v0.0.2 — Rebrand to Libsync, Codex fixes, SDK rename
First release after detach + rebrand. Image: `ghcr.io/arthursoares/libsync:v0.0.2` (also tagged `0.0`, `0`, `latest`).
Highlights
Project rebrand
- Repo renamed: `arthursoares/streamrip` → `arthursoares/libsync`
- New GHCR image path (`ghcr.io/arthursoares/libsync`)
- Internals retain the legacy `streamrip` prefix (env vars, SQLite filename, `.streamrip.json` sentinel, Python module name) for compatibility — full internal rename queued for v1.0
Fixes (from Codex review)
- P1 path traversal in SPA static-file route — `os.path.realpath` containment check
- P1 auto-sync re-evaluation after credential hot-reload — fixes the enable-auto-sync-then-authenticate dead-loop
- P2 case-insensitive boolean config parsing — Pydantic-stringified `"True"`/`"False"` now honored
Infrastructure
- SDK renamed `arthursoares/qobuz_api_client` → `arthursoares/qobuz_tidal_api_client`, now public and GPL-3.0
- Removed dead upstream `poetry-publish.yml` workflow
- CI hardening: dropped flaky poetry venv cache (concurrent push+PR runs no longer race on stale .venv)
- New OAuth-redirect contribution from @leolobato — Qobuz callback uses `window.location.origin` instead of hardcoded `localhost:11111`
Upgrade notes
Existing Docker deployments using `ghcr.io/arthursoares/streamrip:` should switch image references to `ghcr.io/arthursoares/libsync:`. Env vars and on-disk format are unchanged.