Skip to content

Releases: Adoom666/CloudeCode

v1.0.36

Choose a tag to compare

@Adoom666 Adoom666 released this 09 Sep 23:17

Ad-hoc signed macOS build produced by .github/workflows/release.yml.

This is a DRAFT. Verify the DMG opens and the menu bar app starts
before publishing.

The build is ad-hoc signed but not notarized, so macOS Gatekeeper
will warn on first launch: "Cloude Code cannot be opened because it
is from an unidentified developer." Right click the app and choose
Open to get past it. This is the same prompt v0.8.1 produced.

v0.8.1 — always spawn a new session on project click

Choose a tag to compare

@Adoom666 Adoom666 released this 04 Aug 15:36

Multiple sessions per project directory

Clicking a project row now always spawns a new session against that directory instead of adopting the session already running there. You can run as many concurrent Claude Code sessions in one working directory as you want.

What changed

  • SessionManager.create_session uniquifies the tmux session name on collision — cloude_foo → cloude_foo-2 → cloude_foo-3 … (capped at 999) — instead of redirecting into adopt_external_session.
  • The collision check is the union of three sources of truth: the live tmux socket, in-memory backends, and the persisted owned_tmux_sessions set. That makes it agree with rename_session's own guard, so a name minted at create time can never be rejected by a later rename.
  • The numeric suffix is appended after name sanitization, so it is never mangled.

Side benefit

Newly spawned sessions are no longer mislabelled with the EXTERNAL badge.

Still works as before

Explicitly attaching to a specific running session (from the running-sessions list) still goes through adopt_external_session — that path is untouched.


Install: download the DMG below, drag to Applications.

shasum -a 256 "Cloude.Code-0.8.1-arm64.dmg"

00f1beb6af6176ce904d3df472d5d6e37b4400736b2e04255cf72dcbcc89cfa5

v0.8.0 — Provider selector (cld / cldor)

Choose a tag to compare

@Adoom666 Adoom666 released this 04 Aug 14:54

Provider selector on session launch

Every path that spawns a new CLI session now opens a provider-selection modal first, so you pick which backend the session runs on instead of always getting the default.

  • claude — launches the session through your cld zsh function (Keychain OAuth token, standard Anthropic endpoint).
  • any OpenRouter model — launches through cldor <model>, which points Claude Code at OpenRouter with an isolated CLAUDE_CONFIG_DIR and maps the opus/sonnet/haiku/subagent model slots to your chosen model.

Models are add- and remove-able inline in the same modal and persist to config.json, so your model list survives restarts and follows the project.

No secrets are ever handled by the app — the Keychain lookup happens inside the zsh function itself.

Rejoining or adopting an already-running tmux session is unchanged (no command is constructed on that path, so no prompt appears).

New API

  • GET /api/v1/providers — list available providers
  • GET /api/v1/providers/models — list saved OpenRouter models
  • POST /api/v1/providers/models — add a model
  • DELETE /api/v1/providers/models/{model} — remove a model

UX details

  • Full keyboard support: arrow keys, Enter, type-ahead, hover sync.
  • Esc closes reliably (capture-phase key handling, avoiding the focus-scoped listener bug).
  • CSP-safe — no inline scripts.

Security hardening

  • Model IDs are validated with fullmatch, which rejects trailing newlines and leading dashes that could otherwise be smuggled into the launch command as options.
  • showConfirmModal now escapes title, message, and details centrally, closing an HTML-injection path in confirmation dialogs.

Install (macOS, Apple Silicon): download the DMG below, open it, drag Cloude Code to Applications.

shasum -a 256 "Cloude.Code-0.8.0-arm64.dmg"
db4e27391539c7b207f67802e206cd3d7775298f93b24b87a1291e2023ffe034

v0.7.5 — Folder picker UX

Choose a tag to compare

@Adoom666 Adoom666 released this 27 Jun 00:18

Open-from-folder picker

  • Type-ahead navigation — start typing and the list jumps to the first folder with a matching prefix (accumulating buffer, 800ms reset, case-insensitive); arrow keys move the selection, Enter opens. Inactive while the path bar is focused.
  • Editable path bar — type any path and press Enter to jump straight there (supports ~); the bar stays in sync as you browse.
  • Auto mkdir -p — type a path that doesn't exist and it's created and opened in one step.

Under the hood

  • New auth-gated POST /api/v1/filesystem/mkdir endpoint (pathlib, returns the new dir listing); browse now returns 404 for missing/non-directory paths.
  • Folder names are now HTML-escaped in the list (hardening).

