• DcRouter v32.5.0
    Release / build-and-release (push) Failing after 13m3s
    Stable

    jkunz released this 2026-09-26 09:13:58 +00:00 | 17 commits to main since this release

    2026-09-26 - 32.5.0

    Features

    • Let the ACME settings name another CA's ACME directory. IAcmeConfig, AcmeConfigDoc and updateAcmeConfig carry an optional directoryUrl, which dcrouter passes to SmartAcme in place of Let's Encrypt, for example SmartAcme's own server.AcmeServer on the loopback of a disposable rehearsal host; absent, dcrouter orders from Let's Encrypt as before, and null returns to it. updateAcmeConfig accepts only SmartAcme's own rule, an https: URL or an http: URL on localhost, 127.0.0.1 or [::1], without credentials or fragment, and refuses anything else with the rule it breaks, without repeating the URL. A change is treated like an account change: it is refused while certificate jobs or ACME DNS cleanup are unfinished, and issuance waits until SmartAcme is rebuilt on the new directory. A directory stored past that check, by a direct database write, is refused by SmartAcme at startup and now classified as a permanent acme-account-configuration failure instead of consuming the startup retry budget. The settings dialog under Domains > Certificates gains an ACME directory field and keeps the dialog open with dcrouter's reason when it refuses the settings; the settings tile and the configuration view show the directory, and dcrouter's logs name only its origin. Rows written by earlier builds carry no directory and keep Let's Encrypt, so no migration is needed. test/test.acme-directory.node.ts covers the rule against SmartAcme's own refusal, persistence, reload and clearing, the refusal during unfinished DNS cleanup, a dcrouter that rebuilds SmartAcme from the directory stored through updateAcmeConfig onto two loopback CAs in turn, with an account key per directory, and a route certificate and a gateway-client exact certificate issued by the CA of the stored directory.

    Maintenance

    • Release tooling currency: @git.zone/tstest ^6.2.0 → ^6.3.0 (Chromium test files tear down their browser, servers and timers on every outcome and no longer share one browser in a parallel group; no migration), @types/node 26.6.1 → 26.6.2 and packageManager pnpm@12.4.2 → pnpm@12.5.1. The other @git.zone/* dev tools are already at their current releases. The lockfile keeps @types/node 26.6.1 only as the resolution of four @types/* packages' * range.
    Downloads