Releases
2.3
2.3 Recordings Library, Security Hardening
Compare
Sorry, something went wrong.
No results found
co-te
released this
06 Sep 21:01
What's New
Web UI
Full UI redesign — new look, faster, lighter (single HTML file, no external requests, no build step)
New Recordings library view: browse, preview, download, favorite, archive, and delete finished recordings
Real-time log viewer now works during and after recordings (fixed empty logs caused by yt-dlp silencing)
Fixed avatar initials rendering on top of channel avatars
Added GitHub Issues link in Settings → System for bug reports
Dark/light theme, mobile layout improvements, guest account prompt shows only once
Security
Optional password protection: once an account is created, the entire API requires login (PBKDF2-hashed, session cookies, same-origin CSRF protection)
Account management endpoints no longer reachable without authentication
SSRF guards on channel URLs, webhook URLs, and DNS resolution (non-blocking)
Blocked dangerous yt-dlp flags in user-supplied extra args (--exec, --postprocessor-args, downloader overrides, etc.)
Channel credentials are never exported in config backups
Reliability
No more duplicate/zombie recordings — startup sweep kills recorder processes left behind by a crashed or hard-stopped instance
Stop/kill/delete operations now wait for the process tree to fully die before releasing the recording slot
Graceful shutdown drains active recordings before writing final state
Fixed a race where force-killing a recording could let the monitor start a second one on the same channel
DST-safe recording filenames (UTC timestamps prevent overwrite collisions)
Fixes & Improvements
Live recording logs fixed — yt-dlp's --print flag was silencing all output; ffmpeg progress is now visible
--fixup scoped to output format (force only for MP4, warn for MKV/TS)
Malformed HTTP Range headers no longer crash preview; tail ranges (bytes=-N) handled correctly
Login rate limiting no longer blocks the event loop; returns 429 with Retry-After
Blocking DNS lookups moved off the event loop
record_on_add setting is now functional (global auto-record master switch)
Cookies manager UI works end-to-end (upload, list, delete, assign globally)
Bumped python-multipart to 0.0.18 (security advisory)
Docker
WireProxy VPN sidecar is now optional — start with docker compose --profile vpn up -d (no wg0.conf required for normal use)
You can’t perform that action at this time.