswithout its parent-walking resolution, so a service reached at its host's IP resolved to nothing. GET /api/user/mederivedisAdminfrommemberOf, which is only transitive withnestgroup; against a stock server an admin holding their group via nesting lost the entire admin UI while still passing every server-side check.utils/permission.js'sbyGroupsaw only direct membership.- Adding an existing group member, and removing a group's last member, both returned bare 500s; now 409s that explain themselves.
DELETE /api/directory-admin/resources/:iddeleted the resource before its edges and group links, orphaning rows on a mid-way failure./api/directory-admin/audit-logsshelled out totailviaexecSync; replaced with a bounded async read.- Broken
api.htmllink in the published docs.
Changed
@simpleworkjs/directory-schema->^1.1.0, declaring ten metadata keys the admin form always wrote but the schema never listed. Undeclared keys are dropped for non-admin callers — which blanked the portal'sOS:field, hid every service's port, and left machine tokens unable to read the port mapping the firewall consumer exists to render.
ldap-client — v1.1.1
Fixed
- Sets
ldap_group_nesting_level = 5so SSSD walks nested groups itself when pointed at a server withoutnestgroup. Against the SSO's bundled slapd the existingmemberof=access filter is already transitive, so SSH login inherits nesting for free. The explicitapp_super_adminclause is kept, to keep super-admin login working against a directory predating the new nesting.
[1.20.0] - 2026-07-30
Added
setup.shpersistsSSO_GIT_COMMIT/PROXY_GIT_COMMIT/JUMP_GIT_COMMITinto./.env(newenv_upserthelper), whichdocker composeauto-loads on every future invocation in this directory. Previously these were onlyexported for the current shell, so an ad-hocdocker compose up --build <service>run later (outside a fullsetup.shrun) would build with an emptyGIT_COMMITarg — and since each submodule's checked-out.gitis a pointer file, not a real repo, the in-container git fallback can't resolve it either, so the image silently baked "unknown" as its commit hash..gitignore's.envcomment updated to describe this (it was previously labeled "legacy, no longer used").
Submodules bumped
- jump-host
v1.10.2->v1.11.0 - ldap-client
v1.0.0->v1.1.0 - proxy
v1.8.0->v1.9.0 - sso-manager-node
v1.9.0->v1.10.0
sso-manager-node — v1.10.0
Added
app_super_admincross-app group: members are full admins here regardless ofapp_sso_adminmembership. The same group is now also recognized by proxy and jump-host, and byldap-client's SSSD access filter (SSH login on every host).
Changed
- Renamed the Executive page to Overview (route, view,
/api/metrics/overview, nav label, docs)./executivekept as a 301 redirect.
proxy — v1.9.0
Added
app_super_admincross-app group recognized as a global admin (conf.auth.adminGroups).
Changed
- Users and Permissions pages: the always-visible sidebar "Add" forms are now an "Add User"/"Add Permission" button that opens an
app.modaldialog, matching the hosts.ejs convention. - Let's Encrypt ACME account key now defaults to the already-persisted
/datavolume instead of a CWD-relative path (./le_key.cert->/app/le_key.certin the container), which was lost on every image rebuild.
jump-host — v1.11.0
Added
app_super_admin(cross-app) andapp_jump_admingroups: super admins are full admins here same asapp_sso_admin; jump admins get audit page/data access without other admin rights. The Audit page/API is now actually admin-gated server-side (previously the page shell rendered for any logged-in user, only its data was gated).- Host list adds Last connection/Last failed connection columns and highlights rows green (a session is live right now) or yellow (the most recent attempt failed), backed by new per-host last-success/last-fail timestamps.
Changed
- Dashboard's stat boxes and Top hosts/Top users cards moved to the Audit page. "All hosts" renamed to "My hosts".
ldap-client — v1.1.0
Added
app_super_admincross-app group now grants SSH login access to every host (ldap_access_filter+ldap_access_groups), matching the same group's admin rights in sso-manager-node, proxy, and jump-host. Sudo is not yet extended to super admins (ldap_sudo_search_filterremains non-functional on this SSSD version — pre-existing, documented gap).
[1.19.0] - 2026-07-30
Added
- New
ldap-clientsubmodule +ldap-test-hostservice (jump-hostcompose profile): a real SSSD + AuthorizedKeysCommand LDAP-joined downstream host for testing jump-host's actual key-injection -> upstream-connect flow end-to-end against this stack's own local LDAP, instead of a container with a manually-dropped public key inauthorized_keys. Verified live (SSH CLI and WinSCP) through jump-host'suid_-_targetgrammar.
ldap-client — v1.0.0 (first tagged release)
Added
- Docker test fixture (
Dockerfile+entrypoint.sh): Ubuntu 22.04 + sssd + sshd, no systemd required.
Fixed
Building that fixture surfaced three real bugs that would break login on any deployment, not just the test fixture:
sssd.conf.mousedldap_bind_dn/ldap_bind_pw, which aren't real SSSD options — corrected toldap_default_bind_dn/ldap_default_authtok(_type).sssd.conf.mohad no explicitservices =list, so SSSD started only its backend, never the nss/pam responders —getent passwd <ldap-user>silently failed even with the domain reachable.ldap-ssh-key.sh'smemberoffilter was missing thecn=prefix on the group name, so the AuthorizedKeysCommand script always returned zero keys for a correctly-provisioned user — no error, just silently nothing.
sso-manager-node — v1.9.0
Added
- Directory modal's Associated LDAP Groups tab now supports full membership management: view, add, and remove members/owners of each associated group directly from the tab.
app.util.revealItem()(sharedapp-base.js): scrolls a just-added/-edited element into view and flashes its background.
Changed
- Groups page's search/sort bar is now sticky while scrolling.
- Directory table: Kind/Name/Env/Host merged into a single "Resource" column.
proxy — v1.8.0
Added
- Users backed by SSO/OIDC login are now marked "External (SSO)" and read-only (password-change hidden client-side,
PUT /password/:usernamerejects with 403 server-side). Redis user-backend only.
Changed
- All pages now wrap their content in a standard-width container, matching sso-manager-node instead of rendering full-bleed.
- Users and Permissions pages converted from bare
<table>s to the card-grid convention already used on the Groups page.
jump-host — v1.10.2
Changed
- Dashboard, Sessions, and Audit pages now match sso-manager-node/proxy's page width.
- Audit's nav entry is now admin-gated (
groups: ['admin']).
Bumped
- sso-manager-node -> v1.9.0
- proxy -> v1.8.0
- jump-host -> v1.10.2
- ldap-client -> v1.0.0 (new submodule)
[1.18.0] - 2026-07-28
Changed
Cross-app API-token self-service UI unification: all 3 apps now share the
same card-grid list, "+ New Token" modal-based create flow, app.modal-based
secret reveal, and Edit modal (with real created-by/on audit metadata).
sso-manager-node — v1.8.2, v1.8.3
v1.8.2
Fixed
- Creating a new OAuth integration didn't reliably show the "save this client secret now" reveal modal —
saveResource()calledapp.modal.close()immediately before conditionally showing the secret viaapp.modal.open().app.modalis a singleton, andclose()immediately followed byopen()collides with Bootstrap's hide-transition guard. An interveningawait loadResources()made this race unlikely to lose in practice, but not guaranteed to — found while fixing the same, guaranteed-to-lose bug in jump-host and proxy's API-token create flows.
v1.8.3
Changed
profile.ejs's self-service API-token UI unified ontoapp.modal, matching the pattern already shipped this round indirectory.ejs, proxy, and jump-host: the static#secretModal/#editModalelements are retired in favor of the sharedapp.modalsingleton, the always-visible inline create-form card becomes a "+ New Token" button + modal, and badge classes switch frombg-*totext-bg-*.- Checkmark-flash copy feedback (silently broken by FontAwesome's
<i>→<svg>replacement) replaced with toast-basedcopyFieldValue, matching proxy and jump-host.
proxy — v1.7.0
Added
- API tokens: "+ New Token" modal button (replacing the always-visible inline create-form card) and a new Edit modal — continues the cross-app API-token UI unification started in jump-host. The Edit modal's footer shows real created-by/on data; the
PUT /api-token/:idroute already fully supported editing, so no backend change was needed.
