Picked up the four 'Still Open' standardization items from the audit doc
as Option B work. Audited each before starting implementation:
DC-013 (config schema migration) — src/config/migrations.js exists with
a versioned migration system (CURRENT_VERSION=2, v1 dns normalization,
v2 dns.provider field), loadAndMigrate() writes back to disk only when
version changes, called from src/config/site.js on every startup.
Guarded by 21 tests in __tests__/config-migrations.test.js.
DC-014 (monitoring endpoint opt-in) — MONITORING_PUBLIC env var +
config.monitoring.public both work via an IIFE in
src/utilities/middleware.js line 297. Routes are conditionally public
based on the flag. Default is 'true' for back-compat with existing
dashboards that pre-load widget data. Flipping the default to 'false'
is a fresh change with a real UX cost.
DC-015 (CSRF token path duplication) — grep confirms only
/api/v1/csrf-token exists. /api/v1/auth/csrf-token was never
implemented or was already cleaned up.
DC-016 (per-call fetchT timeouts) — src/utils/http.js defines
fetchT(url, opts, timeoutMs) with AbortSignal.timeout() in the
native branch and explicit timeout handlers in the http/https
raw-request branches. 5s default covers most calls; 8 of 77 sites
pass explicit overrides. 5min global request timeout is the backstop.
All four tasks reassigned from krystie → hermes because the work shifted
from 'implement' to 'verify and document'. No code changes in this commit
— only BACKLOG.md and CHANGELOG.md updated to reflect actual state.
This commit is the meta-example for Pitfall 20 (just added to the
standardization pitfalls reference): audit docs decay as fast as fixes
land. Always audit before implementing.
15 KiB
15 KiB
Changelog
All notable changes to DashCaddy are documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
Unreleased
Security
- TOTP recovery system (4-part defense against permanent lockout). Pre-lockout:
.bakfallback credentials file checked at every TOTP init, used silently when primary fails. Diagnostic:/recovery-infoendpoint +/recovery-panelUI on the entry screen with one-click "Import Backup" + "Download Backup" buttons. Post-lockout: friction-free.license-secretrestore flow. (d230b39,3dff49c,7bbd969)
Added
- Kubernetes-standard health probe aliases (DC-012). Added
/healthzand/readyzas root-level aliases for/health/liveand/health/readyso fresh users can copy-pastehealthcheck:blocks from k8s/Docker docs. Liveness (/healthz) is a pure process check — no I/O. Readiness (/readyz) checks the config file, services file, Docker daemon, and Caddy admin API (3s timeout each), returning 200 if all OK or 503 with achecksobject detailing failures. Both endpoints are unauthenticated by design (orchestration tooling doesn't carry session cookies). Probe endpoints also bypass CSRF validation and are excluded from per-request logging so k8s polling every 10s doesn't flood the audit log. Added__tests__/health-probe-aliases.test.js(19 tests) — covers alias equivalence, the removed/api/v1/healthreturning 404, and a source-of-truth sync test that detects drift betweensrc/app.jsmount list andsrc/utilities/middleware.jsallowlist. README and user-guide updated with copy-pastedocker-compose.ymland Kubernetes probe blocks. Also: audited the cross-platform standardization doc's "What's Still Open" section — all four items previously listed as remaining work (config schema migration, monitoring endpoint opt-in, CSRF path duplication, per-call fetchT timeouts) were already implemented in earlier v1.13.x audit passes but never marked done. Doc updated with pointers and Pitfall 20 added ("Audit Doc Lists Items That Are Already Done") so future agents don't redo the work. - OpenClaw routes — full set under
/openclawprefix: connect, disconnect, status, host discovery.docker.clientwrapper fixed; duplicate/apps/paths stripped across sub-routers. - Auto-backup scheduling (premium tier) + storage-limit enforcement (prune oldest when
maxStorageBytesexceeded) + restore-from-backup on update rollback. Bundled workflows included out-of-the-box. - Monitoring widget on main dashboard — CPU/mem data flattened, health summary added;
/api/monitoring/statsexposed as a public route with rate-limit. - Sami Files template — logPath wired into the template and mounted in
start.sh. - Unified logger — single source of truth for logs, errors, and audit events.
- Notification manager + resource alerting (premium tier).
- Update UX — badge→modal flow, orange update button, "Update All", toast notifications, workflow triggers.
- Comprehensive test suite additions: 7 new test files (
dns-propagation,notification-manager,ssl-monitor,log-digest,metrics,config-drift-detector,auto-restart-manager) — 120 new tests, all passing.
Changed
- Route response standardization (DC-010). Every
{success, ...}envelope across 9 route files now flows throughresponse-helpers(success()/ok()). Only 2 intentional raw-array calls remain (routes/services.jslines 360+368 — frontend wire contract). Error-path envelopes useerror()separately. ~62 calls converted acrossbrowse/logs/sites/updates/notifications/tailscale/events/workflows/openclaw/dns/health/ca. /api/v1/versioning: all routes mounted under/api/v1/. Legacy un-versioned/api/mount removed. Frontend, OpenAPI spec, DashCA pages, and all internal path matchers (CSRF exclusions, auth public routes, audit log, rate-limit mounts) updated.scripts/release.shnow stages build-rewritten files (sw.js,index.html) for the published tarball, copiesVERSIONinto the tarball, and writes bothdashcaddy-api/package.jsonAND rootVERSIONon every release. No more version drift.
