CanvasTTY v1.0.2
Pre-release
Pre-release
Highlights
- Added the built-in Browser as a movable, resizable CanvasTTY application with trusted tabs, navigation, downloads, dialogs, safe restore, and browser-data clearing.
- Added scoped browser automation for CanvasTTY-launched Claude Code, Codex, and Kimi sessions over authenticated local-only transports; no TCP listener, remote-debugging port, arbitrary JavaScript, cookie/storage API, or raw CDP surface is exposed.
- Added revision-bound element refs, bounded concurrency and rate limits, per-agent activity isolation, dialog/download handling, and sensitive-region screenshot redaction that fails closed.
- Added a persistent redacted browser audit hash chain under Electron
userData/browser/audit, with 100 MB rotation, 30-day rotated-file retention, integrity checks, and fail-closed unaudited agent mutations. - Integrated Browser cards with canvas selection, click/hover focus, window actions, wheel zoom, and a stable renderer surface during native-view repositioning.
- Hardened Windows agent access with a bundled current-user-only named-pipe host and synchronized Browser/security documentation in English, Russian, and Simplified Chinese.
- Fixed repository secret auditing for linked Git worktrees while preserving personal-path detection in publishable files.
Known issue
If the main CanvasTTY window did not start maximized, opening Browser can make the native browser view cover the window and leave the canvas controls unusable. For this prerelease, start CanvasTTY maximized before opening Browser. A fix is planned for the next patch.
Full changelog: v1.0.1...v1.0.2