Fixed
- Creating an API token didn't show the "save this secret now" reveal modal — the create flow called
app.modal.close()immediately beforeapp.modal.open()(to show the secret) in the same tick; sinceapp.modalis a singleton, that collided with Bootstrap's hide-transition guard and the reveal modal silently never appeared.
jump-host — v1.10.0, v1.10.1
v1.10.0
Added
- API-token UI unified with sso-manager-node/proxy: card grid replacing the bare table, a new Edit modal (footer shows real created-by/on data), and a Description field on both the create and edit flows — the model and API already fully supported all of this, it just wasn't exposed anywhere in the dashboard.
Changed
@simpleworkjs/frontendbumped to^0.2.6(this app was still on^0.2.5).
v1.10.1
Fixed
- The API-token reveal modal silently didn't show after creating a token —
submitApiToken()calledapp.modal.close()immediately beforeshowToken()'sapp.modal.open()in the same tick, colliding with Bootstrap's hide-transition guard on the singleton modal. Same root cause as the OAuth-secret-reveal race fixed in sso-manager-node (v1.8.2) and the create-token race fixed in proxy (v1.7.0).
Bumped
[1.17.0] - 2026-07-28
Added
- proxy's host modal now has a footer (created/updated-by/on metadata) and a linkable
/hosts/{host}URL, migrated onto the same sharedapp.modalcomponent as sso-manager-node's resource modal — continuing the entity-modal standardization across the stack.
Fixed
- proxy: the Let's-Encrypt challenge-type/wildcard-matching visibility logic could stop reacting to the hostname field after the first Add/Edit host, and the SSO allow-list autocomplete could go empty starting on the second Add/Edit — both were DOM-rebuild timing bugs in the same class as the resource-modal fixes already shipped.
- sso-manager-node: the resource modal's "Associated LDAP Groups" autocomplete went empty after the first Add/Edit — same DOM-rebuild timing bug, now fixed.
Bumped
[1.16.0] - 2026-07-28
Added
- "Quick Jump" copy-to-clipboard section on the jump-host dashboard — one-click-copy SSH commands (interactive-picker mode, plus a per-host
uid_-_targetgrammar-mode command) instead of having to remember/reconstruct the format by hand.
Fixed
- jump-host audit records for a failed downstream connection only ever said
upstream-unreachable, with no way to tell a network-layer failure from an auth failure — the real error (ECONNREFUSED, ETIMEDOUT, an ssh2 auth-failure message, etc.) is now captured and shown as a tooltip on the audit table's fail badge.
Bumped
- jump-host -> v1.9.0
[1.15.0] - 2026-07-28
Fixed
- sso-manager's Directory data (every site/host/service/oauth-client resource and their relationships/LDAP-group associations) had no persistent volume —
@simpleworkjs/ormfell back to./config/inventory.sqlite(relative to the app's/appcwd) wheneverconf.ormwasn't set, which sits in the container's ephemeral writable layer, not any mounted volume. Every container recreate (docker compose up --build,down/up, an image rebuild) silently wiped the entire Directory Management page.setup.sh's generatedsso-secrets.js(and the example template) now setorm: { dialect: 'sqlite', storage: '/data/inventory.sqlite' }, co-locating it with the already-persistedsso-datavolume (where Redis lives). Existing deployments: this repo doesn't rewrite an operator's existingconfig/sso-secrets.js(re-runningsetup.shleaves it untouched by design) — add theormblock above manually, and copy the container's current/app/config/inventory.sqliteto/data/inventory.sqlitebefore recreating the container, or the existing Directory data will be lost on the next recreate instead of migrated.
Bumped
- sso-manager-node -> v1.8.0
[1.14.0] - 2026-07-28
Fixed
- jump-host's Redis had zero persistence (
--save '' --appendonly no, no data-dir volume) — every container rebuild/recreation (including asetup.shre-run) silently wiped all sessions, in-flight OAuth logins, and any admin-created API token. This is the root cause of the reported "re-running setup.sh breaks OAuth with jump" — the jump-host container gets recreated, and any token or in-flight login vanished with it, while proxy was unaffected because its Redis was already persisted. Now jump-host's Redis persists (AOF + periodic RDB) to/data, mounted as a new named volume,jump-redis-data. Verified live: minted a PAT, force-recreated the container, confirmed the same PAT still authenticated afterward.
Changed
docker-compose.yml: added thejump-redis-datavolume, mounted at/dataon thejump-hostservice.
Bumped
- jump-host -> v1.8.1
[1.13.0] - 2026-07-28
Fixed
Found via feedback on a fresh install:
- jump-host's OAuth client had no parent in the Directory.
seedDirectory()only ever linked the proxy's OAuth client; jump-host's own (minted byprovisionJumpHost) was created but never passed through, so it never got aResourceEdge. Existing deployments self-heal on the nextsetup.shrun. - TUI-mode SSH connections (bare
ssh user@host) could drop with "PTY allocation request failed" / "shell request failed" — a session-listener race in jump-host, same class of bugrunGrammaralready had a fix for. - Every form submit briefly showed literal HTML instead of a loading spinner, across all three apps.
POST /api/user/andPUT /api/user/passwordhad no success message — a green notification with nothing in it right after adding a user.- The login page gave no explanation for why the user landed there when redirected mid-OAuth-flow.
Changed
- Directory: tree view is now the only view; clicking a resource's name opens its detail modal.
Bumped
No setup.sh or compose change. Also confirmed (no fix needed): the Let's Encrypt ACME account key persists correctly across container rebuilds — lua-resty-auto-ssl's Redis storage adapter writes through the bundled Redis, which is started with --appendonly yes into /data, mapped to the persisted proxy-data volume. Only an explicit docker-compose down -v / volume removal would lose it (which is also what's required, and expected, on a domain change).
[1.12.0] - 2026-07-28
Bumped
- sso-manager-node -> v1.6.3 — fixes the root cause of a real "lost user" report:
routes/group.jsnever invalidated the User cache on membership changes, so an account added to theapp_sso_service_accountmarker group (which hides accounts from the Users page's People tab) could look like it had vanished for up to 5 minutes — and, separately, could be added to that group with no warning at all. Both fixed; see the linked release for detail.
No setup.sh or compose change.
[1.11.0] - 2026-07-28
Added
test/check_jump_ldap_tls.js, wired into theLintworkflow: a static consistency check on the jump-secrets.js templatebootstrap.jsgenerates, so theldap://+tlsOptionsmistake that broke every SSH login in 1.10.0 fails CI before it ever reaches a real deployment again.- A static "no native
alert()/confirm()/prompt()" check is now part of all three apps' own test suites (they block all further browser events on the page — see 1.9.0/1.10.0's release notes).
Bumped
- sso-manager-node -> v1.6.2 — fixes
DELETE /api/oauth/client/:id(client.remove is not a function, a genuine 500 masked by tests that never checked the response status), plus the regression test above. - proxy -> v1.5.2 — the regression test above.
- jump-host -> v1.7.1 — the regression test above.
No setup.sh or compose change.
