Skip to content

v0.2.43

Choose a tag to compare

@MickyGX MickyGX released this 01 Mar 21:00
· 35 commits to main since this release

Changelog

[v0.2.43] - 2026-03-01

Added

  • Expanded built-in app catalog and assets with additional integrations/categories, including refreshed default category/icon mapping (Photos, System, Documents, Finance, and Requesters using requesters.svg).
  • Added multi-instance support metadata to built-in app definitions (supportsInstances, maxInstances, instanceNamePlaceholder) and surfaced instance management in Settings -> Apps.
  • Added new overview/data modules and dashboard wiring for specialty integrations:
    • MeTube queue
    • Audiobookshelf recently added
    • Tdarr stats
    • Immich recent + thumbnail proxy
    • Wizarr overview
    • Uptime Kuma status
    • Guacamole overview
    • Traefik overview
  • Added Settings -> Apps -> General controls for app-level behavior defaults (auto-open single submenu item, sidebar app-settings/activity visibility toggles, and per-role short/long press actions).

Changed

  • Reworked app settings navigation to include a dedicated General app-settings category tab that appears before app-category tabs.
  • Moved Add default app and Add custom app controls to the top of Settings -> Apps -> General so they are always visible before per-role app behavior controls.
  • Updated category/support docs to reflect the expanded integrations matrix and current overview/widget support levels.
  • Updated user-menu/logout button styling to match menu typography consistently across themes/collapsed sidebar states.

Fixed

  • Fixed custom-app creation regression (0.2.42) where adding a custom app failed with crypto.randomBytes is not a function (GitHub issue #22).
  • Fixed add-default-app actions from app general/custom sidebars, including invalid nested form behavior and layout regressions.
  • Fixed Apps settings behaviors where saving/app-instance actions could jump to unexpected tabs/pages.
  • Fixed multiple sidebar/app visibility UX inconsistencies, including role filter behavior and app-general placement workflows.

Security

  • Hardened proxy and request handling:
    • conditional/hop-limited trust proxy (TRUST_PROXY, TRUST_PROXY_HOPS)
    • tighter body parser defaults + per-route payload guards on sensitive endpoints
  • Added baseline security response headers compatible with Launcharr iframe usage.
  • Added CSRF protections for unsafe methods and removed state-changing GET behavior (/logout, /switch-view moved to POST).
  • Strengthened local password policy enforcement (minimum 12 chars with upper/lower/number/symbol requirements).

Migration Notes

  • No schema migration required.
  • Rebuild/restart Launcharr and hard refresh browser assets once after upgrade.
  • If you deploy behind a reverse proxy, validate TRUST_PROXY / TRUST_PROXY_HOPS and body-limit env settings for your topology.

Verification Checklist

  • Settings -> Apps -> General shows add-default/add-custom rows directly under the section title.
  • Custom app add succeeds from both sidebar manager and apps-general workflows.
  • Multi-instance app create/delete/save flows work without forced navigation jumps.
  • New overview modules load for supported specialty integrations.
  • Sidebar app-button press actions/toggles persist when saved from Apps -> General.
  • Security-sensitive routes (/logout, /switch-view) require POST and work from UI controls.