berryssh 0.7.0
An authenticated bridge, so the handset can reach a tailnet it cannot join.
The bridge now proves a shared key before it will connect anywhere, and answers with the names it will connect to rather than taking an address — so no IP is ever typed into the phone. See tools/wsbridge-install.md for the server half, including the Tailscale policy that bounds what a compromised bridge could reach.
Two fixes on the way: host keys are now stored per bridge target, so two machines behind one bridge no longer look like one machine whose key keeps changing; and a bridged connection with no saved password no longer loses its WebSocket path at the password prompt.
Profiles are format 4; connections saved by 0.6.0 still load.