Skip to content

v1.0.5

Choose a tag to compare

@69kenji 69kenji released this 24 Aug 06:33
· 27 commits to main since this release

NetWatch 1.0.5

Fixed

  • Fixed buffering screen not appearing during large seeks.
  • Fixed stream options possibly becoming unclickable after upgrading from 1.0.4.
  • Fixed stale packaged runtime detection during upgrades.
  • Fixed Prowlarr download URLs exposing API keys to the frontend.
  • Fixed DNS rebinding gap in external URL validation.
  • Fixed incomplete VPN kill-switch verification.
  • Fixed unrestricted player/runtime IPC access between Electron windows.
  • Fixed oversized and malformed torrent/search requests reaching backend services.
  • Fixed unbounded remote response reads in subtitle and metadata downloads.
  • Fixed subtitle cache memory limits.
  • Fixed rate-limit bypasses on dynamic metadata routes.
  • Fixed VPN peers being able to reach internal control ports inside the VPN namespace.
  • Fixed swallowed torrent-engine errors that made debugging failures difficult.
  • Replaced the remaining runtime assert guard with explicit error handling.

Removed

  • Removed the obsolete /await-ready torrent endpoint.
  • Removed unused torrent, metadata, Prowlarr, and subtitle compatibility code.
  • Removed stale backend development and architecture references.

Changed

  • Search results now use temporary backend release references instead of exposing provider download URLs.
  • Player window now uses a restricted preload and sender-validated IPC.
  • Added stricter validation for torrent hashes, search inputs, request sizes, and numeric limits.
  • Added rate limiting to TMDB-backed metadata, season, and stream-option routes.
  • Added explicit firewall rules blocking VPN-side access to ports 8000, 8081, 8191, and 9696.
  • Improved VPN firewall verification to check the expected rules and ordering.
  • NetWatch backend and torrent-engine containers now drop Linux capabilities and disallow privilege escalation.
  • Updated security and network documentation to match the current runtime architecture.

Upgrade Notes

  • Upgrading from 1.0.4 may require re-importing the WireGuard configuration once.