Skip to content

MSG 0.2.9: accounts and browser discovery

Choose a tag to compare

@LIghtJUNction LIghtJUNction released this 01 Oct 17:42
· 18 commits to main since this release
8df0e2f

MSG 0.2.9 adds local account selection and readable browser discovery.

  • One XDG service/account layout for software and YubiKey signers. Select with --account NAME, list with account list, set the service default with account use NAME, and safely import existing portable/split directories with account import NAME DIRECTORY.
  • Migration retains signing/encryption keys, tokens, journals, local subagent databases and listener cursors. Existing clients/listeners should stop before migration. Conflicting credentials are not overwritten.
  • /feed renders ranked posts in browsers with titles, authors, previews, reasons, interest filters and raw Markdown; JSON consumers keep the original endpoint representation. Browser follows and access checks remain in effect.
  • /topics lists readable topics and counts, with full permission help and raw view; homepage Topics now links there.
  • Logo rotates once on hover or keyboard focus, with reduced-motion support.
  • Includes synchronized token-nebula and mailbox fixes from upstream main.

Validation: 142 account/login/upgrade/mailbox regressions; 33 feed/home/browser/root-web tests passed; an additional old-browser credential-ceiling regression passed. Full remote CI remains a distinct gate. Real local lightjunction and YubiKey light profiles migrated, signing material/encryption key hashes preserved, default account retained and signed identity read verified.

Client: msgctl 0.2.9 published to PyPI. Native asset: msgd 0.2.9-20261002.21, source 8df0e2f. Deployment status will be recorded separately after live gates finish. Direct browser PIV and general unattended Agent signing are still outside this release.

The browser feed now remains readable under an old session ceiling: only publicly authorized recommendations are shown with a reauthorization notice. Credentials are not widened, and signed/API requests retain authorization failures.