Repository navigation
v1.15.0
Optional reading on a phone through the user's own server. Data stays V1/V2; no migration is needed.
Added
web --token-file <file> --public-origin https://<site>: the reader still binds to loopback, takes a fixed token from a
root-readable file (never printed to logs) and accepts the public site's Origin, for use behind an HTTPS reverse proxy
that asks for a login and adds the token.web --login-file: a login page for the hosted reader (one account, scrypt hash, signed HttpOnly/Secure/SameSite=Strict
session cookie for 14 days, sign-out button, lockout after repeated failures; a new password signs every device out).web --banks-dir <dir>: several people on one server, each account reading only its own bank; login files hold
several accounts (format 2; the single-account format still loads).- Reading-first Web design: phone list and full-screen reader with previous/next, swipe and back gesture; three columns
on wide screens (sidebar with overview, study views, topics and tools, inline filters, reader); key points with
their sources; optional think-first mode; placeholders that explain how to import, answer and export via the agent. tools/deploy/: a hardened systemd unit (unprivileged user, read-only filesystem except the bank, starts only once a
login exists), nginx snippets that add the token and client address and rate-limit logins,set-login.py(accounts:
add, passwd, remove, list; passwords typed on the server),sync.sh(a bank's data, config and manifest to one
account) andbackup.shwith a daily systemd timer (14 verified backups per bank).- web.md: “Reading on your own server”.
Changed
- The Web page loads its assets and calls its API by relative paths, so it also works under a path such as
/ibank/;
the brand link stays inside the reader, and a read-only notice takes precedence over the V1 notice.