Skip to content

[FEATURE] Expose installed Tinyauth version via /api/context/app API endpoint #1160

Description

@crivchri

Is your feature request related to a problem? Please describe.

I use Argus to monitor GitHub releases, and I am always frustrated that the /api/context/app API endpoint does not return the currently installed Tinyauth version.

Describe the solution you'd like.

I would suggest to add the Tinyauth version to the /api/context/app endpoint.

This would allow tools such as Argus to reliably determine the installed version and notify users about available updates.

Thank you for considering this feature request and kind regards!

Describe alternatives you've considered.

No response

Additional context

No response

Human Written Confirmation

  • I confirm this request was written by me and not generated by an LLM or AI assistant.

Activity

  1. steveiliop56 commented on Sep 25, 2026

    @steveiliop56
    Member

    Hello @crivchri,

    Yep that does sound like a good idea. Although it would have to be protected, not available to everyone. This is because a version of Tinyauth may include a specific vulnerability and a public version endpoint gives an attacker an easy way to see if any vulnerabilities are present in that version.

  2. crivchri commented on Sep 25, 2026

    @crivchri
    Author

    Hello @crivchri,

    Yep that does sound like a good idea. Although it would have to be protected, not available to everyone. This is because a version of Tinyauth may include a specific vulnerability and a public version endpoint gives an attacker an easy way to see if any vulnerabilities are present in that version.

    Hi @steveiliop56,

    You're absolutely right. I was under the impression that the /api/context/app endpoint was protected, but it turns out it isn't.
    Do you think this endpoint should be protected, as it returns other sensitive information?

    Kind regards.

  3. steveiliop56 commented on Sep 25, 2026

    @steveiliop56
    Member

    Nope, the app context endpoint is public by design to provide the necessary information for the fontend to work for unauthenticated users.

  4. crivchri commented on Sep 25, 2026

    @crivchri
    Author

    Nope, the app context endpoint is public by design to provide the necessary information for the fontend to work for unauthenticated users.

    Hi @steveiliop56,

    Is there another protected endpoint, which could expose the version?

  5. steveiliop56 commented on Sep 26, 2026

    @steveiliop56
    Member

    Yep, we can do it at the /api/user/context endpoint or we can just add a new protected endpoint for /api/version (I will probably do the second one).

  6. crivchri commented on Sep 27, 2026

    @crivchri
    Author

    Yep, we can do it at the /api/user/context endpoint or we can just add a new protected endpoint for /api/version (I will probably do the second one).

    Hi @steveiliop56,

    Sounds great, thank you.
    Could this be implemented by next release?

    Thank you in advance and kind regards!

  7. steveiliop56 commented on Sep 28, 2026

    @steveiliop56
    Member

    Will try to include it if I have time.

  8. bsaurusrex commented on Oct 9, 2026

    @bsaurusrex

    Opened #1181 for this: a protected GET /api/version that returns the running version only to an authenticated user (anonymous requests get the standard 401), so the version is not publicly exposed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions