Skip to content

onWatch v2.14.8

Latest

Choose a tag to compare

@github-actions github-actions released this 02 Oct 13:48

onWatch 2.14.8 makes Mistral recover by itself after a browser-access failure. It also closes an auth gap for dashboards served under a base path.

Security

Tray endpoints behind a reverse proxy

The tray endpoints (/menubar, /api/menubar/summary, preferences, refresh, tray-title and the new Mistral retry) skip login for requests from the local machine. Two cases exposed them to remote users:

  • Base path setups. These endpoints now always require login when ONWATCH_BASE_PATH is set. Base-path deployments sit behind a reverse proxy, and a proxy on the same host connects from 127.0.0.1. The native tray does not use the base path, so it is unaffected.
  • Forwarded requests. A request carrying X-Forwarded-For, X-Real-IP or Forwarded is no longer treated as local, whatever path onWatch is served on.

If you serve onWatch through a reverse proxy, make sure it sets X-Forwarded-For. nginx does not set it by default, so add proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;.

Fixes

Mistral browser access and recovery

A browser-access failure could leave Mistral showing stale usage until a long backoff ran out, even after you had granted access.

  • Clearer diagnostics. onWatch now tells apart a blocked browser folder, a denied or locked Keychain or keyring, a missing Mistral login, and a session that Mistral rejected. Messages are fixed text and never include cookie values or file paths.
  • Retry connection. The Mistral card on the dashboard and in the menu bar has a Retry connection button. It keeps your browser and profile selection, and it respects a 30-second cooldown and Mistral's rate limits.
  • Grant from the card (macOS). In the native menu bar, the Mistral card can open the Grant Browser Access picker and retries as soon as access is confirmed.
  • Rate limits. A 429 or 5xx response without a Retry-After header now waits at least two minutes, so retrying cannot hammer Mistral.
  • Asset caching. The recovery controls use content-versioned asset URLs, so a rebuild with the same version still loads the new controls.

Thanks to @sgogriff (#143).

Full Changelog: v2.14.7...v2.14.8