[1.10.0] - 2026-07-27
Fixed
bootstrap/bootstrap.js's jump-secrets.js template now points jump-host atldaps://sso-manager:636, notldap://sso-manager:389. The plain-port URL combined with jump-host'stlsOptionsmadeldaptsattempt implicit TLS against a port serving plaintext LDAP — slapd dropped every connection before any LDAP message parsed, so SSH password login failed for every account, with any password, indistinguishable from a wrong credential. Root-caused by standing up a local jump-host, editing its config, and callinggetUser/checkPassworddirectly inside the container. Existing deployments must edit./config/jump-secrets.jsthemselves (this template only affects fresh bootstraps) — see theta42/theta-env#99. Companion defensive fix: simpleworkjs/ldap v1.0.2 now rejects thisldap://+tlsOptionscombination outright.
Bumped
- jump-host -> v1.7.0 — adds self-service API tokens (create/list/rotate/revoke from its dashboard); jump-host previously had none.
No setup.sh or compose change.
[1.9.0] - 2026-07-27
Bumped
Both apps had every native alert()/confirm() call removed, replaced by
@simpleworkjs/frontend's app.messages.action/confirm/toast (the
same modules adopted in 1.8.0). This was found live,
mid browser-verification of that release: clicking sso-manager-node
directory.ejs's "Rotate Client Secret" triggered a native confirm(),
which blocks all further browser events on the page — a real hazard for
anyone driving the app with browser automation, not just a cosmetic
inconsistency. sso-manager-node also dropped app.user.remove/
app.oauthClient.remove from public/js/app.js (dead code with a native
confirm() guard and zero callers).
No setup.sh, compose, or config change.
[1.8.0] - 2026-07-27
Bumped
All three apps adopt the newly published @simpleworkjs/frontend package's
app.messages, app.modal, and app.validate modules, replacing the
vendored app.util.actionMessage/actionConfirm/alert in
public/lib/js/app-base.js (byte-identical across all three apps) and the
vendored public/lib/js/val.js (byte-identical in sso-manager-node and
jump-host, and the same engine plus proxy-only DNS/hostname rules in proxy).
Message content is now HTML-escaped — the ad hoc app.util.alert() this
replaces had none — and app.messages.action falls back to a page-wide
toast when there's no inline .actionMessage target on the page. proxy's
host/target/hostname wildcard-DNS validation rules (mirroring
utils/hostname_validate.js) move to its own public/js/app.js, registered
via $.validateSettings, since they're proxy-specific and don't belong in
the shared package's generic rule set (eq/user/password/ip).
jump-host doesn't currently use any [validate] attributes, so its val.js
swap is dedup/future-proofing rather than a behavior change.
app.api/app.auth/app.pubsub/app.socket in each app's app-base.js
are untouched: they're app-specific (a dual-mode callback/promise API with
auth-token header injection) and not something the frontend package's
generic app.js provides, so it isn't loaded.
No setup.sh, compose, or config change.
[1.7.0] - 2026-07-27
Bumped
Two production bugs fixed: PUT /api/user/:uid 500'd with an LDAP
ObjectClassViolationError when setting sshPublicKey on any account
predating the ldapPublicKey objectClass (notably the bootstrap admin) —
and the exact same bug, in the shared @simpleworkjs/ldap package's
addSshKey, was silently aborting SSH connections at jump-host's
key-injection step for the same class of accounts. Both are fixed by
ensuring the objectClass is present before writing the attribute. Also
fixed: the Directory's "add resource" modal left the parent-Service
dropdown blank when adding an OAuth Integration.
Jump-host's web dashboard also gained a "Hosts you can reach" list (admins see "All hosts") — previously it only showed usage metrics with no way to see your actual access from the browser.
No setup.sh, compose, or config change.
[1.6.0] - 2026-07-26
Bumped
- jump-host -> v1.4.0
Jump-host gains standalone mode: it can now run with no LDAP directory and
no SSO Manager at all, storing users and hosts itself via
@simpleworkjs/orm (Sequelize; SQLite by default, any Sequelize-supported
dialect). This is an app-internal capability, opt-in via
standalone.enabled in jump-host's own config — the bundled theta-env stack
is unaffected and continues to wire jump-host to the shared LDAP directory
and SSO Manager as before. Two bugs were also fixed in jump-host's SSH
server: an ephemeral listen port (0) was silently overridden back to the
default, and session listeners could miss a client's immediate exec/shell
request.
No setup.sh, compose, or config change on the theta-env side.
[1.5.0] - 2026-07-26
Bumped
This release finishes the UI half of the unification that 1.4.0 deferred: the
three apps now share one front-end shell. views/top.ejs, views/bottom.ejs
and public/lib/js/app-base.js are byte-identical across sso-manager-node,
proxy and jump-host, and everything per-app moved into each repo's new
nodejs/utils/ui.js (nav items and the groups that may see them, footer links,
favicon, profile/logout targets, update-banner on/off). Nav gating is one model
everywhere — the shell reveals .group-required-<cn> from GET /api/user/me,
normalising sso's LDAP DNs and the OIDC clients' group CNs to the same shape,
with the clients' isAdmin flag exposed as a synthetic admin group. jQuery is
4.0.0 and EJS 3.1.10 in all three.
Five client-side bugs were fixed along the way, including two that broke real
flows: app.api.delete ignored the callback that formAJAX passes (so
DELETE-method forms — the proxy's host and DNS delete buttons — never refreshed),
and the login page threw on every logged-out visit while revealing its card.
No setup.sh, compose or config change: this is app-internal UI work. Verified
by driving a full stack of all three apps in a browser — every page renders
console-clean, nav gating is correct per role, and the OIDC login round trip
completes on both OIDC clients.
sso-manager-node 1.5.0:
Changed
- Unified the front-end UI shell across the three theta42 apps.
views/top.ejs,views/bottom.ejsandpublic/lib/js/app-base.jsare now byte-identical in sso-manager-node, proxy and jump-host, so the apps look and behave the same and a shell change lands in one edit per repo instead of three divergent ones. Everything that differs between the apps moved into a newnodejs/utils/ui.js, exposed to every render asuiviaapp.locals: nav items and the groups that may see them, footer repo/license/docs/Terms links, favicon, the profile and post-logout targets, and whether the update banner exists at all. - One nav-gating model everywhere.
app-base.jsreveals.group-required-<cn>elements for each group the current user is in, read fromGET /api/user/me. sso-manager-node reports LDAP DNs inmemberOfand the OIDC clients report CNs ingroups; both normalise to CNs client-side, and the clients' effective-rightsisAdminflag is exposed as a syntheticadmingroup — so one gating model covers a group-based provider and boolean-admin clients without either app learning the other's response shape. GET /api/user/meis fetched once per page load and cached (app.auth.loadUser). The nav, per-viewforceLoginand every group-gated element read that one promise instead of issuing their own request.app.auth.isLoggedInis dual-mode: it returns a Promise and invokes an optional node-style callback, so the async and callback call styles both work against one sharedtop.ejs.app.auth.forceLoginno longer uses$.holdReady(removed in jQuery 4). An unauthenticated user is redirected to/login?redirect=<path>; group requirements are still enforced, andlogOutnow only clears the session, leaving the destination to the caller (ui.logoutRedirect).- Dependency alignment across all three apps:
jquery^4.0.0andejs^3.1.10.
Fixed
app.api.deletedropped its callback when called byformAJAX.formAJAXalways passes the serialized form as the second argument, so a DELETE-method form's callback landed in the data slot and never ran.deletenow accepts both(url, callback)and(url, data, callback).app.api.post/putreferenced an undefinedcallback2and threw when handed a non-function callback. Both are now dual-mode Promise/callback.- The login page's "reveal the card once we know you're logged out" branch threw (
Cannot read properties of null) whenever the logged-in check answered before the parser reached that element — which it always did without a stored token. It now runs on DOM ready. logInRedirecton the legacy/login/<path>form kept only the path. The OIDC provider routes an unauthenticated authorization request through/login/oauth/authorize?client_id=…&state=…; dropping the query there loses the entire authorization request. The suffix form now preserves its query string.
