Skip to content

Releases: black-candle-technologies/openmgmt-android

v0.3.3

Choose a tag to compare

@rileycalhoun rileycalhoun released this 24 Sep 06:18

What's changed

  • OAuth login fix (#4): fixed the OAuth redirect handling so sign-in completes correctly in the Android app.
  • CI hardening (#1): all GitHub Actions pinned to full commit SHAs, 15-minute job timeouts, least-privilege token (contents: read, no persisted checkout credentials), JVM unit tests for PKCE (RFC 7636 Appendix B vector) and OAuth defaults, a CI guard that fails when zero tests execute, and weekly Dependabot maintenance for the action pins.

Install

Download openmgmt-v0.3.3-debug.apk below and install on Android 8.0+.

Full Changelog: v0.3.2...v0.3.3

v0.3.2 — review fixes

Choose a tag to compare

@rileycalhoun rileycalhoun released this 24 Sep 04:02
b4fc601

Fixes

Addresses the automated code-review findings from recent pull requests.

  • Editing a task survives rotation. Rotating the phone with the task editor open used to close it and lose your changes; the editor and your edits now stay.
  • Project badges. Tasks in a project named after a status (e.g. "Done" or "Ready") lost their project badge in v0.3.1. Only the genuine duplicate — an Inbox task in the Inbox project — is hidden now.
  • Sign-out during sync. The Settings sign-out button is disabled while a sync or sign-in is running, like on the Sync page.
  • Build security. The build workflow runs with a read-only GitHub token (no change to the app itself).

Install

Download openmgmt-v0.3.2-debug.apk below and install it on your Android device.

Uninstall any earlier version first. Each release is signed with a different debug key, so Android will refuse to install this over v0.3.1, and uninstalling removes local data. If you're signed in, sync before uninstalling; your data comes back when you sign in and sync on v0.3.2. Debug-signed — fine for testing, not for the Play Store.

Test checklist

  1. Settings shows version 0.3.2 (6)
  2. Open a task, change its status, rotate the phone: the editor stays open with your change
  3. Create a project called "Done" and complete a task in it: the task still shows its project badge
  4. An Inbox task with no project shows a single "Inbox" badge

Full changes: #6

v0.3.1 — Galaxy S26 Ultra polish

Choose a tag to compare

@rileycalhoun rileycalhoun released this 24 Sep 03:51
82dadc9

Fixes

Tuned on the Samsung Galaxy S26 Ultra, including One UI's default 3-button navigation, the punch-hole camera, and larger font sizes.

  • Navigation bar: no more white strip behind the 3-button navigation bar; the dark drawer now runs to the bottom edge.
  • Landscape:
    • The "New task" button no longer slides under the navigation buttons.
    • The menu button and lists stay clear of the camera punch hole.
    • Pages are centered at a readable width instead of stretching across the screen.
    • The date picker shows the whole month instead of hiding the first week.
  • Larger fonts: dashboard card labels wrap instead of being cut off ("Blocked / waiting").
  • Inbox tasks no longer show an "Inbox" badge twice.

Install

Download openmgmt-v0.3.1-debug.apk below and install it on your Android device.

Uninstall any earlier version first. Each release is signed with a different debug key, so Android will refuse to install this over v0.3.0, and uninstalling removes local data. If you're signed in on v0.3.0, sync before uninstalling; your data comes back when you sign in and sync on v0.3.1. Debug-signed — fine for testing, not for the Play Store.

Test checklist

  1. Settings shows version 0.3.1 (5)
  2. With 3-button navigation, open the drawer: it reaches the bottom edge and the buttons stay visible
  3. Rotate to landscape: the "New task" button is fully visible, and nothing sits under the camera
  4. In landscape, edit a task and pick a due date: the whole month is visible

Full changes: #5

v0.3.0 — working sync and a redesigned UI

Choose a tag to compare

@rileycalhoun rileycalhoun released this 23 Sep 23:45
002794e

Highlights

  • Sync works end to end. Local changes are now pushed to the sync server and changes from your other devices (including the desktop app) are pulled in and applied. Previously the app sent nothing and saved nothing it received.
  • Signing out disconnects the device. Nothing syncs until you sign in again; the next sign-in (any account) registers this device fresh and sends all your local data.
  • Same statuses as desktop: Inbox, Backlog, Scheduled, Ready, In progress, Blocked, Waiting, Done. Existing "Open" tasks become Inbox.
  • Redesigned UI: fixed Dashboard cards collapsing to zero width, the drawer overlapping the status bar, squashed filter chips and off-brand colors; page titles live in the top bar; floating "New" buttons; Undo for completing and deleting.
  • Task editor: tap any task to edit its title, notes, status, due date, and project, or delete it.

