Skip to content

Releases: JSap0914/kakao-headless

v0.3.0: Guarded image sending

Pre-release

Choose a tag to compare

@JSap0914 JSap0914 released this 15 Sep 15:29

Guarded single-image sending

  • New preview CHAT_ID --image-file FILE --ack-risk command for one PNG or JPEG, up to 10 MiB.
  • Private image snapshot, SHA-256 binding, generic upload filename, and account/recipient revalidation.
  • Durable reservation before a single SHIP → POST → stream → COMPLETE attempt. No high-level retries or extra WRITE.
  • Exact own-history image metadata verification and read-only reconciliation. Ambiguous results never authorize retrying.
  • Updated English documentation and managed Aside skill. Existing text previews and receipts remain supported.

Validation

250 offline tests passed with the actual pinned provider enabled. One approved PNG photo was sent once to an existing direct room, immediately history-verified, then reconciled in a fresh process. An additional read-only download matched the approved image's SHA-256 exactly. The original receipt was preserved; an offline duplicate attempt was blocked before network access. This is not a recipient-read or receiver-rendering claim. JPEG has offline coverage, not a live-send result.

A clean global installation, isolated Aside install/uninstall, and local runtime/managed-skill update were verified. Photo transport deliberately depends on version-checked private modules in agent-messenger@2.37.1.

Verify the tarball with SHA256SUMS-v0.3.0. Install the provider separately as documented. No captions, galleries, video, audio or general file uploads. Image metadata is preserved; remove sensitive metadata before previewing. Unofficial community integration, not an official Kakao or Aside product; account restrictions remain possible.

v0.2.1: English README, new banner and managed Aside installation

Choose a tag to compare

@JSap0914 JSap0914 released this 15 Sep 14:31

Kakao Headless: Read. Approve. Send.

  • English-only README with the new community-integration hero banner.
  • Global CLI installation plus aside install --account N; no manual copying of internal package paths.
  • Managed skill installation, update checks, selective uninstall, and preservation of operator-edited files.
  • Exact runtime paths and explicit local account selection. Publisher namespace is not an account connection.
  • Includes the 0.2.0 features and corrects macOS temporary-directory canonicalization in the new CLI test fixtures without weakening path/symlink checks.

Validation: 207 local tests passed; all five CI jobs passed on the release commit. A clean-prefix global install and offline account installation passed. The local runtime and real Aside account skill were updated and verified. Existing real-account history remains readable; no additional message was sent for this release.

See README for setup and docs/VALIDATION.md for live-test scope. Existing-room text is the supported write scope. This is an unofficial community integration, not an official Kakao or Aside product, and account restrictions remain possible.

Verify the attached tarball with SHA256SUMS-v0.2.1. Install the separate agent-messenger@2.37.1 provider as documented. Distribution is through GitHub Releases, not the npm registry.

v0.2.0: managed Aside integration and a new project identity

Choose a tag to compare

@JSap0914 JSap0914 released this 15 Sep 14:27

Read. Approve. Send.

A cleaner installation experience and a new project identity for Kakao Headless.

What's new

  • English-only README with a new hero banner, a concise quickstart and command reference.
  • kakao-headless aside install --account N: connect an existing Aside account without manually copying node_modules files.
  • aside doctor and aside uninstall: hash-based ownership, exact runtime paths, selective removal, and protection for edited/unmanaged skills.
  • Explicit account selection. The package publisher scope does not connect users to the maintainer's account.
  • Community-integration branding with an attributed Aside icon, not an official partnership claim.

Validation

207 tests passed, including 27 new installer and CLI tests. The documented global install was exercised in a clean prefix with the separate pinned provider, followed by install/doctor against a temporary account. The actual local installation and managed skill were updated to 0.2.0; real-account history still reads correctly. No additional message was sent for this release.

Existing text-send, reconciliation and encrypted token-refresh behavior is unchanged from 0.1.1. See docs/VALIDATION.md for the precise live-testing boundary. This remains an unofficial client with account-restriction risk; attachments, new-room creation and push listeners are not CLI features.

Install from the attached npm-format tarball plus agent-messenger@2.37.1, following README. Verify SHA256SUMS-v0.2.0. The package is not published on the npm registry.

v0.1.1: live-verified reads, guarded sends and encrypted token refresh

Choose a tag to compare

@JSap0914 JSap0914 released this 15 Sep 14:06

KakaoTalk CLI: verified reads, text sending and token rotation

  • Fix safe-integer echoed chat-ID decoding while preserving strict log-ID precision.
  • Add read-only reconcile with exact account/recipient/log/text/type/time checks. Original ambiguous receipts stay intact; no automatic resend.
  • Fix token-refresh persistence using AES-256-GCM encrypted local credentials rooted in the existing Keychain secret. No Keychain ACL changes or direct root updates required.
  • Keep non-secret registration metadata local, so clearing pending login does not require a Keychain mutation.
  • Replace setup-progress wording with installation, authentication, read/send, verification and storage documentation.

Validation

180 local tests passed. Real-account room lookup, message history, forward paging, one approved direct-room text send and read-only reconciliation succeeded. Token refresh, encrypted persistence and fresh-process login/history retrieval also succeeded. The actual durable send reservation blocked another attempt before any network call.

The initial live WRITE returned an ambiguous local receipt; a fresh own-history lookup verified the message. The parser correction is covered by wire-format regression tests. No second message was sent merely to repeat that parser test. These checks do not establish that a recipient read the message.

Text in existing rooms is the supported write scope. Attachments, quoted replies, new rooms and push listeners are not exposed by this CLI. Initial Keychain creation and explicit logout still require normal macOS permissions. Unofficial access carries account-restriction risk.

Install the attached .tgz and the separate pinned provider following README. Verify SHA256SUMS-v0.1.1. No credentials or private conversation data are included in this release.

v0.1.0 alpha: guarded UI-free KakaoTalk bridge

Choose a tag to compare

@JSap0914 JSap0914 released this 15 Sep 11:33
c62dc7d

Experimental alpha: live Kakao verification pending

Original MIT bridge for local, UI-free KakaoTalk text reading/writing through an explicitly installed, pinned LOCO provider. Not affiliated with Kakao and does not alter Aside's built-in connector.

  • macOS Keychain credential storage and two-step phone registration
  • Exact room/member-bound preview and durable single-attempt WRITE reservation
  • Strict packet/body checks, unknown-outcome handling, no WRITE replay
  • Independent history match distinguished from acceptance, delivery and read receipts
  • Aside user skill, security/architecture documentation and CI

Validation: 97 local tests passed, including actual agent-messenger@2.37.1 API/strict-history contract tests with network stubbed. macOS Keychain access and Swift type checking verified. No live account was authenticated and no Kakao message was sent. Use a dedicated test account; unofficial access can cause account restrictions.

Install the attached npm-format tarball into a dedicated local directory, then install agent-messenger@2.37.1 explicitly as described in README. The provider is not bundled and its license metadata requires separate review. This package is not published on the npm registry. Verify SHA256SUMS before installing.