Fixed (sso-manager-node)
public/lib/js/val.jsshadowedmessagewithletinsidevalidateField, so a custom rule's return value never reachedvalidateMessageand the caller always saw the generic length message. Resolved by adopting the shared validator, which also brings thetarget/hostnamerules and the real password policy (>= 8 chars, and either 12+ or 3 of 4 character classes) to this app.public/js/app.jsused$.isFunction, removed in jQuery 4.
Added (sso-manager-node)
GET /api/user/menow also reportsisAdmin(membership inapp_sso_admin), the single effective-rights flag the shared UI shell gates the update banner on. Group-level gating still readsmemberOf.
Verified
- Browser-verified against a full theta-env stack (sso-manager + proxy + jump-host): every top-level page renders with a clean console; nav gating is correct for admin and non-admin;
forceLogin's onboarding and group gates fire;val.jsblocks a weak password and accepts a strong one through a real form submit; the DELETE-method forms work; and the OIDC login round trip (authorize with PKCE -> login -> consent -> callback -> token fragment) completes on both OIDC clients.
proxy 1.4.0:
Changed
- Unified the front-end UI shell across the three theta42 apps.
views/top.ejs,views/bottom.ejsandpublic/lib/js/app-base.jsare now byte-identical in sso-manager-node, proxy and jump-host, so the apps look and behave the same and a shell change lands in one edit per repo instead of three divergent ones. Everything that differs between the apps moved into a newnodejs/utils/ui.js, exposed to every render asuiviaapp.locals: nav items and the groups that may see them, footer repo/license/docs/Terms links, favicon, the profile and post-logout targets, and whether the update banner exists at all. - One nav-gating model everywhere.
app-base.jsreveals.group-required-<cn>elements for each group the current user is in, read fromGET /api/user/me. sso-manager-node reports LDAP DNs inmemberOfand the OIDC clients report CNs ingroups; both normalise to CNs client-side, and the clients' effective-rightsisAdminflag is exposed as a syntheticadmingroup — so one gating model covers a group-based provider and boolean-admin clients without either app learning the other's response shape. GET /api/user/meis fetched once per page load and cached (app.auth.loadUser). The nav, per-viewforceLoginand every group-gated element read that one promise instead of issuing their own request.app.auth.isLoggedInis dual-mode: it returns a Promise and invokes an optional node-style callback, so the async and callback call styles both work against one sharedtop.ejs.app.auth.forceLoginno longer uses$.holdReady(removed in jQuery 4). An unauthenticated user is redirected to/login?redirect=<path>; group requirements are still enforced, andlogOutnow only clears the session, leaving the destination to the caller (ui.logoutRedirect).- Dependency alignment across all three apps:
jquery^4.0.0andejs^3.1.10.
Fixed
app.api.deletedropped its callback when called byformAJAX.formAJAXalways passes the serialized form as the second argument, so a DELETE-method form's callback landed in the data slot and never ran.deletenow accepts both(url, callback)and(url, data, callback).app.api.post/putreferenced an undefinedcallback2and threw when handed a non-function callback. Both are now dual-mode Promise/callback.- The login page's "reveal the card once we know you're logged out" branch threw (
Cannot read properties of null) whenever the logged-in check answered before the parser reached that element — which it always did without a stored token. It now runs on DOM ready. logInRedirecton the legacy/login/<path>form kept only the path. The OIDC provider routes an unauthenticated authorization request through/login/oauth/authorize?client_id=…&state=…; dropping the query there loses the entire authorization request. The suffix form now preserves its query string.
Added
.group-required { display: none }inpublic/css/styles.css, the base rule the shared gating model reveals against.- Admin-only nav items lost their inline
display: nonein favour of that class, and the brand link points at/instead of#.
Verified
- Browser-verified against a full theta-env stack (sso-manager + proxy + jump-host): every top-level page renders with a clean console; nav gating is correct for admin and non-admin;
forceLogin's onboarding and group gates fire;val.jsblocks a weak password and accepts a strong one through a real form submit; the DELETE-method forms work; and the OIDC login round trip (authorize with PKCE -> login -> consent -> callback -> token fragment) completes on both OIDC clients.
jump-host 1.3.0:
Changed
- Unified the front-end UI shell across the three theta42 apps.
views/top.ejs,views/bottom.ejsandpublic/lib/js/app-base.jsare now byte-identical in sso-manager-node, proxy and jump-host, so the apps look and behave the same and a shell change lands in one edit per repo instead of three divergent ones. Everything that differs between the apps moved into a newnodejs/utils/ui.js, exposed to every render asuiviaapp.locals: nav items and the groups that may see them, footer repo/license/docs/Terms links, favicon, the profile and post-logout targets, and whether the update banner exists at all. - One nav-gating model everywhere.
app-base.jsreveals.group-required-<cn>elements for each group the current user is in, read fromGET /api/user/me. sso-manager-node reports LDAP DNs inmemberOfand the OIDC clients report CNs ingroups; both normalise to CNs client-side, and the clients' effective-rightsisAdminflag is exposed as a syntheticadmingroup — so one gating model covers a group-based provider and boolean-admin clients without either app learning the other's response shape. GET /api/user/meis fetched once per page load and cached (app.auth.loadUser). The nav, per-viewforceLoginand every group-gated element read that one promise instead of issuing their own request.app.auth.isLoggedInis dual-mode: it returns a Promise and invokes an optional node-style callback, so the async and callback call styles both work against one sharedtop.ejs.app.auth.forceLoginno longer uses$.holdReady(removed in jQuery 4). An unauthenticated user is redirected to/login?redirect=<path>; group requirements are still enforced, andlogOutnow only clears the session, leaving the destination to the caller (ui.logoutRedirect).- Dependency alignment across all three apps:
jquery^4.0.0andejs^3.1.10.
Fixed
app.api.deletedropped its callback when called byformAJAX.formAJAXalways passes the serialized form as the second argument, so a DELETE-method form's callback landed in the data slot and never ran.deletenow accepts both(url, callback)and(url, data, callback).app.api.post/putreferenced an undefinedcallback2and threw when handed a non-function callback. Both are now dual-mode Promise/callback.- The login page's "reveal the card once we know you're logged out" branch threw (
Cannot read properties of null) whenever the logged-in check answered before the parser reached that element — which it always did without a stored token. It now runs on DOM ready. logInRedirecton the legacy/login/<path>form kept only the path. The OIDC provider routes an unauthenticated authorization request through/login/oauth/authorize?client_id=…&state=…; dropping the query there loses the entire authorization request. The suffix form now preserves its query string.
Added
.group-required { display: none }inpublic/css/styles.css, the base rule the shared gating model reveals against.#spa-shelldropped its inlinemargin-top;styles.cssalready sets it and the shared shell adjusts it when a banner is shown.
Verified
- Browser-verified against a full theta-env stack (sso-manager + proxy + jump-host): every top-level page renders with a clean console; nav gating is correct for admin and non-admin;
forceLogin's onboarding and group gates fire;val.jsblocks a weak password and accepts a strong one through a real form submit; the DELETE-method forms work; and the OIDC login round trip (authorize with PKCE -> login -> consent -> callback -> token fragment) completes on both OIDC clients.
