Skip to content

Releases: firatkarakas/onset-host

Release list

Onset Host 1.0.0

Choose a tag to compare

@firatkarakas firatkarakas released this 02 Oct 12:17

Onset Host 1.0.0

The first release of Onset Host: the server for the Onset app, with its local control panel, in one Windows installer.

Highlights

  • One installer. Onset-Host-1.0.0-x64.msi installs the server and a control panel that opens in your browser at http://127.0.0.1:9090 and is reachable only from this PC.
  • Its own identity, no certificate authority. The server creates a long-lived self-signed certificate. The control channel is always HTTPS/WSS, in both LAN and Internet mode. You do not need a domain, port 80 or a paid certificate.
  • Copy invite. The panel shows the server's SHA-256 fingerprint and an invite (host:port#<fingerprint>) that the Onset app checks on the very first connection.
  • LAN or Internet mode. In Internet mode, UPnP finds your public IPv4 address and maps the control TCP port (default 8080) and the voice and screen UDP ports (defaults 9000 and 9001). Mappings use a one-hour lease that is renewed while the server runs, and mappings owned by other devices are never overwritten. Manual forwarding works when UPnP is off. The panel reports CGNAT when your router has no public IPv4.
  • Scheduled, encrypted backups without downtime. Daily by default (or weekly, or on demand with Create backup), the panel writes a .gcb archive (AES-GCM) with settings, data, uploads and the identity from a live snapshot — calls are not interrupted — and keeps the newest 14. The key is protected by Windows DPAPI; export a recovery key with --export-backup-key and decrypt with --decrypt-backup.
  • Self-healing: a crashed server is restarted with backoff, logs rotate on their own, and connected apps are told before a restart.
  • Control from one place: start, stop and restart, ports, the owner setup and invite tokens, registration (invite token, closed or open), history retention (keep forever by default), call diagnostics, start with Windows and the server log.
  • New encrypted voice protocol (GCA3). ChaCha20-Poly1305, keys for each session, replay protection, and packets re-encrypted for each listener.
  • Faster under load. A message and its read state are saved in one write, screen shares are forwarded without holding up people joining or leaving, and muting sends a small update instead of the whole member list. Interrupted downloads can resume.
  • Hardening. Command budgets for each account, connection caps, upload quotas with disk-space checks, and size limits on diagnostics.

Install

Security and privacy

  • Nothing is hosted by the developers: no relay, no accounts, no telemetry sent to the project.
  • Call diagnostics stay on your server and can be turned off with Keep call diagnostics.
  • Firewall: the installer allows the server on Private and Domain networks from the local subnet. Internet mode adds its own rule after administrator approval, and uninstalling removes it.
  • The MSI is not Authenticode-signed, so Windows SmartScreen may warn. Check it against SHA256SUMS:
    Get-FileHash .\Onset-Host-1.0.0-x64.msi -Algorithm SHA256

Requirements

  • Windows 10 or 11, 64-bit, and administrator rights to install.
  • For Internet mode: a public IPv4 address, and a router with UPnP or manual port forwarding.