Releases: cryptomator/hub
1.4.6
What's Changed
- Show admin section of Hub when Keycloak version is not available (#361)
- Updated Keycloak to 26.4.1
- Updated to Quarkus 3.20.3 LTS
Recommended actions for the 1.4.6 Update
We highly recommend updating Keycloak to version 26.4.1.
You can skip this step if you created your realm with script version 8 or above. If not:
Keycloak starting in version 26.4.0 does not expose it's version by default to non-master realm admins. To be able to see the version of Keycloak again in Hub, please execute the following:
- Open Keycloak
- Select Clients
- Select
realm-management - In
Rolescreate a role with the nameview-system - Select the
cryptomatorhub-systemclient - Under
Service Account Roleassign the createdview-systemclient role to this client
Now you can wait until the cryptomatorhub-system refreshes its token or you restart Hub (by default within a few minutes), then you will see again the Keycloak version e.g. in the Admin section of Hub.
Full Changelog: 1.4.5...1.4.6
1.4.5
What's Changed
- Fix Session Expiration Not Enforced in Cryptomator Hub Web Client (GHSA-69fp-wc9g-5778)
All instances must be updated as soon as possible to address a security vulnerability.
Full Changelog: 1.4.4...1.4.5
1.4.4
What's Changed
- Added Breadcrumb Navigation #345
- Added unsaved changes notice with undo in the WOT settings #346
- Added support for regionalized translations #350
- Added Latvian, Portuguese (Brazil), Russian, Ukrainian and Chinese (Taiwan) translation #350
- Updated Keycloak to 26.3.2
- Updated to Quarkus 3.20.2 LTS
Full Changelog: 1.4.3...1.4.4
1.4.3
What's Changed
- Fix health check in Docker Compose by adding curl to native images (#344)
- Bump dependencies
Full Changelog: 1.4.2...1.4.3
1.4.2
1.4.1
1.4.0
What's Changed
Added
- This CHANGELOG file
- WoT: Users will now have an ECDH as well as ECDSA key (#282)
- WoT: Users can now mutually verify their identity, hardening Hub against injection of malicious public keys (#281)
- WoT: Admins can adjust WoT parameters (#297)
- Permission to create new vaults can now be controlled via the
create-vaultsrole in Keycloak (#206) - Preserver user locale setting (#313)
- New log event entries: UserAccountReset, UserKeysChange and UserSetupCodeChange (#310)
- Audit log filter by event type (#312)
- Show last IP address and last vault access timestamp of devices in user profile (#320)
- Dutch, French, Italian, Korean, Portuguese and Turkish translation
- Added provenance attestation for our container images (#322)
- Show legacy devices in user profile (#331)
- Show direct member count of groups in vault details (#329)
Changed
- Updated Keycloak to 26.1.5
- Updated to Java 21 (#272)
- Updated to Quarkus 3.15.4 LTS
- Updated to Tailwind CSS 4
- Updated to Vite 6
- Reduced number of transitive dependencies
- Bumped build time dependencies
- Migrated remaining commonjs modules in frontend build to ESM (#291)
- Memoize infrequently changing data, reducing XHR roundtrips
- Switched to JWK thumbprint format in user profile
- Switched to Repository Pattern (#273)
- Redesigned Admin Panel (#308)
- Enhanced audit log VaultKeyRetrievedEvent, contains now IP address and device ID (#320)
- Migrate syncer user to cryptomatorhub-system client (#336)
Fixed
- Fixed incorrect ARIA roles improving accessibility
- Fixed incorrect
Content-Typeheader for/api/vaults/{vaultId}/access-token(#284) - Show legacy device name in audit log (#331)
- Added "Browser Language" option to language selection dropdown, enabling users to revert to browser default language (#324)
Required actions for the 1.4.0 Update
1. Migrate to System OIDC Client
Perform the following steps during the update for #336:
cat << 'EOF' > partial-realm-import.json
{
"users": [
{
"username": "system",
"email": "system@localhost",
"enabled": true,
"serviceAccountClientId": "cryptomatorhub-system",
"clientRoles": {
"realm-management": [
"realm-admin"
]
},
"attributes": {
"picture": ""
}
}
],
"clients": [
{
"clientId": "cryptomatorhub-system",
"name": "Cryptomator Hub System",
"clientAuthenticatorType": "client-secret",
"standardFlowEnabled": false,
"serviceAccountsEnabled": true,
"publicClient": false,
"enabled": true,
"secret": "TODO"
}
],
"roles": {
"realm": [
{
"name": "create-vaults",
"description": "Can create vaults",
"composite": false
}
]
}
}
EOF
In Keycloak
- Set
secretinpartial-realm-import.jsonto a secure value - Partially import the
partial-realm-import.jsonrealm (make sure you select user, client and role) - Remove the
synceruser andsyncerrole
In the deployment
- Remove
HUB_KEYCLOAK_SYNCER_USERNAME,HUB_KEYCLOAK_SYNCER_PASSWORDandHUB_KEYCLOAK_SYNCER_CLIENT_ID - Add
HUB_KEYCLOAK_SYSTEM_CLIENT_IDwith valuecryptomatorhub-system - Add
HUB_KEYCLOAK_SYSTEM_CLIENT_SECRETwith thesecretvalue of yourpartial-realm-import.json
2. Vault Creation Permissions
Starting with version 1.4.0, only users with the admin role can create vaults by default.
