Lyrenne v2.10.0
New: setup on first launch
Lyrenne now walks you through setup the first time you open it. It signs you in, then asks where you want downloads to go, what theme and audio quality you like, your region, and whether you use Discord or Last.fm. Everything it asks is still in Settings afterwards, and you can run it again from Settings > System.
If you already use Lyrenne you won't see it. It only shows up on a fresh install.
One thing the setup now says out loud, because it caught people out: when the browser asks about cookies during sign in, choose Accept all. That's how Lyrenne signs in, it reads those cookies once and then throws the browser profile away. If the browser offers to save your password afterwards you can say no, that part doesn't matter.
Security fixes
Three things I found going over the app:
- The updater followed redirects without checking they stayed on HTTPS and on GitHub. It downloads a zip, unpacks it over your install and runs it, so that needed locking down. It now refuses anything that isn't HTTPS on a GitHub host, on every hop.
- Signing out wasn't really signing out. The browser profile Lyrenne creates to log you in was never deleted, so a working Google session sat in your data folder even after you signed out. It was also about 87 MB. It's now cleaned up when you sign in, when you sign out, and once at startup to clear out old ones.
- The update script broke if your install path had a
$in it, and could have run something it shouldn't have. Paths are quoted properly now.
Also the Last.fm password field was showing your password as you typed. Fixed.
Faster and lighter
- Album art is cached to disk now. It was being re-downloaded every single time you opened the app.
- Memory is capped. Lyrenne was sitting around 455 MB because the JVM helps itself to a quarter of your RAM if you don't tell it not to.
- Library lists no longer redraw everything when you search or sort.
Upgrading
Auto update handles it, or grab the zip below and extract over your existing folder. Your library and login carry over.