Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 8, 2025

This PR contains the following updates:

Package Update Change
ghcr.io/steveiliop56/tinyauth (changelog) major v3.6.2 -> v4.0.1

Release Notes

steveiliop56/tinyauth (ghcr.io/steveiliop56/tinyauth)

v4.0.1

Compare Source

Tinyauth v4.0.1

Hey everyone, this is a simple patch release to fix some issues that occurred with v4.

[!WARNING]
This release contains a security fix regarding label discovery, please update as soon as possible.

Improvements

  • Move docker connection check to start-up so as label discovery can fail in case of a socket proxy crash
  • Use GIN recovery module to translate panics to 500 errors
  • Sort OAuth providers based on name length
  • Allow root cookie domain redirects
  • Use more verbose logging for the trace log level

Fixes

  • Ensure data directory exists on docker images
  • Remove trailing spaces before checking OAuth username and name
  • Do not use container name for label discovery

Technical

  • Use docker meta flavors for images
  • Bump dependencies

Please let me know of any issues so as I can fix them as soon as possible.

v4.0.0

Compare Source

Tinyauth v4.0.0

It's been quite a long time, but I am thrilled to announce Tinyauth v4.0.0! It took some time, but it's was definitely worth the wait. The code-base has been significantly revamped with clean code, maintainability and extensibility in mind. Additionally a lot of new features have been added including support for multiple OAuth providers! The release has been extensively tested by the amazing users over in the Discord community and should have no issues (huge thanks to @​Rycochet for helping review the code).

[!WARNING]
This is a breaking release, please follow the migration guide in the
documentation.

[!NOTE]
This release includes a small heartbeat to help me get some insights on the user-base of Tinyauth. Only your version will be collected. Read more about it in the telemetry reference.

New Features

  • SQLite database for storing sessions
  • Warning in UI when current domain doesn't match configured one
  • Trusted proxies configuration option (TRUSTED_PROXIES/--trusted-proxies)
  • File server allowing you to serve static assets like the background image (RESOURCES_DIR/--resources-dir)
  • Dash substitute for slash in IP labels allowing for CIDR usage in Kubernetes
  • Ensure app URL is not in the public suffix list to avoid cookie issues
  • Multiple OAuth providers
  • Helm chart for Kubernetes deployments
  • Health check command

Improvements

  • App labels reworked to allow for cleaner ACL configuration
  • Improved OAuth auto redirect flow for a more seamless redirection
  • Continue screen refactored to a redirect handler removing the need to click extra buttons
  • Autofocus TOTP form
  • Set page title using APP_TITLE environment variable
  • Add cache in the frontend for faster load times

Fixes

  • Disable indexing in the login screen preventing it from appearing in search engines
  • Do not allow authentication if Tinyauth fails to get the labels

Technical

  • A large part of the code base has been rewritten aiming for cleaner, readable and maintainable code
  • Reworked file structure for a better development experience
  • Bump dependencies
  • Update translations

If you face any issues please do let me know so I can fix them as soon as possible.


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from schaermu as a code owner October 8, 2025 18:40
@renovate renovate bot force-pushed the renovate/ghcr.io-steveiliop56-tinyauth-4.x branch 4 times, most recently from 386ec8f to 95cc7fe Compare October 15, 2025 17:38
@renovate renovate bot force-pushed the renovate/ghcr.io-steveiliop56-tinyauth-4.x branch 4 times, most recently from c3e1618 to dd6dff0 Compare October 23, 2025 18:51
@renovate renovate bot force-pushed the renovate/ghcr.io-steveiliop56-tinyauth-4.x branch 3 times, most recently from 16d8036 to 590cb99 Compare October 24, 2025 19:35
@renovate renovate bot force-pushed the renovate/ghcr.io-steveiliop56-tinyauth-4.x branch from 590cb99 to 8255267 Compare October 24, 2025 19:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants