Skip to content

Releases: fkr-0/properpcloud

v0.2.0-rc.7

v0.2.0-rc.7 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 25 Sep 14:27
v0.2.0-rc.7

[0.2.0-rc.7] - 2026-09-25

Added

  • Added a stable, source-neutral Players overview that deduplicates known playback targets across reconnect/discovery and exposes connectivity, playback state, current media, and safe local controls through the existing controller authority.
  • Added audiobook playback state with durable per-book resume, chapter-aware navigation, playback speed, configurable skip intervals, sleep/end-of-chapter stopping behavior, and restore-without-autoplay semantics isolated from normal music queue modes.
  • Added persistent directory bookmarks to the Android folder browser for quick return to known library locations.

Changed

  • Simplified Android pCloud/server settings copy by removing developer-oriented OAuth/client-ID controls and credential-storage implementation banners from the normal user surface while preserving the existing authentication and vault behavior.
  • Updated Android first-run/privacy/user documentation to reflect the production No library connected state; deterministic generated WAV media remains test-only on Android and available as a Linux verification source.

Fixed

  • Android Play folder now queues the recursive subtree, so folders whose top level contains only subdirectories still reach playable descendants; direct-only playback remains an explicit secondary action.
  • Folder and generic-file rows no longer expose the internal “stable source identity” wording in visible labels.
  • Reissued the rc.6 playback-liveness hardening after closing a release-runner-only test discovery defect: the stdlib host gate runs exactly its 40 unittest modules instead of importing the separate pytest-only music-ingest suite. The executed unittest count remains 136, so clean GitHub runners do not require an accidental host pytest installation before tag metadata validation.
  • Carries forward rc.6's bounded Media3 terminal-item skipping, source-neutral terminal-vs-transient stream-resolution classification, stable queue/timeline reconciliation across controller rebind, manual post-error recovery, and removal of the Android production demo source.

Testing

  • The Players/audiobook implementation and subsequent settings-polish pass were independently reviewed; focused core-model/source-server tests and the 136-test local host gate are green before release-candidate packaging.
  • Reproduced the rc.6 GitHub failure on exact tag/SHA and verified it was ModuleNotFoundError: pytest during stdlib discovery rather than a playback regression.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.

Linux packages

The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.

v0.2.0-rc.4

v0.2.0-rc.4 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 28 Aug 20:03
v0.2.0-rc.4

[0.2.0-rc.4] - 2026-08-28

Added

  • Added filesystem-first filename search on Android and native desktop. Search opens from the
    magnifying-glass control, updates automatically from three characters with a short debounce,
    matches names case-insensitively, and keeps deterministic natural/stable ordering without
    requiring embedded metadata.
  • Added persisted search match filters for directories, generic files, audio files, and playlist
    files. Generic files remains the intentional superset, while audio/playlist filters can be
    selected independently when generic files are disabled; duplicate stable identities are removed.
  • Added durable, separately configurable playback history with bounded retention. History is
    disabled by default, stores stable source/node identities rather than stream capabilities, and
    remains distinct from the queue/progress state required for crash/session restoration.

Fixed

  • Hardened Android and desktop playback recovery for stale or failed provider stream locations.
    Retriable HTTP/network failures now re-resolve the playable location from stable media identity,
    rebuild/reprepare the current item, and preserve the intended queue item and position instead of
    repeatedly handing Media3/mpv the already-failed direct URL.
  • Explicit Play after a terminal playback error now enters the same bounded recovery path, so a
    bad HTTP status does not permanently poison later Play/Pause attempts. Recovery recognizes the
    reviewed transient/auth/stale-link status set, follows nested causes, and keeps permanent client
    failures fail-closed rather than retrying indefinitely.
  • Closed the Android Media3 experimental-API lint boundary at the application container so release
    lint remains green without a baseline or global lint suppression.

