Skip to content

Releases: DanielJohn17/tui-chat

LineTalk v1.1.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 22:38

Release v1.1.0: Security Hardening, Real-Time Presence, Bulk Sync & Terminal Architecture

What's Changed Since v1.0.2

This release introduces comprehensive security hardening (shared secret client authentication, timing attack defense, rate limiting, and IDOR prevention), real-time presence synchronization, high-performance bulk chat loading, terminal layout hardening for narrow screens, and an overhauled modular TUI architecture.


🔒 Security & Authentication

  • Client Shared Secret Authentication:
    • Replaced browser-oriented CORS with constant-time SHA-256 ClientSecretAuth middleware, comparing digests via subtle.ConstantTimeCompare to defend against timing attacks and length leaks.
    • Completely removed cors.go and purged github.com/gin-contrib/cors dependency.
    • Enforced mandatory APP_SHARED_SECRET in .env and production environments ($\ge 32$ characters; placeholder/dev keys strictly blocked).
    • Outbound REST requests and WebSocket upgrade handshakes now transmit X-App-Secret.
    • Added fail-fast build guard in Makefile (check-secret) and repository secret validation in .github/workflows/release.yml.
    • (Commit: 57bc2fb)
  • Authentication Rate Limiting:
    • Implemented IP-based token-bucket AuthRateLimiter on /api/v1/auth/register and /api/v1/auth/login.
    • Bound cleaner routine to server graceful shutdown context (signal.NotifyContext) with periodic 5-minute cleanup of stale IPs.
    • (Commit: 57bc2fb)
  • Terminal Escape Sequence & Clipboard Sanitization:
    • Sanitized incoming messages and usernames to strip ANSI CSI codes and OSC 52 clipboard hijacking payloads before rendering.
    • (Commit: 071c585)
  • Client Payload Limit Bounds:
    • Enforced strict payload limits on client HTTP responses (2MB standard, 10MB bulk) and WebSocket frames (512KB via SetReadLimit).
    • Clamped rendered message text at 8,000 characters to prevent terminal rendering stalls.
    • (Commit: 57bc2fb)
  • JWT Secret Enforcement & IDOR Protection:
    • Enforced strong, explicit production JWT secret keys ($\ge 32$ characters, rejecting default fallback).
    • Enforced conversation participant membership verification on all message fetch endpoints, eliminating IDOR risks.
    • (Commit: 57af60f)
  • Direct Conversation Integrity:
    • Added PostgreSQL uniqueness constraint migration (20260928213436_add_direct_conversation_uniqueness.sql) preventing duplicate 1-on-1 direct conversations.
    • Blocked message writes during conversation deletion.
    • (Commit: de04b29)

⚡ Real-Time Presence & WebSocket Concurrency

  • Real-Time Online Presence Tracking:
    • Implemented peer-targeted presence_snapshot on WebSocket handshake, emitting online status only for mutual conversation peers.
    • Added thread-safe Hub.GetOnlineStatus with sync.RWMutex for $O(1)$ memory presence lookups.
    • Synchronized presence state across HTTP initial fetch and WebSocket event streams.
    • Rendered live status indicators in sidebar (● green for online, ○ dim for offline).
    • (Commits: 2fba67b, d500cad, ac633df, 49c7ea8)
  • WebSocket Concurrency & Read Receipt Hardening:
    • Implemented coalescing background read receipt worker to batch DB updates and prevent WebSocket reader lock contention.
    • Synchronized Client.TrySend and Close to prevent send-on-closed-channel panics.
    • Protected Hub.users map operations against concurrent read/write races via read-locking snapshots.
    • Synchronized wsMu before checking connection state, eliminating reader goroutine deadlocks.
    • Distinguished intentional disconnects from network drops to stop reconnect thrashing upon logout.
    • (Commits: 57af60f, 071c585)

