Skip to content

v0.3.0: Merge pull request #3 from SimCubeLtd/feat/google_fonts

Choose a tag to compare

@prom3theu5 prom3theu5 released this 26 Aug 13:00
· 98 commits to main since this release
b47acd4

What's Changed

  • feat: relax link and styling so archify can work by @prom3theu5 in #3

Full Changelog: v0.2.0...v0.3.0


Highlights

Two upload rules become configurable per-server, both off by default. Documents that were rejected
outright can now be accepted deliberately, without loosening the policy for everyone.

  • --allow-font-links / KERYX_ALLOW_FONT_LINKS accepts a <link> whose rel is only
    stylesheet, preconnect, dns-prefetch or preload and whose href host is
    fonts.googleapis.com or fonts.gstatic.com. <base> and every other host stay blocked. The
    flag also widens the CSP on served drafts with style-src https://fonts.googleapis.com and
    font-src https://fonts.gstatic.com, without which an accepted font link would still be blocked
    in the browser.
  • --allow-safe-handlers / KERYX_ALLOW_SAFE_HANDLERS accepts an inline on* handler whose body
    is nothing but ;-separated assignments of literals or dotted property paths, the async-CSS
    idiom onload="this.media='all'". Anything containing (, [, <, a template literal, or a
    blocked scheme is still rejected, so a permitted handler can set properties but cannot call
    anything.

Also in this release:

  • keryx upload reads the server's effective policy from GET /api/me before validating locally.
    --max-html-bytes existed in 0.2.0 but had no effect on CLI uploads, which always validated
    against the hardcoded 512 KB default. Raising the server cap now works end to end.
  • <script type="application/json"> and application/ld+json are accepted with no flag. The HTML
    spec classifies these as data blocks that no browser executes, so rejecting them was a bug in the
    type allowlist rather than a safety control. module, importmap and speculationrules stay
    blocked.
  • URL attributes block a dangerous scheme only at the start of the value, so a URL such as
    https://example.com/?q=javascript:1 is no longer a false positive.

PDF publication keeps its own stricter policy and is unchanged: keryx publish still rejects
scripts and external assets.

Install

Binaries are attached below for three targets. If yours is not one of them, build from source. The
release archives also include the README, licence, and ready-made Keryx agent skills.

Platform Asset
Linux, x86-64 (glibc 2.35+) keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz
macOS, Apple Silicon keryx-0.3.0-aarch64-apple-darwin.tar.gz
Windows, x86-64 keryx-0.3.0-x86_64-pc-windows-msvc.zip

Linux (x86-64)

gh release download v0.3.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz*'

sha256sum -c keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz.sha256
tar -xzf keryx-0.3.0-x86_64-unknown-linux-gnu.tar.gz

sudo install -m755 keryx-0.3.0-x86_64-unknown-linux-gnu/bin/keryx /usr/local/bin/
keryx --version

For a single-user install with no sudo, use ~/.local/bin instead and make sure it is on your
PATH.

macOS (Apple Silicon)

gh release download v0.3.0 --repo SimCubeLtd/keryx \
  --pattern 'keryx-0.3.0-aarch64-apple-darwin.tar.gz*'

shasum -a 256 -c keryx-0.3.0-aarch64-apple-darwin.tar.gz.sha256
tar -xzf keryx-0.3.0-aarch64-apple-darwin.tar.gz

sudo install -m755 keryx-0.3.0-aarch64-apple-darwin/bin/keryx /usr/local/bin/
keryx --version

The binary is not code-signed or notarised. Downloading through a browser may attach a
quarantine flag and cause Gatekeeper to refuse it; clear that flag once with:

xattr -d com.apple.quarantine /usr/local/bin/keryx

Intel Macs: no binary is published. Build from source, or run the Apple Silicon build under
Rosetta 2. Rosetta is unsupported for this release and untested.

Windows (x86-64)

In PowerShell:

gh release download v0.3.0 --repo SimCubeLtd/keryx `
  --pattern 'keryx-0.3.0-x86_64-pc-windows-msvc.zip*'

# Compare against the published checksum
Get-FileHash keryx-0.3.0-x86_64-pc-windows-msvc.zip -Algorithm SHA256
Get-Content keryx-0.3.0-x86_64-pc-windows-msvc.zip.sha256

Expand-Archive keryx-0.3.0-x86_64-pc-windows-msvc.zip -DestinationPath $env:LOCALAPPDATA\Programs

$dir = "$env:LOCALAPPDATA\Programs\keryx-0.3.0-x86_64-pc-windows-msvc\bin"
[Environment]::SetEnvironmentVariable(
  'Path', [Environment]::GetEnvironmentVariable('Path','User') + ";$dir", 'User')

Open a new terminal, then run keryx --version.

The executable is unsigned, so SmartScreen may warn on first run. Nothing here needs
administrator rights.

Build from source (any platform)

Install the Rust nightly toolchain, then:

rustup toolchain install nightly --profile minimal
git clone --branch v0.3.0 --depth 1 https://github.com/SimCubeLtd/keryx.git
cd keryx
cargo +nightly build --release --locked
./target/release/keryx --version

Or install the tagged release straight into ~/.cargo/bin:

cargo +nightly install --git https://github.com/SimCubeLtd/keryx \
  --tag v0.3.0 --locked keryx

--locked uses the exact dependency versions in the committed Cargo.lock.