Skip to content

v0.44.0

Choose a tag to compare

@KIvanow KIvanow released this 17 Sep 10:13
· 56 commits to master since this release
d196deb

Release Notes - v0.44.0

Changes since v0.43.0 (2026-09-09)

🔐 Self-hosted user control

Self-hosted installs gain full authentication and access management, broker sign-in, personal tokens, and settings polish.

  • Sign-in required on self-hosted installs (#432) - better-auth + Kysely integration with bootstrap-only sign-up, automatic owner promotion, IP-based rate limiting, and new workspace status / me endpoints. Fails closed when auth isn't configured.
  • Roles & read-only members (#433) - role decorators and a roles guard make members read-only over HTTP; CLI and monitor WebSocket sockets now require an authenticated session. Mutating controls are locked in the web UI for read-only members.
  • Invitations & Team page (#434) - hashed one-time invite tokens, invite links, an invite-acceptance page, and a Team page for managing members. Hardened against IP spoofing and orphaned users.
  • Activity log (#437) - records workspace mutations, sign-ins/sign-outs, invite acceptances, and browser CLI commands. New Activity tab and GET /workspace/activity for admins, with cursor paging and a daily prune. Sensitive command arguments (CONFIG, ACL, MIGRATE) and payloads are never stored.
  • Personal MCP tokens (#455) - users can create and revoke owner-scoped MCP bearer tokens, plus first-registration / sign-in / member-removal telemetry.
  • Broker sign-in with Google or GitHub (#456, #457) - sign in through the BetterDB broker using signed, embedded-key-verified handoff tokens. New /auth/broker/start and /auth/broker/callback routes; sessions minted via a server-only better-auth plugin.
  • Settings consolidation (#460) - Team and MCP Tokens moved into Settings, with a new account menu.
  • Post-merge authorization hardening (#458) - follow-up fixes addressing review of the user-control authorization work.

🚀 Features

  • Fleet-wide health overview (#453) - new /fleet page backed by GET /fleet/summary, which fans out health + INFO memory/stats across all connections (5s per-instance timeout, 15s cache). Includes status filter, search, sort, 15s polling that pauses when the tab is hidden, click-through to the Dashboard, sidebar navigation, and a g e keyboard chord.
  • Slack and Discord webhook formats (#451) - webhooks can now emit Slack- and Discord-native payloads.

🛡️ Hardening & bug fixes

  • Harden web fetchApi: safe body parsing and opt-in bounded timeout (#445).
  • Handle 204 No Content in fetchApi, fixing a false webhook-delete failure (#452).
  • Reject WebSocket upgrades from untrusted origins; ignore default ports when matching a same-host origin.
  • Drop queued CLI commands after the socket closes; skip CLI commands whose socket closed during actor lookup; record CLIENT arguments only for metadata subcommands.
  • Hide connection controls from read-only members on the empty state.
  • Log the member ID when a broker sign-in undo fails.

What's Changed

  • chore(deps-dev): bump vitest from 4.1.1 to 4.1.11 by @dependabot[bot] in #446
  • fix(web): handle 204 No Content in fetchApi to fix false webhook delete failure by @Kathircpe in #452
  • Harden web fetchApi: safe body parsing, opt-in bounded timeout by @Kathircpe in #445
  • feat(fleet): add fleet-wide health overview by @Kathircpe in #453
  • feature: require sign-in on self-hosted installs (user control phase 1) by @jamby77 in #432
  • feature: read-only members and authenticated CLI/monitor sockets (user control phase 2) by @jamby77 in #433
  • feature: invitations and Team page for self-hosted workspaces (user control phase 3) by @jamby77 in #434
  • feature: activity log for workspace mutations, sign-ins and CLI commands (user control phase 4) by @jamby77 in #437
  • feature: personal MCP tokens and workspace telemetry for self-hosted user control by @jamby77 in #455
  • feature: sign broker handoff tokens for self-hosted sign-in by @jamby77 in #456
  • feature: sign in with Google or GitHub on self-hosted installs by @jamby77 in #457
  • bugfix: address post-merge review of user control authorization by @jamby77 in #458
  • feat(webhooks): add Slack and Discord payload formats by @Kathircpe in #451
  • Move Team and MCP Tokens into Settings and add an account menu by @jamby77 in #460

Full Changelog: v0.43.0...v0.44.0