🚀 Performance & Chat Data Synchronization

  • Bulk Chat Loading & Prefetching:
    • Added GET /api/v1/conversations/bulk leveraging SQL window functions (ROW_NUMBER() <= 50) to fetch initial message batches for all conversations in a single HTTP round-trip.
    • Integrated startup prefetching to eliminate N+1 per-conversation HTTP requests.
    • Added animated spinner loading state in chat view when opening un-hydrated chats, with keyboard (r) and click-to-retry error banners.
    • (Commit: 63798ab)
  • Unread Count Synchronization:
    • Fixed parameter validity flags in MarkConversationReadParams to properly clear unread counters in DB on mark as read.
    • (Commit: 3c17b2e)
  • Deleted Users Archival:
    • Added migration 20260929153702_fix_archive_deleted_row_trigger.sql aligning DB archival trigger schema with soft-deleted users.
    • (Commit: 57bc2fb)

🖥️ Terminal UI Hardening & Visual Experience

  • Narrow Viewport Zero-Wrapping Layout:
    • Rewrote layout calculations across app.go, chat.go, sidebar.go, header.go, footer.go, and statusbar.go.
    • Preserved exact terminal width invariant (sidebarWidth + chatWidth == w) on viewports under 100, 70, 50, and 45 columns without horizontal line wrapping.
    • (Commit: 57bc2fb)
  • Modular App Architecture:
    • Decomposed monolithic internal/tui/app.go into specialized handlers: connection.go, data_sync.go, modals_handler.go, mouse.go, state_handlers.go, and ws_events.go.
    • Added Telegram-style reconnection countdown timer, animated spinner, and ● LIVE status indicator.
    • Implemented status bar notification banners with 5-second auto-clear timer and terminal bell (\a).
    • Added global Ctrl+H / F1 shortcuts for modal help access while in input mode.
    • Fixed sidebar focus retention when new inbound messages dynamically sort chats to the top.
    • (Commit: bab56dc)
  • Dark OLED Theme Enforcement & Password Hints:
    • Enforced #0B0C10 default dark background across entire viewport for contrast consistency on light-themed terminals.
    • Fixed ANSI SGR reset handling in theme renderer to preserve 24-bit RGB and 256-color codes.
    • Added dynamic real-time password requirement checklist hints on the registration view.
    • Local session profile and status/bio edits persistence with explicit sync feedback.
    • (Commits: af81450, 57bc2fb)

🛠️ Tooling, Build & CI/CD

  • Build System & Ldflags:
    • Updated Makefile with check-secret build guard and compiled-in DefaultAppSecret.
    • Automated release artifact cross-compilation for Linux (amd64, arm64, 386, arm), Windows (amd64, arm64, 386), and macOS (amd64, arm64).
    • Added .air.toml configuration for live server reloading during backend development.
    • (Commits: 006d976, 9089a6d, 57bc2fb)
  • GitHub Actions Workflows:
    • Upgraded .github/workflows/ci.yml and release.yml with Go 1.27 environment alignment.
    • Added automated secret validation step in release builds to guarantee binaries are never released without client authentication secrets.
    • Configured CI with valid non-placeholder secret to pass production config validation.
    • (Commits: 9089a6d, 57bc2fb, 41ff9e0)

Detailed Commit Log

Commit Description
41ff9e0 ci: use valid non-placeholder APP_SHARED_SECRET in test and build steps
57bc2fb feat(security): enforce client shared secret authentication, remove CORS, and harden TUI
071c585 fix: harden ws read receipts, server shutdown, and tui terminal security
de04b29 fix(api): enforce dm uniqueness constraint and block message writes during deletion
57af60f fix(api): address jwt secret fallback, conversation message idor, and ws hub concurrency panics
af81450 feat(tui): enforce default background, add auth checklist hints, and isolate tui tests
006d976 build(api): add air configuration for live reloading
49c7ea8 fix(tui): synchronize online presence state across HTTP and WebSocket
ac633df feat(api/ws): implement peer-targeted presence snapshot and real-time updates
[3c17b2e](https://github.com/Danie...
Read more

v1.0.2

Choose a tag to compare

@github-actions github-actions released this 21 Sep 23:56

Full Changelog: v1.0.1...v1.0.2

Full Changelog: v1.0.1...v1.0.2

v1.0.1

Choose a tag to compare

@github-actions github-actions released this 21 Sep 23:17

Full Changelog: v1.0.0...v1.0.1

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 21 Sep 22:14

What's Changed

New Contributors

Full Changelog: https://github.com/DanielJohn17/tui-chat/commits/v1.0.0