Skip to content

Easy-Post Desktop 1.2.1

Choose a tag to compare

@sgf36 sgf36 released this 12 Aug 21:29
· 177 commits to 9042f561d64206a7d1c117f0ceb971637848131a since this release

Version 1.2.1

This release stops the Settings page from displaying stored EasyPost API keys.

  • Stored API keys are no longer shown. Opening Settings used to load both saved keys into their boxes, and Show keys then rendered the production key in plaintext. Anyone looking at the screen — or any screenshot, screen share or recording — captured it. Settings now shows only whether a key is saved, never the key itself.
  • If you ran 1.2.0 or earlier with Settings visible on a shared screen or a recording, rotate that key in the EasyPost dashboard. The exposure was limited to the desktop Settings page: the mobile companion pairs by QR code and never receives a key, and no key was written to logs, to this repository or into any shipped package.
  • An empty key box now means "leave this key unchanged". The boxes start empty by design, so opening Settings and saving for an unrelated reason — changing the label size, say — no longer clears the stored keys.
  • New "Forget stored keys" button, behind a confirmation, for removing both keys from the computer deliberately.
  • Printer type and label calibration have moved into Settings, alongside label format and size. They describe the printer on the desk rather than the parcel, and were previously reachable only from the Export print sheet dialog — that is, only after buying a label.

Windows: download EasyPostDesktop-Windows-x64.zip. macOS (Apple silicon): EasyPostDesktop-macOS-arm64.dmg. Verify downloads against SHA256SUMS.txt.