SHA-256: 236a08f7d0b7f1b5e80ce421ed1c16f2b1cbc6b50036d513b2d842c10b2807e0

Note: signed (Apple Dev, Team 3ZVEJNEQ9G) but not notarized — on first launch use right-click → Open to bypass Gatekeeper.

v0.7.4 — fix /clear context wipe on session rejoin

Choose a tag to compare

@Adoom666 Adoom666 released this 23 Jun 23:28

Fixes

  • Session rejoin no longer wipes your context. Clicking back into an active session used to send two Ctrl+L (0x0c) redraws within 2 seconds — one from the server handshake, one from the client. That tripped Claude Code's built-in double-Ctrl+L /clear chord, which silently typed /clear and cleared the session. The redundant client-side redraw is removed; the server handshake redraw is now the single source, so a rejoin can never trigger the chord. Validated at the byte level (exactly one 0x0c per rejoin). (client/js/terminal.js)
  • Web-client version chip now reads from package.json.

Install (Apple Silicon)

Download Cloude.Code-0.7.4-arm64.dmg below.

sha256: 954d4b2662e5651a7e872f043fd25b7e30fead9d107aa2320be816d9f81b371c

v0.7.3 — Auth: Stop OTP Re-Prompt After Short Sleeps

Choose a tag to compare

@Adoom666 Adoom666 released this 25 May 04:03

What's new in v0.7.3

Fix

  • Auth: stop OTP re-prompt after short laptop sleeps. Access token TTL bumped from 15 minutes to 4 hours so typical sleep durations no longer expire the access token while the laptop is napping. Refresh token TTL unchanged at 7 days. For a single-user LAN dev tool gated by first-pair TOTP, the 4h window aligns with realistic work sessions.
  • Refresh path hardened. Transient post-wake Wi-Fi glitches (NIC re-associating after sleep) no longer nuke the refresh token and force re-OTP:
    • Auth.refresh() returns tri-state and distinguishes network errors from HTTP auth errors. Network errors preserve the refresh token.
    • handleUnauthorized() (REST + image upload) only clears the access token on network error and surfaces a recoverable NetworkUnavailable error — no OTP modal.
    • WebSocket onclose with code 4401 now refresh-first via the single-flight mutex BEFORE reconnect, so the reconnect storm uses a fresh token from the first attempt instead of hammering the server with stale credentials.

Security

Server-side refresh-rotation chain-burn-on-reuse defense, token signing (HS256), token storage (localStorage), and validation strictness all unchanged. The TTL extension is a deliberate UX/security trade-off bounded by the existing threat model (single-user LAN tool, TOTP-gated, no public exposure).

Install

Download the DMG attached below, mount, drag Cloude Code.app to Applications.

Verification

shasum -a 256 "Cloude Code-0.7.3-arm64.dmg"
# expected: 204c171661f71bd0762158d0bac0569797436b3ce91b616c8986e442b6283107

Notes

  • DMG is signed (Developer ID Application) but not notarized (consistent with prior 0.7.x releases). On first launch macOS Gatekeeper may show a warning — right-click the app and choose Open to bypass.
  • Apple Silicon (arm64) only.
  • v0.7.0, v0.7.1, v0.7.2 remain available as prior releases for rollback.

v0.7.2 — Rejoin-Scroll Fix + Theme Audio + tmux Mouse Scope Fix + Polish

Choose a tag to compare

@Adoom666 Adoom666 released this 24 May 06:07

What's new in v0.7.2 (patch on top of v0.7.1)

Fixes

  • tmux session rejoin snaps the viewport to the bottom of the replayed scrollback (most recent output) instead of pinning at the top. Defense-in-depth: programmatic-scroll lock + double-rAF defer + multi-pin schedule survives the WebSocket connect dance's repeated fitAddon.fit() calls.
  • tmux mouse option scope corrected from session-scoped (-s) to global (-g) so mouse mode is enabled across all panes consistently.

Features

  • Theme audio plumbing — sound effects tied to themes (optional, toggleable in launchpad)
  • Backend scrollback capture endpoint — GET /api/v1/sessions?include_scrollback=1 serves base64-encoded tmux capture-pane -p -e -J -S - output for clean session rejoin replay
  • Launchpad pencil-icon inline rename for running sessions (no longer requires leaving the launchpad)

Internal

  • New test coverage for the rejoin-scrollback route (tests/test_session_rejoin_scrollback.py)
  • Manual QA documentation for the audio toggle flow
  • Regenerated README reflecting all v0.7.0 + v0.7.1 + v0.7.2 functionality

Install

Download the DMG attached below, mount, drag Cloude Code.app to Applications.

