- ALLOW_PURGE is now false by default; the UI shows a banner when there is
no authentication.
- Read-only role: AUTH_VIEWER_USER/AUTH_VIEWER_PASS in local mode, or
OIDC_ADMIN_GROUP in OIDC mode; changes get 403 and the admin settings
are greyed out.
- Content-Security-Policy (inline scripts allowed by hash) and other
security headers; cross-site changes are refused.
- Syslog TCP: at most SYSLOG_TCP_MAX_CONNS connections, closed after
SYSLOG_TCP_IDLE of silence; HTTP idle timeout.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The local mode now shows a login page in the colors of the UI (light/dark theme, FR/EN)
with a signed session cookie and the log out button, like the OIDC mode. LOGIN_LOGO shows
a PNG mounted in the container on that page. SESSION_TTL applies to both modes
(OIDC_SESSION_TTL still works). HTTP Basic credentials are still accepted for scripts.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
AUTH_MODE=local keeps the HTTP Basic authentication (unchanged default);
AUTH_MODE=oidc logs in through an OpenID Connect provider with the
authorization code flow and PKCE, standard library only: discovery,
ID token signature (RS/PS/ES) and claims checks, signed session cookie
whose key is kept in DATA_DIR. The UI gets a log out button and reloads
into the login when the session ends.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>