Releases: DanielJohn17/tui-chat
Releases · DanielJohn17/tui-chat
Release list
LineTalk v1.1.0
Release v1.1.0: Security Hardening, Real-Time Presence, Bulk Sync & Terminal Architecture
What's Changed Since v1.0.2
This release introduces comprehensive security hardening (shared secret client authentication, timing attack defense, rate limiting, and IDOR prevention), real-time presence synchronization, high-performance bulk chat loading, terminal layout hardening for narrow screens, and an overhauled modular TUI architecture.
🔒 Security & Authentication
-
Client Shared Secret Authentication:
- Replaced browser-oriented CORS with constant-time SHA-256
ClientSecretAuthmiddleware, comparing digests viasubtle.ConstantTimeCompareto defend against timing attacks and length leaks. - Completely removed
cors.goand purgedgithub.com/gin-contrib/corsdependency. - Enforced mandatory
APP_SHARED_SECRETin.envand production environments ($\ge 32$ characters; placeholder/dev keys strictly blocked). - Outbound REST requests and WebSocket upgrade handshakes now transmit
X-App-Secret. - Added fail-fast build guard in
Makefile(check-secret) and repository secret validation in.github/workflows/release.yml. - (Commit:
57bc2fb)
- Replaced browser-oriented CORS with constant-time SHA-256
-
Authentication Rate Limiting:
- Implemented IP-based token-bucket
AuthRateLimiteron/api/v1/auth/registerand/api/v1/auth/login. - Bound cleaner routine to server graceful shutdown context (
signal.NotifyContext) with periodic 5-minute cleanup of stale IPs. - (Commit:
57bc2fb)
- Implemented IP-based token-bucket
-
Terminal Escape Sequence & Clipboard Sanitization:
- Sanitized incoming messages and usernames to strip ANSI CSI codes and OSC 52 clipboard hijacking payloads before rendering.
- (Commit:
071c585)
-
Client Payload Limit Bounds:
- Enforced strict payload limits on client HTTP responses (2MB standard, 10MB bulk) and WebSocket frames (512KB via
SetReadLimit). - Clamped rendered message text at 8,000 characters to prevent terminal rendering stalls.
- (Commit:
57bc2fb)
- Enforced strict payload limits on client HTTP responses (2MB standard, 10MB bulk) and WebSocket frames (512KB via
-
JWT Secret Enforcement & IDOR Protection:
- Enforced strong, explicit production JWT secret keys (
$\ge 32$ characters, rejecting default fallback). - Enforced conversation participant membership verification on all message fetch endpoints, eliminating IDOR risks.
- (Commit:
57af60f)
- Enforced strong, explicit production JWT secret keys (
-
Direct Conversation Integrity:
- Added PostgreSQL uniqueness constraint migration (
20260928213436_add_direct_conversation_uniqueness.sql) preventing duplicate 1-on-1 direct conversations. - Blocked message writes during conversation deletion.
- (Commit:
de04b29)
- Added PostgreSQL uniqueness constraint migration (
⚡ Real-Time Presence & WebSocket Concurrency
-
Real-Time Online Presence Tracking:
- Implemented peer-targeted
presence_snapshoton WebSocket handshake, emitting online status only for mutual conversation peers. - Added thread-safe
Hub.GetOnlineStatuswithsync.RWMutexfor$O(1)$ memory presence lookups. - Synchronized presence state across HTTP initial fetch and WebSocket event streams.
- Rendered live status indicators in sidebar (
●green for online,○dim for offline). - (Commits:
2fba67b,d500cad,ac633df,49c7ea8)
- Implemented peer-targeted
-
WebSocket Concurrency & Read Receipt Hardening:
- Implemented coalescing background read receipt worker to batch DB updates and prevent WebSocket reader lock contention.
- Synchronized
Client.TrySendandCloseto prevent send-on-closed-channel panics. - Protected
Hub.usersmap operations against concurrent read/write races via read-locking snapshots. - Synchronized
wsMubefore checking connection state, eliminating reader goroutine deadlocks. - Distinguished intentional disconnects from network drops to stop reconnect thrashing upon logout.
- (Commits:
57af60f,071c585)
🚀 Performance & Chat Data Synchronization
- Bulk Chat Loading & Prefetching:
- Added
GET /api/v1/conversations/bulkleveraging SQL window functions (ROW_NUMBER() <= 50) to fetch initial message batches for all conversations in a single HTTP round-trip. - Integrated startup prefetching to eliminate N+1 per-conversation HTTP requests.
