onWatch 2.14.8 makes Mistral recover by itself after a browser-access failure. It also closes an auth gap for dashboards served under a base path.
Security
Tray endpoints behind a reverse proxy
The tray endpoints (/menubar, /api/menubar/summary, preferences, refresh, tray-title and the new Mistral retry) skip login for requests from the local machine. Two cases exposed them to remote users:
- Base path setups. These endpoints now always require login when
ONWATCH_BASE_PATHis set. Base-path deployments sit behind a reverse proxy, and a proxy on the same host connects from127.0.0.1. The native tray does not use the base path, so it is unaffected. - Forwarded requests. A request carrying
X-Forwarded-For,X-Real-IPorForwardedis no longer treated as local, whatever path onWatch is served on.
If you serve onWatch through a reverse proxy, make sure it sets X-Forwarded-For. nginx does not set it by default, so add proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;.
Fixes
Mistral browser access and recovery
A browser-access failure could leave Mistral showing stale usage until a long backoff ran out, even after you had granted access.
- Clearer diagnostics. onWatch now tells apart a blocked browser folder, a denied or locked Keychain or keyring, a missing Mistral login, and a session that Mistral rejected. Messages are fixed text and never include cookie values or file paths.
- Retry connection. The Mistral card on the dashboard and in the menu bar has a Retry connection button. It keeps your browser and profile selection, and it respects a 30-second cooldown and Mistral's rate limits.
- Grant from the card (macOS). In the native menu bar, the Mistral card can open the Grant Browser Access picker and retries as soon as access is confirmed.
- Rate limits. A 429 or 5xx response without a
Retry-Afterheader now waits at least two minutes, so retrying cannot hammer Mistral. - Asset caching. The recovery controls use content-versioned asset URLs, so a rebuild with the same version still loads the new controls.
Full Changelog: v2.14.7...v2.14.8