Skip to content

1.0.3

Choose a tag to compare

@WebTigers WebTigers released this 10 Sep 07:55
· 10 commits to main since this release
0bdd88b

Two installer fixes, both found by AI review and each confirmed against real code before fixing.

Provisioning no longer destroys the secrets it just minted (TIGER-77). do_provision() rebuilt local.ini from scratch on every call, writing only the DB block — so tiger.crypto.key and tiger.security.pepper were wiped, and provisionSecrets() minted replacements because they were now absent. It runs on both the admin and finish steps, so a normal forward pass rewrote the file twice; go back and forward once, or retry finish after an error, and the pepper rotated after the owner's password had been hashed with the old one — locking the operator out of the site they had just installed. It now merges instead of replacing, writes atomically, and reports write failures instead of swallowing them.

Downloads are verified or refused (TIGER-78). Checksum verification was skipped when a release carried no .sha256, and skipped again when the fetch returned empty — exactly the failures the digest exists to catch. An automatic download now requires a matching 64-hex digest and stops before extraction otherwise. Manual upload is unchanged.

Every published release carries its checksum, so automatic installs are unaffected.