Repository navigation
Releases: TOBYCAI/otp-board
Releases · TOBYCAI/otp-board
Release list
v3.2.1
otp-board v3.2.1
适配Android 16:在Android 16 上运行不再静默失效。
中文
- 修复 Android 16(API 36+)兼容:在
AndroidManifest.xml声明ACCESS_NETWORK_STATE。Android 16 对带网络约束的JobScheduler任务强制要求该权限,旧版安装在 Android 16 设备上时转发 Job 会被系统直接拒绝;升级后恢复转发。 - 修正版本号错位:
android/app/build.gradle.kts的versionName改为3.2.1、versionCode改为6(此前误写为3.1.1/5),与 tag 对齐。 - 中英文 README 补充 Android 16 兼容说明。
- tag 移至修正后的提交并触发 CI 重建
OTP.apk,Release 重新定到 main 分支并补齐 Release notes。
English
- Fixed Android 16 (API 36+) compatibility by declaring
ACCESS_NETWORK_STATEinAndroidManifest.xml. Android 16 requires this permission for network-constrainedJobSchedulerwork; on API 36+ devices the forwarding job was silently rejected, and forwarding now works again. - Corrected a version mismatch:
android/app/build.gradle.ktsnow declaresversionName3.2.1andversionCode6(previously3.1.1/5), matching the tag. - Documented Android 16 support in both the Chinese and English READMEs.
- Moved the tag to the corrected commit, rebuilt
OTP.apkin CI, and retargeted the release tomainwith complete release notes.
v3.2.0
otp-board v3.2.0
一键部署终于完整了:图标不再 404,PWA 真正可安装。
中文
- 补齐品牌图标资源:一键部署脚本
install.sh部署时在server/public/下自动生成 6 个图标(favicon-32 / favicon / apple-touch-icon / icon-192 / icon-512 / icon-maskable-512),修复部署后浏览器标签页图标、iOS「添加到主屏幕」图标、PWA 图标全部 404 的问题。 - 同步提交
server/public/*.png,clone 后手动部署(node server.js)与源码包同样具备完整图标。 - 一键部署
install.sh与 otp31.sh 功能体验完全一致:管理控制台、WebAuthn 生物识别、外部通知(Telegram / 企微 / 飞书 / Bark / Webhook / 邮件)、限流审计、PWA 全部对齐。 - 默认安装路径改为通用的
$HOME/otp-board-server(首参可覆盖,如install.sh /opt/otp-board),不再依赖宝塔wwwroot目录结构与交互输入域名。 - 新增「安全与隐私」章节(README.md / README.en.md),澄清数据流向:验证码提取在安卓端本地完成,不发送原始短信正文;服务端仅留存提取结果(带 TTL 自动清理),无遥测、无第三方上报;外部通知全部 opt-in。
- 版本号升至 3.2.0(
install.sh横幅 /package.json/server.js启动日志)。
English
- Completed the brand icon assets:
install.shnow generates six icons underserver/public/(favicon-32 / favicon / apple-touch-icon / icon-192 / icon-512 / icon-maskable-512) on deploy, fixing 404s for the browser tab icon, iOS "Add to Home Screen" icon, and PWA icons. - Committed
server/public/*.pngso manual deployments (node server.js) and the source archive ship the same complete icon set. - Feature parity with the original
otp31.sh: admin console, WebAuthn biometrics, external notifications (Telegram / WeCom / Feishu / Bark / Webhook / email), rate-limit auditing, and PWA support all aligned. - Changed the default install path to the generic
$HOME/otp-board-server(overridable via the first argument, e.g.install.sh /opt/otp-board), removing the dependency on the Baotawwwrootlayout and interactive domain prompts. - Added a "Security & Privacy" section (README.md / README.en.md) clarifying the data flow: OTP extraction happens locally on Android and the raw SMS body is never sent; the server stores only extracted results with TTL cleanup, no telemetry and no third-party reporting; all external notifications are opt-in.
- Bumped the version to 3.2.0 (
install.shbanner /package.json/server.jsstartup log).
v3.1.1
otp-board v3.1.1
服务端 + 安卓客户端 OTP 转发看板(Android 10+),开箱即用。
中文
- 安卓客户端
OTP.apk:生产 keystore 签名(CN=TOBYCAI),可直接下载安装;扫码添加 OTP 账号后即可把收到的验证码转发到自托管服务端看板。 - 服务端(Node.js 看板 + 一键部署
install.sh):支持管理控制台、WebAuthn 生物识别、外部通知(Telegram / 企微 / 飞书 / Bark / Webhook / 邮件)、限流审计与 PWA。 - 验证码提取在安卓端本地完成(
SmsReceiver/NotificationListener调用OtpExtractor),仅向自托管服务端转发提取结果,不发送原始短信正文。 - APK 由 GitHub Actions 在打 tag 时自动构建并签名;服务端见仓库 README 的一键部署说明。
English
- Android client
OTP.apk: signed with the production keystore (CN=TOBYCAI) and ready to install. Scan a QR code to add an OTP account and the device forwards received codes to your self-hosted server board. - Server (Node.js board + one-line
install.sh): admin console, WebAuthn biometrics, external notifications (Telegram / WeCom / Feishu / Bark / Webhook / email), rate-limit auditing, and PWA support. - OTP extraction runs locally on the Android device (
SmsReceiver/NotificationListenercallOtpExtractor); only the extracted result is forwarded to your self-hosted server — the raw SMS body is never sent. - The APK is built and signed automatically by GitHub Actions on every tag; see the repository README for one-command server deployment.
资产说明 / Assets
OTP.apk— 安卓客户端生产签名包 / production-signed Android client.otp-board-src.zip— 完整源码包 / complete source archive.