Releases: Adoom666/CloudeCode
Release list
v1.0.36
Ad-hoc signed macOS build produced by .github/workflows/release.yml.
This is a DRAFT. Verify the DMG opens and the menu bar app starts
before publishing.
The build is ad-hoc signed but not notarized, so macOS Gatekeeper
will warn on first launch: "Cloude Code cannot be opened because it
is from an unidentified developer." Right click the app and choose
Open to get past it. This is the same prompt v0.8.1 produced.
v0.8.1 — always spawn a new session on project click
Multiple sessions per project directory
Clicking a project row now always spawns a new session against that directory instead of adopting the session already running there. You can run as many concurrent Claude Code sessions in one working directory as you want.
What changed
SessionManager.create_sessionuniquifies the tmux session name on collision —cloude_foo→cloude_foo-2→cloude_foo-3… (capped at 999) — instead of redirecting intoadopt_external_session.- The collision check is the union of three sources of truth: the live tmux socket, in-memory backends, and the persisted
owned_tmux_sessionsset. That makes it agree withrename_session's own guard, so a name minted at create time can never be rejected by a later rename. - The numeric suffix is appended after name sanitization, so it is never mangled.
Side benefit
Newly spawned sessions are no longer mislabelled with the EXTERNAL badge.
Still works as before
Explicitly attaching to a specific running session (from the running-sessions list) still goes through adopt_external_session — that path is untouched.
Install: download the DMG below, drag to Applications.
shasum -a 256 "Cloude.Code-0.8.1-arm64.dmg"
00f1beb6af6176ce904d3df472d5d6e37b4400736b2e04255cf72dcbcc89cfa5
v0.8.0 — Provider selector (cld / cldor)
Provider selector on session launch
Every path that spawns a new CLI session now opens a provider-selection modal first, so you pick which backend the session runs on instead of always getting the default.
- claude — launches the session through your
cldzsh function (Keychain OAuth token, standard Anthropic endpoint). - any OpenRouter model — launches through
cldor <model>, which points Claude Code at OpenRouter with an isolatedCLAUDE_CONFIG_DIRand maps the opus/sonnet/haiku/subagent model slots to your chosen model.
Models are add- and remove-able inline in the same modal and persist to config.json, so your model list survives restarts and follows the project.
No secrets are ever handled by the app — the Keychain lookup happens inside the zsh function itself.
Rejoining or adopting an already-running tmux session is unchanged (no command is constructed on that path, so no prompt appears).
New API
GET /api/v1/providers— list available providersGET /api/v1/providers/models— list saved OpenRouter modelsPOST /api/v1/providers/models— add a modelDELETE /api/v1/providers/models/{model}— remove a model
UX details
- Full keyboard support: arrow keys, Enter, type-ahead, hover sync.
- Esc closes reliably (capture-phase key handling, avoiding the focus-scoped listener bug).
- CSP-safe — no inline scripts.
Security hardening
- Model IDs are validated with
fullmatch, which rejects trailing newlines and leading dashes that could otherwise be smuggled into the launch command as options. showConfirmModalnow escapes title, message, and details centrally, closing an HTML-injection path in confirmation dialogs.
Install (macOS, Apple Silicon): download the DMG below, open it, drag Cloude Code to Applications.
shasum -a 256 "Cloude.Code-0.8.0-arm64.dmg"
db4e27391539c7b207f67802e206cd3d7775298f93b24b87a1291e2023ffe034
v0.7.5 — Folder picker UX
Open-from-folder picker
- Type-ahead navigation — start typing and the list jumps to the first folder with a matching prefix (accumulating buffer, 800ms reset, case-insensitive); arrow keys move the selection, Enter opens. Inactive while the path bar is focused.
- Editable path bar — type any path and press Enter to jump straight there (supports
~); the bar stays in sync as you browse. - Auto
mkdir -p— type a path that doesn't exist and it's created and opened in one step.
Under the hood
- New auth-gated
POST /api/v1/filesystem/mkdirendpoint (pathlib, returns the new dir listing);browsenow returns 404 for missing/non-directory paths. - Folder names are now HTML-escaped in the list (hardening).
