Releases: langming58-hash/studyhub-local
Release list
StudyHub Local v0.3.0-beta.1
StudyHub Local v0.3.0-beta.1
This prerelease is the first public macOS DMG for StudyHub Local.
Download
Download StudyHub-Local-v0.3.0-beta.1-macos-arm64.dmg and its matching .sha256 file from the assets below.
Compatibility
- Apple Silicon only (
arm64) - macOS 13 Ventura or later
- Unsigned beta
- Not notarized
Install
- Download and open the DMG.
- Drag StudyHub Local to Applications.
- Try to launch it normally.
- If macOS blocks the unsigned beta, open System Settings -> Privacy & Security and choose Open Anyway for StudyHub Local.
Do not disable Gatekeeper. Git, Node.js, Python, Rust, npm, and Terminal are not required.
Included
- Local course, week, material, and exercise organization
- Local preview and search
- Notes and study records
- Optional source-grounded OpenAI integration
- Bundled local backend
- English and Simplified Chinese UI
This remains an early beta. Please report issues without attaching private course files, API keys, local databases, or personal paths.
StudyHub Local v0.2.0
StudyHub Local v0.2.0 is a source release focused on a clean first run and a more complete local desktop architecture.
Highlights:
- English and Simplified Chinese UI with system detection and live switching
- clean empty first run with no bundled sample courses
- user-managed terms, courses, weeks, imports, classification, and relinking
- local notes, study records, conversations, and source-grounded AI safeguards
- Tauri macOS prototype source with a bundled Python backend architecture
- strict separation between production resources and synthetic test fixtures
- expanded privacy, security, first-run, i18n, product, and packaged-app acceptance coverage
Distribution note: this release publishes source code only. No unsigned .app, .app.zip, or DMG is attached. Signed and notarized macOS distribution remains future work.
StudyHub Local v0.1.5
v0.1.5 focuses on first-time-user polish and privacy-safe response handling.
Highlights:
- hide stale empty courses after switching StudyLibrary
- tighten Ask GPT no-match behavior
- make Notes discoverable and persistent in the UI
- improve plain-text official solution parsing
- sanitize solution metadata responses
- add P2 regression acceptance coverage
- first-time-user retest now PASS
Privacy note:
- internal text-cache paths are no longer exposed in solution payloads
A fresh first-time-user retest now passes without the previous P2 friction. StudyHub Local is still early-stage, and feedback is welcome.
StudyHub Local v0.1.4
Security follow-up for active-content preview isolation.\n\nHighlights:\n- Treats StudyLibrary files as untrusted preview content.\n- HTML, HTM, XHTML, XML, and SVG previews are returned as escaped plaintext, not executable same-origin documents.\n- SVG is not served inline as image/svg+xml.\n- Preview responses preserve nosniff and add stricter generated-preview CSP.\n- Adds synthetic HTML/HTM/SVG active-content regression tests.\n- Preserves exact same-origin enforcement, Host/DNS-rebinding protection, CSRF, loopback-only bind, request-size limits, filesystem containment, MCP read-only behavior, OpenAI opt-in, and path suppression.\n\nValidation:\n- npm run ci PASS\n- privacy acceptance PASS\n- security acceptance PASS\n- bridge acceptance PASS\n- Ask GPT synthetic acceptance PASS
StudyHub Local v0.1.3
Defense-in-depth security tightening for exact same-origin validation.\n\nHighlights:\n- Origin validation now requires exact HTTP scheme, Host hostname literal, and effective port match.\n- Rejects cross-port localhost origins, localhost vs 127.0.0.1 mismatches, and HTTP/HTTPS scheme mismatches.\n- Preserves CSRF token enforcement when Origin is absent.\n- Preserves universal Host validation, DNS-rebinding protection, /api/session bootstrap, loopback-only bind, request-size limits, filesystem containment, MCP read-only boundary, and security headers.\n\nValidation:\n- npm run ci PASS\n- privacy acceptance PASS\n- security acceptance PASS\n- bridge acceptance PASS\n- Ask GPT synthetic acceptance PASS
StudyHub Local v0.1.2
Runtime security follow-up for localhost Host header validation.\n\nHighlights:\n- Added universal loopback Host header validation for all supported request methods.\n- Rejects hostile Host values before GET /api, /preview, /mcp, and static serving.\n- Moved CSRF bootstrap token out of /api/health into /api/session.\n- Added DNS-rebinding regression tests and preview Host privacy coverage.\n- Preserves existing POST CSRF, Origin, Sec-Fetch-Site, loopback binding, path traversal, request-size, and API/MCP privacy protections.\n\nValidation:\n- npm run ci PASS\n- privacy acceptance PASS\n- security acceptance PASS\n- bridge acceptance PASS\n- Ask GPT synthetic acceptance PASS\n- real localhost Host-header smoke test PASS
StudyHub Local v0.1.1
Security hardening release for local API boundaries.\n\nHighlights:\n- Added CSRF protection and same-origin loopback validation for mutating endpoints.\n- Hardened upload path handling, size limits, and atomic file writes.\n- Reduced API/MCP path and provider ID exposure.\n- Added security headers and no-store API/MCP caching.\n- Added synthetic security acceptance tests and privacy-safe commit metadata regression checks.\n\nValidation:\n- npm run ci PASS\n- privacy scan PASS\n- security acceptance PASS\n- bridge acceptance PASS\n- Ask GPT synthetic acceptance PASS
StudyHub Local v0.1.0
Early public release of StudyHub Local.
Highlights:
- Local-first course and week browser
- Synthetic demo mode with no private course materials
- Local search and source previews
- Optional Ask GPT integration with source-grounded context
- Question safety: no generated practice questions
- Read-only MCP endpoint for local integrations
- Privacy-first documentation, security policy, and CI
This project does not include or distribute university course materials. Users are responsible for using only materials they are authorized to process.