• v0.4.0 74cbcfe15f

    Redetzke released this 2026-10-05 06:10:24 +00:00 | 2 commits to main since this release

    Security fixes for API tokens and sign-in, and a new Health card.

    Changes

    • API tokens no longer manage accounts: a full-access token could create a user or reset a password, sign in as that user and so reach backups and two-step sign-in. Users, passwords, API tokens and the "require two-step sign-in" setting now need a signed-in user in the web interface; tokens get HTTP 403 there. Tokens still manage peers, the server, app settings and logs.
    • Sign-in can no longer run the server out of memory: every password check takes 64 MiB, and nothing limited how many ran at once. At most two now run at the same time; when 16 sign-ins are already waiting, more get HTTP 429. A sign-in attempt counts toward the lockout before its password is checked, so parallel attempts can't get past it, and IPv6 addresses are locked out by /64.
    • New Health card: the public IPv4 and IPv6 addresses lead the card, and every other check is a tile with a plain-word status, the raw setting and, when it fails, what is wrong.
    • Dialogs stay visible with password managers: extensions such as Bitwarden that rearrange the page could make a confirmation dialog seem to vanish.
    • Peer names in the peers table are plain text instead of underlined links.

    Update

    Copy the binary for your server to it and run, as root:

    chmod +x GHOSTWIRE-v0.4.0-linux-amd64
    sudo ./GHOSTWIRE-v0.4.0-linux-amd64 update
    

    Update the iOS app too. Its user, password and API token screens moved to the web interface, and older app builds can't open Settings against v0.4.0. For a new installation, use install instead of update; see the README.

    Files

    File For
    GHOSTWIRE-v0.4.0-linux-amd64 64-bit x86 servers
    GHOSTWIRE-v0.4.0-linux-arm64 64-bit ARM, e.g. Raspberry Pi OS 64-bit
    GHOSTWIRE-v0.4.0-linux-armv7 Raspberry Pi OS 32-bit
    SHA256SUMS checksums: shasum -a 256 -c SHA256SUMS
    Downloads