Added
runwisp tui --urlconnects to a remote daemon over HTTP. Attach the TUI to a daemon on another host or in a container — it logs in with the daemon’s password (no--passwordflag; prompted without echo or read fromRUNWISP_PASSWORD, then cached) and “Open Web UI” works against it too. See the TUI tour.- HTTPS by default off loopback. Binding beyond
127.0.0.1now self-signs a certificate and serves TLS automatically — no setup, no proxy required; the CLI/TUI pin the cert on first use and the startup log prints its fingerprint. Bring your own cert withtls_cert/tls_key, or opt out withtls = "off". See[daemon].
Changed
- Restart a running service in one click. A running service now shows a direct Restart button (alongside Stop) instead of only revealing it after a stop — restarting is one confirmed action, not stop-then-restart. See Web UI tour.
- Selecting a run scrolls its row into view. Opening a run from a deep link or the detail panel now brings its row on screen in the (virtualized) run list, so the highlight is always visible; an already-visible selection doesn’t move. See Web UI tour.
- Login hardened with PBKDF2. The password challenge-response now derives its answer with PBKDF2-HMAC-SHA256 (600,000 rounds) instead of a single hash, making a captured login transcript far costlier to brute-force offline. See Auth.
- Auth rate limiting keys off the real TCP peer. The per-IP throttle on the login endpoints ignores client-supplied
X-Forwarded-For/X-Real-IPheaders, so it can’t be sidestepped by rotating them; real client IPs behind a configured trusted proxy (RUNWISP_TRUST_PROXY) are still honored. See Auth. - HTTP-task SSRF guard covers Alibaba Cloud and Oracle Cloud metadata. Alongside private, loopback, and link-local targets (including the
169.254.169.254metadata IP shared by AWS/Azure/GCP), the guard now also rejects100.100.100.200and192.0.0.192, which sit in otherwise-routable ranges. See HTTP tasks. - Session key derivation is as costly as the login itself. The JWT signing key is now derived from the password with PBKDF2-HMAC-SHA256 (600,000 rounds) instead of a single fast hash, so a captured session token is no cheaper to brute-force offline than a login transcript — closing a shortcut around the login’s PBKDF2 hardening on TLS-less deployments. Upgrading rotates the key, so existing browser sessions must log in once more. See Auth.
- Launch-ticket redirect rejects backslash open-redirects. The optional post-login
redirecttarget now drops paths containing a backslash (e.g./\evil.com), which browsers normalize into a scheme-relative//evil.com; only genuine same-origin paths are honored. - A running execution’s duration ticks every second. The “Ran for” readout in the Web UI run detail now counts up live while a run is in-flight (optimistic, client-side) and freezes at the wall-clock total when it ends, instead of only updating on the next event. See Web UI tour.
- Web UI is push-driven, over one SSE connection shared across all tabs. A single
/api/streamfeed (run lifecycle, system samples, config-staleness, notifications) replaces timer polling and the stream-per-concern model; an elected leader tab holds the one connection and rebroadcasts to the rest, so any number of open tabs can’t exhaust the browser’s per-origin connection limit. If live updates ever do stall, the UI flags it (“Updates paused”) and recovers on its own.
- v1.5.1 latest
- v1.5.0
- v1.4.0
- v1.3.1
- v1.3.0
- v1.2.0
- v1.1.0
- v1.0.1
- v1.0.0
- v0.16.4 pre
- v0.16.3 pre
- v0.16.2 pre
- v0.16.1 pre
- v0.16.0 pre
- v0.15.1 pre
- v0.15.0 pre
- v0.14.0 pre
- v0.13.2 pre
- v0.13.1 pre
- v0.13.0 pre
- v0.12.0 pre
- v0.11.0 pre
- v0.10.0 pre
- v0.9.0 pre
- v0.8.0 pre
- v0.7.0 pre
- v0.6.0 pre
- v0.5.0 pre
- v0.4.0 pre
- v0.3.0 pre
- v0.2.0 pre
- v0.1.2 pre
- v0.1.0 pre