Skip to content

server

v3.0.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 8d Alerting & Incidents
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

api cloud free-software go gotify hosting
+5 more
javascript notifications privacy react self-hosted

Affected surfaces

auth rbac breaking_upgrade

Summary

AI summary

Updates https://gotify.net/docs/oidc, https://gotify.net/docs/session-elevation, and https://gotify.net/docs/testing-master across a mixed release.

Full changelog

Notable features:

  • Add OIDC login support. See OIDC Docs (#433 via #941, #977, #982, #1003)
    • Thanks to @KovachVL and @alanturing881 for reporting security issues for this feature.
  • Add session elevation for sensitive actions in the web UI. Session Elevation Docs (GHSA-3hcj-9m7p-wwm9, #944 via #952, #954).
  • Automatically delete inactive clients/sessions (#943 via #959)

Breaking changes:

  • The config.yml file is no longer supported, convert it to the new env format with migrate-config.
  • If you set list or map environment variables, their syntax changed, see List and map syntax.
  • API tokens are no longer returned in the GET endpoints and are only exposed on creation or rotation. See Tokens are only shown once.
  • If you have scripts hitting client-token endpoints, they may now need elevation.
  • The paging.next URL in message list responses is now a relative path. See Paging next URL is relative.

Miscellaneous changes:

  • Rework configuration (#366, #392 via #967)
  • Don't store tokens in plain text (#325 via #971 by @eternal-flame-AD)
  • Publish a gotify/server:master docker image for testing unreleased changes. Docs: Testing master (#953, #956)
  • Allow sending messages with a client token (#964)
  • Allow refreshing application tokens (#985 via #986 by @eternal-flame-AD)
  • Increase token keyspace to >128 bits (#936 via #939 by @eternal-flame-AD)
  • Switch logging to zerolog (#962)
  • Add OCI labels to docker images (#924 via #927 by @eternal-flame-AD)
  • Use use HTTP-only session cookies instead of local storage for UI sessions (#941)
  • Add createdAt to users, clients, applications and plugins (#959)
  • Add a CLI with gotify serve, gotify version and gotify migrate-config commands (#967)
  • Fix Messenger plugins that are added after init (#653 via #998 by @TowyTowy)
  • Update dependencies

Breaking Changes

  • Removed `config.yml` file support; must migrate to new env format with `migrate-config` command.
  • Environment variable list/map syntax changed; see updated docs for correct usage.
  • API tokens are no longer returned in GET endpoints; exposed only on creation or rotation.
  • Paging.next URL in message list responses is now a relative path.

Security Fixes

  • GHSA-3hcj-9m7p-wwm9 – Session elevation hardens sensitive actions against unauthorized access.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track server

Get notified when new releases ship.

Sign up free

About server

A simple server for sending and receiving messages in real-time per WebSocket. (Includes a sleek web-ui)

All releases →

Related context

Beta — feedback welcome: [email protected]