Releases: 69kenji/NetWatch
Releases · 69kenji/NetWatch
Release list
v1.1.3
v1.1.2
NetWatch v1.1.2
Added
- Added optional Windows startup with normal or minimized-to-tray launch.
- Added Ctrl+K and / search shortcuts on Home, Discover, Settings, and search results.
- Added navigation history using mouse Back/Forward and Alt+Left/Alt+Right.
- Added copyable, privacy-respecting runtime diagnostics.
Changed
- Fixed the runtime status button so clicking it again closes the diagnostics panel.
- Improved detection and labeling of unavailable runtime services.
- Preserved title details and loading state while navigating backward and forward.
- Replaced shell-built renderer commands with isolated Electron utility processes.
- Improved startup-setting rollback when Windows login-item configuration fails.
- Updated release documentation.
v1.1.1
NetWatch v1.1.1
Added
- Added a cinematic Home layout for the Home screen with larger 16:9 backdrop cards.
- Added a compact layout button for switching between the standard and cinematic Home layouts.
- Home layout selection is remembered between launches.
- Added an X button to remove individual titles from Keep Watching. Removal updates the cache immediately.
Improved
- Removed the opaque strip beneath the Home search bar. Home banners can now scroll naturally behind the search bar.
Fixed
- When set to minimize to tray, closing from the player saves the current timestamp, exits playback, performs cleanup, and minimizes NetWatch instead of terminating the application.
Internal changes
- Refactored the Electron main.js process into smaller modules for the desktop shell, runtime, setup, settings, IPC, backend access, and WSL management.
- Split player session management into separate window, progress, and subtitle controllers.
v1.1.0
NetWatch 1.1.0
NetWatch 1.1.0 adds background operation, shared Keep Watching history, improved anime release matching, and the PC-side support required by NetWatch Android 1.0.0.
Background operation
- Added an optional Minimize to tray action for the main window's close button.
- Left-clicking the tray icon restores and focuses NetWatch.
- Right-clicking the tray icon opens a menu with Exit NetWatch, which closes the player, stops the remote gateway and backend, and terminates the application.
- Added On Close in Settings with Minimize to tray and Exit choices. Exit remains the default.
- Added single-instance handling so launching NetWatch again restores the existing window instead of starting another copy.
Keep Watching
- Added a Keep Watching row to Home with the normal title artwork and metadata, the last-watched date and time, and a purple playback-progress bar.
- Movies resume from the saved position. TV and anime resume the saved season and episode from the saved position.
- Resume automatically selects the first release allowed by the user's default quality setting. A 1080p limit will not select a 2160p release.
- Playback from the Windows and Android players updates the same history stored on the PC.
- New entries are recorded after 30 seconds of playback and are removed after reaching 95 percent.
- Added a Settings option for 1 to 20 cached titles. The default is 5.
- Disabling Keep Watching asks for confirmation and permanently deletes the saved history.
- History records contain only the catalog ID, title, season and episode when applicable, playback position and duration, and the last-updated time. Torrent names, release references, magnets, artwork, and full title metadata are not stored.
Anime release matching
- Added optional AniList identity matching while keeping TMDB as the catalog and metadata source.
- Added support for Romaji, English, native, and known alternate titles when searching indexers.
- Added installment matching for anime whose TMDB season numbering does not match release naming.
- Added support for season/episode, installment-local, and absolute episode numbering.
- Added a bounded recovery search when a release clearly links an alternate season coordinate to the requested absolute episode.
- Added support for anime films and OVAs. A one-episode OVA is handled as a movie; an OVA with multiple episodes is handled as TV.
- Matching remains limited to a confirmed title identity and episode coordinate so similarly named series, specials, recaps, packs, and unrelated releases are not accepted.
- AniList errors or rate limits do not block the existing TMDB-based fallback searches.
- Added bounded positive and negative AniList caches to reduce repeated lookups.
Settings and resource use
- Reorganized the Remote Access settings so status, network selection, port, actions, pairing, and paired devices use consistent alignment.
- Added Resource usage profiles:
- Standard keeps the normal torrent concurrency, connection limits, 32 MiB range lookahead, and 8 GiB buffer ceiling.
- Reduced lowers torrent concurrency and connection limits, uses a 16 MiB range lookahead, and lowers the buffer ceiling to 4 GiB.
- Changing the resource profile now confirms that streaming services will restart, applies the change, verifies VPN isolation, and restores the previous profile if startup fails.
- Added an in-app FlareSolverr switch. FlareSolverr remains off unless an indexer needs it.
- Stored desktop settings are validated and written atomically.