1.4.0 - 2026-07-25
Bumped
This release unifies the three theta42 apps onto shared @simpleworkjs/* packages
(oidc-client, directory-schema, ldap, app-stack — published under the
simpleworkjs org at 1.0.0), replacing each app's byte-identical forks of the same
code so they share one codebase and API schema. It also fixes a security
regression in the SSO directory discovery API (OAuth client_secret_hash leaked
to every authenticated caller) and the envelope drift that broke jump-host
bridging. The shared UI chrome (top.ejs/bottom.ejs, app-base.js, val.js)
is intentionally not unified in this release — that work is deferred to a
browser-verified session; see UI_UNIFICATION_HANDOFF.md. No setup.sh change:
the new @simpleworkjs/* deps resolve from npm inside each app's image build
(npm ci stays clean; no file:/link:).
sso-manager-node 1.4.0:
Security
- The directory discovery API leaked OAuth
client_secret_hash(and any secret-ish metadata key) to every authenticated caller.Resourcedoesn't overridetoJSON, so the ORM serializedmetadatawholesale — including theclient_secret_hashstored onkind:'oauth'resources — acrossGET /api/discovery/resources,/graph,/me,/resources/:slug, and the directory-adminGET /api/directory-admin/resources. Every discovery read endpoint and the admin list now route throughprojectResource/projectResourcesfrom@simpleworkjs/directory-schema, which unconditionally strips secret keys (anything matching/secret|password|privatekey/i, includingclient_secret_hash) and, for non-directory-admins, reduces metadata to a public allowlist. Admins never receiveclient_secret_hasheither.
Fixed
- Directory discovery envelope drift.
routes/discovery.js(theautoRouter(Resource)mounted live atapp.js:87) returned bare arrays, not the{ results: [...] }envelope the directory contract specifies — so jump-host'sdata.results || []collapsed every per-group query to[]and no user could bridge. Discovery is now served by explicit/resources,/resources/:slug,/graph,/mehandlers that all return the{ results }envelope. The deadroutes/api_discovery.js(mounted atapp.js:112, after the 404 catcher) and its mount were removed. GET /api/discovery/resources?group=<cn>now returns 200 with{ results: [...] }instead of 404.
Added
@simpleworkjs/directory-schema— the directory contract: thekindenum,Resource/ResourceEdge/ResourceGroupfield defs, the{ results }envelope, the security projection (projectResource/projectResources/isDirectoryAdmin), and the discovery client.models/resource.jsimports the field defs; the discovery + directory-admin routes use the projection.@simpleworkjs/ldap—models/user_ldap.jsandmodels/group_ldap.jsnow takeescapeFilter/escapeDNandmakeClient/withClientfrom the shared package (via local wrappers that passconf); sso keeps its richUser.get/Group.get/User.login/User.addSSHkey(posix/write-side stays app-local). sso'smakeClientpasses notlsOptions, so cert validation is unchanged.@simpleworkjs/app-stack— unifiedbuild_info({buildVersion, buildHash, buildYear}) and thestatic-modulesmounting helper.utils/build_info.jsand the static-modules loop inroutes/index.jsuse the shared helpers.- New
tests/discovery.test.js(jest + supertest, runs under the docker harness): locks in the{ results }envelope on/resources,/graph,/me,/resources/:slug, the?group=200-regression, and the no-client_secret_hash/no-secret-key guarantee for every caller.
Changed
- Dependency alignment:
ldapts^8.1.2→^8.1.8. The new@simpleworkjs/*deps resolve from the npm registry (^1.0.0); nofile:/link:entries in the lockfile, sonpm ciis clean in docker builds. build_infoexport shape changed from{commit, version}to{buildVersion, buildHash, buildYear}(the shared shape used by all three apps).
proxy 1.3.0:
Added
@simpleworkjs/oidc-client— the OIDC client (session models, auth router, OIDC utils, safe-redirect, local-admin bootstrap). Deleted the localutils/oidc.js,utils/safe_redirect.js,models/oidc_state.js,models/token.js,models/auth.js,routes/auth.js;models/index.jswires the factory. The per-host SSO inroutes/host_auth.jsis unchanged but consumes the shared OIDC utils.@simpleworkjs/ldap— the ldapts client + RFC 4515/4514 escaping.@simpleworkjs/app-stack— unifiedbuild_info({buildVersion, buildHash, buildYear}) and thestatic-modulesmounting helper.utils/build_info.jsand the static-modules loop inroutes/render.jsnow use the shared helpers.
Security
- LDAP filter injection in
User.get. The user lookup built its search filter by interpolatingdata.usernameraw into(&(objectClass=inetOrgPerson)(uid=<username>)). A username containing*,(,),\, or NUL could widen or alter the filter (e.g.*→ match-all). The filter value is now passed throughescapeFilterfrom@simpleworkjs/ldap(RFC 4515 escaping).
Changed
- Dependency alignment:
model-redis^1.5→^1.6.0,ldapts^8.1.2→^8.1.8. The four new@simpleworkjs/*deps resolve from the npm registry (^1.0.0); nofile:/link:entries in the lockfile, sonpm ciis clean in docker builds. build_infoexport shape changed from{commit, version}to{buildVersion, buildHash, buildYear}(the shared shape used by all three apps). The/healthendpoint and footer now reportbuildVersion/buildHash.
jump-host 1.2.0:
Added
@simpleworkjs/oidc-client— the OIDC client (session models, auth router, OIDC utils, safe-redirect, local-admin bootstrap). Deleted the localutils/oidc.js,utils/safe_redirect.js,models/oidc_state.js,models/token.js,models/auth.js,routes/auth.js;models/index.jswires the factory and the local-admin bootstrap.@simpleworkjs/directory-schema— the sso↔jump-host directory contract.utils/access.jsnow fetches reachable hosts through the sharedcreateDirectoryClient(getResourcesByGroup).@simpleworkjs/ldap—models/user_ldap.jsis now a thin wrapper overcreateLdapClient, preserving this app's loose TLS default (rejectUnauthorized: false) and the exact export shape.@simpleworkjs/app-stack— unifiedbuild_info({buildVersion, buildHash, buildYear}) and thestatic-modulesmounting helper.build_infomoved frommodels/toutils/;routes/render.jsusesmountStaticModules.
Fixed
- Directory envelope drift was silently treated as "no reachable hosts".
utils/access.jspreviously readdata.results || [], so if the SSO directory ever returned a bare array (envelope drift) every per-group query collapsed to[]and no user could bridge. The shared client now validates the{ results }envelope on every call and treats an envelope violation as a failed group fetch rather than silently returning[].
Changed
- Dependency alignment:
ldapts^8.1.2→^8.1.8,redis^4.7→^6.1.0(the directredisdep is unused — onlymodel-redisis used, which already bringsredis^6.1.0). The new@simpleworkjs/*deps resolve from the npm registry (^1.0.0); nofile:/link:entries in the lockfile, sonpm ciis clean in docker builds. build_infoexport shape changed from{commit, version}to{buildVersion, buildHash, buildYear}(the shared shape used by all three apps). The/healthendpoint and footer now reportbuildVersion/buildHash.app-base.jsforceLogin/logInRedirectswitched to the?redirect=query-param convention (matching the server-side/login?redirect=route).
[1.3.7] - 2026-07-23
Added
- The bootstrap now provisions the jump host's web-UI SSO login when the jump host is enabled: it mints a dedicated
theta-jumpOAuth client and writes a fulloidcblock (endpoints, client id/secret, callback) plus a generated local anti-lockout admin password into./config/jump-secrets.js. Matches how the proxy's OIDC client is provisioned. An existing pre-OIDCjump-secrets.js(API token but no OIDC client) is regenerated so upgraders get SSO login. Requires jump-host ≥ v1.1.0.
[1.3.6] - 2026-07-23
Bumped
- sso-manager-node -> v1.3.2
sso-manager-node 1.3.2:
Fixed
- OAuth client management API returned
client_id: undefinedon every GET, which broke this stack's bootstrap: it lists the OAuth clients and rotates by the returnedclient_id, so it called/api/oauth/client/undefined/rotateand got a 500 — abortingsetup.shwithbootstrap failedwheneverproxy-secrets.jshad no usable secret (e.g. a fresh/rotated deployment). The ORM'stoJSON()was stripping the mappedclient_id/scopes/… fields;OAuthClient.get()now emits them explicitly (and omitsclient_secret_hash). Unknown client ids now 404 instead of 500.
