Skip to content

The One File

v4.1.4 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ack-diagram air-gapped break-glass browser-based disaster-recovery documentation
+12 more
encrypted homelab-network html5 network-diagram network-topology offline-first-single-file oidc self self-hosted sso web-crypto zero-dependency

Affected surfaces

auth rbac crypto_tls

Summary

AI summary

Broad release touches Demos, https://github.com/jbr1989, https://github.com/gelatinescreams/The-One-File/issues/44, and https://github.com/gelatinescreams/The-One-File/issues/43.

Full changelog

Version 4.1.4 /\ 3-4-26 : Testers finding the stragglers. Thank you to everyone!

  • Added custom port label logic to the canvas that allows port labels to find the next blank space automatically. (this is v1 and will likely be upgraded). Thanks to jbr1989 #44

  • Fixed an issue where port maps were not showing on the canvas. Thanks to jbr1989 #44

  • Fixed an issue where port maps were not displaying correctly in b&w print preview. Thanks to jbr1989 #44

  • Added version number to the bottom of settings modal for better versioning and TheOneFile_Verse tracking Thanks to jbr1989 #43

  • Core Edition

    • Fixed an issue where connections dropdown were not displaying correctly in node and rack information panel(s)

TheOneFile_Verse /\ 1.8.0 3-4-26 : Added a few settings, fixed some bugs, annoyances, security and production friendly hierarchical structure

Now that most of the core TheOneFile_Verse development is done, I have begun breaking the code into a more production friendly hierarchical structure. This will be completed by 2.0 Stable.

  • New admin settings.

    • Added admin setting to set room themes as default. Custom themes from imported versions will also be able to set as default. Thanks to ahmaddxb #45
    • Added admin setting to show hide admin login link on homepage
    • Added admin setting to force welcome modal to all users even if custom data present
  • Changes + Bug Fixes

    • Fixed an issue where custom styles were not being applied after leaving the room
    • Changed QR code library to local library
    • Changed crypto.randomUUID() to oidc.generateSecureToken(32) for room ID creation
    • Backup code login as fallback (single use)
    • Password required to disable 2FA
    • AES 256 GCM encrypted secret and backup code storage
    • Removed all remaining innerHTML references
    • XSS audit passed
    • Added futher error logging to docker logs
    • Tons of security + performance fixes
  • OIDC Fixes

    • Fixed an admin promotion issue when OIDC is the first user registered
  • Redis Fixes

    • Changed Redis KEYS to SCAN.
    • Added redis.conf with safe limits
  • Docker Fixes

    • Added docker resource limits to default compose file

Download

the-one-file.html
theonefile-networkening.html

Demos

Security Fixes

  • Removed all innerHTML references, passed XSS audit, AES‑256‑GCM encrypted secret/backup code storage, added password requirement to disable 2FA, switched QR library to local version, replaced crypto.randomUUID() with oidc.generateSecureToken(32) for room IDs

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track The One File

Get notified when new releases ship.

Sign up free

About The One File

Visualization and mapping platform

All releases →

Related context

Beta — feedback welcome: [email protected]