12 KiB
12 KiB
Changelog
v0.5.2 Guacamole logout/recovery follow-up
- Fixed an over-aggressive Guacamole browser helper which treated every Guacamole
loggedOutstate as an explicit user logout. - Explicit clicks on Guacamole logout actions still perform full SessionGuard/Pocket ID RP-initiated logout.
- Guacamole-only token loss (for example after a worker restart/failover) now preserves the SessionGuard/Pocket ID session and re-enters Guacamole through header authentication.
v0.5.2 PKCE / logout hotfix
- Added PKCE S256 (
code_challenge/code_verifier) to both SessionGuard OIDC authorization-code flows. - Fixed the Go 1.22+ ServeMux root route conflict by registering
GET /{$}. - Added RP-initiated logout for the primary Director/Admin OIDC flow using the discovered
end_session_endpoint. - Guacamole access logout now sends
client_idon every end-session request andid_token_hintwhen available. - Added
oidc.logout_redirect_urland documented Pocket ID Logout Callback URL requirements.
0.5.2 — Public EdgeGuard security layer
- Added
sessionguard-edgeguard, a dependency-free Go edge pre-check for the public Caddy host. - Static IPv4/IPv6/CIDR blacklist with automatic reload.
- Global and per-IP token-bucket rate limiting plus endpoint-specific OIDC/login limits.
- NAT-safe defaults: ordinary rate-limit hits do not automatically ban a shared public address.
- Scanner/exploit path detection and persistent temporary auto-bans for clearly hostile behavior.
- Bounded per-IP state table prevents rotating-source floods from causing unbounded memory growth; ban persistence is write-debounced to avoid I/O amplification.
- Blocks CONNECT/TRACE/TRACK, validates allowed public hosts and rejects malformed/oversized URIs.
- Local
/healthzand Prometheus-style/metricsendpoints for EdgeGuard. - Added hardened public Caddy deployment: strict SNI/Host matching, 10s header timeout, 64 KiB header ceiling, HTTP/1.1+HTTP/2 only and conservative response security headers.
- Caddy admin API is disabled on the dedicated edge; access logs use bounded file rotation and high-load sampling to reduce log-amplification risk.
- Public-VPS example pins Caddy 2.11.4 instead of an unqualified major tag.
- Public Caddy now hides SessionGuard
/metricsand broker endpoints; Guacamole workers continue to use broker APIs directly over NetBird. - Added a dedicated
Dockerfile.edgeguard, public-VPS Compose stack and CI image publication. - No Master/Agent protocol or database migration; Agent protocol remains version 4.
0.5.1 — Modal-first responsive Web UI
- Master-WebUI neu strukturiert: Terminalserver öffnen in einem großen responsiven Arbeitsdialog statt in einer langen Inline-Detailspalte.
- Serverdetails sind in Tabs für Übersicht, Sitzungen, Apps/Prozesse, Profile/Ereignisse und Konfiguration gegliedert.
- Farms und Published Resources werden als kompakte Karten dargestellt; Anlegen/Bearbeiten erfolgt in eigenen Modals.
- Resource-Editor behält RemoteApp-/Agent-Managed-Felder und dynamische Sichtbarkeit vollständig bei.
- Agent-WebUI bündelt RemoteApps, Profil-Pipeline und Aktivitätslog in einer tab-basierten Betriebsansicht.
- Lokale Agent-Policy wird in einem responsiven Modal bearbeitet und zeigt einen sichtbaren Dirty-State; die Übersichtsseite zeigt nur eine kompakte Policy-Zusammenfassung.
- Mobile Modals wechseln auf Vollbild, Tabellen bleiben horizontal scrollbar, Formulare reduzieren sich responsiv auf eine Spalte.
- Live-Refresh/Dirty-Guards bleiben erhalten; offene Policy-Eingaben werden weiterhin nicht vom 5-Sekunden-Refresh überschrieben.
