Repository navigation
TruthBeacon v0.1.3
TruthBeacon v0.1.3 — Official Release Notes
Orange Heart Industries — Identity Ground-Truth & Community Stewardship
Overview
TruthBeacon v0.1.3 is an essential patch release resolving a critical IPC parameter serialization mismatch in the bot pre-flight verification and server pairing engine.
What's Fixed in v0.1.3
1. Tauri 2 IPC Parameter Normalization (Discord Handshake & Membership Verification Fix)
- Resolved CamelCase Argument Serialization: Tauri 2 commands expect camelCase argument names by default (
guildId). In v0.1.2, passingguild_idin snake_case caused the Rust backend to deserializeguild_idasNone, leading pre-flight handshake diagnostics to always report"Bot Not Found in Target Server"and"Missing Required Moderation Grants". - Automatic Casing Normalization: Added an IPC payload normalization layer in
ui/js/ipc.jsthat automatically transforms all command arguments into both camelCase and snake_case representations, guaranteeing seamless deserialization across all Tauri commands. - Heartbeat & Resilient Daemon Lifecycle: Hardened background Discord Gateway connection lifecycle and periodic heartbeat transmission.
Previous Highlights from v0.1.2
1. Automated 1-Click Bot Authorization & Pre-Calculated Permissions
- Instant Client ID Extraction: TruthBeacon automatically extracts and base64-decodes your bot's application snowflake ID directly from segment 1 of your Bot Token upon pasting. No need to navigate to the Discord Developer Portal's "General Information" tab just to hunt down an Application ID.
-
Pre-Calculated Permissions Bitfield: Eliminates the manual Discord OAuth2 URL Generator. TruthBeacon pre-calculates the exact bitwise integer required for anti-impersonation defense:
$$\text{VIEW_CHANNEL (1024)} \mid \text{KICK_MEMBERS (2)} \mid \text{BAN_MEMBERS (4)} \mid \text{MODERATE_MEMBERS (1099511627776)} = \mathbf{1099511628806}$$ - 1-Click "Authorize & Invite Bot" Button: A prominent action card provides direct 1-click addition of the bot to your Discord server, plus a 1-click "Copy Link" utility for server owners.
2. Automated Server Discovery (Zero Snowflake Hunting)
- Automatic Discord Gateway Server Discovery: Added
fetch_bot_guildsTauri IPC command querying Discord v10 REST API (GET /users/@me/guilds). - Elimination of Developer Mode: Community leaders are no longer forced to enable Discord Developer Mode, right-click their server icon, and copy 19-digit numeric snowflake Guild IDs.
- Dynamic Discovered Servers Dropdown: Discovered servers appear in an interactive dropdown with server names and IDs. If the bot is present in a single server, TruthBeacon auto-selects it instantly.
3. Native OS Keychain & Zeroized In-Memory Cache Resilience
- Persistent Credential Lifecycle: Dual-tier credential architecture combining native OS Secure Enclaves (
keyring-rstargeting Apple Keychain Services, Windows Credential Manager DPAPI, and Linux Secret Service) with zeroized in-memory fallback caches. - Zero-Plaintext Security Policy: Bot tokens remain strictly zeroized and never touch SQLite databases, flat files, or unredacted serialization logs.
Core Security Engine
-
Deterministic Multi-Script Homoglyph Detection:
- Sub-50ms deterministic normalization and skeleton decomposition (NFKD).
- Defeats cross-script lookalike substitutions across Cyrillic, Greek, Mathematical, and Latin lookalikes.
- De-obfuscates invisible unicode anomalies, zero-width spaces, and bidirectional text overrides.
-
Perceptual Avatar Clone Defense:
- Discrete Cosine Transform (DCT) perceptual image hashing (
img_hash). - Automatically flags unauthorized copies and subtle visual perturbations of moderator and VIP avatars.
- Discrete Cosine Transform (DCT) perceptual image hashing (
-
Snowflake Cryptographic Account Age Analysis:
- Parses Discord 64-bit integer IDs directly to extract real account creation epochs.
- Escalates risk tier when brand-new accounts (< 72 hours old) exhibit visual or naming similarity to benchmark staff.
-
Zero-Telemetry Local Data Sovereignty:
- 100% offline-first architecture; all benchmark vaults, audit logs, and incident records are retained exclusively on the operator's machine.
Platform Availability & Supported Operating Systems
- macOS (Universal 2):
- Supports Apple Silicon (M1/M2/M3/M4) and Intel Macs (
macOS 10.15 Catalinaor higher). - Packaged as a drag-and-drop
.dmginstaller with custom Orange Heart backdrop and a standalone portable.appbundle.
- Supports Apple Silicon (M1/M2/M3/M4) and Intel Macs (
- Windows (x64):
- Supports Windows 10 and Windows 11 (64-bit).
- Packaged via WiX (
.msi) for enterprise deployment, NSIS (.exe) for standard setup, and a portable executable.
- Linux (x86_64):
- Supports Ubuntu 20.04+, Debian 11+, Fedora, and Arch.
- Packaged as a native Debian
.debpackage and portable standalone.AppImage.
Verification & Checksums
All binaries are verified through GitHub Actions CI and signed with SHA-256 cryptographic checksums. Check SHA256SUMS.txt and RELEASE_MANIFEST.md for verification details.