Releases: luckofthelefty/LuckyBotReleases
Release list
LuckyBot 0.6.347
Sub counter: renewals count once, plus an "announced only" option
Twitch sends most sub renewals twice: once as a plain subscribe event and again, seconds to minutes later, as the shared resub message. The stats tracker was adding both to your sub count, so a shared resub counted as two subs. Renewals nobody shared in chat (Prime re-subs, lapsed subs coming back, offline renewals) were counted too, which is why a quiet stream could show far more subs than chat ever announced.
- A renewal now counts once, however Twitch delivers it. This applies to everyone with no setup.
- New option under Stats > Settings > Sub counting: Count only subs announced in chat. Off (default) keeps silent renewals in the count, the way Twitch's own analytics do. On, your daily and monthly numbers match what your chat saw: new subs, shared resubs and gifted subs. Applies from the moment you turn it on.
Overlay security: Content Security Policy
A published attack chain turns a crafted Twitch chat message into code running on the streamer's PC when an overlay inserts viewer text as HTML and OBS's built-in browser (CEF 127, sandbox off in OBS 32.2.2 and older) does the rest. LuckyBot's own overlay code never inserts viewer text as HTML, but advanced overlays run your JavaScript and imported StreamElements widgets, which we cannot audit for you.
- Every overlay page LuckyBot serves now carries a Content Security Policy: only scripts LuckyBot wrote into the page (and scripts those load) may run. Inline event handlers, javascript: links and markup-injected script tags are refused.
- This release ships the policy in report-only mode, so nothing you have today can break. If a page runs script outside the policy, LuckyBot records it and shows a Security notice on the Overlays page and Home. The notice says in plain words what tried to run, where, how often, and what to do: treat it as an attack if you did not add it, or dismiss it if it is your own widget.
- Once the field is quiet, a later release turns enforcement on.
Regardless of LuckyBot, update OBS as soon as a build with the newer browser ships.
Also
- The tracker settings endpoint applies only the option you changed, so toggling one no longer resets another.
LuckyBot 0.6.346
Fix for stream tags on the Home page.
- Clicking a tag chip, the tags box, or the Tags label could delete your first tag instead of the one you meant. Removing a tag now only ever removes the tag whose x you clicked.
LuckyBot 0.6.345
Follow-up to the chat translation fix.
- Messages that are already in your target language no longer leave your PC. When the target is English and a message already reads as English, LuckyBot answers locally and sends nothing to the translation services, so only genuinely foreign messages are ever sent. This keeps your request count low and well clear of the free services' limits.
LuckyBot 0.6.344
Chat translation is back.
- Google shut off the free translation endpoint LuckyBot was using, so translated chat messages quietly stopped appearing. LuckyBot now tries three free services in turn and moves to the next one whenever one refuses. If they all fail, the log says so instead of staying silent. No settings to change; translations return as soon as the app updates.
LuckyBot 0.6.343
Small fix to the browser source crash revival added in 0.6.342.
- A LuckyBot browser source set to "Shutdown source when not visible" whose scene is not active has no page by design. The revival was treating that as a crash and refreshing it every two minutes. It now asks OBS whether the source is actually showing before refreshing, and leaves hidden sources alone. Sources that are showing and have lost their page are still refreshed within 30 seconds.
LuckyBot 0.6.342
Browser sources that crash in OBS now come back on their own.
- If OBS kills a LuckyBot browser source mid-stream (for example with an Out of Memory error), OBS never reloads it and the overlay stays dead until someone refreshes it by hand. LuckyBot now notices an overlay whose page has gone missing for 30 seconds and refreshes that source through the OBS websocket, at most once every two minutes per overlay. This needs your OBS websocket address and password entered on the OBS page in LuckyBot. If OBS was never reachable, the log now says so instead of staying silent.
- Every overlay page now reports its memory use to the LuckyBot log every couple of minutes, and immediately when it jumps, so a crashing source leaves a trail of how it grew rather than a bare crash line. Refresh your LuckyBot browser sources in OBS after updating to pick this up.
LuckyBot 0.6.341
Fix for browser source memory growth.
- Alert and widget overlays now fully unload a layer's video and audio the moment the layer is removed. Before, finished alerts left their media decoders behind until the browser got around to cleaning up, and an alerts source that played large video files could grow past a gigabyte and crash with Out of Memory in OBS. No overlay changes are needed; refresh the browser source in OBS after updating and it picks up the fix.
LuckyBot 0.6.340
Chat window fixes.
- Repeated TikTok shares now show as one card with a count, like "harnicita shared the stream (x10)", instead of a column of identical cards. A chat line between two shares still keeps them separate.
- When a chatbot slash action fails, for example /commercial while the ad cooldown is still running, the error no longer posts to your public Twitch chat. It shows as a LuckyBot notice on your own channel tab in the LuckyBot chat window and its popouts instead.
- Channel point and Power-Up redemption cards no longer show twice when Twitch delivers the same redemption twice.
- The Streamer.bot connection log is now archived at launch instead of being wiped, so bug reports keep the hours before a restart.
LuckyBot 0.6.339
Two fixes for the activity feed.
- The main window was silently dropping some Streamer.bot events: follows, Custom Power-Ups and channel point redemptions never made it into the feed. An internal duplicate check was matching each of those events against itself. They show up now.
- The activity popout and the OBS dock keep their own saved history. Before, the popout and the main window overwrote each other's saved list, so a restart could bring back the wrong one and lose events only the popout had received. Each window now remembers its own feed across restarts. The first launch after this update carries your existing history over.
LuckyBot 0.6.338
Small fix for the activity feed popout.
- Custom Power-Up redemptions no longer show twice. When LuckyBot receives them straight from Twitch it now drops the Streamer.bot copy, the same way it already does for the built-in Power-Ups, subs, cheers and follows. Channels where the Twitch feed does not deliver them still see the Streamer.bot copy as before.