Fixed
- Credential route path regression (DC-011).
routes/services.jshad dropped the/services/prefix from credential routes (POST/DELETE/GET) during a refactor, causing 4 test failures and a live 404. Re-applied the prefix; also fixed a latentReferenceErrorwhere invalid serviceIds calledctx.errorResponse()in a factory-destructured module (replaced with the importederrorResponsehelper). - 19 ESLint warnings (DC-004). Reached zero warnings across
src/— most cleared by the refactor, the final 3 (require-awaitonresyncHealthChecker, twomax-depthviolations) fixed insrc/app.js. - Workflow engine init broken —
fetchTnot imported,NotificationManagerconstructor missingnew,servicesStateManagernot hoisted. Fixed; events now fire on startup. - Container-logs feature was misusing
wireModal— short-circuited the rest offeatures.jsand broke unrelated dashboard features. Replaced with the correct wiring. - CSP hash mismatch between Windows and Linux builds — now computed on LF-normalized
index.htmlso hashes are identical across platforms. - SW cache tag now derived from bundle content hash, so the service worker invalidates correctly when bundle content changes.
- Updater false-positive loop when commit hash was unknown — fixed.
Removed
- Dead
/api/v1/health,/api/v1/health/live,/api/v1/health/readyroutes (DC-012) — these were registered inPUBLIC_ROUTESand CSRF exclusion lists but never actually mounted on the apiRouter. Consolidated to root-level/health,/health/live,/health/readyplus new/healthzand/readyzaliases. Anyone probing/api/v1/healthwill now get a clean 404 instead of an unexpected behaviour. - Stale ad-hoc test/debug scripts (
comprehensive-test.js,test-security-fixes.js) moved todashcaddy-api/scripts/legacy/(preserved, not deleted — 875 lines of security test coverage retained as a manual smoke test). - Stale root-level files:
*.bak,server-old.js, and ad-hoc reports (DEPLOYMENT-SUCCESS.md,FINAL-DEPLOYMENT-REPORT.md,DESLOPIFICATION-ROADMAP.md, etc.) — disk-only cleanup, already gitignored. - Dead
routes/directory at API root (replaced bysrc/routes/).
Security (TOTP integration)
- TOTP integration tests now cover the full
/api/auth/check→ session → endpoint flow (DC-006). 25 new tests including:setup(generate + normalize + reject invalid Base32),verify-setup(missing/bad/no-pending/valid-code paths),verifylogin (400/400/401/200),check-session(passthrough when disabled + 401 no-session + 200 valid-session),disable,config(valid/invalid/never-disables), and full end-to-end setup→login→check-session→disable.
Fixed (from merge)
- routes/updates.js — krystie's branch had
if (!ok)referencing the helper function instead of thesecretOkboolean. Would have 500'd every/system/update-notifyrequest. Caught during merge, kept my version with the correct boolean check. - routes/notifications.js — two places where she replaced
res.json({success: result.success, ...})withok(...)would have forcedsuccess: truefor partial-failure delivery. Kept my version with explicitres.jsonto preserve the semantic.
[1.13.4] - 2026-06-12
Changed
- Standardized all route handler responses to use helpers from
src/utils/responses.js(ok,errorResponse,successMessage,notFound,validationError,forbidden,unauthorized,conflict). ~160 rawres.json()calls converted across 32+ files. No behavior changes — response shapes are identical. This ensures future schema changes (e.g., adding arequestIdenvelope) only need to update one module. - Fixed
errorvserrorResponsesignature mismatch inroutes/health.jsCA cert endpoint. Theerrorhelper takes(res, message, statusCode)whileerrorResponsetakes(res, statusCode, message, extras)— the wrong alias was being used for calls that needed the 4-argument form. - Updated
middleware.js,csrf-protection.js,error-handler.js, andlicense-manager.jsto use response helpers for rejection/error responses instead of inlineres.status().json().
Note
- 4 pre-existing test failures in
services.routes.test.js(credential storage) remain from before this release. They are unrelated to the standardization pass.
1.5.0 - 2026-05-17
Changed (BREAKING)
- API routes now mounted exclusively under
/api/v1/. The legacy un-versioned/api/mount has been removed. Frontend, OpenAPI spec, DashCA pages, and all internal path matchers (CSRF exclusions, auth public routes, audit log, rate-limit mounts) updated accordingly. Existing integrations that hit/api/...directly must update to/api/v1/.... Held at minor bump (1.5.0) rather than major (2.0.0) — DashCaddy is still pre-1.0-API-stable.
Added
LICENSE(proprietary EULA) at repo root.CHANGELOG.md(this file) — Keep a Changelog format.- Gitea Actions workflow (.gitea/workflows/ci.yml)
that runs
npm test(with coverage) andnpm run linton every push tomain/masterand on PRs, plus asecurityjob runningnpm auditand the security-focused test subset.
