Security
Security review: fixes across the cloud and the self-hosted server
- Workspace roles. Adding a member now checks the role it is given. Before, a workspace admin could change the owner's role or grant themselves owner through the invite form. An owner's role can no longer be changed there, and only an owner can add another owner.
- Self-hosted dashboard password. Set
VITRUS_PASSWORDand the self-hosted dashboard, its read API and the replay settings ask for it; the tracker and ingest stay public. Without it,vitrus startwarns that anyone who can reach the port can read the analytics — which was true, silently, until now. - Password guessing is limited per address and per account, and an account that signs in only with Google or GitHub now answers a password attempt in the same time as any other.
- Security headers on every response: pages cannot be framed by another site, content types are not sniffed, and HSTS is sent behind TLS.
- Ingest bodies are capped at 64 KB, on the cloud and in the self-hosted server.