LNbits is a simple multi-user and account system for Lightning
@ -41,44 +41,26 @@ path: ""
defaultUsername:""
deterministicPassword:true
releaseNotes:>-
🚨 Critical Security Update:This update addresses a critical security vulnerability in LNbits. Please update as soon as possible.
In this release, we introduce a whole suite of new security features to harden your LNbits instance. Our goal is to make these features
accessible and keep every instance as safe as possible to protect user funds from possible security breaches.
🔧 Extension Management Changes:
New and existing users should follow these steps to install extensions:
1. Copy your unique LNbits password from the LNbits' app store page on your Umbrel:'umbrel.local/app-store/lnbits'.
2. Access the Super Admin page of LNbits at 'umbrel.local:3007/uuidv4/<your-lnbits-password>'. Replace '<your-lnbits-password>' with the password you copied before.
3. You can now install and uninstall extensions from this page.
You will find a new Security panel in your Manage Server AdminUI that you can access as the super user. All features are opt-in and are also accessible via the LNbits API.
🔄 Extension Restoration for Existing Users:
The Security panel has six components:
- If an extension was previously installed, it won't show up after the update.
- Server logs 📝
- Reinstall the extension from the Super Admin page to restore its enabled state and data.
- IP blocker 🚫
- Rate limiter 🐌
🔓 Extension Enabling/Disabling:
- Security notifications 🔔
- Once installed, any user can enable/disable extensions from their user page.
- Killswitch 🪓
- Existing LNbits users that are updating their app may need to hard refresh their browser on the extensions page in order to enable/disable extensions.
👥 Granting Admin Access:
- From the Super Admin page, you can make other users admins.
- Admins can install extensions without visiting the Super Admin page.
- Watchdog 🐕 (coming soon)
📄 Full Release Notes and detailed information is available at:https://github.com/lnbits/lnbits/releases