11.0.283

KoljaB/RealtimeTTS11.0.283Jun 25, 2026by adubovikov

AI Summary

Security release addressing three critical vulnerabilities.

Key Highlights

  • Validates rawquery in statistics API to prevent SQL injection
  • Removes hardcoded default admin password
  • Enforces JWT authentication when secret is empty

New Features

  • Security hardening

Full Release Notes

## Security release

This release closes three coordinator security advisories. See [docs/SECURITY.md](https://sipcapture.github.io/homer/SECURITY/) for upgrade notes.

### Fixes
* **GHSA-f46q-3v67-fmm4** — validate `rawquery` in `POST /api/v4/statistics/query` (read-only SQL only) ([#837](https://github.com/sipcapture/homer/pull/837))
* **GHSA-6xp5-7rcx-xfgx** — remove hardcoded default admin password `sipcapture`; random bootstrap password when hash omitted ([#838](https://github.com/sipcapture/homer/pull/838))
* **GHSA-rqcc-94gv-wjm9** — enforce JWT on protected routes when `coordinator.jwt.secret` is empty; auto-persist `.homer_jwt_secret` ([#839](https://github.com/sipcapture/homer/pull/839))

### Documentation
* Add [Security hardening](https://sipcapture.github.io/homer/SECURITY/) guide; update auth, coordinator, wizard, and OpenAPI docs.

### Upgrade notes
* **Docker Compose** (`examples/docker/`) with explicit `JWT_SECRET` and `ADMIN_PASSWORD_HASH` — no credential changes.
* **Empty JWT secret** — API now requires authentication; check coordinator logs for `jwt_secret_file`.
* **Fresh install without admin hash** — bootstrap password logged once at startup.

**Full Changelog**: https://github.com/sipcapture/homer/compare/11.0.281...11.0.283