Skip to content

Releases: TOBYCAI/otp-board

v3.2.1

Choose a tag to compare

@github-actions github-actions released this 27 Aug 01:45

otp-board v3.2.1

适配Android 16:在Android 16 上运行不再静默失效。

中文

  • 修复 Android 16(API 36+)兼容:在 AndroidManifest.xml 声明 ACCESS_NETWORK_STATE。Android 16 对带网络约束的 JobScheduler 任务强制要求该权限,旧版安装在 Android 16 设备上时转发 Job 会被系统直接拒绝;升级后恢复转发。
  • 修正版本号错位:android/app/build.gradle.kts 的 versionName 改为 3.2.1、versionCode 改为 6(此前误写为 3.1.1 / 5),与 tag 对齐。
  • 中英文 README 补充 Android 16 兼容说明。
  • tag 移至修正后的提交并触发 CI 重建 OTP.apk,Release 重新定到 main 分支并补齐 Release notes。

English

  • Fixed Android 16 (API 36+) compatibility by declaring ACCESS_NETWORK_STATE in AndroidManifest.xml. Android 16 requires this permission for network-constrained JobScheduler work; on API 36+ devices the forwarding job was silently rejected, and forwarding now works again.
  • Corrected a version mismatch: android/app/build.gradle.kts now declares versionName 3.2.1 and versionCode 6 (previously 3.1.1 / 5), matching the tag.
  • Documented Android 16 support in both the Chinese and English READMEs.
  • Moved the tag to the corrected commit, rebuilt OTP.apk in CI, and retargeted the release to main with complete release notes.

v3.2.0

Choose a tag to compare

@TOBYCAI TOBYCAI released this 25 Aug 03:13

otp-board v3.2.0

一键部署终于完整了:图标不再 404,PWA 真正可安装。

中文

  • 补齐品牌图标资源:一键部署脚本 install.sh 部署时在 server/public/ 下自动生成 6 个图标(favicon-32 / favicon / apple-touch-icon / icon-192 / icon-512 / icon-maskable-512),修复部署后浏览器标签页图标、iOS「添加到主屏幕」图标、PWA 图标全部 404 的问题。
  • 同步提交 server/public/*.png,clone 后手动部署(node server.js)与源码包同样具备完整图标。
  • 一键部署 install.sh 与 otp31.sh 功能体验完全一致:管理控制台、WebAuthn 生物识别、外部通知(Telegram / 企微 / 飞书 / Bark / Webhook / 邮件)、限流审计、PWA 全部对齐。
  • 默认安装路径改为通用的 $HOME/otp-board-server(首参可覆盖,如 install.sh /opt/otp-board),不再依赖宝塔 wwwroot 目录结构与交互输入域名。
  • 新增「安全与隐私」章节(README.md / README.en.md),澄清数据流向:验证码提取在安卓端本地完成,不发送原始短信正文;服务端仅留存提取结果(带 TTL 自动清理),无遥测、无第三方上报;外部通知全部 opt-in。
  • 版本号升至 3.2.0(install.sh 横幅 / package.json / server.js 启动日志)。

English

  • Completed the brand icon assets: install.sh now generates six icons under server/public/ (favicon-32 / favicon / apple-touch-icon / icon-192 / icon-512 / icon-maskable-512) on deploy, fixing 404s for the browser tab icon, iOS "Add to Home Screen" icon, and PWA icons.
  • Committed server/public/*.png so manual deployments (node server.js) and the source archive ship the same complete icon set.
  • Feature parity with the original otp31.sh: admin console, WebAuthn biometrics, external notifications (Telegram / WeCom / Feishu / Bark / Webhook / email), rate-limit auditing, and PWA support all aligned.
  • Changed the default install path to the generic $HOME/otp-board-server (overridable via the first argument, e.g. install.sh /opt/otp-board), removing the dependency on the Baota wwwroot layout and interactive domain prompts.
  • Added a "Security & Privacy" section (README.md / README.en.md) clarifying the data flow: OTP extraction happens locally on Android and the raw SMS body is never sent; the server stores only extracted results with TTL cleanup, no telemetry and no third-party reporting; all external notifications are opt-in.
  • Bumped the version to 3.2.0 (install.sh banner / package.json / server.js startup log).

v3.1.1

Choose a tag to compare

@github-actions github-actions released this 23 Aug 04:00

otp-board v3.1.1

服务端 + 安卓客户端 OTP 转发看板(Android 10+),开箱即用。

中文

  • 安卓客户端 OTP.apk:生产 keystore 签名(CN=TOBYCAI),可直接下载安装;扫码添加 OTP 账号后即可把收到的验证码转发到自托管服务端看板。
  • 服务端(Node.js 看板 + 一键部署 install.sh):支持管理控制台、WebAuthn 生物识别、外部通知(Telegram / 企微 / 飞书 / Bark / Webhook / 邮件)、限流审计与 PWA。
  • 验证码提取在安卓端本地完成(SmsReceiver / NotificationListener 调用 OtpExtractor),仅向自托管服务端转发提取结果,不发送原始短信正文。
  • APK 由 GitHub Actions 在打 tag 时自动构建并签名;服务端见仓库 README 的一键部署说明。

English

  • Android client OTP.apk: signed with the production keystore (CN=TOBYCAI) and ready to install. Scan a QR code to add an OTP account and the device forwards received codes to your self-hosted server board.
  • Server (Node.js board + one-line install.sh): admin console, WebAuthn biometrics, external notifications (Telegram / WeCom / Feishu / Bark / Webhook / email), rate-limit auditing, and PWA support.
  • OTP extraction runs locally on the Android device (SmsReceiver / NotificationListener call OtpExtractor); only the extracted result is forwarded to your self-hosted server — the raw SMS body is never sent.
  • The APK is built and signed automatically by GitHub Actions on every tag; see the repository README for one-command server deployment.

资产说明 / Assets

  • OTP.apk — 安卓客户端生产签名包 / production-signed Android client.
  • otp-board-src.zip — 完整源码包 / complete source archive.