Skip to content

docs: server 0.2.0 authz changes, MANTIS_PUBLIC_PATH, changelog - #14

Open
adamXbot wants to merge 1 commit into
mainfrom
docs/audit-fixes-0.2.0
Open

adamXbot wants to merge 1 commit into
mainfrom
docs/audit-fixes-0.2.0

Conversation

@adamXbot

@adamXbot adamXbot commented Sep 5, 2026

Copy link
Copy Markdown
Collaborator

Documents the behaviour changes shipped in mantis server v0.2.0 (privacykey/mantis#86) and regenerates the changelog for v0.2.0 / cli-v0.2.1.

  • api.md — new "Notification rows in hit listings" section: target is null for non-admins on global-destination rows, with the new destination_scope field. POST /api/api-keys is admin-only. /api/audit?actor= must be a UUID. The external_id claim rules now depend on the caller: creator/admin unchanged; cross-key enroll claim → trigger URL only (memo: null), audited cross_key: true; other full keys → 409. The enroll-key security caveat is narrowed accordingly.
  • single-user.md — same rules in the operator summary.
  • configuration.mdMANTIS_PUBLIC_PATH no longer needs a reverse-proxy rewrite (server ≥ 0.2.0); notes the dashboard security headers on custom prefixes.
  • changelog.mdxnpm run sync-changelog against the new releases.

npm run check passes locally.

🤖 Generated with Claude Code

…0.2.0 / cli-v0.2.1

- api.md: hit listings redact global-destination targets for non-admins
  (new "Notification rows in hit listings" section, `destination_scope`);
  POST /api/api-keys is admin-only; /api/audit validates `actor`; the
  external_id claim rules now depend on who asks (creator/admin, cross-key
  enroll → URL only with memo null, other full keys → 409).
- single-user.md: same rules in the operator-facing summary.
- configuration.md: MANTIS_PUBLIC_PATH no longer needs a reverse-proxy
  rewrite (server ≥ 0.2.0); note the dashboard headers on custom prefixes.
- changelog.mdx: regenerated from GitHub Releases (v0.2.0, cli-v0.2.1).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 5, 2026

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
docs-mantis cbc9680 Commit Preview URL

Branch Preview URL
Sep 05 2026, 10:05 AM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant