11.0.283
dograh-hq/dograh11.0.283Jun 25, 2026by adubovikov
AI Summary
A critical security release that addresses three advisories including SQL injection prevention, credential hardening, and JWT enforcement.
Key Highlights
- Prevented SQL injection in `POST /api/v4/statistics/query`
- Removed hardcoded default admin password and added random bootstrap password
- Enforced JWT authentication when `coordinator.jwt.secret` is empty
New Features
- Security patch for SQL injection
- Credential management improvements
- JWT authentication enforcement
Full Release Notes
## Security release This release closes three coordinator security advisories. See [docs/SECURITY.md](https://sipcapture.github.io/homer/SECURITY/) for upgrade notes. ### Fixes * **GHSA-f46q-3v67-fmm4** — validate `rawquery` in `POST /api/v4/statistics/query` (read-only SQL only) ([#837](https://github.com/sipcapture/homer/pull/837)) * **GHSA-6xp5-7rcx-xfgx** — remove hardcoded default admin password `sipcapture`; random bootstrap password when hash omitted ([#838](https://github.com/sipcapture/homer/pull/838)) * **GHSA-rqcc-94gv-wjm9** — enforce JWT on protected routes when `coordinator.jwt.secret` is empty; auto-persist `.homer_jwt_secret` ([#839](https://github.com/sipcapture/homer/pull/839)) ### Documentation * Add [Security hardening](https://sipcapture.github.io/homer/SECURITY/) guide; update auth, coordinator, wizard, and OpenAPI docs. ### Upgrade notes * **Docker Compose** (`examples/docker/`) with explicit `JWT_SECRET` and `ADMIN_PASSWORD_HASH` — no credential changes. * **Empty JWT secret** — API now requires authentication; check coordinator logs for `jwt_secret_file`. * **Fresh install without admin hash** — bootstrap password logged once at startup. **Full Changelog**: https://github.com/sipcapture/homer/compare/11.0.281...11.0.283