NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #857 by repository stars
Last release 4 days ago
05 Oct 2026
Ships unpredictably
gaps range from 8 days to 11 months
Rarely documented
notes for 12 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
5 years old
194 releases · first in 2022
One column per quarter.
Nothing published for this version
caddy-security v1.4.0 adds optional cross-device portal login and typed custom claims in authorization policies. It also incorporates go-authcrunch's
Released October 5, 2026.
caddy-security v1.4.0 adds optional cross-device portal login and typed custom
claims in authorization policies. It also incorporates go-authcrunch's fix for
unconditional ACL rules and upgrades Caddy to v2.11.7.
These notes cover caddy-security v1.3.0 → v1.4.0 and the bundled go-authcrunch
update from v1.3.8 → v1.3.11, including changes in v1.3.9 and v1.3.10.
caddy-security changes
enable cross-device login and disable cross-device login. Users can requestcookie cross-device session id name <name> directive customizes its browseracl fieldtype string and type string list, work with existing ACL rules andmatch any transforms with token refresh, portal OIDC providers, and Systemgo-authcrunch changes included in this release
match any and default allow/deny rules now executeexp. This fixes skipped default-denyDependency updates
| Component | Previous | v1.4.0 |
|---|---|---|
| go-authcrunch | v1.3.8 | v1.3.11 |
| Caddy | v2.11.4 | v2.11.7 |
| CertMagic | v0.25.4 | v0.25.6 |
| tested | v1.0.2 | v1.1.0 |
Upgrade notes
acl default deny overrides an earlierallow stop when a successful rule shouldFull changes: caddy-security v1.3.0…v1.4.0
and go-authcrunch v1.3.8…v1.3.11.
github.com/greenpau/go-authcrunch was updated from v1.3.8 to v1.3.11.
Compare: greenpau/go-authcrunch@v1.3.8...v1.3.11
Nothing published for this version
This release adds an option to keep users signed in across Caddy restarts, makes it possible to protect applications with direct OAuth sign-in, and gi
This release adds an option to keep users signed in across Caddy restarts, makes
it possible to protect applications with direct OAuth sign-in, and gives
administrators more control over GitHub access rules, password hashing, and log
noise. It also fixes login return URLs and includes security improvements from
the underlying AuthCrunch library.
Keep login state across restarts. The new optional state block saves
authentication state to a private directory. With the same storage, public
address, and compatible configuration, completed sessions can survive a Caddy
restart, so users do not have to sign in again just because the service
restarted. This includes generated signing keys, refresh sessions, and OpenID
Connect sessions and grants. Logout and token-reuse protections also survive
restarts. Session expiration still applies, and unfinished sign-ins must start
again. Persistence remains disabled unless you configure it.
Sign in through an external provider without a separate portal. An
authorization policy can now use an OAuth identity provider directly. Users
visiting a protected application are sent to the provider to sign in and then
returned to the application. You can configure this without creating an
authentication portal, local user database, or JWT signing keys. The policy
manages the application's session and logout, and checks its access rules on
each request. This mode suits applications that need provider sign-in without
the portal's profile pages, local MFA, or user transforms. Sessions have a
fixed lifetime; they do not automatically renew through the provider.
Control GitHub access using account IDs and organizations. Portal user
transforms can now match a GitHub account's numeric ID or organization
membership, using exact matches or regular expressions. An ID-based rule
continues to identify the same person if they rename their GitHub account.
You can combine an ID and an organization requirement in one rule before
assigning a role. Organization matching requires user_org_filters on the
GitHub provider and uses the public memberships returned by its lookup;
private memberships are not discovered by this feature.
Generate Argon2id password hashes. The local password generator now
supports Argon2id, with configurable memory, iteration, and parallelism
settings. Run
authcrunch security local generate password hash --algorithm argon2
to enter a password privately and receive a ready-to-use Caddyfile password
directive. This release also adds integration coverage for importing Argon2id
hashes and using them through browser, JSON, and Basic login. Bcrypt remains
the default, existing passwords are not automatically converted, and API keys
continue to use bcrypt.
Reduce repetitive authentication logs. A new logging block inside
security lets you suppress selected AuthCrunch diagnostic messages using
exact text, partial text, prefixes, suffixes, or regular expressions. This
helps reduce expected noise, such as selected missing-token diagnostics,
while keeping other messages visible. Filtering affects logging only;
access decisions stay the same. These rules do not filter Caddy's independent
authentication-middleware logger or access logs.
Return users to the correct application after login. The HTTP/3 login
redirect fix preserves the application's full return address instead of
sometimes reducing it to a path. This matters when the login portal and
application use different hostnames. Regression coverage checks browser login
over HTTP/1.1, HTTP/2, and HTTP/3, including paths and query strings.