Android support
- Added remote Keep Watching listing, resume, and playback-progress endpoints.
- Added automatic release selection with the PC's configured quality ceiling.
- Added artwork and subtitle proxying through the pinned remote gateway instead of exposing backend service ports.
- Added download speed, buffer state, and connected-peer data for the Android player's Network panel.
- Added ordered progress updates so delayed reports from an older playback session cannot overwrite newer history.
- Added torrent-session leases so one remote playback session cannot remove a torrent still used by another session.
Fixes and reliability
- Fixed production builds using development user-data and cache locations.
- Fixed transient backend or torrent-status interruptions ending an otherwise valid player preparation attempt.
- Fixed remote asset requests that could remain open after the phone disconnected or the backend response ended early.
- Added size limits and approved-path checks for artwork and subtitle responses sent through Remote Access.
- Added stricter validation for device names, playback requests, progress reports, catalog IDs, and release references.
- Limited metadata, AniList, and anime-identity caches to prevent unbounded memory or disk growth.
- Updated torrent-engine resource limits to follow the selected resource profile.
- Updated Remote Access, network security, packaging, and build documentation.
Repository
- Added Git LFS tracking for the bundled
mpv.exebinary. - Removed development-only test scripts, test suites, test dependencies, and player smoke hooks from the release source tree.
- Removed stale Android build instructions from the Windows repository and linked the separate Android repository instead.
Compatibility
- Windows 11 x64 23H2 or newer.
- NetWatch Android 1.0.0 requires this release or newer.
- Existing NetWatch settings, provider credentials, and runtime data are preserved during upgrade.
v1.0.9
NetWatch 1.0.9
- Added secure remote access for Android clients.
- Added QR code and manual pairing.
- Added pinned HTTPS connections over private IPv4 interfaces.
- Added remote catalog, search, playback, episode and subtitle APIs.
- Added session expiry, request limits and security diagnostics.
- Added remote access configuration to Settings.
- Updated application dependencies and runtime metadata.
v1.0.8
NetWatch v1.0.8
Security
- Hardened SubDL subtitle downloads against server-side request forgery.
- Added manual redirect validation for subtitle downloads.
- Added DNS pinning for validated subtitle download hosts.
- Prevented SubDL API credentials from being forwarded across redirect origins.
- Rejected private, loopback, and otherwise unsafe redirect destinations.
- Hardened torrent storage paths so runtime save directories are generated internally instead of being derived from request-controlled values.
- Added bounds and escaping for dynamic season and episode regex inputs.
- Replaced TMDB image filename regex validation with fixed length, character, and extension checks.
- Added CodeQL suppression for sanitized setup-state logging that does not expose credential values.
Fixed
- Fixed remaining unsafe redirect handling in SubDL download paths.
- Fixed CodeQL path-traversal findings by removing request-derived torrent save-directory names.
- Fixed regex-injection and regex-complexity findings in metadata handling.
Internal
- Added regression tests for private-address subtitle redirects.
- Added regression tests confirming SubDL credentials are stripped on cross-origin redirects.
- Added regression coverage for generated torrent save directories.
- Added metadata validation coverage for bounded season, episode, and image inputs.
- Application version updated to 1.0.8.
- Runtime marker updated to
1.0.8-pkg40.
v1.0.7
NetWatch 1.0.7
Changed
- Reorganized the VPN section in Settings for clearer grouping and alignment.
- Renamed the VPN
Testaction toTest connection. - Simplified the README and supporting documentation to remove repeated explanations and unnecessary implementation detail.
- Consolidated native helper and mpv provenance documentation into their existing README files.
- Simplified packaging documentation.
- Simplified the network threat model while preserving the current security model.
- Updated documentation and release references for 1.0.7.
Cleanup
- Removed the top-level
tests/folder. - Removed
DESIGN_SYSTEM.md. - Removed
SECURITY_PATCH_NOTES.md. - Removed
packaging/write-sha256.js. - Removed the obsolete release checklist from
packaging/PACKAGING.md. - Removed separate
BUILD-PROVENANCE.mdfiles after merging their useful content into the corresponding README files. - Removed an unused duplicate NetWatch icon.
- Removed unused Electron helper/export code.
- Removed unused Python imports.
- Removed stale torrent compatibility fields with no remaining consumers.
- Removed an obsolete URL-validation compatibility wrapper.
- Removed stale signing logic from the prerequisite-helper build script.
- Removed stale development, candidate, and version-specific comments.
- Removed unused CSS left over from older UI and player implementations.
- Excluded backend test files and smoke-test scripts from packaged runtime/container build contexts while keeping the source files available for development.