SHA-256: 236a08f7d0b7f1b5e80ce421ed1c16f2b1cbc6b50036d513b2d842c10b2807e0
Note: signed (Apple Dev, Team 3ZVEJNEQ9G) but not notarized — on first launch use right-click → Open to bypass Gatekeeper.
v0.7.4 — fix /clear context wipe on session rejoin
Fixes
- Session rejoin no longer wipes your context. Clicking back into an active session used to send two
Ctrl+L(0x0c) redraws within 2 seconds — one from the server handshake, one from the client. That tripped Claude Code's built-in double-Ctrl+L/clearchord, which silently typed/clearand cleared the session. The redundant client-side redraw is removed; the server handshake redraw is now the single source, so a rejoin can never trigger the chord. Validated at the byte level (exactly one 0x0c per rejoin). (client/js/terminal.js) - Web-client version chip now reads from
package.json.
Install (Apple Silicon)
Download Cloude.Code-0.7.4-arm64.dmg below.
sha256: 954d4b2662e5651a7e872f043fd25b7e30fead9d107aa2320be816d9f81b371c
v0.7.3 — Auth: Stop OTP Re-Prompt After Short Sleeps
What's new in v0.7.3
Fix
- Auth: stop OTP re-prompt after short laptop sleeps. Access token TTL bumped from 15 minutes to 4 hours so typical sleep durations no longer expire the access token while the laptop is napping. Refresh token TTL unchanged at 7 days. For a single-user LAN dev tool gated by first-pair TOTP, the 4h window aligns with realistic work sessions.
- Refresh path hardened. Transient post-wake Wi-Fi glitches (NIC re-associating after sleep) no longer nuke the refresh token and force re-OTP:
Auth.refresh()returns tri-state and distinguishes network errors from HTTP auth errors. Network errors preserve the refresh token.handleUnauthorized()(REST + image upload) only clears the access token on network error and surfaces a recoverableNetworkUnavailableerror — no OTP modal.- WebSocket
onclosewith code4401now refresh-first via the single-flight mutex BEFORE reconnect, so the reconnect storm uses a fresh token from the first attempt instead of hammering the server with stale credentials.
Security
Server-side refresh-rotation chain-burn-on-reuse defense, token signing (HS256), token storage (localStorage), and validation strictness all unchanged. The TTL extension is a deliberate UX/security trade-off bounded by the existing threat model (single-user LAN tool, TOTP-gated, no public exposure).
Install
Download the DMG attached below, mount, drag Cloude Code.app to Applications.
Verification
shasum -a 256 "Cloude Code-0.7.3-arm64.dmg"
# expected: 204c171661f71bd0762158d0bac0569797436b3ce91b616c8986e442b6283107
Notes
- DMG is signed (Developer ID Application) but not notarized (consistent with prior 0.7.x releases). On first launch macOS Gatekeeper may show a warning — right-click the app and choose Open to bypass.
- Apple Silicon (arm64) only.
- v0.7.0, v0.7.1, v0.7.2 remain available as prior releases for rollback.
v0.7.2 — Rejoin-Scroll Fix + Theme Audio + tmux Mouse Scope Fix + Polish
What's new in v0.7.2 (patch on top of v0.7.1)
Fixes
- tmux session rejoin snaps the viewport to the bottom of the replayed scrollback (most recent output) instead of pinning at the top. Defense-in-depth: programmatic-scroll lock + double-rAF defer + multi-pin schedule survives the WebSocket connect dance's repeated fitAddon.fit() calls.
- tmux mouse option scope corrected from session-scoped (
-s) to global (-g) so mouse mode is enabled across all panes consistently.
Features
- Theme audio plumbing — sound effects tied to themes (optional, toggleable in launchpad)
- Backend scrollback capture endpoint —
GET /api/v1/sessions?include_scrollback=1serves base64-encodedtmux capture-pane -p -e -J -S -output for clean session rejoin replay - Launchpad pencil-icon inline rename for running sessions (no longer requires leaving the launchpad)
Internal
- New test coverage for the rejoin-scrollback route (
tests/test_session_rejoin_scrollback.py) - Manual QA documentation for the audio toggle flow
- Regenerated README reflecting all v0.7.0 + v0.7.1 + v0.7.2 functionality
Install
Download the DMG attached below, mount, drag Cloude Code.app to Applications.
Verification
shasum -a 256 "Cloude Code-0.7.2-arm64.dmg"
# expected: 4f6638acf63645e6a631572b120119e6ea1b804337bbea68e2180d4b4422c3d7
Notes
- DMG is unsigned and not notarized (consistent with all prior releases). Right-click → Open on first launch to bypass Gatekeeper.
- Apple Silicon (arm64) only.