Behavior changes

  • Deleting archives. Deleted tasks are canceled and deleted projects/organizations are archived, so the removal reaches your other devices.
  • Every task has a project. Tasks without a project go into Inbox, and projects without an organization into Personal, because the desktop app requires both.
  • Your local data is kept when updating, and sent on the first sync.

Install

Download openmgmt-v0.3.0-debug.apk below and install it on your Android device.

Uninstall any earlier version first. Every release so far has been signed with a different debug key, so Android will refuse to install this over an older build. Previous versions could not sync, so local data from them can't be carried over. Debug-signed — fine for testing, not for the Play Store.

Test checklist

  1. Settings shows version 0.3.0 (4)
  2. Sign in from the Sync page (the browser opens, then returns to the app), then tap Sync now: the device registers and "Last sync" shows a time
  3. Create a task on the phone, sync, then sync the desktop app: the task appears there (in Personal › Inbox if it has no project)
  4. Change a task on desktop, sync both: the change appears on the phone
  5. Sign out: "This device" shows Not registered and syncing is no longer offered

Full changes: #3

v0.2.1 - Fix OAuth token in registration header

Choose a tag to compare

@rileycalhoun rileycalhoun released this 23 Sep 23:04
625b2b0

Fixes

  • Critical: device registration was sending the literal string Bearer <redacted> as the Authorization header instead of the real OAuth token, so every registration failed with 401 unauthorized. Now sends the actual token.
  • Security (Codex review): the OAuth access token is now sent only to /omgp/v1/devices/register, never to /omgp/v1/hello — the token leaves the device exactly once at registration time, as documented.

Install

Download openmgmt-v0.2.1-debug.apk below and install on your Android device. Debug-signed — fine for testing, not for the Play Store.

Test checklist

  1. Sign in with your Black Candle account (browser flow opens, then returns to the app)
  2. Device should register on the server without the old unauthorized error
  3. Pull-to-sync should fetch the event list

v0.2.0 — real OAuth with refresh tokens

Choose a tag to compare

@rileycalhoun rileycalhoun released this 23 Sep 22:51

Proper native OAuth is now wired end to end.

Install on your phone: download the APK below, open it on your device, and allow 'Install unknown apps' when prompted.

What's new in this build:

  • Real OAuth sign-in: the app self-registers with the Black Candle auth service as a native public client (DCR, PKCE S256, no secret) — no more metadata-document placeholder
  • Refresh tokens: sessions now survive past the 1-hour access token; the app rotates tokens transparently
  • Device registration uses a fresh-or-refreshed token, so sync works after the app has been idle

Server side (shipped today): authd now accepts native DCR clients — http loopback redirects for desktop (RFC 8252 §7.3, any ephemeral port) and reverse-DNS custom schemes for mobile (RFC 8252 §7.1) — with rotating refresh tokens, reuse detection, and 8 new security/integration tests.

Note: debug-signed early build, fine for personal use. Sign in from the Sync screen, then Sync now to register the device.

v0.1.0 — first installable build

Choose a tag to compare

@rileycalhoun rileycalhoun released this 23 Sep 22:37

First installable Android build of OpenMGMT.

Install on your phone: download the APK below, open it on your device, and allow 'Install unknown apps' when prompted.

What's in this build:

  • Full app UI matching the desktop theme (Dashboard, Daily Operations, Tasks, Schedule, Projects, Organizations, Board, Sync, Settings)
  • Local Room database — tasks, projects, and organizations persist on-device
  • Black Candle account sign-in via OAuth (browser flow)
  • Sync screen wired to the OMGP server (event sync still being completed)

Note: this is a debug-signed early build. OAuth login and sync are under active development — the app works fully offline with local data.