Changed

  • Queue state is persisted after successful queue/selection mutations and restored by stable
    identity at startup. Expiring provider URLs are never used as durable queue identity.
  • Playback progress now checkpoints on a 30-second cadence and at lifecycle/transition boundaries
    such as pause, item change, stop/close, completion, and forced shutdown paths, avoiding repeated
    per-second paused writes while preserving bounded resume accuracy.
  • Android DataStore and desktop SQLite persistence were extended additively for the new player,
    history, and search-preference state; malformed/stale positions are normalized conservatively and
    existing persistence remains backward-compatible.
  • pCloud and local-folder library adapters now expose stable generic/playlist file nodes needed by
    filename search instead of discarding every non-audio entry from the searchable library model.

Testing

  • Added deterministic loopback-HTTP recovery coverage proving failed/stale stream resolution is
    reacquired and resumed without persisting the ephemeral URL, plus Android explicit-recovery tests.
  • Added search/filter, queue/progress/history persistence, repository codec/SQLite, and desktop
    process-smoke coverage. The release gate exercises filename search plus queue, progress, history,
    and filter restoration after SQLite reopen.
  • Revalidated the complete Android/JVM/desktop/docs/Linux release stack, including packaged crash
    recovery, local-tag recovery, MPRIS controls, locked-keyring handling, accessibility capture,
    release metadata, and zero-vulnerability documentation dependencies.

Known limitations

  • Search in this candidate is filename/name based. ID3 artist, title, year, and other embedded-tag
    match types remain intentionally deferred until the filesystem-first path is established.
  • This candidate does not promote stable 0.2.0: physical power-cut durability, physical media-key
    and suspend/resume observations, GNOME/KDE session evidence, protected EU/US provider validation
    and soak, and the existing Linux accessibility/promotion boundaries remain explicit blockers.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.

Linux packages

The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.

v0.2.0-rc.2

v0.2.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 23 Aug 05:09

[0.2.0-rc.2] - 2026-08-23

Testing

  • Added a packaged native-desktop recovery smoke that externally sends SIGKILL only after
    the recovery-armed atomic tag replacement completes, then starts a fresh packaged process,
    supplies the selected scratch root again, rediscovers durable recovery authority, and verifies
    exact-hash guarded rollback without retaining private paths, provider URLs, or credentials.
  • Revalidated the release candidate with the pinned Docker toolchain, desktop JVM/JUnit suite,
    complete Linux CI smoke set, host specification checks, and fail-closed 0.2.0 readiness gates.

Changed

  • Promotion evidence now distinguishes verified packaged process restart/reselection recovery
    from still-unverified physical power-loss durability.
  • Linux screen-reader/AT-SPI promotion status now records the current Compose Multiplatform Linux
    accessibility boundary as an upstream blocker instead of presenting it as an ordinary manual
    check that could be completed on the existing packaged UI.

Known limitations

  • Physical power-cut durability, physical media-key and suspend/resume observation, GNOME/KDE
    session checks, protected EU/US provider accounts and retained provider soak, and the exact
    post-tag v0.2.0 Arch rebuild remain explicit promotion gates.
  • Real Linux AT-SPI/screen-reader traversal is blocked by the current Compose Multiplatform
    Linux accessibility boundary; final promotion requires an explicit documented exception or a
    supported Linux accessibility bridge/UI strategy rather than silently marking that gate passed.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.

Linux packages

The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.

v0.2.0-rc.1

v0.2.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 22 Aug 20:57
v0.2.0-rc.1

[0.2.0-rc.1] - 2026-08-22

Added

  • Folder metadata-suite playlist generation now supports deterministic direct-folder and
    explicit subtree .m3u8 plans with relative paths, natural filename, disc/track tag,
    tagged-title, or modification-time ordering, trusted-duration EXTINF, safe tag-derived
    display naming, stale-evidence preflight, and bounded playlist-only post-sync regeneration.
  • A shared local-root metadata-suite session adds revision-bound preview/confirmation for tag
    and playlist work, keeps recursive playlist consent independent from recursive tag mutation,
    revokes stale reviews/queued regeneration on reconciliation signals, and requires a fresh
    post-write scan before deriving playlists after confirmed tag changes.
  • A neutral local-filesystem workbench host now proves explicit writable-root and atomic-move
    capability, registers a real JVM WatchService lease before scanning, invalidates reviews on
    relevant events before debounce, reconciles overflow/invalid observers through full rescans,
    and never turns watcher or post-sync activity into tag writes.
  • Native Compose Desktop can now bind an explicitly user-selected local directory to that host as
    a separate filesystem-first AudioSource, with opaque stable source/node IDs, direct browsing
    and playback, live/stale reconciliation state, preview/dry-run/confirmation tag controls, and
    independently gated direct or recursive playlist materialization. The selected private root is
    session-scoped rather than persisted, and source switching closes the observer and local queue
    authority.
  • A cheap host-side make local-check workflow is now the default routine developer gate,
    with optional portable-JVM make fast-test when the pinned image is already available,
    while GitHub Actions retains Robolectric, Android lint, APK assembly, docs, and the complete
    make ci merge verification.

Planned

  • Complete the remaining folder-scoped Tag workbench release boundary with a truthful Flatpak
    document-portal directory lease/path mapping (without broad host/home access), Android SAF as a
    separate platform adapter, and the remaining conflict/power-loss/rollback plus
    accessibility/platform evidence before claiming the full workbench release-ready.
  • 0.2.0 promotion only after the protected EU/US provider, alternate desktop,
    physical media-key/suspend, and real screen-reader gates are complete.
  • Verified offline pinning, saved roots, long-form controls, and Android Auto after
    cross-platform queue/progress semantics stabilize.

Known limitations

  • This is a release candidate for hands-on testing, not the final 0.2.0 promotion.
  • Physical power-cut durability, real packaged restart/reselection recovery, selected-folder
    screen-reader/focus review, physical media keys and suspend/resume, GNOME/KDE observations,
    and protected EU/US provider soak/account evidence remain explicit final-release blockers.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.

Linux packages

The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.

v0.1.10

Choose a tag to compare

@github-actions github-actions released this 05 Aug 21:43
v0.1.10
0bb7c6e

[0.1.10] - 2026-08-05

Added

  • Shared Android/Linux signed-link retry policy and desktop stream-failure classification
    that distinguish unexpected playback loss from normal EOF, explicit stop, and process exit.
  • Keyboard-first library and queue focus with visible selection, F1 help, complete play,
    append, inspect, reorder, and remove alternatives, and modal shortcut suppression.
  • Executable current-session Secret Service/MPRIS evidence, immutable Arch clean-build,
    bounded resilience-soak, and fail-closed 0.2.0 promotion validation commands.
  • A canonical 0.2.0 promotion matrix and release evidence schema separating automated,
    current-session, visual, protected-provider, and explicitly accepted boundary states.
  • Isolated locked-keyring, 200% high-contrast capture, externally driven MPRIS control,
    and packaged logind sleep-monitor gates with redacted retained evidence.
  • A normative folder-scoped Tag workbench specification for reviewing one directory at a
    time, reconciling live changes, proposing deterministic corrections, and applying only
    explicitly approved local edits through an atomic, verified, rollback-capable pipeline.

Changed

  • The documentation header now exposes the latest published release from canonical
    changelog data, and the landing page provides direct Android APK, AppImage, Flatpak,
    checksum, evidence, source, and package-channel links.
  • The repository changelog is now generated as a first-class searchable documentation
    page, and the Pages workflow rebuilds when VERSION or CHANGELOG.md changes.
  • Documentation synchronization removes duplicate copied page headings and validates the
    rendered release badge, binary links, changelog route, and release-token closure.
  • Linux playback now performs one bounded capability re-resolution per stable media
    identity and cooldown window, resuming from durable progress without automatically
    restarting the mpv process or exposing provider URLs in state or diagnostics.
  • The roadmap now treats published 0.1.9 AppImage/Flatpak evidence as complete and lists
    only executable current-host, alternate-session, visual, soak, and protected-provider
    blockers before 0.2.0.
  • Desktop credential restoration performs bounded Secret Service lookup off the UI thread;
    a locked collection leaves the client responsive and exposes a fixed recovery message.
  • The Linux client listens for logind PrepareForSleep, force-checkpoints and pauses active
    playback before sleep, then resolves a fresh capability and resumes once after wake.
  • Compose Desktop now exposes explicit heading, selection, current-track, and player-state
    semantics plus a deterministic black/white/yellow high-contrast palette and non-color labels.