Security and reliability improvements. The AuthCrunch dependency moves
from v1.3.4 to v1.3.8. Its changes add stricter validation and size limits for
OAuth provider responses, improve handling of malformed identity data, harden
redirect construction, and escape untrusted content in registration emails
and portal status messages. Portal HTML pages now block framing to protect
against clickjacking. Management APIs reject oversized requests, and malformed
SSO certificates or keys produce startup errors instead of crashes. Password
configuration errors also avoid echoing credential values.
When upgrading, account for these configuration and deployment changes:
Persistence requires a stop/start deployment. Once persistent state is
enabled, stop Caddy completely before starting its replacement. Overlapping
reloads are rejected, and only one running instance may own the directory.
Use a private directory on a durable local Unix filesystem; Windows,
network filesystems, and sharing the directory between active replicas are
unsupported. Local user databases must also be file-backed. First enabling
persistence does not import existing in-memory sessions, so plan for users to
sign in again. Later security-configuration changes can also require a fresh
login.
Existing Caddyfile authorize syntax stays the same. It now adapts to a
dedicated authorization handler that correctly preserves OAuth redirects,
callbacks, logout responses, and denials. If you deploy previously generated
JSON, regenerate it from your Caddyfile before adopting direct OAuth. The
legacy JSON authentication provider remains available for existing uses.
Keep declarations in one global security block. Duplicate blocks now
fail validation instead of silently replacing earlier configuration.
Open the portal as a page rather than inside an iframe. The new framing
protection blocks embedded portal pages, including login and account flows.
Choose direct OAuth access rules deliberately. Allowing the default
authp/user role permits every account accepted by the configured provider.
Use narrower identity or provider-role rules when only selected people should
have access, and ensure the OAuth callback and logout paths reach the same
authorization policy as the application.
github.com/greenpau/go-authcrunch was updated from v1.3.4 to v1.3.8.
Compare: greenpau/go-authcrunch@v1.3.4...v1.3.8
Nothing published for this version
Nothing published for this version
github.com/greenpau/go-authcrunch was updated from v1.3.3 to v1.3.4 .
github.com/greenpau/go-authcrunch was updated from v1.3.3 to v1.3.4.
Compare: greenpau/go-authcrunch@v1.3.3...v1.3.4
Thank you to @openai Daybreak Blue agents for auditing the caddy-security and go-authcrunch codebases for vulnerabilities.
This release adds an OpenID Connect provider, renewable login sessions, a
standalone authentication client, and conditional authentication policies. It
also improves credential handling, authorization, portal usability, and Caddy
configuration validation.
These notes cover caddy-security v1.1.64 → v1.2.1, including the embedded
go-authcrunch upgrade from v1.1.41 to v1.3.3.
| Component | Previous release | This release |
|---|---|---|
| caddy-security | v1.1.64 | v1.2.1 |
| go-authcrunch | v1.1.41 | v1.3.3 |
| Caddy dependency | v2.11.4 | v2.11.4 |
| Minimum Go version for source builds | 1.25.8 | 1.26.0 |
Use your portal as an OpenID Connect provider. Downstream applications can
authenticate local users through discovery, authorization code flow with S256
PKCE, consent, ID tokens, UserInfo, and revocation. Supported capabilities
include query and form-post responses, public and confidential clients,
signed RS256 Request Objects, authentication-context mappings, and profile,
email, address, and phone claims. OIDC refresh tokens rotate and require
explicit offline-access consent. Native public clients support dynamic ports
on literal IPv4/IPv6 loopback callbacks.
Provider configuration.
Provision named OAuth applications and persistent signing keys. New
oauth application, oauth registration store, and portal oidc provider
configuration works with the security oauth and security oidc commands.
Create credentials once, persist them privately, and explicitly rotate client
secrets or provider signing keys. Normal adaptation and startup load existing
credentials instead of silently generating replacements.
Provisioning guide.
Keep local-user sessions active with rotating refresh credentials. The
opt-in token refresh block adds bounded session lifetimes, replay detection,
family revocation, and session-capacity controls. Browser support coordinates
refresh and logout across tabs and provides a continuation flow after access
tokens expire. Native clients can explicitly opt into body-based refresh.
Portal refresh and OIDC refresh grants are separate mechanisms.
Refresh configuration.
Choose authentication steps based on enrolled factors. Conditional
policies support ordered alternatives and password, TOTP-only, or
WebAuthn-only flows. Static local users can carry ordered challenge rules;
portal transforms can select a flow while existing require rules remain
additive. Profile APIs expose registered methods, effective challenges, and
policy sources, and support validated policy replacement or reset. Issued
amr claims describe factors actually verified during authentication.
Authentication flow guide.