- v0.7.0 and v0.7.1 remain available as prior releases.
v0.7.1 — Native tmux scroll fix
What's fixed
Native tmux scroll actually works now. v0.6.1 added set-option -s mouse on to the cloude socket on session start, but tmux's mouse is a session-scope option, not server-scope. The -s call silently no-op'd (because check=False swallowed the error), leaving mouse off even though the WheelUpPane / WheelDownPane bindings were installed correctly. tmux only routes wheel events to those bindings when mouse mode is on — so the bindings were never reached. One-character fix: -s → -g. Verified live: tmux -L cloude show-options -gv mouse now returns on.
Install
```
shasum -a 256 "Cloude.Code-0.7.1-arm64.dmg"
expected: d62775ccf3d5d7de28b5310bda9181f380f4935f8a1f35d9b4cbaa9ba541ae4a
```
v0.7.0 — Project themes + toast notifications + Claude Code hooks + Slack
What's new
Project-scoped themes. Theme is now keyed by PROJECT (the session's working_dir), not by tmux session. Canonical store: <working_dir>/.cc.theme — a one-line file containing the theme id. Server reads on attach, writes on theme change, atomic. Same project on two laptops → same theme. Old pinned_themes.json kept as fallback for one release with auto-migration on first attach; will be removed in v0.8.x. New endpoint PATCH /sessions/{name}/theme; old /pinned-theme route still works as a deprecated alias.
Toast notifications in-browser. Claude Code lifecycle events (Stop, PermissionRequest, Notification) now surface as toast popups in every browser attached to that session. Toasts stay open until acknowledged. Acking on one tab dismisses on every other tab attached to the same session (WS broadcast). Toast color comes from the project's theme accent so you can tell at a glance which session needs you.
Claude Code hook integration. cloudecode now writes a managed hook block into ~/.claude/settings.json on startup (marker-tagged so it won't clobber your own hooks). Each spawned session gets a per-session HMAC token (CLOUDECODE_HOOK_TOKEN) and id (CLOUDECODE_SESSION_ID) injected as env vars; hooks curl back to a new loopback-only /hooks/claude-event endpoint that validates the token and creates a toast. Opt-out: notifications.disable_claude_hooks: true in config.
Slack incoming-webhook fanout. Every Claude Code lifecycle event also POSTs to a Slack incoming webhook URL configured at notifications.slack_webhook_url. Single channel, no OAuth, fire-and-forget. Disabled silently when the URL is empty.
Install
```
shasum -a 256 "Cloude.Code-0.7.0-arm64.dmg"
expected: f328081ab8f18fa2ed7de67e9033a9f5a6de7a3633804e17eeaef81da7a5961e
```
Tests
86 new pytest cases. Full suite: 348 passed, 1 failed (pre-existing unrelated).
v0.6.1 — Scrollback replay + mid-stream scroll + native tmux scroll
What's fixed
Browser scrollback replay no longer jumbled. Resuming a session in the browser used to paint a misaligned mess (duplicated lines at multiple rows, truncated leading columns) because the captured bytes carried alt-screen escape sequences that xterm had no prior state for. Three coordinated fixes: tmux capture-pane no longer joins wrapped lines (drop -J); a screen-reset preamble (\x1b[?1049l\x1b[2J\x1b[H) is written before the replay so the xterm parser starts clean; a Ctrl+L follow-up fires 50ms after the WS opens so the live app (Claude's TUI) repaints fresh on top of the replayed history. scrollback_lines default also bumped 3000 → 10000.
Mid-stream scroll-up works. While Claude was streaming output, scrolling up would snap the viewport back to the bottom on every chunk. The wheel handler was racing the scroll-listener's 100ms debounce; the PTY flush cycle was faster. Fixed by flipping autoScrollEnabled = false synchronously inside the wheel handler. Scroll-to-bottom still re-engages auto-follow.
Server-side desktop tmux scroll. When sitting at the Mac in a native terminal attached to a -L cloude session, the mouse wheel was being forwarded to whatever TUI was in the pane (Claude → cycle prompt history). Now set -s mouse on is set on the cloude socket and WheelUpPane / WheelDownPane are bound to enter copy-mode when the pane is in alt-screen. The browser path is unaffected.
Install
```
shasum -a 256 "Cloude.Code-0.6.1-arm64.dmg"
expected: 466ff38454bc0e51a791fec8347bc813fd51a7ed8d25223b7d0f106870bd9999
```