[1.3.5] - 2026-07-23
Added
- Optional SSH jump host (theta42/jump-host) as a third, opt-in submodule. Enable with
CFG_JUMP_HOST_ENABLED=trueinsetup.env: setup.sh clones/tag-tracks the submodule and builds it behind thejump-hostcompose profile, the bootstrap mints a directory API token and writes./config/jump-secrets.js(LDAP admin bind so it can inject users'sshPublicKey), the jump host is registered as a proxy Host (its web UI) and seeded as a directory service. Users thenssh uid_-_host@jump.<domain>(WinSCP-friendly) orssh uid@jump.<domain>for a TUI host picker; the web UI on :3002 shows audit + metrics. Off by default — existing installs are unaffected.
[1.3.4] - 2026-07-23
Bumped
- sso-manager-node -> v1.3.1
sso-manager-node 1.3.1:
Added
- The Directory documentation (
docs/directory.md) is now surfaced: registered in-app at/docs/directory("Directory & Inventory"), help-linked from the Directory page header, and linked from the docs-site index. Extended with the shared slug conventions (site_<name>,host_<hostname>— as used by ldap-client and the theta-env seed), the automatic-registration story (theta-env stack seeding, ldap-client Linux host enrollment), and the API surface (admin at/api/directory-admin, read-only graph at/api/discovery).
Changed
- Direct LDAP binds are described as first-class, not "legacy", across README, DEPLOYMENT.md, docs, and the Dockerfile: Linux hosts are a primary consumer of the directory (PAM/SSSD login, LDAP-backed
sudoviasudoRole, SSH public keys via openssh-lpk) — exactly what the custom schemas exist for.
theta-env own changes
Added
CFG_SITE_NAMEinsetup.env(right belowCFG_DOMAIN, defaultlocal): names the SSO directory site the stack registers itself under — slugsite_<name>, matching theparentSlugconvention ldap-client-joined Linux hosts use, so they land under the same site.- The directory seed now collects real host facts on the machine (hostname, IP, MAC of the default-route interface, OS pretty-name, kernel — same collection as
ldap-client/index.sh) and registers the stack host ashost_<hostname>with that metadata, plus fills in each service's internal port and git repo (sso-manager3001,proxy3000,openldap389/636,openresty443). Existing resources from the earlier seed layout (stack-host, domain-slug site) are adopted in place — seed metadata only fills fields the operator hasn't set, never overwrites. - The bootstrap now seeds the SSO directory with the stack's own resources: a site (from the configured domain), a "Stack host", and the SSO Manager + Proxy services (with their public URLs in metadata), linking the proxy's auto-registered OAuth client under its service. Also seeds the two non-obvious services the stack runs: the OpenLDAP directory (advertising the
ldaps://endpoint Linux hosts and LDAP-native apps bind to, honoringldap.ldapsHost) and the OpenResty edge (the 80/443 data plane every hostname flows through, with a wildcardhttps://*.<domain>address). The Directory page is populated out of the box instead of starting empty. Idempotent — resources whose slug already exists are operator-owned and never touched, and a seed failure only warns (never fails a bring-up, e.g. against an older sso-manager image without/api/directory).
[1.3.3] - 2026-07-23
Bumped
- sso-manager-node -> v1.3.0 (from v1.1.18; includes the intermediate v1.2.1 release)
sso-manager-node 1.3.0:
Added
- OAuth client management API at
/api/oauth/client(groupapp_sso_oauth_admin): list, create, update, delete, and rotate-secret for OAuth clients, backed by the Resource model. Accepts form-style string inputs (newline-separatedredirect_uris/allowed_groups, space-separatedscopes). - Dockerized test suite:
docker-compose -f docker-compose.test.yml up --buildspins up OpenLDAP + Redis + a test-runner that seeds the test user and runs the full jest suite (174 tests) against them.tests/globalSetup.jshonorsREDIS_URL.
Fixed
- Completed the model-redis →
@simpleworkjs/ormport that shipped half-finished in 1.2.1:OtpToken.issue/verifycalled nonexistentfind()/listDetail()— every OTP login 500'd.- Impersonation create/revoke called nonexistent
ImpersonationToken.listDetail()— both endpoints 500'd. OAuthClientreadis_validfrom the Resource model, which has no such column — every client evaluated as disabled and all/oauth/authorizerequests were rejected with 400. Client validity now lives inmetadata(absent = valid).OAuthClient.adddidn't set the required-uniqueResource.slug; clients now get a slug derived from the client name.GET /api/token/:name/:tokenreturned{results: null}with 200 for unknown tokens (ormget()returns null instead of throwing); now 404s.
User.loginreturns a clean 401 instead of crashing when neitheruidnorusernameis supplied.- Depend on published
@simpleworkjs/orm^0.2.8 andmodel-redis^1.6.0 instead of a localfile:link that brokenpm ciin docker builds.
Changed
- Removed the Mobile Phone field from the user create/edit form.
sso-manager-node 1.2.1:
Added
- Actionable Metrics: New real-time metrics tracking for failed logins, top IPs, and service usage per user.
- LDAP Monitor: Background service to parse OpenLDAP binds over port 389 and track metrics for legacy apps.
- UI Updates: Executive dashboard now displays actionable metrics cards instead of raw logs. User profiles show individual service usage stats to admins.
- Directory Management: Integrated site/host/service abstractions into directory UI and allowed associating OAuth apps directly to services.
[1.3.2] - 2026-07-21
Bumped
- proxy -> v1.2.2
proxy:
Fixed
- Multi-target load balancing (added in 1.2.0) crashed every request to a load-balanced host:
ops/nginx_conf/targetinfo.luarequired a nonexistentresty.balancer.round_robinmodule. Thelua-resty-balancerrock actually installed providesresty.roundrobininstead, with a different constructor API. Fixedtargetinfo.luato use the real module — verified end-to-end that requests now round-robin across targets with no Lua errors.
[1.3.1] - 2026-07-21
Bumped
proxy:
Fixed
- The bootstrap anti-lockout admin account was always created as
proxyadmin2regardless ofconf.auth.adminUsers, whilemigrations/permission_bootstrap.jsgrants the global-admin permission toconf.auth.adminUsers[0]. If an operator customizedadminUsersaway from the default, the bootstrapped account and the permissioned account were two different (non-matching) usernames, so the anti-lockout account ended up with no admin access.models/user_redis.jsnow derives the bootstrap username fromconf.auth.adminUsers[0](falling back toproxyadmin2), matchingpermission_bootstrap.js. - Corrected a
secrets.js.examplecomment that claimed the bootstrap admin's password "defaults to the username itself" — it actually generates a random password printed to the container log on first boot.
Changed
- Refreshed all README screenshots (hosts, per-host SSO auth, per-host basic auth) against the current UI, and added a new load-balancing screenshot for the multi-target feature.
sso-manager-node:
Added
- N-Way Multi-Master LDAP replication:
LDAP_SERVER_ID+LDAP_REPLICATION_HOSTSconfiguresyncreplpeers in the bundled OpenLDAP, and a new/sitespage (nav: Sites) shows each configured peer's LDAP URL and live reachability. - A
locationproperty on users, editable from the profile and user-edit forms.
Fixed
/sites(added above) 500'd on every load:views/sites.ejsincluded nonexistent partialsheader/footerinstead of this app's actualtop/bottom. Fixed to match every other view.
Changed
- Refreshed all README screenshots (dashboard, users, groups, OAuth apps) against the current UI, and added a new Sites & Replication screenshot.
theta-env own changes
- Refreshed
docs/images/sso-dashboard.pnganddocs/images/proxy-hosts.pngto match the submodules' updated screenshots.
