Releases: pfrest/pfSense-pkg-RESTAPI
Release list
pfSense REST API v2.10.0
Important
This release includes important security enhancements including fixes for GHSA-w3w4-mvcc-vmgr, as well as important optimizations and preparations for pfSense CE 2.9.0. It is recommended for all users. Please review the notes below for potential breaking changes introduced in this release.
Fixes
- Fixes a command prompt injection flaw in the /api/v2/interface/group and /api/v2/interface/groups endpoints GHSA-w3w4-mvcc-vmgr (thank you to @senti-man for discovering and reporting this issue!)
- Implements core Command auto-escaping to guard against future command injection risks
- Fixes an issue where ACME certificate issuance results no longer populated due to out-of-band changes in the upstream acme package
- Addresses a Validator object order-of-precedence issue that caused out of sequence validations for some fields
- Various PHP >8.2 syntax issues fixed in preparation for pfSense CE 2.9.0
Breaking Changes
- Adds
sensitiveflag to OpenVPNClientauth_passfield - Adds
sensitiveflag to Useripsecpskfield - Adds
sensitiveflag to WireGuardPeerpresharedkeyfield
Note
These changes will prevent these fields from being included in API responses by default. If your integrations require read access to these fields, you can add sensitive field overrides for the associated field(s) in the REST API settings.
Changes
- Remaining shell_exec and exec calls have been replaced with \RESTAPI\Core\Command to take advantage of added protections
- Basic authentiatcion is now only considered the requested authentication method when a client provides both a username AND password. Previously either the presence of basic authentication username or password would elect basic authentication as the requested method.
- Auth now uses header presence to determine the client's requested auth method
- Additional guard clauses have been added during auth handling to exit quicker upon invalid auth
Full Changelog: v2.9.0...v2.10.0
pfSense REST API v2.9.0
Important
This release contains a fix for a potential high severity vulnerability found in the /api/v2/system/restapi/settings/sync endpoint. For more information, please refer to GHSA-8q8g-9f77-8g8g.
New
- Adds /api/v2/system/hasync endpoint to configure XMLRPC configuration sync #843
- Adds /api/v2/status/wireguard/tunnels endpoint to view status of current WireGuard tunnels #790
- Adds /api/v2/status/wireguard/peers endpoint to view status of current WireGuard peers #790
Breaking changes
- RESTAPISettings
hasync_usernamenow must holdpage-allprivileges to successfully sync on HA peers - RESTAPISettings
hasyncmust now be enabled on remote HA peers before settings sync can occur
Fixes
- Addresses a potential privilege escalation issue in /api/v2/system/restapi/settings/sync
- Fixes a weak deserialization pattern in /api/v2/system/restapi/settings/sync
New Contributors
Full Changelog: v2.8.4...v2.9.0
pfSense API v1.9.0
Breaking Changes
- Removes
page-system-apiprivilege from /api/v1/system/api/sync
Full Changelog: v1.8.1...v1.9.0
pfSense REST API v2.8.4
New
- Adds
dscpfield to FirewallRule #918
Fixes
- Optimizes parameter ordering
- Uses sane maximum value for LogSetting's
logfilesizeparameter #917
New Contributors
- @scottmsilver made their first contribution in #919
Full Changelog: v2.8.3...v2.8.4
pfSense REST API v2.8.3
Fixes
- Increases the maximum length of FreeRADIUSUser motp_pin to 8 #915
- Fixes an issue that prevented nested aliases from being used when replacing all firewall aliases
Full Changelog: v2.8.2...v2.8.3
pfSense REST API v2.8.2
Fixes
- Adjusts timing and placement of WireGuardTunnel 'addresses' update validation pre-conditions #902
Full Changelog: v2.8.1...v2.8.2
pfSense REST API v2.8.1
New
- Adds build for pfSense Plus 26.03.1
Fixes
- Adds additional error handling when refreshing releases cache #900.
- Fixes an issue where WireGuardTunnel
addressescould be unnecessarily validated #902 - Addresses an issue where devel variant packages were still being rejected by dispatchers #905
Full Changelog: v2.8.0...v2.8.1
pfSense REST API v2.8.0
New
- New releases now trigger Ansible Collection builds to sync changes between the REST API and Ansible modules
- Adds the /api/v2/system/enum endpoint to allow clients to obtain a definitive list of options for a given model field, including dynamic options
- Adds validity information for /api/v2/system/certificate endpoints #834
- Adds the
namefield to /api/v2/system/table endpoints - Adds more available fields for /api/v2/services/freeradius/user* to be more comprehensive #431, #21
- Adds /api/v2/services/freeradius/mac endpoint to add FreeRADIUS MAC entries #431, #21
- Adds /api/v2/services/freeradius/ldap endpoint to configure FreeRADIUS LDAP settings #431, #21
- Adds /api/v2/services/freeradius/eap endpoint to configure FreeRADIUS EAP settings #431, #21
- Adds /api/v2/system/update endpoint to trigger a pfSense upgrade process
- Adds new
allow_development_packagesREST API settings to allow development package to be used by Models/Endpoints #877 - Implements new
dry_runcommon control parameter to allow clients check requests without actually making any changes
Fixes
- Fixes an issue that allowed /api/v2/status/system to return a CPU usage percentage over 100%
- Fixes an issue where a Model class with no Fields could result in an invalid OpenAPI schema
- Implements safe fallbacks for certificate status info
Changes
- Adds Ansible specific argument names to reserved-field names to prevent conflicts with module auto-generation
- Deprecates support for pfSense Plus < 25.11.1 and pfSense CE 2.8.0.
- Removes default sorting attribute for PortForwards
Enhancements
- Replaces various dynamic
choicesdefinitions with achoices_callableto prevent inconsistent schema choices - Models with internal callables can now leverage pagination parameters directly #860, #806
- Improves the verbose names of models and fields throughout the entire project
- Pagination for log file endpoints has been better optimized to lower memory utilization when using pagination #860, #806
- Releases now include include schema files as release assets
New Contributors
- @guillaumearnx made their first contribution in #834
- @JeremiahChurch made their first contribution in #860
Full Changelog: v2.7.7...v2.8.0
pfSense REST API v2.8.0-dev-784d1f7
ci: correct typo in ansible collection repo name
pfSense REST API v2.7.7
New
- /api/v2/vpn/ipsec/phase2/encryption
keylenfield now accepts0as representation forauto#880
Changes
- The default maximum number of items for
many(array) fields have increased from 128 to 65535 #879 - Bumps webonyx/graphql-php from 15.31.3 to 15.32.3 #875, #882
- Bumps firebase/php-jwt from 7.0.4 to 7.0.5 #881
Full Changelog: v2.7.6...v2.7.7