Aarnav Tale
b3c0c1c691
fix(agent): always spawn agent with pre-auth key and auto-approve
...
- Generate a fresh pre-auth key for every agent startup
- Preserve existing tailscale state to avoid creating a new host
- Auto-approve pending auth requests via /api/v1/auth/approve
- Show approval link in settings UI as fallback
Closes HP-558
2026-07-13 11:00:43 -04:00
Tommy Nevtelen
fb73181cba
fix: treat Go pseudo-versions as unknown server versions ( #590 )
...
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
2026-07-12 18:18:21 -04:00
Aarnav Tale
948cfad58c
fix: handle registration keys on headscale 0.29+
...
Closes HP-555.
2026-07-04 00:07:53 -04:00
Aarnav Tale
12cee9763e
fix(ui): stop split DNS from crashing the page when undefined
...
Closes HP-548.
2026-06-22 20:23:40 -04:00
Aarnav Tale
0439175e73
feat(auth): support role sync on re-login
2026-06-22 16:40:29 -04:00
Aarnav Tale
a3cd8444a3
chore(auth): add more informative logs
2026-06-22 16:40:29 -04:00
Aarnav Tale
10055541cc
feat(config): simplify required headscale config
2026-06-22 16:40:29 -04:00
Aarnav Tale
dc32427cff
feat(config): use minimal headscale config
2026-06-22 16:40:28 -04:00
Aarnav Tale
e29221e5f7
feat: add support for headscale 0.29+
2026-06-20 18:03:14 -04:00
Aarnav Tale
846c030bc1
chore: update to react router v8
2026-06-20 13:33:24 -04:00
Aarnav Tale
5d6eef5843
feat: update to the v8 middleware api
2026-06-20 12:38:09 -04:00
Aarnav Tale
0c4d175eb7
feat(auth): support deriving roles from the IDP
...
Closes HP-352.
2026-06-20 11:53:09 -04:00
Aarnav Tale
96f2721272
feat(auth): support reverse-proxy driven proxy auth
...
Closes HP-353.
2026-06-20 11:41:44 -04:00
Aarnav Tale
3252482e0b
feat: switch logging to pino
...
Closes HP-279
2026-06-17 15:58:48 -04:00
Aarnav Tale
21806caa05
fix(oidc): correctly handle client_secret_basic fallback
2026-06-17 11:13:46 -04:00
Aarnav Tale
2f3a440de5
fix: auto read dns.extra_records_path instead of making it required
...
Closes HP-538
2026-06-17 11:11:20 -04:00
Aarnav Tale
e74e0d4542
fix: don't require postgres pass when password_file is supplied
...
Closes HP-528
2026-06-17 11:09:12 -04:00
Aarnav Tale
62817efa6e
feat: gate the healthcheck listen file to docker only
2026-05-30 20:46:32 -04:00
Aarnav Tale
b95d601ff6
feat: automate health check with a written file
2026-05-30 20:45:15 -04:00
Aarnav Tale
ea27c846e2
feat: add support for https
2026-05-30 19:39:02 -04:00
Aarnav Tale
d7f1d665a4
feat: bump headscale minimum to 0.27
2026-05-30 17:32:00 -04:00
Aarnav Tale
7901f37002
fix: correctly handle user id passthrough on headscale actions
2026-05-30 17:14:28 -04:00
Aarnav Tale
56c5e5ac8c
feat: make api calls more resilient and stuff
2026-05-25 17:14:26 -04:00
Aarnav Tale
0512565f8e
feat: replace openapi hashing system with /version
...
Apparently I didn't use my brain cells and rely on the /version
endpoint that Headscale has exposed since 0.26 (our lowest supported
version). Switching to that significantly simplifies the API surface.
2026-05-25 11:51:02 -04:00
Aarnav Tale
d4eee702e9
refactor(server): replace AppContext undefined sentinels with Feature<T>
...
Co-authored-by: Amp <amp@ampcode.com >
Amp-Thread-ID: https://ampcode.com/threads/T-019e5550-4435-7118-8393-cdcc97042178
2026-05-23 16:56:34 -04:00
Aarnav Tale
1e0ff7ead6
fix: encode headscale rename path segments
...
(cherry picked from commit 623e7c03f1 )
2026-05-14 13:47:04 -04:00
Aarnav Tale
deb284e2b4
feat: ditch hono
2026-04-26 23:52:49 -04:00
Aarnav Tale
5a2098eea5
chore: format everything with oxfmt
2026-04-26 20:38:45 -04:00
Aarnav Tale
b961b339bb
feat: add support for OIDC logouts
...
Closes HP-407.
2026-04-26 20:36:52 -04:00
croatialu
9e5e5a613a
fix: harden OIDC weak RSA fallback
2026-04-22 00:07:47 +08:00
croatialu
d110dd2bcb
feat: add OIDC subject claim fallbacks
2026-04-16 18:07:57 +08:00
croatialu
addef55f30
Add weak RSA OIDC verification fallback
2026-04-16 18:04:48 +08:00
Aarnav Tale
0f19fdf0da
feat: rebuild browser ssh from the ground up
2026-04-09 21:56:42 -04:00
Aarnav Tale
10278d0cc9
fix: correctly expire pre-auth-keys in 0.28.0+
2026-04-07 00:24:50 -04:00
Aarnav Tale
43cff2f4b7
feat: i guess we're undoing agent work
2026-04-06 21:19:27 -04:00
Aarnav Tale
61e7303363
fix: handle URI components in provider ID
2026-04-06 21:19:27 -04:00
Aarnav Tale
4b47b1bbed
chore: update auth-service to not be class based
2026-04-03 16:57:39 -04:00
Aarnav Tale
1259642f8a
feat: replace openid-client with clean-room oidc system
2026-04-03 16:36:27 -04:00
Aarnav Tale
4cd0c1e206
fix: use headscale.api_key where possible
2026-04-03 16:34:50 -04:00
Aarnav Tale
73b5d5514e
fix: don't nuke agent working dir
2026-03-30 14:02:39 -04:00
Aarnav Tale
838a2cd732
fix: store profile picture in db to prevent header overload
2026-03-30 13:58:29 -04:00
Aarnav Tale
ee59a2d06d
feat: switch agent to a periodic dump rather than long running process
2026-03-27 13:32:59 -04:00
Aarnav Tale
2c57187628
feat: switch to a generalized api key config
2026-03-27 13:32:59 -04:00
Aarnav Tale
5f81822366
feat: correct package.json dependencies and remove libsql
2026-03-17 13:31:35 -04:00
Aarnav Tale
b1361e9062
feat: upgrade to node 24 and drizzle
2026-03-17 13:22:48 -04:00
Aarnav Tale
8f6fe05c83
fix: actually fix type errors
2026-03-16 23:41:09 -04:00
Aarnav Tale
25dc09e025
perf: switch to SSE dispatched changes
...
Previously we would use naive revalidators which would invalidate EVERY
SINGLE action loader every 3 seconds, resulting in several fetches. It
would also bubble fetches across the layout actions into the individual
pages.
This new approach selectively has live stores of resources which then
poll for changes on the server side and then dispatches updates to the
client via a new /events/live SSE endpoint.
2026-03-16 23:32:06 -04:00
Mathias Rangger
0741567754
fix: validate required Docker API version
2026-03-15 02:08:07 +01:00
Aarnav Tale
a26faab139
feat: add ownership transfer support
2026-03-14 15:17:45 -04:00
Aarnav Tale
e255407115
feat: redo user page to match account linking
2026-03-14 14:56:04 -04:00