Skip to content

v0.1.7

Choose a tag to compare

@github-actions github-actions released this 03 Aug 19:30
· 82 commits to main since this release
v0.1.7

[0.1.7] - 2026-08-03

Added

  • Secret-safe local OAuth configuration that reads only the public
    PCLOUD_CLIENT_ID from an ignored .env.
  • A committed .env.example and host-side regression tests for dotenv parsing,
    quoting, environment precedence, duplicate keys, and malformed identifiers.

Changed

  • Tagged builds now receive properpcloud's registered public pCloud application ID
    through the GitHub repository variable, enabling the ordinary OAuth button.
  • Android account settings describe direct username/password sign-in only as a
    collapsed fallback when OAuth is configured.

Security

  • .env* files are excluded from Git and Docker build contexts. Client tooling
    exports only the public application ID and never reads or passes
    PCLOUD_CLIENT_SECRET to Gradle, containers, binaries, CI, or release artifacts.

Testing

  • The build path is validated from dotenv/environment configuration through Make,
    Docker, Gradle, and Android BuildConfig, with malformed configuration failing
    closed before client compilation.

Known limitations

  • Protected live OAuth authorization, denial, regional logout, and device-log
    redaction evidence remains a maintainer/device gate outside public CI.

Artifact status

The attached APK is an installable debug-signed demo build produced by the pinned Docker toolchain. Production signing remains an external maintainer boundary.

The deterministic demo source is fully exercised in public CI. Protected live pCloud OAuth, fallback direct-login, and regional-account validation require maintainer-provided sandbox credentials and are reported separately rather than simulated.

The exact jaudiotagger source archive used by the metadata adapter is attached under third-party/, checksum-verified, and rebuildable through the tagged Gradle project.

Linux packages

The release includes an x86_64 AppImage and a single-file Flatpak bundle. Both contain the application runtime. Playback still uses the distribution's installed mpv; the Flatpak invokes that host command through flatpak-spawn. Install the Flatpak bundle with flatpak install ./properpcloud-*.flatpak.