Skip to content

v1.15.0

Choose a tag to compare

@EXIST-D EXIST-D released this 08 Oct 09:24
· 6 commits to main since this release

Optional reading on a phone through the user's own server. Data stays V1/V2; no migration is needed.

Added

  • web --token-file <file> --public-origin https://<site>: the reader still binds to loopback, takes a fixed token from a
    root-readable file (never printed to logs) and accepts the public site's Origin, for use behind an HTTPS reverse proxy
    that asks for a login and adds the token.
  • web --login-file: a login page for the hosted reader (one account, scrypt hash, signed HttpOnly/Secure/SameSite=Strict
    session cookie for 14 days, sign-out button, lockout after repeated failures; a new password signs every device out).
  • web --banks-dir <dir>: several people on one server, each account reading only its own bank; login files hold
    several accounts (format 2; the single-account format still loads).
  • Reading-first Web design: phone list and full-screen reader with previous/next, swipe and back gesture; three columns
    on wide screens (sidebar with overview, study views, topics and tools, inline filters, reader); key points with
    their sources; optional think-first mode; placeholders that explain how to import, answer and export via the agent.
  • tools/deploy/: a hardened systemd unit (unprivileged user, read-only filesystem except the bank, starts only once a
    login exists), nginx snippets that add the token and client address and rate-limit logins, set-login.py (accounts:
    add, passwd, remove, list; passwords typed on the server), sync.sh (a bank's data, config and manifest to one
    account) and backup.sh with a daily systemd timer (14 verified backups per bank).
  • web.md: “Reading on your own server”.

Changed

  • The Web page loads its assets and calls its API by relative paths, so it also works under a path such as /ibank/;
    the brand link stays inside the reader, and a read-only notice takes precedence over the V1 notice.