- Normalized native Go helper builds with
-buildvcs=falseto avoid embedding stale local Git metadata. - Corrected mpv runtime lookup documentation.
Fixed
- Fixed the VPN Settings controls being visually scattered across the section.
- Fixed stale documentation references to removed files and outdated build behavior.
- Fixed native helper provenance builds depending on local Git checkout metadata.
v1.0.6
NetWatch 1.0.6
Changed
- OpenSubtitles is now optional during first-run setup.
- SubDL is now optional during first-run setup.
- OpenSubtitles and SubDL can be added or replaced later from Settings.
- Settings now shows whether API credentials are configured.
- TMDB API keys must be exactly 32 characters.
- Prowlarr API keys must be exactly 32 characters.
- OpenSubtitles API keys must be exactly 32 characters.
- SubDL API keys must be exactly 49 characters total.
- SubDL input now uses a fixed
subdl_prefix and accepts exactly 43 characters after it. - Invalid credential lengths are rejected before provider validation.
- Optional subtitle providers now use a normal
not configuredstate when no key is present. - Missing subtitle credentials no longer block first-run completion.
- Tracks/subtitle UI now handles unconfigured online subtitle providers cleanly.
- Runtime marker updated to
1.0.6-pkg39.
Fixed
- Fixed first-run setup getting stuck on the
Readyscreen when Prowlarr was already configured and TMDB/subtitle credentials were validated afterward. - Fixed optional subtitle credentials being treated as mandatory setup requirements.
- Fixed missing optional subtitle providers being reported as configuration failures.
- Fixed replacement API credentials potentially affecting an existing working configuration before validation.
Removed
- Removed
SECURITY_PATCH_NOTES.mdfrom the repository.
v1.0.5
NetWatch 1.0.5
Fixed
- Fixed buffering screen not appearing during large seeks.
- Fixed stream options possibly becoming unclickable after upgrading from 1.0.4.
- Fixed stale packaged runtime detection during upgrades.
- Fixed Prowlarr download URLs exposing API keys to the frontend.
- Fixed DNS rebinding gap in external URL validation.
- Fixed incomplete VPN kill-switch verification.
- Fixed unrestricted player/runtime IPC access between Electron windows.
- Fixed oversized and malformed torrent/search requests reaching backend services.
- Fixed unbounded remote response reads in subtitle and metadata downloads.
- Fixed subtitle cache memory limits.
- Fixed rate-limit bypasses on dynamic metadata routes.
- Fixed VPN peers being able to reach internal control ports inside the VPN namespace.
- Fixed swallowed torrent-engine errors that made debugging failures difficult.
- Replaced the remaining runtime
assertguard with explicit error handling.
Removed
- Removed the obsolete
/await-readytorrent endpoint. - Removed unused torrent, metadata, Prowlarr, and subtitle compatibility code.
- Removed stale backend development and architecture references.
Changed
- Search results now use temporary backend release references instead of exposing provider download URLs.
- Player window now uses a restricted preload and sender-validated IPC.
- Added stricter validation for torrent hashes, search inputs, request sizes, and numeric limits.
- Added rate limiting to TMDB-backed metadata, season, and stream-option routes.
- Added explicit firewall rules blocking VPN-side access to ports
8000,8081,8191, and9696. - Improved VPN firewall verification to check the expected rules and ordering.
- NetWatch backend and torrent-engine containers now drop Linux capabilities and disallow privilege escalation.
- Updated security and network documentation to match the current runtime architecture.
Upgrade Notes
- Upgrading from 1.0.4 may require re-importing the WireGuard configuration once.
v1.0.4
v1.0.4
Hardens Windows prerequisite setup and improves compatibility with endpoint security software.
Changes
- Replaced the PowerShell-based WSL, Ubuntu, and Docker prerequisite flow with a fixed-purpose native Windows helper.
- Removed PowerShell from NetWatch's prerequisite installation path.
- Added installer heartbeat and interruption detection so blocked or terminated setup operations are reported instead of hanging or being mistaken for success.
- Added stronger Ubuntu provisioning checks to distinguish a registered distro from a fully initialized and usable installation.
- Added a safe recovery flow for incomplete Ubuntu first-run setup.
- Preserved NetWatch's existing UAC boundary: Setup remains unelevated and requests elevation only for required WSL machine servicing.
- Preserved Docker download restrictions and Windows signature verification before installation.
- Improved handling of partially completed prerequisite installations without automatically resetting or unregistering user data.
- Updated installer and security documentation for the native prerequisite architecture.
The new prerequisite flow was validated on a clean Windows system with Malwarebytes Real-Time and Exploit Protection enabled at aggressive detection settings.