This release includes 1 security fix for security teams reviewing exposed deployments.
Published 8d
Alerting & Incidents
✓ No known CVEs patched
This release patches 1 known CVE
Topics
api
cloud
free-software
go
gotify
hosting
+5 more
javascript
notifications
privacy
react
self-hosted
Affected surfaces
auth
rbac
breaking_upgrade
Summary
AI summaryUpdates https://gotify.net/docs/oidc, https://gotify.net/docs/session-elevation, and https://gotify.net/docs/testing-master across a mixed release.
Full changelog
Notable features:
- Add OIDC login support. See OIDC Docs (#433 via #941, #977, #982, #1003)
- Thanks to @KovachVL and @alanturing881 for reporting security issues for this feature.
- Add session elevation for sensitive actions in the web UI. Session Elevation Docs (GHSA-3hcj-9m7p-wwm9, #944 via #952, #954).
- Automatically delete inactive clients/sessions (#943 via #959)
Breaking changes:
- The
config.ymlfile is no longer supported, convert it to the new env format withmigrate-config. - If you set list or map environment variables, their syntax changed, see List and map syntax.
- API tokens are no longer returned in the GET endpoints and are only exposed on creation or rotation. See Tokens are only shown once.
- If you have scripts hitting client-token endpoints, they may now need elevation.
- The paging.next URL in message list responses is now a relative path. See Paging next URL is relative.
Miscellaneous changes:
- Rework configuration (#366, #392 via #967)
- Don't store tokens in plain text (#325 via #971 by @eternal-flame-AD)
- Publish a
gotify/server:masterdocker image for testing unreleased changes. Docs: Testing master (#953, #956) - Allow sending messages with a client token (#964)
- Allow refreshing application tokens (#985 via #986 by @eternal-flame-AD)
- Increase token keyspace to >128 bits (#936 via #939 by @eternal-flame-AD)
- Switch logging to zerolog (#962)
- Add OCI labels to docker images (#924 via #927 by @eternal-flame-AD)
- Use use HTTP-only session cookies instead of local storage for UI sessions (#941)
- Add
createdAtto users, clients, applications and plugins (#959) - Add a CLI with
gotify serve,gotify versionandgotify migrate-configcommands (#967) - Fix Messenger plugins that are added after init (#653 via #998 by @TowyTowy)
- Update dependencies
Breaking Changes
- Removed `config.yml` file support; must migrate to new env format with `migrate-config` command.
- Environment variable list/map syntax changed; see updated docs for correct usage.
- API tokens are no longer returned in GET endpoints; exposed only on creation or rotation.
- Paging.next URL in message list responses is now a relative path.
Security Fixes
- GHSA-3hcj-9m7p-wwm9 – Session elevation hardens sensitive actions against unauthorized access.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About server
A simple server for sending and receiving messages in real-time per WebSocket. (Includes a sleek web-ui)
Related context
Related tools
Beta — feedback welcome: [email protected]