Releases: pfrest/pfSense-pkg-RESTAPI
Release list
pfSense REST API v2.10.2
Fixes
- Corrects the wrong cherry-picked commit for version formatting fix included in v2.10.1 #930
Full Changelog: v2.10.1...v2.10.2
pfSense REST API v2.10.1
New
- Adds Kea-specific netboot fields to DHCPServer
- Adds support for pfSense CE 2.9.0 #933
- Adds support for pfSense Plus 26.07 #933
Fixes
- Fixes a version formatting issue in RESTAPIVersion that resulted in an inaccurate installed version value #930
Changes
- FirewallApplyDispatcher now dispatches process using /etc/rc.filter_configure_sync
- Removes/replaces various defunct pfSense function calls
- Various minor compatibility and testing adjustments for pfSense CE 2.9.0 and Plus 26.07
Full Changelog: v2.10.0...v2.10.1
pfSense API v1.9.1
Fixes Changed
- Fixes authentication bug for v1 HA API sync by #935
New Contributors
- @cipwurzel362 made their first contribution in #936
Full Changelog: v1.9.0...v1.9.1
pfSense REST API v2.10.0
Important
This release includes important security enhancements including fixes for GHSA-w3w4-mvcc-vmgr, as well as important optimizations and preparations for pfSense CE 2.9.0. It is recommended for all users. Please review the notes below for potential breaking changes introduced in this release.
Fixes
- Fixes a command prompt injection flaw in the /api/v2/interface/group and /api/v2/interface/groups endpoints GHSA-w3w4-mvcc-vmgr (thank you to @senti-man for discovering and reporting this issue!)
- Implements core Command auto-escaping to guard against future command injection risks
- Fixes an issue where ACME certificate issuance results no longer populated due to out-of-band changes in the upstream acme package
- Addresses a Validator object order-of-precedence issue that caused out of sequence validations for some fields
- Various PHP >8.2 syntax issues fixed in preparation for pfSense CE 2.9.0
Breaking Changes
- Adds
sensitiveflag to OpenVPNClientauth_passfield - Adds
sensitiveflag to Useripsecpskfield - Adds
sensitiveflag to WireGuardPeerpresharedkeyfield
Note
These changes will prevent these fields from being included in API responses by default. If your integrations require read access to these fields, you can add sensitive field overrides for the associated field(s) in the REST API settings.
Changes
- Remaining shell_exec and exec calls have been replaced with \RESTAPI\Core\Command to take advantage of added protections
- Basic authentiatcion is now only considered the requested authentication method when a client provides both a username AND password. Previously either the presence of basic authentication username or password would elect basic authentication as the requested method.
- Auth now uses header presence to determine the client's requested auth method
- Additional guard clauses have been added during auth handling to exit quicker upon invalid auth
Full Changelog: v2.9.0...v2.10.0
pfSense REST API v2.9.0
Important
This release contains a fix for a potential high severity vulnerability found in the /api/v2/system/restapi/settings/sync endpoint. For more information, please refer to GHSA-8q8g-9f77-8g8g.
New
- Adds /api/v2/system/hasync endpoint to configure XMLRPC configuration sync #843
- Adds /api/v2/status/wireguard/tunnels endpoint to view status of current WireGuard tunnels #790
- Adds /api/v2/status/wireguard/peers endpoint to view status of current WireGuard peers #790
Breaking changes
- RESTAPISettings
hasync_usernamenow must holdpage-allprivileges to successfully sync on HA peers - RESTAPISettings
hasyncmust now be enabled on remote HA peers before settings sync can occur
Fixes
- Addresses a potential privilege escalation issue in /api/v2/system/restapi/settings/sync
- Fixes a weak deserialization pattern in /api/v2/system/restapi/settings/sync
New Contributors
Full Changelog: v2.8.4...v2.9.0
pfSense API v1.9.0
Breaking Changes
- Removes
page-system-apiprivilege from /api/v1/system/api/sync
Full Changelog: v1.8.1...v1.9.0
pfSense REST API v2.8.4
New
- Adds
dscpfield to FirewallRule #918
Fixes
- Optimizes parameter ordering
- Uses sane maximum value for LogSetting's
logfilesizeparameter #917
New Contributors
- @scottmsilver made their first contribution in #919
Full Changelog: v2.8.3...v2.8.4
pfSense REST API v2.8.3
Fixes
- Increases the maximum length of FreeRADIUSUser motp_pin to 8 #915
- Fixes an issue that prevented nested aliases from being used when replacing all firewall aliases
Full Changelog: v2.8.2...v2.8.3
pfSense REST API v2.8.2
Fixes
- Adjusts timing and placement of WireGuardTunnel 'addresses' update validation pre-conditions #902
Full Changelog: v2.8.1...v2.8.2
pfSense REST API v2.8.1
New
- Adds build for pfSense Plus 26.03.1
Fixes
- Adds additional error handling when refreshing releases cache #900.
- Fixes an issue where WireGuardTunnel
addressescould be unnecessarily validated #902 - Addresses an issue where devel variant packages were still being rejected by dispatchers #905
Full Changelog: v2.8.0...v2.8.1