← Back to Clusters

Device Auth and Security Fixes

This cluster addresses various security and authentication issues related to device authorization and control UI handling.

13 PRs
fix auth security Representative: #17378
# Title Author Created GitHub
8402 fix(ui): bypass /api in Control UI handler LarHope 2026-02-04 View
16827 fix: allow device tokens with empty scopes to accept requested scopes MisterGuy420 2026-02-15 View
17378 fix(gateway): allow dangerouslyDisableDeviceAuth with trusted-proxy auth mode rep ar-nadeem 2026-02-15 View
17572 fix: make dangerouslyDisableDeviceAuth bypass device identity checks gitwithuli 2026-02-15 View
17605 fix: preserve scopes when disableControlUiDeviceAuth is enabled MisterGuy420 2026-02-16 View
17705 fix(gateway): allow trusted-proxy auth to bypass device-pairing gates dashed 2026-02-16 View
17746 fix(gateway): add shared-secret fallback to trusted-proxy auth dispatcher dashed 2026-02-16 View
19389 Fix #2248: Allow insecure auth bypass when device signature validation fails cedillarack 2026-02-17 View
20089 fix(gateway): preserve control-ui scopes when dangerouslyDisableDeviceAuth is... vashkartik 2026-02-18 View
20422 Fix/tailscale device pairing slagyr 2026-02-18 View
22807 fix: parameterize magic numbers in ensureA2uiReady (issue #22745) ambicuity 2026-02-21 View
22966 fix(onboard): error on unknown --auth-choice in non-interactive mode miloudbelarebia 2026-02-21 View
23280 fix(control-ui): remove stale allowInsecureAuth suggestion from error message... anillBhoi 2026-02-22 View