Anaphora 0.18: safer sign-in and security updates

Anaphora 0.18 is a security update for the sign-in. It locks the settings that come from your environment, limits the first-time setup page to user accounts, and updates components in the image. It carries no database migration, so you can go back to 0.17 the same way. Most installations need no action. If you sign in with single sign-on only, read "Before you upgrade" before you install it.
Locked settings
Settings that come from your environment variables, such as the OIDC client, are now locked. The settings page cannot change them.
Anaphora also does not save the OIDC client secret from your environment in its database any more, and the settings page does not show it. The secret stays in the memory of the running server only.
The first-time setup page
When an installation has no administrator yet, Anaphora shows a setup page to create the first one. This page now creates local user accounts and nothing else. It cannot change any other setting. It also keeps the sign-in methods that are already set. Before, it switched OIDC off.
While the page is open, the start log warns you, and the upgrade script shows it as a problem, with the address of the page. Create the first administrator there before you make the installation reachable.
If OIDC_SYSTEM_GROUPS names your administrators, they sign in with single sign-on from the first start, and the setup page does not open.
Sign-in and security
Connections that stay open (WebSockets) get the same sign-in checks as normal page loads, and they close when the user signs out. Anaphora itself does not use them.
The image gets security fixes:
perl-base5.36.0-7+deb12u4 (CVE-2026-13221 and six more),handlebars4.7.10 (CVE-2026-106445, CVE-2026-106446),shell-quote1.12.0 (CVE-2026-102422),sharp0.35.5 (GHSA-wq5f-xc86-pv6w) andsource-map-js1.2.2 (CVE-2026-93749).The sign-in service is now Authfish 1.0.190.
Fixes
If the first start of a new installation fails, Anaphora keeps no half-saved settings. The next start begins clean.
Before you upgrade
Single sign-on only
If your users sign in only with single sign-on and you have no local administrator, create one in Settings before you upgrade. It is your way in when single sign-on is off, for example after a mistake in an
OIDC_*variable or a change of licence. Without it, the setup page opens again while single sign-on is off.
Administrator from the environment
ADMIN_USERNAMEandADMIN_PASSWORDapply only to the first start of an empty installation. If the start log says that no one can administer Anaphora yet, open the address it shows and create the first administrator there. Setting the variables later does not close the page.
The full list of changes is in the changelog.