[1.1.20] - 2026-07-20
Bumped
- proxy -> v1.1.17
proxy:
Fixed
- An existing single-label subdomain host (e.g.
sso.nl.wgnode.com) could not be attached to a wildcard cert added later (e.g.*.nl.wgnode.com):Host.lookUpWildcardParent()only checked the wildcard-as-child position (the wildcard's own base domain) and missed the far more common wildcard-as-sibling case, so the edit form's "Parent Wildcard" option stayed permanently greyed out. It now checks both positions, and a regression test covers the sibling case.
[1.1.19] - 2026-07-18
Bumped
- sso-manager-node -> v1.1.17
sso-manager-node:
Added
conf.ldap.ldapsHostandconf.ldap.ldapsPortconfig options for advertising a separate, internal-only LDAPS hostname on the/integrationspage. Falls back to the public OAuth issuer host when unset.- Contextual help panel on
/integrations→ LDAP explaining why LDAPS needs a hostname, why port 636 should not be forwarded publicly, and the recommended internal-DNS / Docker-internal alternatives. - Tests for the
/integrationsroute's LDAPS URL derivation andldapsHostoverride.
Changed
nodejs/package.json/package-lock.jsonversion bumped to1.1.17.routes/index.jsnow derives the displayed LDAPS URL fromconf.ldap.ldapsHost/ldapsPortwith fallback to the OAuth issuer host.docs/configuration.md,docs/ldap.md,DEPLOYMENT.md, andsecrets.js.exampledocument the newldapsHost/ldapsPortoptions and recommended network layouts.
theta-env own changes
setup.env.exampleadds optionalCFG_LDAPS_HOSTfor the internal LDAPS hostname.setup.shpassesCFG_LDAPS_HOSTinto the generated./config/sso-secrets.jsasldap.ldapsHost.config.example/sso-secrets.js.exampledocumentsldap.ldapsHost/ldap.ldapsPort..env.exampleaddsLDAPS_HOSTfor legacy.envmigrations.docker-compose.ymlcomments warn against forwarding 636 to the public internet.README.mdexplains theCFG_LDAPS_HOSTrecommendation in the port-forwarding section.
[1.1.18] - 2026-07-18
Bumped
proxy:
Changed
- Public-release packaging: removed
"private": truefromnodejs/package.json, corrected the repository URL tohttps://github.com/theta42/proxy.git, and fixed the MITLICENSEcopyright line. - Genericized committed config defaults in
conf/base.jsandconf/development.js(example.com/localhostinstead of theta42 infrastructure). - The bootstrap
proxyadmin2account now gets a random, one-time password whenauth.localAdminPassis unset, instead of the well-known default.
Security
- Sanitized rendered docs HTML with
xssinroutes/docs.js. - The Unix socket JSON-RPC socket is now created with mode
660instead of world-writable777.
Fixed
- The global error handler no longer leaks
err.keys, stack traces, or internal details in JSON responses. DEPLOYMENT.mdanddocs/docker.mdnow correctly describe theCONF_SECRETSenv-var mechanism.
sso-manager-node:
Security
- Hardened LDAP filter and DN construction against injection in
models/group_ldap.jsandmodels/user_ldap.js. - Replaced
Math.random()-based token/UUID/OTP generation withcrypto.randomUUID()/crypto.randomInt()inmodels/token.js,models/oauth_code.js, andmodels/oauth_client.js. - Refused startup when
oauth.jwtSecretis missing or placeholder. - Sanitized rendered docs/Terms-of-Service HTML with
xssto block malicious markdown output. - Removed full-object
console.logof new-user data and reduced login error logging toname/messageonly.
Changed
- Public-release packaging: removed
"private": truefromnodejs/package.jsonand bumped version to1.1.16.
Fixed
models/email.js: fixed from-address template rendering bug.
theta-env own changes
CHANGELOG.mdnow embeds the full app-level release notes for each submodule bump, not just links..env.exampleno longer ships realistic-looking default passwords; values are clearly placeholders.config.example/*.js.examplecomments now describe the actualCONF_SECRETSenv-var loading mechanism.setup.shsummary no longer prints generated passwords to stdout; it points to./config/*.js.bootstrap/bootstrap.jsfails hard instead of falling back to weak default passwords when config is missing.
1.1.17 - 2026-07-18
Bumped
Both apps' bare-metal install.sh now installs to /opt/theta42/<app> and seeds /etc/<app>/secrets.js on first run, matching a wget -O - .../install.sh | sudo bash one-line install for both (previously proxy-only); re-running it prints the version it's updating from/to. sso-manager-node's installer was rewritten from a flag-driven, copy-based script into the same idempotent git-clone pattern proxy already used, and now bootstraps OpenLDAP itself on first run instead of requiring the repo to already be checked out locally. None of this affects the Docker/unified-stack deployment this repo orchestrates — bare-metal-only.
1.1.16 - 2026-07-18
Bumped
Both: bumped @simpleworkjs/conf to 1.2.0 and jq-repeat to 2.2.0.
Changed
./config/sso-secrets.jsand./config/proxy-secrets.jsare now loaded via each app'sCONF_SECRETSenv var (set by the entrypoint) instead of being symlinked into/app/conf/secrets.js— neither container needs write access to its ownconf/directory anymore. No change to the config file format or bind mounts; existing./config/directories keep working as-is.
1.1.15 - 2026-07-17
Bumped
proxy:
Fixed
- The host edit form's "Parent Wildcard" option stayed greyed out even when a valid wildcard actually existed for that host, so an already-created host could never be switched onto one from the edit modal (only brand-new hosts, via the field's
keyuphandler, ever saw it become available). The underlying/host/lookup/:itemcheck also had the same self-match issue as the recently-fixed backend bug: it resolved an already-existing host to its own record instead of a sibling wildcard. Added a dedicated/host/wildcard-parent/:itemendpoint that checks both directions, and the edit form now actually runs the check when it opens. - Fixed an nginx startup warning:
the "listen ... http2" directive is deprecated, use the "http2" directive instead. Migrated to the standalonehttp2 on;directive (nginx 1.25.1+).
Added
- Four new plain-language docs aimed at less technical readers, replacing the system-design-level Architecture/Installation docs as the target of most card help links: Hosts & HTTPS, DNS Providers, Users, Groups & Permissions, and API Tokens. Each links onward to the deeper technical reference for readers who want it; the technical docs link back the other way too. The personal-access-token card (previously missed entirely) now has a help link.
Fixed
- The in-app docs viewer rendered every
docs/*.mdpage with a garbled heading and a stray horizontal rule at the top — Jekyll front matter (meant only for the GitHub Pages build) was never stripped before being handed to the markdown renderer. Also fixed: cross-doc links never resolved in-app, since this viewer serves docs at/docs/<slug>with no.htmlsuffix — they're now rewritten to the correct in-app URL (by registered slug, falling back to the doc's real filename), the same way image paths already were.
sso-manager-node:
Added
- Three new plain-language docs aimed at less technical readers, replacing the schema-level LDAP/OAuth/API docs as the target of most card help links: Accounts, Groups & Managers, Connecting Apps (SSO), and API Tokens. Each links onward to the deeper technical reference for readers who want it; the technical docs link back the other way too. The personal-access-token card (previously missed) now links to its own doc.
Fixed
- The in-app docs viewer rendered every
docs/*.mdpage with a garbled heading and a stray horizontal rule at the top — Jekyll front matter (meant only for the GitHub Pages build) was never stripped before being handed to the markdown renderer. Also fixed: cross-doc links (ldap.html,index.html, etc.) never resolved in-app, since this viewer serves docs at/docs/<slug>with no.htmlsuffix — they're now rewritten to the correct in-app URL, the same way image paths already were. - The new concept docs' cross-links (
concepts-accounts.htmletc.) are the correct, working URL on the Jekyll/GitHub Pages build (where the page's URL is its filename stem) but didn't resolve in the in-app docs viewer, which serves docs at a separate short slug (/docs/accounts). The in-app renderer now also resolves a doc's real filename as a fallback, so one link written in a doc works on both targets.