Verification

shasum -a 256 "Cloude Code-0.7.2-arm64.dmg"
# expected: 4f6638acf63645e6a631572b120119e6ea1b804337bbea68e2180d4b4422c3d7

Notes

  • DMG is unsigned and not notarized (consistent with all prior releases). Right-click → Open on first launch to bypass Gatekeeper.
  • Apple Silicon (arm64) only.
  • v0.7.0 and v0.7.1 remain available as prior releases.

v0.7.1 — Native tmux scroll fix

Choose a tag to compare

@Adoom666 Adoom666 released this 20 May 18:59

What's fixed

Native tmux scroll actually works now. v0.6.1 added set-option -s mouse on to the cloude socket on session start, but tmux's mouse is a session-scope option, not server-scope. The -s call silently no-op'd (because check=False swallowed the error), leaving mouse off even though the WheelUpPane / WheelDownPane bindings were installed correctly. tmux only routes wheel events to those bindings when mouse mode is on — so the bindings were never reached. One-character fix: -s → -g. Verified live: tmux -L cloude show-options -gv mouse now returns on.

Install

```
shasum -a 256 "Cloude.Code-0.7.1-arm64.dmg"

expected: d62775ccf3d5d7de28b5310bda9181f380f4935f8a1f35d9b4cbaa9ba541ae4a

```

v0.7.0 — Project themes + toast notifications + Claude Code hooks + Slack

Choose a tag to compare

@Adoom666 Adoom666 released this 20 May 03:28

What's new

Project-scoped themes. Theme is now keyed by PROJECT (the session's working_dir), not by tmux session. Canonical store: <working_dir>/.cc.theme — a one-line file containing the theme id. Server reads on attach, writes on theme change, atomic. Same project on two laptops → same theme. Old pinned_themes.json kept as fallback for one release with auto-migration on first attach; will be removed in v0.8.x. New endpoint PATCH /sessions/{name}/theme; old /pinned-theme route still works as a deprecated alias.

Toast notifications in-browser. Claude Code lifecycle events (Stop, PermissionRequest, Notification) now surface as toast popups in every browser attached to that session. Toasts stay open until acknowledged. Acking on one tab dismisses on every other tab attached to the same session (WS broadcast). Toast color comes from the project's theme accent so you can tell at a glance which session needs you.

Claude Code hook integration. cloudecode now writes a managed hook block into ~/.claude/settings.json on startup (marker-tagged so it won't clobber your own hooks). Each spawned session gets a per-session HMAC token (CLOUDECODE_HOOK_TOKEN) and id (CLOUDECODE_SESSION_ID) injected as env vars; hooks curl back to a new loopback-only /hooks/claude-event endpoint that validates the token and creates a toast. Opt-out: notifications.disable_claude_hooks: true in config.

Slack incoming-webhook fanout. Every Claude Code lifecycle event also POSTs to a Slack incoming webhook URL configured at notifications.slack_webhook_url. Single channel, no OAuth, fire-and-forget. Disabled silently when the URL is empty.

Install

```
shasum -a 256 "Cloude.Code-0.7.0-arm64.dmg"

expected: f328081ab8f18fa2ed7de67e9033a9f5a6de7a3633804e17eeaef81da7a5961e

```

Tests

86 new pytest cases. Full suite: 348 passed, 1 failed (pre-existing unrelated).

v0.6.1 — Scrollback replay + mid-stream scroll + native tmux scroll

Choose a tag to compare

@Adoom666 Adoom666 released this 20 May 02:22

What's fixed

Browser scrollback replay no longer jumbled. Resuming a session in the browser used to paint a misaligned mess (duplicated lines at multiple rows, truncated leading columns) because the captured bytes carried alt-screen escape sequences that xterm had no prior state for. Three coordinated fixes: tmux capture-pane no longer joins wrapped lines (drop -J); a screen-reset preamble (\x1b[?1049l\x1b[2J\x1b[H) is written before the replay so the xterm parser starts clean; a Ctrl+L follow-up fires 50ms after the WS opens so the live app (Claude's TUI) repaints fresh on top of the replayed history. scrollback_lines default also bumped 3000 → 10000.

Mid-stream scroll-up works. While Claude was streaming output, scrolling up would snap the viewport back to the bottom on every chunk. The wheel handler was racing the scroll-listener's 100ms debounce; the PTY flush cycle was faster. Fixed by flipping autoScrollEnabled = false synchronously inside the wheel handler. Scroll-to-bottom still re-engages auto-follow.

Server-side desktop tmux scroll. When sitting at the Mac in a native terminal attached to a -L cloude session, the mouse wheel was being forwarded to whatever TUI was in the pane (Claude → cycle prompt history). Now set -s mouse on is set on the cloude socket and WheelUpPane / WheelDownPane are bound to enter copy-mode when the pane is in alt-screen. The browser path is unaffected.

Install

```
shasum -a 256 "Cloude.Code-0.6.1-arm64.dmg"

expected: 466ff38454bc0e51a791fec8347bc813fd51a7ed8d25223b7d0f106870bd9999

```