Repository navigation
v0.44.0
Release Notes - v0.44.0
Changes since v0.43.0 (2026-09-09)
🔐 Self-hosted user control
Self-hosted installs gain full authentication and access management, broker sign-in, personal tokens, and settings polish.
- Sign-in required on self-hosted installs (#432) - better-auth + Kysely integration with bootstrap-only sign-up, automatic owner promotion, IP-based rate limiting, and new workspace status /
meendpoints. Fails closed when auth isn't configured. - Roles & read-only members (#433) - role decorators and a roles guard make members read-only over HTTP; CLI and monitor WebSocket sockets now require an authenticated session. Mutating controls are locked in the web UI for read-only members.
- Invitations & Team page (#434) - hashed one-time invite tokens, invite links, an invite-acceptance page, and a Team page for managing members. Hardened against IP spoofing and orphaned users.
- Activity log (#437) - records workspace mutations, sign-ins/sign-outs, invite acceptances, and browser CLI commands. New Activity tab and
GET /workspace/activityfor admins, with cursor paging and a daily prune. Sensitive command arguments (CONFIG, ACL, MIGRATE) and payloads are never stored. - Personal MCP tokens (#455) - users can create and revoke owner-scoped MCP bearer tokens, plus first-registration / sign-in / member-removal telemetry.
- Broker sign-in with Google or GitHub (#456, #457) - sign in through the BetterDB broker using signed, embedded-key-verified handoff tokens. New
/auth/broker/startand/auth/broker/callbackroutes; sessions minted via a server-only better-auth plugin. - Settings consolidation (#460) - Team and MCP Tokens moved into Settings, with a new account menu.
- Post-merge authorization hardening (#458) - follow-up fixes addressing review of the user-control authorization work.
🚀 Features
- Fleet-wide health overview (#453) - new
/fleetpage backed byGET /fleet/summary, which fans out health + INFO memory/stats across all connections (5s per-instance timeout, 15s cache). Includes status filter, search, sort, 15s polling that pauses when the tab is hidden, click-through to the Dashboard, sidebar navigation, and ag ekeyboard chord. - Slack and Discord webhook formats (#451) - webhooks can now emit Slack- and Discord-native payloads.
🛡️ Hardening & bug fixes
- Harden web
fetchApi: safe body parsing and opt-in bounded timeout (#445). - Handle
204 No ContentinfetchApi, fixing a false webhook-delete failure (#452). - Reject WebSocket upgrades from untrusted origins; ignore default ports when matching a same-host origin.
- Drop queued CLI commands after the socket closes; skip CLI commands whose socket closed during actor lookup; record CLIENT arguments only for metadata subcommands.
- Hide connection controls from read-only members on the empty state.
- Log the member ID when a broker sign-in undo fails.
What's Changed
- chore(deps-dev): bump vitest from 4.1.1 to 4.1.11 by @dependabot[bot] in #446
- fix(web): handle 204 No Content in fetchApi to fix false webhook delete failure by @Kathircpe in #452
- Harden web fetchApi: safe body parsing, opt-in bounded timeout by @Kathircpe in #445
- feat(fleet): add fleet-wide health overview by @Kathircpe in #453
- feature: require sign-in on self-hosted installs (user control phase 1) by @jamby77 in #432
- feature: read-only members and authenticated CLI/monitor sockets (user control phase 2) by @jamby77 in #433
- feature: invitations and Team page for self-hosted workspaces (user control phase 3) by @jamby77 in #434
- feature: activity log for workspace mutations, sign-ins and CLI commands (user control phase 4) by @jamby77 in #437
- feature: personal MCP tokens and workspace telemetry for self-hosted user control by @jamby77 in #455
- feature: sign broker handoff tokens for self-hosted sign-in by @jamby77 in #456
- feature: sign in with Google or GitHub on self-hosted installs by @jamby77 in #457
- bugfix: address post-merge review of user control authorization by @jamby77 in #458
- feat(webhooks): add Slack and Discord payload formats by @Kathircpe in #451
- Move Team and MCP Tokens into Settings and add an account menu by @jamby77 in #460
Full Changelog: v0.43.0...v0.44.0