Dulus 3.11.5
Dulus 3.11.5
Fixed
- Sign-in is device-code now, everywhere. The loopback PKCE callback (127.0.0.1) broke logins whenever the browser was not the same machine — and landed everyone else on a raw localhost page. CLI
/login, the startup sign-in gate, and the GUI login all use the OAuth device grant: approve from any device./login loopbackkeeps the old flow. - TLS in the desktop build. The frozen app could die with CERTIFICATE_VERIFY_FAILED against Auth0. Python now uses the Windows trust store (truststore; opt out with DULUS_NO_TRUSTSTORE=1).
- AskUserQuestion/permission answers land through the webchat auth guard — no more agents stuck until the 300s timeout.
- Kimi hosts updated (api.kimi.com → api.kimi.ai) across harvester, auth and endpoints.
SHA256: see Dulus-3.11.5-windows-setup.exe.sha256