- Added animated spinner loading state in chat view when opening un-hydrated chats, with keyboard (
r) and click-to-retry error banners. - (Commit:
63798ab)
- Added
- Unread Count Synchronization:
- Fixed parameter validity flags in
MarkConversationReadParamsto properly clear unread counters in DB on mark as read. - (Commit:
3c17b2e)
- Fixed parameter validity flags in
- Deleted Users Archival:
- Added migration
20260929153702_fix_archive_deleted_row_trigger.sqlaligning DB archival trigger schema with soft-deleted users. - (Commit:
57bc2fb)
- Added migration
🖥️ Terminal UI Hardening & Visual Experience
- Narrow Viewport Zero-Wrapping Layout:
- Rewrote layout calculations across
app.go,chat.go,sidebar.go,header.go,footer.go, andstatusbar.go. - Preserved exact terminal width invariant (
sidebarWidth + chatWidth == w) on viewports under 100, 70, 50, and 45 columns without horizontal line wrapping. - (Commit:
57bc2fb)
- Rewrote layout calculations across
- Modular App Architecture:
- Decomposed monolithic
internal/tui/app.gointo specialized handlers:connection.go,data_sync.go,modals_handler.go,mouse.go,state_handlers.go, andws_events.go. - Added Telegram-style reconnection countdown timer, animated spinner, and
● LIVEstatus indicator. - Implemented status bar notification banners with 5-second auto-clear timer and terminal bell (
\a). - Added global
Ctrl+H/F1shortcuts for modal help access while in input mode. - Fixed sidebar focus retention when new inbound messages dynamically sort chats to the top.
- (Commit:
bab56dc)
- Decomposed monolithic
- Dark OLED Theme Enforcement & Password Hints:
- Enforced
#0B0C10default dark background across entire viewport for contrast consistency on light-themed terminals. - Fixed ANSI SGR reset handling in theme renderer to preserve 24-bit RGB and 256-color codes.
- Added dynamic real-time password requirement checklist hints on the registration view.
- Local session profile and status/bio edits persistence with explicit sync feedback.
- (Commits:
af81450,57bc2fb)
- Enforced
🛠️ Tooling, Build & CI/CD
- Build System & Ldflags:
- Updated
Makefilewithcheck-secretbuild guard and compiled-inDefaultAppSecret. - Automated release artifact cross-compilation for Linux (amd64, arm64, 386, arm), Windows (amd64, arm64, 386), and macOS (amd64, arm64).
- Added
.air.tomlconfiguration for live server reloading during backend development. - (Commits:
006d976,9089a6d,57bc2fb)
- Updated
- GitHub Actions Workflows:
- Upgraded
.github/workflows/ci.ymlandrelease.ymlwith Go 1.27 environment alignment. - Added automated secret validation step in release builds to guarantee binaries are never released without client authentication secrets.
- Configured CI with valid non-placeholder secret to pass production config validation.
- (Commits:
9089a6d,57bc2fb,41ff9e0)
- Upgraded
Detailed Commit Log
| Commit | Description |
|---|---|
41ff9e0 |
ci: use valid non-placeholder APP_SHARED_SECRET in test and build steps |
57bc2fb |
feat(security): enforce client shared secret authentication, remove CORS, and harden TUI |
071c585 |
fix: harden ws read receipts, server shutdown, and tui terminal security |
de04b29 |
fix(api): enforce dm uniqueness constraint and block message writes during deletion |
57af60f |
fix(api): address jwt secret fallback, conversation message idor, and ws hub concurrency panics |
af81450 |
feat(tui): enforce default background, add auth checklist hints, and isolate tui tests |
006d976 |
build(api): add air configuration for live reloading |
49c7ea8 |
fix(tui): synchronize online presence state across HTTP and WebSocket |
ac633df |
feat(api/ws): implement peer-targeted presence snapshot and real-time updates |
[3c17b2e](https://github.com/Danie... |
v1.0.2
Full Changelog: v1.0.1...v1.0.2
Full Changelog: v1.0.1...v1.0.2
v1.0.1
v1.0.0
What's Changed
- Feat/tui chat wireframe by @DanielJohn17 in #1
- experimenting with go websocket by @DanielJohn17 in #2
- Feat/api implementation by @DanielJohn17 in #3
New Contributors
- @DanielJohn17 made their first contribution in #1
Full Changelog: https://github.com/DanielJohn17/tui-chat/commits/v1.0.0