Skip to content

0.3.1

Choose a tag to compare

@liliang-dev liliang-dev released this 03 Oct 23:37
· 41 commits to main since this release
426c030

No database migration, so going back to 0.3.0 is safe, and no new setting: upgrading
is a change of image tag.

The reasons to take it: an account can now be deleted from Settings, by its owner,
without database access; a wrong current password in Settings no longer signs you
out; and the application has its new logo. If you script against the API, one
behaviour changed: POST /api/auth/password answers a wrong current password with
403 instead of 401 (see Fixed), and the new POST /api/auth/delete-account
does the same. The rest of this release is the showcase site, which a self-hosted
instance does not run.

Added

  • Deleting your account, from Settings → Account. A "Delete account" section
    opens a confirmation that says, in the user's language, that the account and all
    its data are deleted immediately and for good, says how many projects and checks
    that is, and asks for two things a stray click cannot supply: a word typed out
    (DELETE, or SUPPRIMER in French) and the account's password. It removes the
    user, its sessions, and every project it is the only member of, with their
    checks, ping and incident history, API keys and alert channels. A project shared
    with other members only loses this member; an account that is the only owner of
    a project other people belong to is refused, whole, with a 409, rather than
    leaving that project without an owner. Behind it is POST /api/auth/delete-account
    (a user session and the password; an API key is refused), whose failed attempts
    count towards the same lockout as a login. The security log records it, with the
    address, for its retention period. Until now an account could not be deleted
    without database access.
  • Legal pages on the site, in French and English: legal notice, privacy policy
    and terms of use
    , linked from the footer. The privacy policy is written from
    what the application actually stores (accounts, sessions, the security log,
    heartbeat history, alert deliveries, and how long each is kept), names the
    processors (OVH, Mailjet) and lists the one cookie, sw_refresh, which is
    strictly necessary. The legal notice names the host (OVH) and a contact address;
    the publisher, a private individual, stays anonymous as French law allows
    (LCEN, art. 6-III-2), and site/src/legal.ts is where a fuller identity goes
    the day the service is run as a business.

Fixed

  • A wrong current password no longer signs you out of the interface. Changing
    the password answered a wrong current password with a 401, which is also what
    tells the browser its session expired: it refreshed the session, sent the same
    wrong password a second time (counting twice towards the lockout) and then sent
    the user to the login page. It now answers 403, which leaves the session alone and
    shows "Current password is incorrect" in place.

Changed

  • A new logo, everywhere the application and the site show one. The pale
    rounded tile with a monitor and a heartbeat replaces the purple square with a
    white trace: in the application header and on the sign-in page (an image now, not
    a drawing in the page's colours), as the favicon (favicon.svg, plus a
    favicon.ico for browsers that ignore an SVG one, and an apple-touch-icon.png
    for an iPhone's home screen), on the site, and on the sharing cards. It is cut out
    of its white margin, with transparent corners rather than white ones. The new
    files are listed among the brand files that are not under the licence.
  • The site is in English by default; French is under /fr/. It was the other
    way round. A browser whose first language is French is taken to the matching
    French page once, unless the visitor picked a language with the picker (the
    choice is remembered in the browser). Search engines and link previews see
    English, which is also x-default for hreflang. The French addresses move:
    /job-monitoring/ is now /fr/job-monitoring/, and the English ones lose their
    /en/ (/en/job-monitoring/ is /job-monitoring/). Nobody has bookmarked these
    yet, so there is no redirect from the old ones.
  • The footer no longer lists "Cron job monitoring" beside "Job monitoring": it
    said the same thing twice. The page itself stays, linked from the pages that
    discuss cron.

Container image

ghcr.io/liliang-dev/silencewatch:0.3.1