- Keine neue Runtime oder Build-Chain: weiterhin ausschließlich eingebettetes HTML/CSS/Vanilla-JavaScript.
- Agent-Protokoll bleibt Version 4; keine Datenbank- oder API-Migration erforderlich.
0.5.0 — Integrated Guacamole Access Auth
- SessionGuard Master now provides
/auth/verifyas a Traefik ForwardAuth endpoint for Guacamole. - Added a dedicated PocketID/OIDC
access_authflow, independent from the Master administration login. - Added opaque server-side access sessions persisted in the existing control-plane store; only the SHA-256 browser-token hash is used as the lookup key.
- Added strict
X-Guacamole-Useremission only for valid access sessions, group restrictions and allowed return-host validation. - Added RP-initiated OIDC logout using the discovered
end_session_endpoint. - Added OIDC Back-Channel Logout with signature/issuer/audience/event/
iat/jtivalidation and replay protection. - Added concurrent-safe per-flow OIDC state cookies and external-prefix-aware callback cookie paths.
- Guacamole extension now ships a framework-free JS helper which redirects Guacamole logout into full SessionGuard/PocketID logout and periodically detects revoked/expired access sessions.
- Added Traefik header-scrubbing/ForwardAuth deployment guidance and migration away from
traefik-forward-auth. - Agent protocol remains version 4; no Agent data/schema migration is required.
0.4.1 — RemoteApp PowerShell/CLIXML robustness
- RemoteApp PowerShell execution now keeps stderr separate from JSON stdout.
- Suppresses PowerShell progress/information/verbose/debug/warning streams for machine-readable RemoteApp calls.
- Forces UTF-8 console output where supported.
- JSON decoder defensively extracts the first valid JSON object/array and tolerates CLIXML/banner noise before or after the payload.
- Added regression tests for the
#< CLIXMLcontamination observed on Windows PowerShell 5.1. - Protocol remains version 4; no Master/Agent schema migration is required.
0.4.0 — Agent-managed RemoteApps
- Added a farm-scoped RemoteApp desired-state model to Published Resources.
- Windows Agent discovers RemoteApps through
root\CIMv2\TerminalServices/Win32_TSPublishedApplication. - Optional Agent-managed publication creates/updates aliases, executable/icon settings and command-line policy through the Terminal Services WMI provider.
- Reconciliation deletes only aliases originally created by SessionGuard; pre-existing/manual RemoteApps remain in place if management is later disabled.
- Agent heartbeat reports per-app executable, publication, ownership, sync and error state.
- Managed RemoteApps are brokered fail-closed per host until the Agent reports
published + path_exists + in_sync. - Master WebUI now exposes application path, alias, icon, command-line policy and per-farm readiness.
- Agent WebUI now includes a RemoteApps inventory/status view.
- Protocol version increased from 3 to 4; Master and Agent must be upgraded together.
- No Node.js/npm/frontend framework or build step introduced.
0.3.4 — Modern Web UI
- Master- und Agent-WebUI vollständig modernisiert, weiterhin ohne Framework oder Build-Schritt.
- Responsive Sidebar-Navigation mit Mobile-Menü und Scroll-Tracking.
- Dark-/Light-Theme mit lokaler Browser-Präferenz.
- Neue Dashboard-Karten, Panel-Hierarchie, Status-Badges, moderne Formulare/Switches und Tabellen.
- Live-Bereiche und Editoren bleiben weiterhin getrennt; automatische Refreshes überschreiben keine Eingaben.
- Verbesserte Darstellung für Farms, Broker, Published Resources, Director, Alerts, Audit und lokale Agent-Ansichten.
- Keine neue Runtime-Abhängigkeit: HTML/CSS/Vanilla-JavaScript bleiben direkt in den Go-Binaries eingebettet.
0.3.3
- Fix: Master-WebUI definiert und aktualisiert
agentCache, bevor die Farm-Mitglieder berechnet werden. - Behebt
ReferenceError: agentCache is not definedin der Farm-/Broker-Ansicht. - Die Farm-Agent-Anzahl verwendet weiterhin dieselbe Membership-Logik wie der Broker (
farm.agent_ids,agent.farm_ids,required_tags).