Security

  • Current-session evidence uses a disposable random Secret Service value, clears it
    immediately, and records neither the value nor the session D-Bus address.
  • The locked-keyring gate operates on a private ephemeral D-Bus/keyring, returns no
    credential, enforces a five-second maximum, and never touches the real user collection.
  • Stream refresh status is fixed and redacted; signed URLs and provider response content
    remain outside persistence, UI state, logs, and evidence.

Testing

  • Added shared retry-policy, mpv EOF/stop/failure classification, shortcut resolution,
    selection bounds, readiness-schema, session-audit, Arch-gate, and soak-contract tests.
  • Added sleep-transition policy, blocked-vault timeout, external MPRIS method, Flatpak
    logind permission, accessibility semantics, and current-host evidence contract coverage.

Known limitations

  • The Tag workbench is a reviewed specification in this release, not an implemented file
    mutation surface. Existing Tag studio export behavior remains unchanged.
  • 0.2.0 still requires protected EU/US provider evidence, GNOME and KDE observations,
    physical media-key and suspend/resume checks, and a real screen-reader review.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.

Linux packages

The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.

v0.1.9

Choose a tag to compare

@github-actions github-actions released this 03 Aug 23:31
v0.1.9
fbd2542

[0.1.9] - 2026-08-03

Added

  • Explicit unexpected-mpv-exit state with a user-controlled restart-and-resume action;
    automatic player restart attempts remain exactly zero.
  • A real-host crash-recovery smoke that forcibly terminates mpv, verifies stable queue
    identity, and requires resumed playback to remain within a five-second checkpoint bound.
  • A clean-profile runner for packaged desktop and AppImage smoke tests, including an
    isolated temporary directory that prevents stale extract-and-run state, plus isolated
    Flatpak application HOME/config/data/cache/state paths.
  • A deterministic AppImage smoke path that explicitly extracts into a private directory,
    verifies the reviewed AppRun, embedded version metadata, and launcher containment,
    then executes the packaged smoke instead of trusting runtime extract-and-run caching.
  • Retrying MPRIS identity and playback-status probes so transient D-Bus registration
    races cannot fail an otherwise healthy Flatpak package run.
  • A complete release-graph validator covering immutable version/tag/commit provenance,
    required artifact kinds and filenames, sizes, SHA-256 evidence, checksum closure,
    release notes, symlink rejection, and forbidden secret/ephemeral fields.
  • An Arch PKGBUILD renderer that requires a real HTTPS source archive and calculates
    its checksum instead of accepting SKIP or unresolved placeholders.
  • A detailed GNOME/KDE/i3, accessibility, package, and soak evidence matrix whose
    unverified cells remain explicit blockers for 0.2.0.

Changed

  • The Linux gate now includes forced crash recovery and packaged clean-profile smokes in
    addition to unit, application-image, normal mpv/SQLite, and MPRIS checks.
  • Tagged AppImage and Flatpak jobs run application smokes with isolated user state, and
    publication revalidates the finalized artifact graph against GITHUB_SHA.
  • Player IPC polling reports fixed local health messages and cannot expose provider
    response data through process-exit diagnostics.

Security

  • A crashed player is never restarted automatically; recovery requires an observable
    user action that re-resolves the current stream and uses durable progress.
  • Release publication rejects artifact symlinks, unsafe paths, missing or extra checksum
    entries, mismatched evidence, and secret-bearing evidence keys.
  • Arch package preparation rejects insecure source URLs and floating/skipped checksums.

Testing

  • Added pure exit-state tests, real mpv termination/restart coverage, clean-profile
    environment tests, release-graph mutation tests, Arch renderer tests, and a simulated
    delayed Flatpak playback-status registration regression.

