Releases: DimaVasilenko-Intune/Portra
Releases · DimaVasilenko-Intune/Portra
Release list
0.7.0
Add customer sorting: custom order, A-Z, Z-A, most used (#1) Closes #1. The list could only ever show insertion order. Four modes, chosen from a control next to the search box and remembered between launches: - Custom order — the stored order, now rearrangeable by dragging a card. - Name A-Z / Z-A — system locale collation, so Nordic users get æ/ø/å in the right place, and numeric so "Customer 2" precedes "Customer 10". - Most used — by how often the customer's portals have been opened, breaking ties on most recently opened and then name so the order is stable. Sorting is a view concern and never rewrites the stored order, so switching to A-Z and back leaves a hand-arranged list intact. Dragging is only offered in custom mode with no active search, since reordering a sorted or filtered list has no meaningful result — the list says so when a search hides it. "Most used" needs usage data, so each customer now carries openCount and lastOpenedAt, incremented locally when a portal opens. Counted on your machine only; nothing leaves it, and the counters survive an export/import round-trip rather than resetting everyone's history. One bug found while testing the drag path: the dragged id was React state, so dragover and drop read a stale value when they fired in the same tick as dragstart. Moved it to a ref, with the dataTransfer payload as a fallback. 18 new tests cover the sort modes, the reorder helper, locale and numeric ordering, tie-breaking, non-mutation, and counter normalisation on import. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
0.6.2
Repo and bundle hygiene for a public repo with real users Audited the public repo for leaked secrets: all 47 files ever committed, plus every commit's content, scanned for keys, tokens, certificates, connection strings and private keys. Nothing found. No repository secrets are configured, so CI has nothing to leak. Screenshots use Contoso, not real customers. Hardening, since the repo is public and other people run this: - .gitignore now blocks Portra's own data and exports (customers.enc, portra-export*.json), which contain customer names and admin usernames, and signing material (*.p12, *.pfx, *.pem, *.key, .env). None of this was ever committed; this stops the first accident. - Added .github/SECURITY.md so vulnerabilities get reported privately rather than in a public issue — Portra holds admin sessions for other people's tenants, so a public report exposes them before a fix exists. It also lists the two known, documented limitations so they are not re-reported as findings. - Stopped shipping electron/dataFormat.test.js inside the app bundle, and moved react/react-dom to devDependencies: Vite bundles them into dist/, so electron-builder was packaging a second unused copy. app.asar is now 1.9 MB. Verified the packaged app still renders and runs. - build/** narrowed to build/icon.* so the entitlements plist stops shipping. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
0.6.1
v0.6.1 Fix session isolation break, add workspace sign-out, document real po…
0.5.3
v0.5.3 v0.5.3: Spoof Chrome user agent for portal windows — fixes Microsoft …
0.5.2
v0.5.2 v0.5.2: Fix WebAuthn/FIDO2/YubiKey — enable flags, permissive permiss…
0.5.1
v0.5.1 v0.5.1: Single username per customer, passkey/YubiKey support, cleane…
0.5.0
v0.5.0 v0.5.0: Built-in isolated browser per workspace, regenerated icons, c…
0.4.8
v0.4.8 Prefer Chromium browsers + login_hint and update security docs
0.4.7
v0.4.7 Standard set + multi-add portal support + icon alignment
0.4.6
v0.4.6 Remove duplicate Endpoint Manager portal