Discover public signing keys and use Ed25519. Portals publish asymmetric
access-token signing keys at <portal-base>/.well-known/jwks.json. Ed25519
signing and verification support both EdDSA and Ed25519 algorithm labels,
including verification of upstream OAuth tokens. Private signing-key export
is available only through authenticated admin access with an additional,
independently enabled export setting.
Key discovery and export.
Updated portal and OIDC pages. Consent, continuation, and browser error
pages now share portal branding and custom-template support. The embedded UI
adds SVG branding, responsive phone layouts, clearer controls and keyboard
focus, and a QR view that restores the previous form and focus when closed.
API error responses retain their JSON contract.
New caddy-authenticator CLI. Log in with named profiles using passwords,
TOTP, or API keys, without requiring the portal admin API. The client stores
credentials privately, reuses cached access tokens, supports native refresh,
and provides explicit interactive and forced-login modes. Separate archives
target Linux, macOS, and Windows on amd64 and arm64; Go installation is also
supported. Browser SSO and WebAuthn assertions are outside this client's scope.
Installation and usage.
Local-user administration from the Caddy binary. security local adds
login, realm/user inspection, account creation and deletion, account status,
password resets, role changes, and challenge-policy management through the
running portal's admin API. Offline commands generate bcrypt password hashes
and API keys with Caddyfile output.
Local administration guide.
Dependency diagnostics. security version reports the linked
go-authcrunch version, including local replacement information.
More complete Caddyfile support. Shared parsers bring consistent cookie,
OAuth, admin API, refresh, and transform handling. OAuth providers gain explicit
issuer and access-token audience settings. Transforms support field-existence
matching, typed and nested custom claims, and claim deletion. Runtime
environment/secret resolution preserves argument boundaries.
Build custom claims from the user logging in. Caddy resolves environment
variables and secret references when loading the configuration, while leaving
{claims.*} placeholders in transform actions for AuthCrunch to evaluate
against each user's claims during login. Previously, these placeholders could
fail configuration loading because Caddy tried to resolve them before a user
identity was available. For example, inside an authentication portal:
transform user {
match realm local
add label "{env.MEMBER_LABEL} {claims.sub}" as string
}With MEMBER_LABEL=Member, configuration loading preserves the value as
Member {claims.sub}. When a user whose sub claim is alice logs in, the
action adds "label": "Member alice" to their claims. This supports per-user
labels and application identifiers from one configuration. Expansion applies
to supported transform action values; matcher values remain literal, and
this does not enable {claims.*} placeholders throughout the Caddyfile.
The go-authcrunch fixes below are included in the Caddy integration through the
v1.3.3 dependency upgrade.
no-store.match, malformed redirect-trust input, and multiline native-JSON instructionsmatch any transforms are rejected when portal refresh or OIDC is enabled,match realm local.redirect_uri directive per callback.authdb server: go-authcrunch adds its own HTTP/2 and TLSauthcrunch and caddy-authenticatorpkg/authclient exposescaddy-authenticator implements it. authdbctl fixes includeThe repositories add race-enabled tests and broader real Caddy/TLS/browser
coverage for authentication, refresh, OIDC, key rotation, authorization, and
reloads. Test reports retain failures and use versioned artifact names.
An opt-in OpenID Foundation conformance workflow exports readable reports and
complete evidence; OpenID certification is not claimed. Recorded
qualification also retains security findings and manual protocol-review
outcomes; see the qualification notes
for their tested revisions and limits.
For maintainers, make release and make minor-release run the local quality
gate before atomic branch/tag publication. make fast-release and
make fast-minor-release skip that local gate while preserving version/Git
checks; GitHub release validation still runs before publication of binaries.
Thank you to @openai Daybreak Blue agents for auditing the caddy-security and
go-authcrunch codebases for vulnerabilities.
Full changes: caddy-security v1.1.64…v1.2.1,
go-authcrunch v1.1.41…v1.3.3.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
github.com/greenpau/go-authcrunch was updated from v1.1.40 to v1.1.41 .
github.com/greenpau/go-authcrunch was updated from v1.1.40 to v1.1.41.
Compare: greenpau/go-authcrunch@v1.1.40...v1.1.41
e03784f breakfix: caddy placeholder not replaced within user_group_filters (or other []interface{})
Nothing published for this version
Nothing published for this version
Nothing published for this version
f58591d upgrade to github.com/greenpau/go-authcrunch v1.1.39
7f80e63 feat: add PKCE support for OAuth 2.0 authorization flow
c902769 upgrade to github.com/greenpau/go-authcrunch v1.1.36
a77b167 upgrade to github.com/greenpau/go-authcrunch v1.1.35
a3338ba upgrade to github.com/greenpau/go-authcrunch v1.1.34
Nothing published for this version
b9450c6 upgrade to github.com/greenpau/go-authcrunch v1.1.33
ee2f84c upgrade to github.com/greenpau/go-authcrunch v1.1.32
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →