Skip to content

Releases: Latestinssan/Aartiq

Aartiq Browser v0.3.8

Choose a tag to compare

@github-actions github-actions released this 04 Oct 16:05

🚀 Aartiq Browser v0.3.8

Release Date: October 4, 2026
Codename: Palisade
Channel: Stable — promoted from v0.3.8-beta.1, which carried local listener authentication; this build adds everything merged after the beta.

✨ New Features

  • The Agent API grew from 30 to 36 tools across 11 categories, and Deep Research became a real job — the agent could click and type but could not read the page it was already on, search, or fill a form. It now can: page_find searches an already-open page with no network request (search is real egress — it sends the user's query to a third party and returns somebody else's page, which is the wrong trade when the answer is on screen), dom_query and get_page_text read the tab through the same redaction and injection filtering as the rest of the read path, web_search/news_search report which provider is configured and whether it scrapes, and filling and submitting are two tools rather than one with a flag — fill_form carries the input verb and never submits, form_submit is sideEffecting and goes through the approval gate, so a caller cannot reach the side effect by passing a parameter. Refs bind by a data-aartiq-ax stamp with backendNodeId as first-priority identity and fail loudly when stale instead of scripting whatever element now sits where the target used to be. Deep Research runs plan → search → fetch → extract claims → cross-verify → rank → generate with every collaborator injected so the pipeline tests without network access: the claim is the unit of verification, keyed on subject|verb so two conflicting figures stay one claim with a disagreement rather than being averaged away, corroboration requires ≥2 distinct domains re-derived from each claim's own URLs (uk.reuters.com and news.reuters.com are one source, not two), and a "last source" is named only when publication dates are real — otherwise "unknown", with the reason attached. Three of the bugs this work shipped with were found by tests written before the fix (typeScript threw a bare clearFirst on every type_ref, contenteditable detection reported plain divs as filled, and a fallback could fill or submit an arbitrary form).
  • Master PIN is stored in the native OS keychain — a 6-digit PIN hashed with PBKDF2-SHA256 (100,000 iterations, 32-byte derived key, cryptographically random salt). Desktop keeps it in Apple Keychain / Windows DPAPI / Linux Secret Service via Electron safeStorage, mobile in the Android Keystore (flutter_secure_storage with encryptedSharedPreferences). The raw PIN never leaves the device — only salt and hash travel over the sync channel — and five consecutive failures trigger a 10-minute lockout with a live countdown.
  • Pair once, stay paired — the first authenticated pairing mints a 256-bit permanent token (crypto.randomBytes(32)), and later connections over Wi-Fi or the cloud validate it without asking for a code or an approval again. Paired devices are kept in a ledger with model, illustration and permanentSync: true across restarts, and the pairing handshake itself is unit-tested on both sides (tests/pairing-auth.test.js, pairing_auth.dart).
  • Dual-gate approvals from the phone — the new 📱 Mobile button delegates an execution plan to a paired device. The plan arrives with risk tiers (Critical / High / Medium / Low), per-step shell blocks, factors and mitigations, and authorising it needs both gates: the Master PIN, and Android's own screen lock or biometrics (local_auth). Desktop resolves the pending promise in real time over IPC + WebSocket the moment the phone confirms.
  • Unified session manager — an EventEmitter singleton tracks open tabs, navigation history, running and finished automation tasks and granted permissions, streams them live to the phone, and persists archives to OS application-data directories with atomic writes.
  • The Firebase device bridge: same Google account, devices find each other — each device publishes its P2P id at devices/<uid>/<deviceId>/p2pId, the peer reads it back and signals land in p2p_signals/<uid>/<p2pId>, so two devices signed into the same Google account need no manual address exchange. Both derive the same pairing master key from pairing/<uid>/masterKey, and a signal that does not verify against that key is dropped, not passed through. Permission requests and session sync relay through Firebase as the fallback when the phone is not on the LAN.
  • Real device identity in the UI — native OS friendly computer name ("Sandip's MacBook Pro"), the phone's hardware model, and illustrated devices (MacBook, iMac, Android phone, iPhone) with live status and permanent-sync badges on both sides.

🐛 Bug Fixes

  • The desktop app could not start on Linux — setupLinuxIPCHandlers() registered five linux: IPC channels that main.js then registered again at module scope. Electron's ipcMain.handle throws on a second registration of a channel, the call was not wrapped in a try, and it ran at module top level, so the main process stopped executing at linux:notify, before the window was created. macOS and Windows were unaffected, which is why it went unnoticed. main.js's copies are the ones kept rather than the module's, because they carry a process.platform !== 'linux' check answering { error: 'Not Linux' } on the other two platforms where setupLinuxIPCHandlers() never runs — removing those instead would have traded a Linux-only crash for every preload invoke on macOS and Windows rejecting with No handler registered. Not confirmed by booting the AppImage; the fix is backed by a test that calls the real registration function.
  • iOS could not initialise Firebase at all — GoogleService-Info.plist was never referenced by Runner.xcodeproj, so it never reached the app bundle, and Info.plist carries no inline keys while AppDelegate.swift initialises nothing. Firebase.initializeApp() had nothing to configure from and iOS sign-in could not work. PRODUCT_BUNDLE_IDENTIFIER was also com.aartiq-com.aartiq while the plist declares com.aartiq, which Firebase treats as fatal; it is now aligned across Debug, Release and Profile.
  • Flutter versionCode was pinned at 10 — pubspec.yaml had drifted to 0.3.5+10 against a package.json at 0.3.7, and no workflow passed --build-number, so every Play upload since v0.3.5 was a version-code conflict. sync-version.ts now derives it from semver, and auto-tag.yml fails the release if the two versions disagree.
  • An approval ticket could be redeemed twice — consumeTicket in src/lib/approval-gate.js is async, and its only await sat between the check that a ticket was unconsumed and the mark that consumed it. Eight simultaneous redemptions of one ticket returned eight successes. The claim now happens above the first await: JavaScript runs synchronous statements without interleaving another async caller, so deleting the ticket there is the atomic claim. The hash check still runs afterwards and a mismatch still fails closed.
  • Closing the desktop control window no longer strands the phone — the pairing code was regenerated on every desktop start, so a phone holding the previous code was answered "Invalid pairing code" after each relaunch, and sync events were addressed to the window captured at registration time — which is what disconnected mobile clients when the control window closed. The code now persists in the app store and is read back on start, and every handler resolves the live window at send time instead of holding a captured one.
  • Waiting for AI output could hang forever — send-prompt reported success to the phone while remote-ai-prompt never reached the renderer, so the phone waited for output that could never arrive. The events now follow the live window, and the regression test makes send-prompt fail when the renderer was never reached.
  • Approval tickets were hardened after the atomic-claim fix — ticket ids come from a module-global counter plus the timestamp, so two gate instances built in the same millisecond no longer mint the same id; inputs are hashed over a recursive canonical JSON that understands arrays, numbers, booleans and null, so an equivalent input with a different key order still matches while a genuinely different input still fails closed; and consumed tickets are tracked with a TTL and swept by a periodic cleanup so the set cannot grow without bound.

⚡ Changes

  • iOS 13 and 14 are no longer supported — the deployment target is 15.0 in the Podfile and the Xcode project, with a post_install hook forcing every pod target to match. Xcode 27 refuses to build any target below 15.0 and the pods still declared 9.0 to 13.0, so the build failed before compiling a file. Nothing relied on the older versions.
  • The Claude Desktop config must be regenerated — the session token now travels in the mcp-remote URL, because mcp-remote accepts a bare URL and nothing else. The token regenerates on every Aartiq start, so a config written before this upgrade is answered with 401 until Auto-Configure is run again. The setup screens say so and show the current URL.
  • Existing shell grants migrate on first load — a grant for a command that can still take one is kept and narrowed to that exact command line; a grant for a network-capable, script-capable or destructive command is dropped and each drop is written to the audit log. Grants made deliberately in Settings → Permissions are untouched.
  • The browser ships Apache-2.0 everywhere — the repository root, the README badge and GitHub's API all reported Apache-2.0 while aartiq-browser/LICENSE.txt was a restrictive EULA — the file the Windows NSIS installer displays. The installer's licence text is now byte-identical to the root Apache-2.0 text, package.json declares "license": "Apache-2.0", and the replaced EULA is preserved verbatim in `doc...
Read more

Aartiq Browser v0.3.8-beta.1 — Palisade

Choose a tag to compare

@github-actions github-actions released this 04 Oct 10:03
72085f0

🚀 Aartiq Browser v0.3.8

Release Date: October 4, 2026
Codename: Palisade
Channel: Pre-release — published as v0.3.8-beta.1. v0.3.7 remains the current stable release until this is promoted, and the Firebase download links were not repointed by the beta.

🐛 Bug Fixes

  • The desktop app could not start on Linux — setupLinuxIPCHandlers() registered five linux: IPC channels that main.js then registered again at module scope. Electron's ipcMain.handle throws on a second registration of a channel, the call was not wrapped in a try, and it ran at module top level, so the main process stopped executing at linux:notify, before the window was created. macOS and Windows were unaffected, which is why it went unnoticed. main.js's copies are the ones kept rather than the module's, because they carry a process.platform !== 'linux' check answering { error: 'Not Linux' } on the other two platforms where setupLinuxIPCHandlers() never runs — removing those instead would have traded a Linux-only crash for every preload invoke on macOS and Windows rejecting with No handler registered. Not confirmed by booting the AppImage; the fix is backed by a test that calls the real registration function.
  • iOS could not initialise Firebase at all — GoogleService-Info.plist was never referenced by Runner.xcodeproj, so it never reached the app bundle, and Info.plist carries no inline keys while AppDelegate.swift initialises nothing. Firebase.initializeApp() had nothing to configure from and iOS sign-in could not work. PRODUCT_BUNDLE_IDENTIFIER was also com.aartiq-com.aartiq while the plist declares com.aartiq, which Firebase treats as fatal; it is now aligned across Debug, Release and Profile.
  • Flutter versionCode was pinned at 10 — pubspec.yaml had drifted to 0.3.5+10 against a package.json at 0.3.7, and no workflow passed --build-number, so every Play upload since v0.3.5 was a version-code conflict. sync-version.ts now derives it from semver, and auto-tag.yml fails the release if the two versions disagree.
  • An approval ticket could be redeemed twice — consumeTicket in src/lib/approval-gate.js is async, and its only await sat between the check that a ticket was unconsumed and the mark that consumed it. Eight simultaneous redemptions of one ticket returned eight successes. The claim now happens above the first await: JavaScript runs synchronous statements without interleaving another async caller, so deleting the ticket there is the atomic claim. The hash check still runs afterwards and a mismatch still fails closed.

⚡ Changes

  • iOS 13 and 14 are no longer supported — the deployment target is 15.0 in the Podfile and the Xcode project, with a post_install hook forcing every pod target to match. Xcode 27 refuses to build any target below 15.0 and the pods still declared 9.0 to 13.0, so the build failed before compiling a file. Nothing relied on the older versions.
  • The Claude Desktop config must be regenerated — the session token now travels in the mcp-remote URL, because mcp-remote accepts a bare URL and nothing else. The token regenerates on every Aartiq start, so a config written before this upgrade is answered with 401 until Auto-Configure is run again. The setup screens say so and show the current URL.
  • Existing shell grants migrate on first load — a grant for a command that can still take one is kept and narrowed to that exact command line; a grant for a network-capable, script-capable or destructive command is dropped and each drop is written to the audit log. Grants made deliberately in Settings → Permissions are untouched.

🔒 Security

  • Local listeners now require a credential — the MCP browser bridge listened on every interface and answered every route without one, and pairing completed the moment any client opened the SSE stream. It now binds 127.0.0.1, requires a server-generated per-process token on every route including SSE, validates Host and any browser Origin against an allow-list, and logs rejections with the reason, method and path but never a token value. The route that accepted a caller-chosen token is gone. The same checks now cover the Agent API HTTP server and the native macOS bridge, whose CLI token already existed but which no route read. x-agent-id remains an identifier, not an authenticator.
  • Shell commands no longer auto-run — Aartiq created session grants for low and medium shell commands on every start, with an eight-hour lifetime and no setting controlling it. Because the classifier treated every non-destructive command as medium, cp, mv, mkdir, npm, git, curl and osascript ran unprompted for eight hours after each launch. Those grants are no longer created; auto-approval is now the autoApproveLowRiskShell setting, default off, covering read-only commands only.
  • The risk classifier gained a low tier — it previously returned high for a destructive pattern and medium for everything else, so low was never produced for a shell command. Network- and script-capable commands (curl, wget, npm, npx, git, node, python, osascript) are not low; an unrecognised command is medium, never low; a command line containing a URL is never low; chmod stays high. The per-command table now lives in one file read by both the classifier and the documentation generator.
  • "Allow Always" now applies to one command — grants were keyed on the first word, so answering "Always" to one curl authorised every later curl. Grants are keyed on the whole command line, and eligibility is an allow-list of binaries the classifier knows rather than a deny-list, so an unclassified binary is offered Allow Once only. That command is medium precisely because nothing is known about it, and a grant which promises to repeat something nobody can describe is a promise about behaviour rather than about the text. Nothing becomes unusable: Allow Once always works.
  • The Android upload keystore was in a public repository and has been rotated — it was committed in plaintext at flutter_browser_app/android/app/keystore-base64.txt, so it has been extractable by anyone since it was created. Rotation is what closed the hole: untracking does not, and neither would rewriting history, because anyone who cloned already has the old key. Two ignore rules were also wrong, which is why the file stayed tracked after a commit claimed to have gitignored Firebase config — one matched ios/Runner/GoogleService-Info.plist while the file lives at ios/GoogleService-Info.plist, and nothing covered keystore-base64.txt because the existing patterns only matched *.jks and *.keystore.
  • X-Aartiq-Native-Token is accepted again — it is the header the shipped CLI and the macOS native panels send, and the first cut of the token gate did not read it, so every native-bridge request was answered with 401 after upgrade.

⚠️ Known Limitations

  • Android users may have to uninstall before updating, and this could not be verified from the repository. If release APKs were signed directly with the upload key and Play App Signing was never enrolled, Android cannot update an existing install across a key change. If Play App Signing is enrolled, the rotated key is only the upload key and existing installs update normally. Check the Play Console before describing the Android upgrade as seamless.
  • The Android keystore remains retrievable from git history. A history purge would not help anyone who already cloned, so it was left out of scope deliberately.
  • Five linux: IPC channels are registered once and invoked by nothing — linux:get-desktop, linux:shortcut-action, linux:speak, linux:get-voices and linux:start-voice. Fixing the startup crash removed the duplication, not the dead channels.
  • The approval-ticket fix reached a module with no callers, so no user was affected and it is not a live vulnerability. The approval path the app actually uses is src/core/approval-ticket-manager.js, whose redeemTicket is fully synchronous and therefore has no interleaving point. Ticket ids there can still collide between two ApprovalGate instances built in the same millisecond; the id scheme is unchanged.
  • Four features are marked works with neither a test nor a signed-off manual check, so no page may present them as available: apple-intelligence.generate-image, apple-intelligence.summary, http-api.native-bridge, keyboard.global-hotkeys. One manual check, siri.appintents, is unsigned.
  • docs:check runs only when a person runs it. It is not wired into any GitHub workflow, so it protects a commit only by being remembered.
  • Written up as issue drafts in aartiq-browser/docs-audit/issues/: allow-always-granularity.md, remote-mode-auth-design.md, wifi-sync-bind-address.md, pdf-sync-bind-address.md, pairing-token-in-url.md.

🧪 Testing & CI

  • Full suite: 980 passed, 26 skipped, 0 failed across 35 suites on this tag.
  • tests/local-server-auth.test.js (44 cases, real sockets), tests/shell-command-tiers.test.js (193), tests/shell-approval-defaults.test.js (61), tests/docs-sync-match-source.test.js (17), tests/approval-gate-concurrency.test.js (11), tests/linux-ipc-registration.test.js (6).
  • The credential header list is pinned by a test that reads the shipped clients rather than a copy of their header, so a client that changes what it sends fails the suite instead of the app.
  • tests/linux-ipc-registration.test.js calls the real setupLinuxIPCHandlers() against an Electron stub whose ipcMain.handle throws on a duplicate, exactly as the real one does. This test could not exist before: the module named a parameter interface, a reserved word in strict mode, so Jest could not load the file at all.
  • The classifier's four invariants are asserted directly against the table, so the c...
Read more

Aartiq Browser v0.3.7

Choose a tag to compare

@github-actions github-actions released this 13 Sep 14:43

🚀 Aartiq Browser v0.3.7

Codename: AppContainer
Channel: Stable
Release Date: September 13, 2026

✨ New Features

  • Windows OS-Level Sandboxing — The Windows sandbox now provides the same OS-enforced isolation as macOS (Seatbelt) and Linux (bubblewrap). Commands run as an AppContainer under a restricted, Low-integrity token inside a verified Job Object.
  • Hardened macOS & Linux sandboxes — Seatbelt now denies AF_UNIX sockets and mounts, confines signals and executable mappings; bubblewrap adds user/cgroup namespaces and a new session.

🔒 Security

  • OS-enforced directory allowlist — the AppContainer's package SID is the only principal granted access to allowlisted directories, the workspace, and the resolved executable (icacls ACL grants). Every other path stays denied at the kernel level. Grants are revoked and the AppContainer profile deleted after each run.
  • Restricted token — dangerous privileges (SeDebug, SeImpersonate, SeLoadDriver, …) are deleted from the token; the Low mandatory integrity label is applied. Traversal privilege is retained so allowlisted paths still resolve.
  • AppContainer launch — the process is created SUSPENDED as an AppContainer via the SECURITY_CAPABILITIES startup-info attribute list (Microsoft LaunchAppContainer pattern) and only resumed after verified Job Object assignment.
  • Network denied by default — zero AppContainer capabilities means no network sockets; high/critical-risk commands get "deny all network" on every platform.
  • Isolated temp state — TEMP/TMP/LOCALAPPDATA are rerouted into the per-run AppContainer profile folder.
  • macOS (Seatbelt) hardening — profiles additionally (deny system-socket) for AF_UNIX IPC, (deny signal) confined to self/children, (deny file-map-executable) mirroring the exec allowlist, and (deny file-write-mount file-write-umount).
  • Linux (bubblewrap) hardening — namespaces expanded from pid/net/ipc/uts to also include user and cgroup, plus --new-session; the capability pre-flight probes the same expanded flags and fails closed.
  • Fail closed — any sandbox-construction failure (profile, SID, ACL, process creation, job verification) denies the command with SANDBOX_SETUP_FAILED. There is no unsandboxed fallback.
  • Results now report isolation: { filesystem: true, network: true, process: true } on all three platforms, plus appContainer, restrictedToken, and integrityLevel fields on Windows.

🧪 Testing & CI

  • The sandbox suites run on all three runners: windows-latest (real AppContainer), macos-latest (real Seatbelt enforcement, incl. AF_UNIX + signal confinement runtime proofs), and ubuntu-latest (bubblewrap; runtime blocks skip where the runner restricts user namespaces).
  • macOS runtime tests prove a sandboxed process cannot bind AF_UNIX sockets or signal host processes, while self-signalling still works.

📝 Documentation

  • README, CHANGELOG, and the security audit report document the AppContainer sandbox, the hardened macOS/Linux profiles, and the remaining platform testing caveats (no honest overselling).

📥 Download Installers

Desktop

Platform File
🪟 Windows Aartiq.Browser.Setup.*.exe
🪟 Windows (Store/AppX) *.msix
🪟 Windows Microsoft Store
🍎 macOS Apple Silicon *-arm64.dmg
🍎 macOS Intel *-x64.dmg
🐧 Linux Aartiq.Browser-*.AppImage

Claude Desktop

Platform File
🤖 Claude Desktop aartiq-mcp-extension.mcpb (double-click to install)

Mobile

Platform File
📱 Android app-release.apk
🍎 iOS Aartiq.ipa

Built with ❤️ by Latestinssan

Aartiq Browser v0.3.6

Choose a tag to compare

@github-actions github-actions released this 19 Aug 18:02

🚀 Aartiq Browser v0.3.6

Release Date: August 19, 2026
Codename: Aegis
Channel: Stable

image ## ✨ New Features
  • Agent API Tool Server — Browser capabilities are exposed to AI agents through a single, security-enforced tool registry served over two transports: MCP (Model Context Protocol) for clients such as Claude Desktop, and HTTP for local scripts, the in-product assistant, and remote access over Tailscale / LAN.
  • Security-Enforced Tool Calls — Every tool call (navigation, tab control, form filling, extension management, snapshots, theming, OS actions) is routed through the SecurityPipeline before it runs. The pipeline checks agent trust, enforces the origin/verb policy (fail-closed), and scans tool output for prompt injection.
  • Multiple Agents, One Browser — More than one agent can connect to the same browser. Each connection gets a trust level that scopes its verbs and origins. A per-tab lock manager prevents two agents from driving the same tab at once.
  • Accessibility Snapshots with Stable @ref Ids — Agents receive an AX (accessibility) tree where each interactive node carries an identity-bound @ref id derived from the page's backend node id. References stay stable across snapshots and are never reused; a stale reference fails loudly instead of acting on the wrong element.
  • Encrypted Autofill Vault — Credentials and profiles are stored in an AES-GCM vault keyed by a passphrase-derived key (the same E2EE2 scheme used elsewhere). A field matcher maps page inputs to stored values by autocomplete token, name, type, and label without exposing unrelated entries. Filling requires an explicit user action or approval.
  • Chrome Extension Import + CRX3 Verification — Extensions can be loaded from an on-disk unpacked directory or installed from the Chrome Web Store. Web Store packages are validated as CRX3: the signature is verified with the embedded public key (RSA-SHA256, as Chromium's sandboxed_unpacker does) before any code is loaded. Packages that fail verification or request disallowed permissions are rejected.
  • UI Themes and Modes — Selectable themes plus UI modes (normal, focus, reader, zen, presentation) that change what is shown and how the assistant presents itself, independent of the automation capabilities.
  • Local Model Providers — LM Studio (OpenAI-compatible) and Ollama can run models on-device; an OpenClaw-compatible local-agent bridge is supported for agent logic without a cloud provider.

🐛 Bug Fixes

  • Agent-trust gating no longer fails open: the SecurityPipeline and AgentRegistry now share one AgentTrustRegistry, so a registered agent's trust level is actually enforced at the tool gate (previously the gate read an empty registry and allowed actions).
  • Agent API tool registry tab-lock test now shares one AgentRegistry across contexts, so the second-agent lock rejection is exercised correctly.
  • Autofill vault tests use a passphrase that satisfies the vault's minimum length requirement.

⚡ Changes

  • New src/lib/agent-api/ modules: types, registry, bridge, providers, tools, server, bootstrap — the tool registry, transports, and main-process wiring.
  • New src/lib/guardrails/ modules: prompt-injection, origin-guard, agent-trust, spotlight plus a SecurityPipeline that ties them into one gate.
  • New src/lib/agent/ modules: agent-registry (multi-agent coordination) and tab-lock (per-tab leases with timeout and handoff).
  • New src/lib/snapshot/ (AX-tree collection with identity-bound @ref), src/lib/autofill/matcher + vault, src/lib/extensions/chrome-importer + crx-verifier + permission-analyzer, and src/lib/theme/resolver.
  • main.js starts the Agent API during app readiness, wrapped so a failure there never blocks the browser.
  • The new modules compile to runnable CommonJS via tsconfig.agentapi.json.

📝 Documentation

  • README documents the Agent API & Tool Server, multi-agent support, AX-tree snapshots, form filling, CRX3-verified extension install, UI themes/modes, and local model providers.
  • Security section updated to describe the new guardrails and the agent tool-gate, and to stay explicit about what the test suite does and does not prove.

🔒 Security

  • Fail-closed origin/verb policy — an agent action is denied unless an explicit policy permits it; the kill switch denies everything.
  • Agent-trust scoping — each connected agent is limited to the verbs and origins its trust level allows; unknown agents have no capabilities.
  • Prompt-injection scan — tool output that may carry attacker-controlled web content is scanned and quarantined on detection before it reaches the model.
  • CRX3 signature verification — Web Store extension packages are verified (RSA-SHA256 over signed data, extension id = SHA-256 of public key) before any code loads; verification failure rejects the package.
  • Encrypted autofill vault — stored credentials are AES-GCM encrypted under a passphrase; plaintext is never written to disk.
  • Per-tab locking — two agents cannot act on the same tab concurrently; the lock is leased with a timeout and supports explicit handoff.
  • Tests cover the prompt-injection guard, origin/verb policy, agent-trust registry, CRX3 verifier, autofill vault, accessibility snapshots, and multi-agent tab locking. These confirm the security logic behaves as designed; they are not a substitute for a formal audit.

📦 Downloads

Platform File
🪟 Windows Aartiq.Browser.Setup.*.exe or .msix
🪟 Windows Microsoft Store
🍎 macOS Apple Silicon *-arm64.dmg
🍎 macOS Intel *-x64.dmg
🐧 Linux Aartiq.Browser-*.AppImage
📱 Android app-release.apk

Built with ❤️ by Latestinssan

Aartiq Browser v0.3.5

Choose a tag to compare

@github-actions github-actions released this 23 Jul 08:13

🚀 Aartiq Browser v0.3.5

Release Date: July 22, 2026
Codename: Nebula
Channel: Stable

✨ New Features

  • Directory Allowlist System — AI file access is restricted to explicitly approved directories with fine-grained read/write permissions. Replaces the single hardcoded sandbox-workspace with a dynamic, user-controlled set of directories.
  • Path Canonicalization via fs.realpath() — Resolves symlinks before allowlist checking to prevent symlink traversal attacks. The resolved path is checked, not the user-supplied path.
  • Just-in-Time Permission Prompts — request-directory-access IPC handler requests approval before accessing new directories. Permissions are granted on-demand, not upfront.
  • Batched Multi-Directory Approval — Approve multiple directory paths in a single ticket via CapabilityController. One approval covers all pending directory access requests.
  • Settings UI for Directory Allowlist — Access level dropdown (Read Only / Read & Write), recursive toggle, granted date display, grantedVia badge, and per-entry revoke button in Settings → AI Permissions.
  • OS-Level Sandboxing — Platform-specific sandboxing enforced at the kernel level: Seatbelt profiles on macOS, bubblewrap namespaces on Linux, Job Objects on Windows.
  • Windows AppContainer Sandboxing — Job Objects with process confinement, ACL-based filesystem restrictions via icacls, and Windows Firewall network rules via PowerShell P/Invoke.
  • File Management Handlers — file-move, file-copy, file-open, file-print operations route around the shell sandbox entirely, using Node.js fs APIs directly with isPathAllowed() checks.
  • Vault Migration — Proactive re-encryption of legacy LCL: and E2EE: vault data to the modern E2EE2: format with PBKDF2 600K iterations.
  • Vault Migration IPC Handlers — vault-check-migration and vault-migrate-to-modern for startup migration and manual triggering.

🐛 Bug Fixes

  • CapabilityController.approveAndExecute() now calls approveTicket before redeemTicket — previously the ticket was redeemed without prior approval
  • command-validator.js checkShellPermission() uses real PermissionStore with dependency injection pattern instead of returning hardcoded true
  • execShellCommand() pipeline fixed: validateCommand → checkShellPermission → directory allowlist → executeSandboxed — previously skipped directory allowlist check

⚡ Changes

  • Security model expanded from 3 layers to 6 layers of defense-in-depth
  • PermissionStore allowlist entries now support {path, recursive, access, grantedAt, grantedVia} object format with backward-compatible migration from string format
  • Sandbox profiles generated dynamically from the directory allowlist — no stale cached profiles
  • Environment variables sanitized in all sandboxed processes — API keys, tokens, and secrets are never exposed
  • sandbox-executor.js exports new Windows sandbox functions: generateJobObjectScript, generateFilesystemRestrictionScript, generateNetworkRestrictionScript, createWindowsSandbox
  • preload.js exposes new IPC bridges: vaultCheckMigration, vaultMigrateToModern

📝 Documentation

  • Security page updated with 6 defense-in-depth layers and 10 threat scenarios
  • AI-GUIDE.md updated with new security architecture (layers 4–7)
  • Search index updated with directory allowlist, OS sandboxing, capability-scoped execution, and vault migration entries
  • llms.txt updated with six-layer security description
  • README updated with defense-in-depth layers 4–7

🔒 Security

  • Directory Allowlist prevents AI from accessing sensitive directories outside the approved set
  • Symlink Traversal Attacks blocked via fs.realpath() resolution before allowlist checking
  • Read/Write Separation enforced — read-only grants cannot delete or overwrite files
  • Windows: Job Objects confine processes with process count limits and kill-on-close behavior
  • Windows: ACL-Based Filesystem restrictions deny writes outside allowlisted directories
  • Windows: Firewall Rules block all outbound network except explicitly allowlisted domains
  • macOS: Seatbelt Profiles restrict filesystem writes and network access per execution
  • Linux: bubblewrap creates isolated namespaces with read-only system paths
  • Legacy Vault Data (LCL:, E2EE:) proactively migrated to E2EE2: format with 600K PBKDF2
  • All 35 directory-allowlist tests passing

📦 Downloads

Platform File
🪟 Windows Aartiq.Browser.Setup.*.exe or .msix
🪟 Windows Microsoft Store
🍎 macOS Apple Silicon *-arm64.dmg
🍎 macOS Intel *-x64.dmg
🐧 Linux Aartiq.Browser-*.AppImage
📱 Android app-release.apk

Built with ❤️ by Latestinssan

Aartiq Browser v0.3.4

Choose a tag to compare

@github-actions github-actions released this 20 Jul 08:59

🚀 Aartiq Browser v0.3.4

Release Date: July 20, 2026
Codename: Nebula
Channel: Stable

Downloads

✨ New Features

  • Token-Based Claude Desktop MCP Pairing — Replaced manual PIN-echo flow with secure token-based pairing that auto-confirms when Claude Desktop connects via the local MCP server. User clicks Auto-Configure, restarts Claude Desktop, and pairing happens automatically.
  • MCP Pairing Token with 10-Min Expiry — Generated on auto-configure, sent to local server via POST /pairing/token. Tokens expire after 10 minutes for security.
  • Auto-Confirm on Local SSE Connection — When mcp-remote connects to the SSE endpoint (http://127.0.0.1:3001/sse), the server marks pairing as confirmed. Only local processes can reach 127.0.0.1.
  • Pairing Status UI Polling — UI polls /pairing/status every 2s, shows "Waiting for connection..." → "Claude Desktop connected!" in real time.
  • Searchable Command Palette (⌘K) — Quick access to all actions, settings, and navigation via keyboard.
  • Trust Model — Every action answers 5 trust questions before execution: intent, scope, risk, reversibility, context.
  • Keyboard Shortcuts for AI Controls — Play/pause/stop with global hotkeys for the AI sidebar.
  • Action Cards with Explainability — Each action shows reason, risk level, and required permission in a visual card.
  • Enhanced Agent State Indicator — Visual states for idle, planning, executing, paused, error, and complete.
  • Timestamped Vertical Timeline for Action Chain — Chronological view of all agent actions with timestamps.
  • Smart Message Rendering with Expandable Results — Collapsible tool outputs in chat, code blocks, and structured output display.
  • Workflow Recording and Playback with DOM-Aware Steps — Record browser actions and replay them with live DOM context.
  • AutomationManager Persistence and CRUD — Create, read, update, delete saved automations.
  • DOM Click Element with Multi-Strategy Fallback Chain — Tries multiple click strategies for reliability.
  • MULTI_FILL_FORM Command — Atomic multi-field form filling with optional delay, retry, and verification.
  • Centralized DOM Interaction Engine — Unified API for all DOM operations (click, fill, scroll, extract).

🐛 Bug Fixes

  • Added FILL_FORM, CLICK_AT, SCROLL_TO, MULTI_FILL_FORM, RECORD_WORKFLOW, PLAY_WORKFLOW to COMMAND_REGISTRY
  • Crash-proof main.js PDF templates — simplified generation with source favicons
  • Fixed React hydration errors with ClientOnlyPage wrapper
  • Shell noise hidden — clean progress results instead of raw terminal output
  • SEARCH_RESULTS auto-navigates and reads full page content
  • Removed automatic pre-flight web search — AI now decides when to search
  • Replaced failing web search with MCP backend, skill-based prompt injection, and DOM_SEARCH fallbacks
  • Fixed multiFillForm type signature — now accepts Record<string, string> fields
  • Fixed pullOllamaModel type — callback-based, matches preload implementation
  • Fixed importOllamaModel type — renamed from ollamaImportModel, takes { filePath } object
  • Fixed ollamaListModels return type with proper models array structure
  • Fixed LLMProviderSettings store property mismatches: azureOpenaiApiKey, azureOpenaiEndpoint, azureOpenaiModel
  • Removed non-existent openAppleIntelligence electronAPI call
  • Fixed OPEN_APP routing for VS Code and other desktop applications
  • Fixed Swift type-checker timeout in downloads panel build
  • Resolved all TypeScript build errors in aartiq-browser

⚡ Changes

  • MCP pairing flow simplified: auto-configure → restart Claude → auto-verify (no copy/paste tokens)
  • MCP server auto-confirms pairing on local SSE connection (security boundary: 127.0.0.1 only)
  • Removed manual PIN/prompt copy-paste flow that failed due to LLM safety training
  • Updated electron.d.ts with correct multiFillForm, pullOllamaModel, importOllamaModel, ollamaListModels types
  • Complete UX polish — agent state, action chain, planning screen, compressible steps, action cards, live terminal, permission dialogs, batch permissions, high-risk warnings, auto-approve
  • Tool output bubbles simplified to minimal expandable text in AI sidebar

📝 Documentation

  • Created Claude MCP Architecture guide
  • Updated README for 64-tool MCP server
  • Updated AI-GUIDE.md with v0.3.4 version and token-based pairing workflow
  • Updated changelog with accurate v0.3.4 details

🔒 Security

  • MCP server binds to 127.0.0.1 only — no external network exposure for pairing
  • Pairing tokens expire after 10 minutes
  • Biometric approval (Touch ID / Windows Hello) required for high-risk actions
  • Medium-risk approval required — every action must pass 5 trust questions
  • Per-action approval prompts with native OS dialogs for medium-risk operations
  • Encrypted local vault (AES-256-GCM) with OS keychain backup for credentials

📦 Downloads

Platform File
🪟 Windows Aartiq.Browser.Setup.*.exe or .msix
🪟 Windows Microsoft Store
🍎 macOS Apple Silicon *-arm64.dmg
🍎 macOS Intel *-x64.dmg
🐧 Linux Aartiq.Browser-*.AppImage
📱 Android app-release.apk

Built with ❤️ by Latestinssan

Aartiq Browser v0.3.3

Choose a tag to compare

@Latestinssan2 Latestinssan2 released this 13 Jul 15:05

🚀 Aartiq Browser v0.3.3

Release Date: July 13, 2026
Codename: Nebula
Channel: Stable

Downloads

✨ New Features

  • Claude Desktop MCP Server (64 Tools) — Complete MCP server rewrite: 64 tools across 11 categories (AI chat, tabs, bookmarks, history, settings, scheduling, permissions, security, panels, app knowledge). Claude Desktop gets full control over a running Aartiq browser.
  • MCP HTTP Bridge Architecture — stdio MCP server communicates with the running browser over HTTP (port 46203). All tools require the browser to be running, so Claude gets the full AI pipeline (RAG, web search, PDF, navigation, structured output).
  • MCP AI Sidebar Integration — send_ai_prompt routes through the actual sidebar component for full capabilities: RAG, web search, PDF generation, navigation, structured output.
  • MCP Bookmark Management — Claude can add, list, and remove bookmarks in the running browser.
  • MCP History Access — Claude can browse and clear browsing history.
  • MCP Settings Control — Claude can read and modify any browser setting.
  • MCP Scheduled Tasks — Claude can create, list, toggle, delete, and run scheduled tasks.
  • MCP Permission Management — Claude can list, grant, and revoke permissions.
  • MCP Security Management — Claude can read security settings, update them, and change firewall levels.
  • MCP Panel Control — Claude can open any browser panel (settings, history, bookmarks, downloads, clipboard, permissions, sync, command center).
  • MCP App Knowledge — Built-in explain_feature, list_all_features, get_security_overview tools.
  • MCP Web Search — Real browser-based search with DuckDuckGo default, Google fallback, ad filtering. No API keys required.
  • Standalone MCP Server Package — Claude Desktop extension bundle (.mcpb) with auto-configure.
  • Cross-Platform Native Approval Manager — Windows and Linux dialogs for MCP permission prompts.
  • Native Swift ApprovalCard — QR code, PIN entry, and keyboard shortcuts (Shift+Tab, Esc) for macOS MCP approvals.
  • AI Preference Learning Toggles — Privacy controls for cross-session memory and preference learning.
  • Vector Memory Stats and Clear — View and clear vector memory from settings.
  • Biometric Every Action Toggle — Optional per-action Touch ID approval for high-risk commands.

🐛 Bug Fixes

  • Fixed prompt handler to wait 5s for renderer sidebar pickup before falling back to AiGateway path
  • Reclassified destructive file commands (rm, unlink, del) as high risk instead of silently blocking
  • Fixed MCP web_search stealth browser for Google — avoids bot detection with real browser user agent
  • Fixed MCP web_search to use real browser instead of API keys, default to DuckDuckGo, filter ads, auto-fallback from Google
  • Fixed MCP _getSearchView to return webContents consistently instead of BrowserView
  • PDF generation uses transparent icon, fixes UTF-8 encoding, adds page break rules
  • Fixed MCP server startup ordering and added auto-configure for Claude Desktop
  • Fixed Windows minimize/maximize/close buttons on right side of title bar
  • Fixed TypeScript type errors in SchedulingIntentDetector and automation tests
  • Resolved all TypeScript build errors in aartiq-browser

⚡ Changes

  • Extracted auth handlers from main.js into dedicated auth-handlers.js module
  • Added ~16 bridge endpoints in main.js for sidebar, bookmarks, history, settings, permissions, automation, app-info
  • New bridge-client.js — HTTP client with prompt-wait logic (opens sidebar, sends prompt, polls state until AI responds)
  • MCP manifest and package bumped to v2.0.0
  • Removed extra macOS entitlements (keychain, iCloud, associated-domains, TCC)
  • Replaced sidebar rail with inline three-dot tools dropdown
  • Replaced popup BrowserWindows with IPC-forwarded actions
  • Rebranded Swift native panels from Comet to Aartiq
  • Firebase config loaded from /api/config endpoint instead of env vars

📝 Documentation

  • Rewrote README with badges, comparison table, architecture diagram, and 64-tool MCP table
  • Created Claude Desktop MCP setup guide and available tools documentation
  • Added MCP permission model and approval UX documentation
  • Added v0.3.3 release notes and changelog entry
  • Updated landing page changelog with accurate v0.3.3 details

🔒 Security

  • MCP tool risk classification — Low/Medium/High with corresponding approval UX per tool
  • Destructive file operations (deletion, disk writes) classified as high risk
  • Batch shell approval with per-command toggles and irreversible command warnings
  • Permission approval layer with biometric auth for Claude Desktop MCP tools
  • Approval preload script for MCP approval popup IPC

📦 Downloads

Platform File
🪟 Windows Aartiq.Browser.Setup.*.exe or .msix
🪟 Windows Microsoft Store
🍎 macOS Apple Silicon *-arm64.dmg
🍎 macOS Intel *-x64.dmg
🐧 Linux Aartiq.Browser-*.AppImage
📱 Android app-release.apk

Built with ❤️ by Latestinssan

Aartiq Browser v0.3.2

Choose a tag to compare

@github-actions github-actions released this 10 Jul 13:35

🚀 Aartiq Browser v0.3.2

Release Date: July 10, 2026
Codename: Nebula
Channel: Stable

Downloads

✨ New Features

  • Plugin & Extension System — Dynamic plugin SDK with manifest-based loading, page analyzer plugin, auto-seed, toggle fix, and handler fixes
  • Component Scanner with Code Analysis — Extracts imports, interfaces, hooks, exports, and API usage for per-component live documentation
  • Agent Skill Cards — Modular skill documentation files for automation, browsing, documents, scheduling, security, research, MCP, apple-intelligence, and image generation
  • AI User Preference Auto-Learning — AI detects and remembers user preferences (response style, tone, language, behavior) across sessions
  • SAVE_PREFERENCE Command — AI can persist preferences via SAVE_PREFERENCE:key:value in responses
  • Cross-session RAG Persistence — Past conversations ingested into vector memory and available as RAG context in future sessions
  • Biometric Per-Session Tracking — First low-risk shell action triggers Touch ID; subsequent ones auto-approve within the session
  • Batch Shell Command Approval — Consecutive shell commands in one combined modal with per-command toggles (Select All / Deselect All)
  • Irreversible Command Warnings — Red/amber banners for destructive commands (rm -rf, dd, mkfs, etc.) before approval
  • macOS Siri Shortcuts Bridge — Native Swift binary exposes Aartiq AI commands to Siri and Apple Shortcuts
  • Neural Vault — AES-256-GCM vault encryption with cross-platform native keychain backup (macOS iCloud Keychain / Windows Credential Manager / Linux secret-tool)
  • Autofill Engine — Comprehensive form detection, classification (28+ field types), and credential/card/address autofill
  • Native OS Credential Save Dialogs — macOS NSAlert, Windows .NET Forms, Linux zenity for credential save prompts

🐛 Bug Fixes

  • Fixed Neural Vault save not persisting on macOS — iCloud Keychain sync now fully functional
  • Fixed get-passwords-for-site handler (was referencing non-existent keychain.js)
  • Fixed TypeScript type error in SchedulingIntentDetector (extracted cast to any)
  • Fixed bare return statements in automation tests (replaced with this.skip())
  • Fixed model/provider selection not persisting across restarts — llm-set-active-provider and llm-configure-provider handlers now use correct electron-store keys
  • Fixed get-stored-api-keys returning wrong data shape — frontend can now restore all provider models on startup
  • Fixed extract-page-content race condition with webContents null check retry
  • Fixed Shift+Tab bypass — restricted to non-high-risk commands only
  • Fixed scheduling task CRUD — update, delete, toggle, run methods added to preload
  • Fixed webContents null/destroyed guards in browser-handlers.js IPC handlers
  • Fixed build errors — backtick in template literal, electronAPI type scope, ExtensionManager toggle type mismatch

⚡ Changes

  • Upgraded Electron to v43.1.0
  • Renamed CLI binary from "comet" to "aartiq" in package.json bin field
  • API keys now stored in native OS keychain instead of plaintext electron-store
  • Added build-siri-bridge step to all macOS build and dist scripts
  • Added RAG IPC handlers (ragIngest, ragRetrieve, ragContext) to preload.js
  • Conversations now auto-ingest into BrowserAI vector memory on save for cross-session RAG
  • Component scanner enhanced with deep code analysis (imports, interfaces, hooks, exports)
  • Removed stale release-optimized workflow

🔒 Security

  • Session-scoped biometric authentication — Touch ID required once per session for shell commands
  • Batch shell approval modal with per-command granular control
  • AES-256-GCM vault for sensitive credential storage with OS keychain backup
  • API keys migrated from plaintext electron-store to native OS keychain
  • Mobile high-risk approval relay via sync handlers and cloud messages

📦 Downloads

Platform File
🪟 Windows Aartiq.Browser.Setup.*.exe or .msix
🪟 Windows Microsoft Store
🍎 macOS Apple Silicon *-arm64.dmg
🍎 macOS Intel *-x64.dmg
🐧 Linux Aartiq.Browser-*.AppImage
📱 Android app-release.apk
🍎 iOS Aartiq.ipa

Built with ❤️ by Latestinssan

Aartiq Browser v0.3.1

Choose a tag to compare

@github-actions github-actions released this 07 Jul 13:43

🚀 Aartiq v0.3.1 — AI Preference Learning & Cross-Session RAG

Release Date: July 07, 2026
Channel: Stable
Codename: Nebula

Downloads


🧠 AI Preference Auto-Learning

  • AI now detects and remembers user preferences (response style, tone, language, behavior) across sessions — no manual config needed
  • New SAVE_PREFERENCE command: AI can persist preferences via SAVE_PREFERENCE:key:value in responses
  • Persistent JSON-based storage for AI-observed preferences in userData (via IPC)

🔄 Cross-Session RAG Persistence

  • Past conversations are automatically ingested into BrowserAI vector memory on save
  • Available as RAG context in future sessions for true conversational continuity
  • New RAG IPC handlers (ragIngest, ragRetrieve, ragContext) exposed via preload

💾 Provider Persistence Fixes

  • Fixed: Model/provider selection now persists across restarts — llm-set-active-provider and llm-configure-provider handlers use correct electron-store keys
  • Fixed: get-stored-api-keys returning boolean flags instead of actual model/API key values — frontend can now restore all provider models on startup

🧩 Plugin & Extension System

  • Full plugin SDK with page analyzer, auto-seed, and toggle support
  • Extension manager with type-safe API
  • Component scanner with code analysis — extracts imports, interfaces, hooks, exports, API usage for per-component docs

📚 Documentation

  • README updated with AI user preference and RAG persistence features
  • Landing_Page overview, release notes, search index, and llms.txt updated for v0.3.1
  • AI-GUIDE.md synced to v0.3.1

📥 Download

Desktop

Platform File
🪟 Windows Aartiq.Browser.Setup.*.exe or .msix
🪟 Windows Microsoft Store
🍎 macOS Apple Silicon *-arm64.dmg
🍎 macOS Intel *-x64.dmg
🐧 Linux Aartiq.Browser-*.AppImage

Mobile

Platform File
📱 Android app-release.apk
🍎 iOS Aartiq.ipa

Built with ❤️ by Latestinssan

Aartiq Browser v0.3.0

Choose a tag to compare

@github-actions github-actions released this 07 Jul 08:53

🚀 Aartiq v0.3.0 — Microsoft Store & Security Hardening

Release Date: July 07, 2026
Channel: Stable
Codename: Nebula

Downloads


🎯 Microsoft Store

  • Aartiq is now published on the Microsoft Store — direct install link
  • Automated Windows MSIX build workflow with identity injection for Store submission
  • Self-signed code signing certificate generation for MSIX sideloading
  • MSIX MinVersion set to 10.0.17763.0 per Store requirements
  • Transparent logo for clean MSIX/AppX packaging across Windows and Linux

🛡️ Security Hardening

  • Base64 Payload Decoding: SecureDOMParser now decodes inline base64 strings and re-scans decoded content against all injection patterns — previously raw base64 shell commands passed through undetected
  • Consistent Shell Severity: All shellPrimitives matches (dd, mkfs, shutdown, format, halt, systemctl) now consistently treated as critical and redacted from LLM content
  • Credential URL Regex Fix: Requires URI scheme prefix — eliminates false-positive over-redaction on ordinary text
  • Privacy policy added for Store submission

🪟 Windows Title Bar Redesign

  • Standard minimize/maximize/close buttons replace macOS traffic lights on non-Mac platforms
  • Hover/active states and sizing tuned for native feel across TitleBar, WelcomeScreen, StartupSetupUI

🐛 Bug Fixes

  • BrowserView now preserves cookies/auth across restarts (fixed persistent partition)
  • Settings page crash fixed
  • Navigation detection handles redirect-heavy pages; retry logic for JS-heavy page extraction
  • deepseek-r1 model defaults no longer hardcoded — user must select from installed options
  • WelcomeScreen broken IPC icon load fixed (uses direct URL)
  • 16x16 icon replaced with 256x256 for Windows builder
  • Artifact upload directory flattened for CI release
  • app:registerAppFileProtocol() call fixed
  • OCR/robot service initialization fixed; DOM/OCR preference toggle added

💎 Improvements

  • Enhanced store/selectors for state management
  • Web search service refactored
  • Browser/file handlers updated
  • First-run onboarding flow with native window controls
  • StartupSetupUI, TitleBar, VirtualizedTabBar enhancements
  • Updated READMEs with Microsoft Store links and website URL

📚 Documentation

  • Microsoft Store links across all READMEs and landing pages
  • Privacy policy with contact info

📥 Download

Desktop

Platform File
🪟 Windows Aartiq.Browser.Setup.*.exe or .msix
🪟 Windows Microsoft Store
🍎 macOS Apple Silicon *-arm64.dmg
🍎 macOS Intel *-x64.dmg
🐧 Linux Aartiq.Browser-*.AppImage

Mobile

Platform File
📱 Android app-release.apk
🍎 iOS Aartiq.ipa

Built with ❤️ by Latestinssan