Known limitations

  • Clean-profile workflow wiring is automated, but final AppImage/Flatpak evidence still
    belongs to the immutable tagged release run.
  • GNOME, KDE Plasma, and i3 keyring/MPRIS/suspend cells, the manual accessibility matrix,
    a four-hour soak, the final Arch makepkg --cleanbuild, and protected EU/US provider
    validation remain external blockers for 0.2.0.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.

Linux packages

The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.

v0.1.8

Choose a tag to compare

@github-actions github-actions released this 03 Aug 23:18
v0.1.8
a1eac9f

[0.1.8] - 2026-08-03

Added

  • A shared queue-restoration algorithm that repairs stale snapshots by stable identity,
    preserves the selected surviving item, and chooses a deterministic nearest fallback.
  • Desktop Secret Service regression coverage for missing tooling, caller-buffer clearing,
    and invalid key rejection.
  • Host-side tests for the Flatpak-to-host mpv argument boundary.

Changed

  • Android and Linux now persist partially repaired queues immediately and report omitted
    entries rather than rediscovering the same stale state on every launch.
  • Desktop progress is force-checkpointed before queue mutation, on playback failure,
    during disconnect, and on orderly shutdown instead of only at five-second boundaries.
  • mpv JSON IPC commands carry request IDs, ignore unrelated messages, enforce bounded
    responses, and require an explicit successful command result.
  • Desktop pCloud disconnect removes the active source locally first, stops pCloud
    playback, persists a disconnect tombstone and clears affected queue state before
    attempting Secret Service cleanup and typed remote session revocation.
  • AppStream metadata now records release history and release validation requires the
    current VERSION to be represented.

Security

  • Secret Service subprocesses are bounded and terminated on timeout, caller credential
    buffers are cleared in finally, lookup keys are constrained, and oversized results
    are rejected.
  • The Flatpak host-mpv bridge rejects arbitrary host command flags and accepts only the
    deterministic properpcloud playback contract plus its private runtime socket.
  • mpv failures expose a fixed command error rather than response data that may include an
    ephemeral signed stream location.

Testing

  • Added shared restoration tests for missing predecessors, missing selected entries,
    end-of-queue fallback, and fully unavailable queues.
  • Added Android orchestration coverage proving the repaired selection and rewritten
    persisted index.
  • Expanded desktop mpv protocol tests for event filtering, response correlation, and
    redacted command failures.

Known limitations

  • Protected pCloud account validation and the GNOME/KDE/i3 compatibility matrix remain
    external gates; this patch makes no new live-provider claim.
  • Automatic mpv crash restart, long-duration soak evidence, broad desktop accessibility,
    and reproducible Arch packaging are intentionally assigned to 0.1.9.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.

Linux packages

The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.

v0.1.7

Choose a tag to compare

@github-actions github-actions released this 03 Aug 19:30
v0.1.7

[0.1.7] - 2026-08-03

Added

  • Secret-safe local OAuth configuration that reads only the public
    PCLOUD_CLIENT_ID from an ignored .env.
  • A committed .env.example and host-side regression tests for dotenv parsing,
    quoting, environment precedence, duplicate keys, and malformed identifiers.

Changed

  • Tagged builds now receive properpcloud's registered public pCloud application ID
    through the GitHub repository variable, enabling the ordinary OAuth button.
  • Android account settings describe direct username/password sign-in only as a
    collapsed fallback when OAuth is configured.

Security

  • .env* files are excluded from Git and Docker build contexts. Client tooling
    exports only the public application ID and never reads or passes
    PCLOUD_CLIENT_SECRET to Gradle, containers, binaries, CI, or release artifacts.

Testing

  • The build path is validated from dotenv/environment configuration through Make,
    Docker, Gradle, and Android BuildConfig, with malformed configuration failing
    closed before client compilation.

Known limitations

  • Protected live OAuth authorization, denial, regional logout, and device-log
    redaction evidence remains a maintainer/device gate outside public CI.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.

Linux packages

The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.

v0.1.6

Choose a tag to compare

@github-actions github-actions released this 02 Aug 19:42

[0.1.6] - 2026-08-02

Added

  • A clearly labelled interim direct pCloud sign-in path implementing the provider's
    documented HTTPS userinfo authentication with explicit Europe/United States choice.
  • Token-kind-aware session persistence and SDK authentication for OAuth bearer tokens
    and direct-login auth tokens.
  • A safer account-settings layout that separates recommended OAuth, interim direct
    sign-in, and advanced developer configuration.
  • The supplied raster properpcloud logo in README and in-app About branding.

