Changelog
New features, improvements, security fixes, and bug fixes, newest first.
A security fix for the audit log
Version 0.7.1 ·
Audit entries about token abuse now record an address that nobody can fake.
Security fixes
-
Token-abuse audit entries record an address that cannot be faked low
The audit log took the address from a header that any client can set. Someone probing stolen agent tokens could therefore write any address they liked into the rows that record the probing. Those entries now use the address our proxy sets. A fake address is worse than none, because it sends a defender after an address the attacker chose.