DC-023: operational fixes — DNS, rate limiter, version sync
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled

- VERSION: bump from 1.14.4 to 1.14.6 to match package.json (HEAD had stale value)
- middleware.js: apply existing totpLimiter (10/15min) to /totp/setup endpoint
  (was previously unmetered, allowing secret enumeration)
- dashcaddy-update.sh: hook post-deploy-patches.sh into the update flow
  so the container can survive transitions between broken → fixed tarballs
- start.sh: add --add-host flags for get.dashcaddy.net and get2.dashcaddy.net
  so the container can resolve the release server (was failing with ENOTFOUND)
This commit is contained in:
Krystie
2026-07-01 03:10:53 -07:00
parent e73bfbb0a1
commit a5f51e4a0c
4 changed files with 23 additions and 1 deletions
@@ -473,6 +473,11 @@ module.exports = function configureMiddleware(app, {
});
app.use('/api/v1/totp/verify', totpLimiter);
app.use('/api/v1/totp/verify-setup', totpLimiter);
// /totp/setup was previously unmetered — an attacker could enumerate
// secrets or DoS the QR generator. Apply the same 10/15min limit as the
// other TOTP endpoints. The standardHeaders config above emits
// RateLimit-Limit / RateLimit-Remaining for clients to see.
app.use('/api/v1/totp/setup', totpLimiter);
// ── Audit logging middleware (logs non-GET API requests) ──
app.use(auditLogger.middleware());