0.3.1
No database migration, so going back to 0.3.0 is safe, and no new setting: upgrading
is a change of image tag.
The reasons to take it: an account can now be deleted from Settings, by its owner,
without database access; a wrong current password in Settings no longer signs you
out; and the application has its new logo. If you script against the API, one
behaviour changed: POST /api/auth/password answers a wrong current password with
403 instead of 401 (see Fixed), and the new POST /api/auth/delete-account
does the same. The rest of this release is the showcase site, which a self-hosted
instance does not run.
Added
- Deleting your account, from Settings → Account. A "Delete account" section
opens a confirmation that says, in the user's language, that the account and all
its data are deleted immediately and for good, says how many projects and checks
that is, and asks for two things a stray click cannot supply: a word typed out
(DELETE, orSUPPRIMERin French) and the account's password. It removes the
user, its sessions, and every project it is the only member of, with their
checks, ping and incident history, API keys and alert channels. A project shared
with other members only loses this member; an account that is the only owner of
a project other people belong to is refused, whole, with a 409, rather than
leaving that project without an owner. Behind it isPOST /api/auth/delete-account
(a user session and the password; an API key is refused), whose failed attempts
count towards the same lockout as a login. The security log records it, with the
address, for its retention period. Until now an account could not be deleted
without database access. - Legal pages on the site, in French and English: legal notice, privacy policy
and terms of use, linked from the footer. The privacy policy is written from
what the application actually stores (accounts, sessions, the security log,
heartbeat history, alert deliveries, and how long each is kept), names the
processors (OVH, Mailjet) and lists the one cookie,sw_refresh, which is
strictly necessary. The legal notice names the host (OVH) and a contact address;
the publisher, a private individual, stays anonymous as French law allows
(LCEN, art. 6-III-2), andsite/src/legal.tsis where a fuller identity goes
the day the service is run as a business.
Fixed
- A wrong current password no longer signs you out of the interface. Changing
the password answered a wrong current password with a 401, which is also what
tells the browser its session expired: it refreshed the session, sent the same
wrong password a second time (counting twice towards the lockout) and then sent
the user to the login page. It now answers 403, which leaves the session alone and
shows "Current password is incorrect" in place.
Changed
- A new logo, everywhere the application and the site show one. The pale
rounded tile with a monitor and a heartbeat replaces the purple square with a
white trace: in the application header and on the sign-in page (an image now, not
a drawing in the page's colours), as the favicon (favicon.svg, plus a
favicon.icofor browsers that ignore an SVG one, and anapple-touch-icon.png
for an iPhone's home screen), on the site, and on the sharing cards. It is cut out
of its white margin, with transparent corners rather than white ones. The new
files are listed among the brand files that are not under the licence. - The site is in English by default; French is under
/fr/. It was the other
way round. A browser whose first language is French is taken to the matching
French page once, unless the visitor picked a language with the picker (the
choice is remembered in the browser). Search engines and link previews see
English, which is alsox-defaultforhreflang. The French addresses move:
/job-monitoring/is now/fr/job-monitoring/, and the English ones lose their
/en/(/en/job-monitoring/is/job-monitoring/). Nobody has bookmarked these
yet, so there is no redirect from the old ones. - The footer no longer lists "Cron job monitoring" beside "Job monitoring": it
said the same thing twice. The page itself stays, linked from the pages that
discuss cron.
Container image
ghcr.io/liliang-dev/silencewatch:0.3.1