I think that a proper warning about deprecated API authentication with this release was at least essential.
Problem is that I have a strange success/fail API authentication entries in the logs even after downgrade and restoring the last backup.
Can you please suggest should downgrade restore old-API authentication working, before third-party software can fix it from their side?
There is already important note due to removal of compatibility with old version passwords.
Third party software should have been fixed long time ago ,new authentication method was introduced back in May 2018.
Sorry, can’t see anything about deprecation of old-style authentication both in the changelogs or API link you posted above.
Can you please post a link to the important note you’re mention?
I still can’t see any API-related warnings in the release.
Just to be sure that you can understand my point:
Removing compatibility with old version passwords
Ok, I really can’t say that it should be intuitive for any user that it will affect their API authentication somehow.
user - removed insecure password storage;
Same here.
I didn’t trying to hype on that, but I strongly believe that another important notice about old-style API authentication deprecation starts with this release will be very pleased for many MikroTik users.
Yea, i basically did same thing in my patch i just wrote “how it fastly fix”.
Infact i don’t see any advantage to use old style API because having unpatched ROS (pre-6.43) is big security hole
For those who are using old good routeros_api.class.php from Denis Basta. The urls are no longer active. The needed changes to make it work again with new /login
Right now, PEAR2_Net_RouterOS supports the new login method only in the development version. That is, the currently unreleased 1.0.0b7. You can only get it via Composer by specifying “dev-develop” as your required version.
Generating PHARs is a little bit difficult and time consuming right now, which is why I haven’t done it yet… Since these new versions no longer support the old authentication method, I’ll try to make a release this weekend.
@amardeep704 I’m surprised b6 works to be honest. As for disabling hotspot, you can use f.e.