0.3.2
- Fixed Farm member count in the Master WebUI. The table now uses the same membership rules as the broker: explicit
farm.agent_ids, agent-sideagent.farm_ids, andrequired_tags. - Farm member names are available as a tooltip on the member count.
0.3.1 - Web UI editor stability
- Fixed Master live refresh replacing Farm, Resource and server-control forms every five seconds.
- Split live server metrics from editable server-control fields.
- Farm and Resource editors are mounted once; only their data tables and broker leases refresh.
- Added explicit reset/reload actions instead of implicit form replacement.
- Added Agent policy dirty-state protection and visible "Ungespeicherte Änderungen" state.
- Added explicit Agent policy reload with confirmation before discarding unsaved edits.
- Added
Cache-Control: no-store, max-age=0for the Web UI HTML and JavaScript. - Added browser-level regression verification covering a full live-refresh cycle.
0.3.0 - Broker & Director production candidate
Broker and farm control
- Added logical Farms with explicit agent IDs, agent-side farm IDs and required-tag membership.
- Added Published Resources for desktop and RemoteApp mappings.
- Added health-aware broker with existing-session reconnect preference, leases and configurable global single-session behavior.
- Added strict farm isolation and fail-closed unknown/disabled-farm handling.
- Added
online,drain, andmaintenanceserver modes. - Added
restart_when_drainedworkflow. - Added broker-specific API key and
/api/v1/broker/resolve//api/v1/broker/tokensAPIs. - Added Guacamole 1.6 extension using token injection instead of database rewriting.
Director
- Added WTS logon/connect/last-input and client-address telemetry where available.
- Added idle-time calculation and persistent disconnect timestamps.
- Added Windows process inventory per user session and process termination command.
- Added CPU, RAM and system-disk telemetry.
- Added RDP-listener/profile-store health checks and composite health score.
- Added indexed session history and observed logon/restore timing.
- Added configurable threshold alerts and generic webhook notifications.
- Extended Master UI with health, session/process control, logon telemetry, farms, resources, leases, alerts and policy rollback.
Enterprise control plane
- Added PostgreSQL production persistence and single-active-master advisory-lock protection.
- Split append-only audit/session history into indexed tables while keeping small control-plane state in JSONB.
- Added group-to-role RBAC.
- Added policy versioning/rollback for global, farm and agent policies.
- Added environment-secret overrides for database, enrollment, broker, OIDC and webhook credentials.
- Added hardened Docker deployment example.
- Added bounded agent telemetry/process heartbeat payloads.
- Bound queued process-termination commands to the observed RDS session and revalidated PID/session ownership before termination.
Fixes/hardening
- Farm policies now also apply to centrally selected members (
agent_ids/ required tags), not only agents with explicit localfarm_ids. - Broker never reuses an existing session from a different requested farm.
- Drain hosts are reconnect-only; maintenance hosts are excluded from both reconnect and new placement.
- Broker resources cannot silently fall through to a disabled/unknown farm.
0.2.0 - Profile & Session Lifecycle
- Added selected-folder profile backup/restore with transactional snapshot activation and history retention.
- Added backup-before-cleanup gating and retries.
- Added disconnected-session timeout with native WTS logoff and the same backup/cleanup pipeline.
- Added master queued session control and result audit.
- Added Windows service session-change wakeups.
- Added Prometheus metrics and profile/session operation documentation.
0.1.1
- Fixed Master editor refresh overwriting in-progress form input.
- Added persistent Dry-Run/activity log to local and Master UI.
- Added structured Templates editor and heartbeat transfer of active policy.
0.1.0
- Initial Windows Agent / Linux Master MVP with WTS inventory, delayed profile cleanup, templates, PocketID/OIDC and master-agent heartbeats.