1.1.14 - 2026-07-17
Bumped
Both: moved the help (❓) link out of the global header and onto each relevant card individually, so it deep-links straight to the doc that actually covers that card instead of one generic per-page guess.
1.1.13 - 2026-07-17
Bumped
Both: added a help icon (❓) in the top-right header that deep-links to the doc most relevant to the current page, and made the in-app docs viewer (/docs) searchable (a simple line-substring search over the local doc set, no new dependency, still works with no internet access).
1.1.12 - 2026-07-17
Bumped
- proxy -> v1.1.9
proxy:
Added
- The host list now shows who created each host, and when.
- Plain (non-wildcard) hosts can now be renamed after creation — the hostname field is no longer permanently locked. Wildcard hosts, wildcard children, and auto-created subdomain cache entries stay locked, since other records reference them by name.
- More inline help text on the host create/edit form (Target SSL, wildcard matching behavior).
Fixed
- The host create/edit modal's tabs could overflow awkwardly on narrow (mobile) screens — they now scroll horizontally instead.
- Fixed a bug in the vendored
model-redislibrary's record-rename path: renaming a record's primary key while anotheralways-type field (e.g.updated_on) is defined earlier in the schema left a stray, incomplete hash behind under the old key, making that name permanently unavailable for reuse. Worked around inHost.prototype.update().
1.1.11 - 2026-07-17
Bumped
- proxy -> v1.1.8
proxy:
Fixed
- Couldn't attach an existing host to a parent wildcard. The host edit form's "Parent Wildcard" option submitted correctly, but
Host.prototype.update()had nochallengeTypehandling at all (onlyHost.create()did) — selecting it and saving silently did nothing. Added the same wildcard-parent lookup toupdate(). - Couldn't register a wildcard's own base domain as a host. A wildcard cert's
altNamesalready cover both the base domain and*.base domain, but the lookup tree stores the wildcard one level below its base domain, and a lookup for the bare base domain landed on that empty parent node and found nothing — even though the already-issued cert covers it.buildLookUpObj()now also stamps the parent node so this resolves correctly, without re-issuing or duplicating the cert.
1.1.10 - 2026-07-17
Bumped
- sso-manager-node -> v1.1.9
sso-manager-node:
Added
- Every account's personal Unix group (its primary GID holder) can now have supplementary members managed from the account's profile page ("Members of
<uid>'s group", admin-only) — e.g. to share write access to files owned by that group. Uses the standardmemberUidattribute (RFC 2307posixGroup).
1.1.9 - 2026-07-17
Bumped
- sso-manager-node -> v1.1.8
sso-manager-node:
Added
- Group membership is now editable directly from a user's profile page ("My groups" -- add via a group-name picker, remove with a button per row), instead of only from each group's own card on the Groups page. Admin-only, using the existing per-group member add/remove endpoints.
Fixed
- The Edit Profile form's Mobile Phone field had a stray
validate=":9"making it effectively required (submission was blocked with "Please fix the form errors" if left blank) -- it was always meant to be optional, matching the "Add user" form. Removed. - A service account's profile always showed
Name: Service Account-- every service account has the same literal filler given/last name (a schema-satisfying placeholder, not meant to be shown), making them indistinguishable by name. The Name line is now hidden for service accounts. - The Users page's Service Accounts tab, and a freshly-created service account's own profile, could appear empty/not-a-service-account for up to 5 minutes right after creation. Creating a user caches it via
User.get()before the route handler marks it as a service account (group membership), so the cached copy hadisServiceAccountstuck wrong until the cache TTL expired. Now cleared and re-fetched immediately after marking. - A user belonging to exactly one LDAP group had their
memberOfattribute returned as a bare string instead of a one-element array (ldapts's normal behavior for single-valued attributes) -- client-side permission checks (for(let group of user.memberOf)) would then iterate the DN character-by-character instead of once, causing pages gated on that group (e.g. Groups) to incorrectly show "You do not have permission to be here." NormalizedmemberOfto always be an array, same fix already applied tomanager.
1.1.8 - 2026-07-17
Bumped
- sso-manager-node -> v1.1.7
sso-manager-node:
Changed
- Service accounts unified to one kind. Removed the LDAP bind-only service account type (the Integrations → LDAP "Service Accounts" card, and its
/api/service-accountroutes) -- every service account is now a real Unix/POSIX account with a UID, created from the new Users → Service Accounts tab. Email and password are both optional for service accounts; a blank password means nouserPasswordis set at all (the account simply can't bind). - Added a
managerfield to every account. Multi-valued (a list of usernames), defaults to whoever created the account (the admin who added it, or whoever sent the invite), and reassignable from the account's Edit form. Anyone listed as a manager can edit that account -- same fields an admin can (mobile, description, SSH key, date of birth, home directory, login shell, manager list) -- without needingapp_sso_admin. homeDirectoryandloginShellare now editable from the Edit Profile form (previously view-only).
1.1.7 - 2026-07-16
Bumped
Both: redesigned the GitHub Pages docs site to match each app's own look (dark navbar/footer, Bootstrap 5, Font Awesome) instead of the generic jekyll-theme-cayman theme, added a real cross-page nav, SEO (jekyll-seo-tag + jekyll-sitemap), and mobile-responsive layout. theta-env's own docs site got the same treatment in this release too (see below).
Changed
- theta-env's own docs site redesigned the same way -- dark navbar/footer using the shared theta42 logo (this repo has no app UI of its own), cross-page nav, SEO, mobile-responsive.
docs/index.md's "More docs" section removed (redundant with the new nav). - Added
docs/_siteto.gitignore(missing entirely before).
1.1.6 - 2026-07-16
Bumped
- proxy -> v1.1.6
proxy: Hosts admin UI's Authentication tab radios (Off / Basic / SSO) had no shared name, so clicking one didn't uncheck the others. Added name="auth_mode" to restore standard exclusive radio-group behavior.
1.1.5 - 2026-07-16
Bumped
Both: bumped jq-repeat 2.0.1 -> 2.1.0. proxy fixed real breakage from the removed __setPut/__setTake API (insert/remove row hooks in the admin UI); sso-manager-node fixed a stale-data flash in the edit-profile flow caused by update()'s new throttling.
1.1.4 - 2026-07-16
Added
- White-label support in both proxy and sso-manager-node --
<title>, navbar brand, and logo are now conf-driven (conf.name/conf.logo) instead of hardcoded. Closes proxy#45 and sso-manager-node#6.
Fixed
- sso-manager-node: the bundled default LDAP ppolicy had
pwdLockout: FALSE, silently making "deactivate user" not actually block login. Fixed, with a drift-correction path for already-deployed instances.
Bumped
1.1.3 - 2026-07-16
Added
CHANGELOG.md(this file). Closes #43.
Bumped
1.1.2 - 2026-07-16
Changed
docs/index.md(the published site's home page) never linked toarchitecture.md,quickstart.md, orstandalone.md— added a "More docs" section so they're reachable from the site instead of only by direct URL.
Bumped
1.1.1 - 2026-07-16
Changed
setup.shnow pinsproxyandsso-manager-nodeto their latest release tag (vX.Y.Z) instead of the tip ofmaster. A rebuild now always lands on a tagged, versioned release of each app rather than whatever was most recently merged upstream.
Bumped
1.1.0 - 2026-07-16
First tagged release. Establishes the vX.Y.Z tag convention going forward.
Added
setup.shnow reports which submodules actually moved to a newer commit during an update, instead of updating silently.