If you migrate from an earlier version of Hub you need to configure the create-vaults role behaviour to your needs:
To use the new default bahaviour
- Log in to Keycloak with
adminprivileges. - Navigate to Realm Roles > admin > Assign Role.
- Select and apply the
create-vaultsrole.
To restore the pre-1.4.0 behavior where all users can create vaults follow the steps above but use the user role instead of the admin role.
Recommended Steps for the 1.4.0 Update
1. Allow Proxy Address Forwarding
If Hub is running behind a reverse proxy, make sure to apply QUARKUS_HTTP_PROXY_PROXY_ADDRESS_FORWARDING: true to the deployment file (required for #320).
2. Update Keycloak to 26.0.5
We highly recommend updating Keycloak to version 26.0.5. Prior to the update, please verify the following changes:
-
Health Check URL Update
Modify the Keycloak health check URL as follows:
- http://localhost:8080/health/live + http://localhost:9000/health/live
-
Environment Variable Adjustments
Update the Keycloak environment variables to the following values:
- KC_HOSTNAME: keycloak_url - KC_PROXY: edge + KC_HOSTNAME: https://keycloak_url + KC_PROXY_HEADERS: xforwarded
Important Considerations after the 1.4.0 Update
Optional configuration of Web of Trust parameters. See https://docs.cryptomator.org/hub/admin/#hub-admin-wot for more information on this topic.
Full Changelog: 1.3.4...1.4.0
1.4.0-rc3
What's Changed
- Migrate syncer user to cryptomatorhub-system client (#336)
- Updated to Quarkus 3.15.4 LTS
Important Considerations for the 1.4.0-rc3 Update
Perform the following steps during the update for #336:
cat << 'EOF' > partial-realm-import.json
{
"users":[
{
"username": "system",
"email": "system@localhost",
"enabled": true,
"serviceAccountClientId": "cryptomatorhub-system",
"clientRoles" : {
"realm-management" : [ "realm-admin" ]
},
"attributes": {
"picture": ""
}
}
],
"clients":[
{
"clientId": "cryptomatorhub-system",
"name": "Cryptomator Hub System",
"clientAuthenticatorType": "client-secret",
"standardFlowEnabled": false,
"serviceAccountsEnabled": true,
"publicClient": false,
"enabled": true,
"secret": "TODO"
}
]
}
EOF
In Keycloak
- Set
secretinpartial-realm-import.jsonto a secure value - Partially import the
partial-realm-import.jsonrealm (make sure you select user and client) - Remove the
synceruser andsyncerrole
In the deployment
- Remove
HUB_KEYCLOAK_SYNCER_USERNAME,HUB_KEYCLOAK_SYNCER_PASSWORDandHUB_KEYCLOAK_SYNCER_CLIENT_ID - Add
HUB_KEYCLOAK_SYSTEM_CLIENT_IDwith valuecryptomatorhub-system - Add
HUB_KEYCLOAK_SYSTEM_CLIENT_SECRETwith thesecretvalue of yourpartial-realm-import.json
Full Changelog: 1.4.0-rc2...1.4.0-rc3
1.4.0-rc2
What's Changed
- Show direct member count of groups in vault details (#329)
- Added "Browser Language" option to language selection dropdown, enabling users to revert to browser default language (#324)
- Reload device lists upon device removal
- Added pointer cursor to device remove "button" text
- Show device only when available in audit log vault key retrieve event
Full Changelog: 1.4.0-rc1...1.4.0-rc2