Skip to content

Squorli Server 0.7.0

Choose a tag to compare

@github-actions github-actions released this 29 Sep 23:00
· 30 commits to main since this release

Signing a device out now holds. Until this version a device that was signed out still had the account's key and was back in with one click; now every device has a key of its own, and a device that was signed out is refused until somebody signs in on it again with name and password.

Before you update

  • One migration. It adds the list of devices of server accounts and remembers for every session which device it belongs to. It runs at the start and cannot be undone; squorli update backs up first. No new variable, no deploy file to fetch again.
  • Installations with automatic updates take this version by themselves.
  • Desktop app 0.10.0 follows this release. Older apps and older web clients keep working as before, until an account signs one of its devices out for the first time. From then on that account gets in only from a device with a current client; an older app is refused for it and has to be updated. It loses nothing by that.
  • Squorli accounts (@name) need a Squorli Directory that knows devices. At directory.squorli.com signing devices out is switched on once desktop app 0.10.0 is out; until then Settings > Devices lists the devices and says that signing out follows. Server accounts (~name) need nothing but this version.
  • A server that stays on an older version keeps admitting everybody who holds an account's key, signed out or not. Updating is what closes that.
  • Your members stay signed in. Nobody has to sign in again because of the update.

New

  • Devices in place of sessions (Settings > Devices). The list shows every device that is signed in with the account, where it signed in from (the site of a browser, or the desktop app), when it was signed in and last used, and which one you are sitting at: for a Squorli account on all servers, for a server account on this server. "Sign out" per device and "Sign out all other devices" ask for the password, and for a code while an authenticator is set up.
  • A device that was signed out is out. It falls back to the sign-in at once, with a notice that says why, loses the account's key and no longer offers "Continue as". It gets back in only with name, password and second factor. An open voice connection of that device ends with it. What this does not undo: somebody who copied the account's key before can still read direct messages they get hold of on the way; the directory hands them none any more. Checked with two browsers, the desktop app and the automatic tests, not yet with two machines over the internet.
  • "Sign out" removes the key from the device. The client's own sign-out signs the device out and takes the key along; name and password bring it back. For a Squorli account without a password the key exists on that device only, so the client asks before it removes it.
  • At most ten devices per account. At the eleventh, the sign-in shows the ten others after the password was right, and you pick the one that is signed out for it.
  • Devices that were not used for 90 days are signed out by themselves.
  • The device's key cannot be read out. Browsers and the desktop app make it themselves and keep it where no script can copy it, only use it. Where a browser cannot do that (an older one, some private windows), the key is an ordinary one. Checked in Chrome, in the desktop app and in Firefox; not yet in Safari.
  • A new password signs the other devices of a server account out.

Fixed

  • Signing in with a server account on a second device works. Since server accounts exist, the second device answered the right password with "user name or password wrong". Accounts and passwords need nothing; it works with the update.

Image: ghcr.io/danielklessa/squorli-server:v0.7.0 (also :latest). Update an installation made with the install script: squorli backup, then squorli update; with Compose by hand: set APP_IMAGE=ghcr.io/danielklessa/squorli-server:v0.7.0 in .env, then docker compose pull and up -d. Windows without Docker: the package squorli-server-0.7.0-windows-x64.zip below, with its .sha256 file; update an installation with squorli update in a window opened as administrator (it backs up first). Database migrations run by themselves at the start and cannot be undone: back up first. Guide: https://squorli.com/en/docs/install/