mirror of
https://github.com/Dokploy/dokploy.git
synced 2026-07-21 22:05:23 +02:00
071d9eacee9744f13193e92757a7fcd3bab0956a
The .one / getRepositories / getBranches / testConnection handlers for github, gitlab, gitea and bitbucket resolved a provider by bare id under protectedProcedure and returned the full row (OAuth tokens, app private keys, webhook secrets) with no organization or entitlement check, letting any authenticated user read another org's git-provider credentials (IDOR). Adds assertGitProviderAccess() in the git-provider service (rejects cross-org with NOT_FOUND and non-entitled same-org with FORBIDDEN, reusing the existing getAccessibleGitProviderIds entitlement logic) and calls it in every read handler before returning secret-bearing data. Closes GHSA-66r5-5m5f-57vg
Dokploy is a free, self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases.
✨ Features
Dokploy includes multiple features to make your life easier.
- Applications: Deploy any type of application (Node.js, PHP, Python, Go, Ruby, etc.).
- Databases: Create and manage databases with support for MySQL, PostgreSQL, MongoDB, MariaDB, libsql, and Redis.
- Backups: Automate backups for databases to an external storage destination.
- Docker Compose: Native support for Docker Compose to manage complex applications.
- Multi Node: Scale applications to multiple nodes using Docker Swarm to manage the cluster.
- Templates: Deploy open-source templates (Plausible, Pocketbase, Calcom, etc.) with a single click.
- Traefik Integration: Automatically integrates with Traefik for routing and load balancing.
- Real-time Monitoring: Monitor CPU, memory, storage, and network usage for every resource.
- Docker Management: Easily deploy and manage Docker containers.
- CLI/API: Manage your applications and databases using the command line or through the API.
- Notifications: Get notified when your deployments succeed or fail (via Slack, Discord, Telegram, Email, etc.).
- Multi Server: Deploy and manage your applications remotely to external servers.
- Self-Hosted: Self-host Dokploy on your VPS.
🚀 Getting Started
To get started, run the following command on a VPS:
Want to skip the installation process? Try the Dokploy Cloud.
curl -sSL https://dokploy.com/install.sh | bash
For detailed documentation, visit docs.dokploy.com.
Contributors 🤝
📺 Video Tutorial
🤝 Contributing
Check out the Contributing Guide for more information.
Description
Open Source Alternative to Vercel, Netlify and Heroku.
backendbackupsdatabasesdeploymentdevopsdockerfrontendmariadbmongodbmysqlnextjspostgresqlself-hostedvps
Readme
102 MiB
Languages
TypeScript
99%
Go
0.7%
CSS
0.2%