Changed

  • Tagged releases no longer require a pCloud client ID while the developer console is
    unavailable; a configured ID is still validated and immediately enables preferred OAuth.
  • Legacy-auth SDK reads move all method parameters and the auth token from URL queries
    into HTTPS form POST bodies.
  • Disconnect invalidates OAuth and legacy tokens with their respective documented
    transport conventions while preserving local-first removal.

Security

  • Direct-login passwords are held only in short-lived UI/request state, removed from the
    form before the request starts, never persisted/logged/exported/backed up, and sent only
    to the explicitly selected allowlisted regional pCloud API over HTTPS POST.
  • Direct authentication disables redirects, bounds response size and time, avoids
    cross-region credential probing, and retains only numeric provider rejection codes.
  • Direct-login tokens request a 90-day absolute lifetime and 30-day inactivity lifetime
    rather than the provider's longest possible lifetime.

Testing

  • Added direct-login result, buffer-clearing, network/redaction, legacy SDK request
    transformation, regional-host rejection, and Compose account-settings coverage.

Known limitations

  • pCloud's public direct-login documentation does not describe a two-factor challenge;
    affected accounts may require OAuth once application registration becomes available.
  • Live direct-login and OAuth validation require a disposable provider account and remain
    outside public CI; the release is an evaluation build signed with an Android debug key.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Live pCloud OAuth/direct-login and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.

v0.1.2

Choose a tag to compare

@github-actions github-actions released this 02 Aug 14:35

[0.1.2] - 2026-08-02

Added

  • Dedicated now-playing destination with large artwork fallback, title and filename
    context, seekable elapsed/remaining timeline, transport controls, queue position,
    up-next preview, and one-tap queue/folder/metadata navigation.
  • Canonical metadata domain records for provenance, confidence, tag snapshots,
    Keep/Clear/Set patches, revision-or-hash-guarded edit plans, and deterministic
    common-field, candidate, and track-sequencing batch operations.
  • metadata-tags module using a replaceable jaudiotagger adapter for real local tag
    inspection, copy-on-write staging, SHA-256 guarding, tag reread, and field verification.
  • metadata-online module with an identified, HTTPS MusicBrainz recording client,
    serialized request-rate gate, secure XML parser, Cover Art Archive references, and
    opt-in AcoustID/Chromaprint lookup contracts without embedded service keys.
  • Comprehensive Android UX modernization and metadata maintenance specifications,
    including the guarded pCloud remote-replacement state machine and audit boundaries.

Changed

  • Mini-player now opens the first-class player and displays thin playback progress.
  • Queue rows use one compact overflow menu while retaining move-up/down alternatives,
    containing-folder navigation, metadata inspection, and removal.
  • Provider inspection uses a grouped adaptive bottom sheet instead of an oversized
    blocking dialog.
  • Settings disclose the exact metadata-tool status and the fact that remote file
    replacement remains disabled until conditional upload and readback are implemented.

Security

  • Local metadata edits never modify source bytes in place; failed candidates are
    removed and intended fields must pass reread verification.
  • MusicBrainz XML parsing rejects document types and external entities, and online
    matching remains explicit, rate-limited, provenance-preserving, and non-mutating.
  • Added jaudiotagger's LGPL 2.1-or-later notice and complete license text to the
    repository and APK asset set.

Testing

  • Added metadata plan, sequencing, revision/hash guard, real WAV staged-edit,
    MusicBrainz query/parser, rate-gate, and dedicated now-playing Compose tests.

Known limitations

  • The metadata editor UI, Android Chromaprint implementation, artwork writes, and
    expected-revision pCloud replacement are specified but intentionally not enabled.
  • Live pCloud account validation, production signing, physical-device accessibility,
    and Android 17 runtime validation remain external release gates.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Live pCloud OAuth and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.