Fixed
- 9 pre-existing
no-emptyESLint errors inbackup-manager.jsandroutes/backups.js(intentional ignore-failure catches now annotated).
Removed
- Stale files at repo root:
*.bak,server-old.js, and ad-hoc deployment/migration/test reports (DEPLOYMENT-SUCCESS.md,FINAL-DEPLOYMENT-REPORT.md,DESLOPIFICATION-ROADMAP.md,error-handling-*.md,WHAT-IS-DASHCADDY.md, etc.). Already gitignored — disk-only cleanup.
1.4.10 - 2026-05-17
Fixed
release.shnow stages build-rewritten files (sw.js,index.html) so they're included in the published tarball.
1.4.9 - 2026-05-17
Fixed
- Container-logs feature was misusing
wireModal, which short-circuited the rest offeatures.jsand broke unrelated dashboard features.
1.4.8 - 2026-05-17
Fixed
- CSP hash now computed on LF-normalized
index.htmlso Windows and Linux builds produce identical hashes.
1.4.7 - 2026-05-17
Fixed
- Dashboard unbroken: corrected bundle order, closed dangling IIFE, removed
duplicate
constdeclaration.
1.4.6 - 2026-05-17
Fixed
sw.jscache tag now derived from bundle content hash, so service worker invalidates correctly when bundle content changes.
1.4.5 - 2026-05-17
Fixed
- Frontend deploy routed through the host-side updater (matches the API container's own update path).
1.4.4 - 2026-05-16
Fixed
notifyendpoint exempted from CSRF (it's called by the host-side updater, not the browser).release.shJSON parsing made portable (no longer assumes GNUjqsemantics on every host).
1.4.3 - 2026-05-16
Added
- Seamless release flow: push-notify endpoint, VERSION file copy into release tarball, robust SSH mirror handling on port 22022.
1.4.2 - 2026-05-16
1.4.1 - 2026-05-16
Changed
- Version bump only — packaging plumbing for the 1.4.x release line.
1.4.0 - 2026-05-06
Added
scripts/release.sh— one-command release cutting and publishing.
1.3.1 - 2026-05-06
Fixed
- Installer: added
src/directory to the deploy manifest; droppedMakeDirectory=yesfrom the systemd updater path unit. - Self-updater: copies
src/, replacesroutes/in place instead of nesting it inside the existing tree.
1.3.0 - 2026-05-06
Added
- Self-updater supports
DASHCADDY_API_SOURCE_DIRenv override for non-standard deploy layouts.
Fixed
- Self-updater now clears all pending history entries, not just one.
1.2.0 - 2026-05-14
Added
- Container Log Viewer with streaming, search, and download.
- Service filter, batch operations across multiple services, and snapshot capture.
- Auto CSP hash updates during build.
- Dashboard version button and self-update UI wiring.
- Release policy checks and dashboard version verification.
Changed
- All routine
console.logcalls gated behindwindow.DASHCADDY_DEBUGflag for quieter production output. - All
console.errorcalls routed throughErrorHandlerfor consistent tracking.
Fixed
- Updater no longer triggers a false-positive "update available" loop when commit hash is unknown.
1.1.5 - 2026-03-23
Added
- Pylon health relay for remote service health checks (with relay
fallback on
/probe/:id). - Host-side auto-updater for zero-touch API container rebuilds.
Fixed
- Service edit preserves service ID on subdomain change; accepts
localhostas a valid IP. - Taxi theme accent color now distinct from text.
- Prevents encryption key conflicts; adds license backup on rotation.
1.1.1 - 2026-03-23
Fixed
- Service edit, CSRF token stability, and license restore.
[1.0.x] - 2026-03-05 → 2026-03-22
Initial release line. Highlights from work between v1.0 and v1.1:
Added
- Cross-platform path support (Windows + Linux deployments).
- Subdirectory routing mode for public-domain deployments.
- Auto-update system for DashCaddy instances.
- Batched status endpoint (frontend performance).
- Install-wide onboarding tour (no longer per-browser).
- Daily log digest and Docker hygiene/maintenance.
- Unified backup/restore v2.0 with full state capture.
- DNS uptime bars and fully-dynamic DNS server config.
Changed
- Phase 1-3 refactor: extracted config/context/utils into
src/, split monolithicserver.js, standardized all 25+ route files with explicit dependency injection. - Unified error handling system (throw-based, migrated 25 route files).
- ESLint + Prettier baseline with auto-fixes.
Security
- 7 critical + 16 high/medium API security bugs fixed.
- 7 frontend security vulnerabilities fixed (4 critical, 3 high).
- Logger sanitization to prevent log injection.
Tests
- Comprehensive test suite reaching 80%+ coverage threshold.
docker-securitytest suite (41 tests).auth-managerandcredential-managertest suites.
1.0.0 - 2026-03-05
Initial release of DashCaddy. Unified dashboard for Docker container management, Caddy reverse proxy configuration, DNS automation, and SSL certificate provisioning.