Component: hotspot
118 changelog entries across 66 version(s)
Activity over time (changelog entries per month)
- added TOTP support for local hotspot users;
- improved system stability;
- prevent service from starting unnecessarily in the background on export/print commands;
- allow only "http:" and "https:" schemas in dst field;
- improvements to memory usage;
- properly escape all reserved URI characters;
- fixed an issue where extra "flash/" is added to html-directory for devices with flash folders (introduced in v7.17);
- fixed an issue where extra "flash/" is added to html-directory for devices with flash folders (introduced in v7.17);
- properly escape all reserved URI characters;
- fixed incorrect host moving to VLAN 0 when receiving packets through bridge;
- allow number as a first symbol in the Hotspot server DNS name;
- improved stability when receiving bogus packets;
- improved stability when receiving bogus packets;
- fixed setting of "address" parameter for IP binding;
- restore cookie timeout on reboot;
- added "install-hotspot-queue" parameter to control dynamic queue creation;
- fixed maximum allowed connections limitation;
- fixed minor memory leak after each successful login from WEB;
- improved limitation of maximum allowed connections;
- improved system stability when clients migrate between bridge ports or VLANs;
- fixed service initialization when HTML directory configured on an external disk;
- fixed SSL usage on all HotSpot pages;
- improved stability when receiving bogus packets;
- limit maximum allowed connections based on free RAM resources;
- removed "routerboard.com" URL from default HotSpot advertise;
- automatically reject all HTTPS requests passing through HotSpot server for unauthorized users;
- improved stability when receiving bogus packets;
- limit maximum allowed connections based on free RAM resources;
- removed "https-redirect" option;
- fixed ARP resolution for clients when address pool is specified on the server;
- fixed Walled Garden entries with action=deny;
- fixed login page over HTTPS;
- fixed memory leak on every web page loading;
- fixed web page loading using HTTPS;
- fixed web page loading using HTTPS;
- fixed "idle-timeout" usage with RADIUS authentication;
- fixed special character parsing in "target" variable (CVE-2021-3014);
- fixed "idle-timeout" usage with RADIUS authentication;
- fixed special character parsing in "target" variable (CVE-2021-3014);
- added "vlan-id" parameter support for hosts and HTML pages;
- added support for captive portal advertising using DHCP (RFC7710);
- fixed "html-directory" parameter export;
- improved management service stability when receiving bogus packets;
- do not verify Hotspot interface status when detecting if HTTP/HTTPS login method is allowed;
- ignore packets from host while MAC authentication is in progress;
- ignore packets from host while MAC authentication is in progress;
- do not verify Hotspot interface status when detecting if HTTP/HTTPS login method is allowed;
- updated splash page design ('/ip hotspot reset-html' required);
- fixed redirect to log in page (introduced in v6.45);
- fixed redirect to log in page (introduced in v6.45);
- fixed non-local NAT redirection to port TCP/64873;
- fixed RADIUS CoA "address-list" update;
- fixed default profile values not being used (introduced in v6.45);
- moved "title" HTML tag after "meta" tags;
- added "interface-mac" variable to HTML pages;
- moved "title" HTML tag after "meta" tags;
- added "https-redirect" under server profiles;
- added per-user NAT rule generation based on "incoming-filter" and "outgoing-filter" parameters;
- properly update dynamic "walled-garden" entries when changing "dst-host";
- properly update dynamic "walled-garden" entries when changing "dst-host";
- allow to properly configure Hotspot directory on external disk for devices that have flash type storage;
- fixed RADIUS CoA & PoD by allowing to accept "NAS-Port-Id";
- fixed user authentication when queue from old session is not removed yet;
- fixed user authentication when queue from old session is not removed yet;
- improved HTTPS matching in Walled Garden rules;
- fixed "dst-port" to require valid "protocol" in "walled-garden ip";
- fixed Walled Garden IP functionality when address-list is used;
- fixed "dst-port" to require valid "protocol" in "walled-garden ip";
- fixed Walled Garden IP functionality when address-list is used;
- improved user statistics collection process;
- require "dns-name" to contain "." symbol under Hotspot Server Profile configuration;
- fixed missing "/ip hotspot server profile" if invalid "dns-name" was specified;
- improved user statistics collection process;
- added access to HTTP headers using $(http-header-name);
- fixed rare kernel crash on multicore systems;
- fixed redirect to URL where escape characters are used (requires newly generated HTML files);
- show Host table commentaries also in Active tab and vice versa;
- fixed redirect to URL where escape characters are used (requires newly generated HTML files);
- show Host table commentaries also in Active tab and vice versa;
- fixed rare kernel crash on multicore systems;
- fixed nat rule port setting in "hs-unauth-to" chain by changing it from "dst-port" to "src-port" on Walled Garden ip "return" rules;
- fixed nat rule port setting in "hs-unauth-to" chain by changing it from "dst-port" to "src-port" on Walled Garden ip "return" rules;
- fixed nat rule dst-port by making it visible again for Walled Garden ip return rules;
- fixed nat rule dst-port by making it visible again;
- show comments from user menu also in active menu;
- clean-up all dead entries at once;
- fixed possible deadlock;
- improved html page resistance against attacks;
- make video tag work properly on hotspot login.html page
- added missing favicon.ico in hotspot html pages;
- fixed missing image at login;
- added html-directory-override & recognize default hotspot user;
- fixed export of default trial user;
- fixed memory leak on https requests;
- show cookie add/remove events in hotspot,debug log;
- allow static entries with the same mac on multiple hotspot servers;
- do not remove mac-cookie in case of radius timeout;
- added byte limits option for default-trial users;
- fixed login by mac-cookie when roaming among hotspot servers;
- add html-directory-override for read-only directory on usb flash;
- add uptime, byte and packet counter variables to logout script;
- added option to login user manually from cli;
- fixed trial-uptime parsing from CLI to Winbox/Webfig;
- added missing favicon.ico in hotspot html pages;
- fixed missing image at login;
- add mac-auth-mode setting for mac-as-passwd option;
- add login-timeout setting to force login for unauth hosts;
- ignore PoD remote requests if no HotSpot configured;
- fix kernel failure when www plugin aborts on broken html source;
- fix html-directory path on small flash devices;
- do not account traffic to local hotspot pages;
- fixed chap error after failed http-chap login (broken in v6.1);
- fixed problem when after upgrade hotspot html directory was empty;
- fixed universal client;
- added mac-cookie login method;
- added login redirect through http status 302;
- fixed https login (broken in v5.9);
- fixed login page to better handle big load;