Skip to content

Releases: shahabsalehi/testonini

v0.1.8 — scoring fix, security hardening, brand-free AI instructions

Choose a tag to compare

@shahabsalehi shahabsalehi released this 18 Sep 22:59

What changed since v0.1.7

Fixes

  • Tests written without a per-question points value (common in AI-authored tests) now score one point per question instead of showing 0 / 0. Explicit values — including 0 for self-marked questions — are still honored.
  • Untimed practice mode truly never submits: the hidden 60-minute auto-submit countdown is gone.
  • The AI authoring instructions embedded in the app no longer mention any exam brand. The app is and remains 100% exam-agnostic.

Security hardening (full model in release/SECURITY-AUDIT.md)

  • DNS-rebinding protection: the Host header is validated on every route — a foreign domain resolving to 127.0.0.1 is rejected before any file access.
  • Cross-origin (CSRF) rejection now applies to GET requests too: a web page from another site cannot read your tests/ or pdfs/ folders.
  • Request body-size caps and atomic file writes on every write path.

Build

  • CI: dropped the retired macos-13 runner leg that left releases hanging for 24 h. Intel macOS: build locally (see PLATFORMS.md).

Install

Platform File
Windows 10/11 x64 TestPractice-windows-x64.zip
Linux x64 TestPractice-linux-x64.zip
Apple Silicon (M1–M3) TestPractice-macos-arm64.zip

Binaries are unsigned: expect a SmartScreen / Gatekeeper prompt on first run (right-click → Open on macOS). Each zip carries a .sha256 sidecar to verify the download. Runs 100% locally — no accounts, no telemetry, no outbound connections.

v0.1.7 — fix silent first-launch failure on Windows

Choose a tag to compare

@shahabsalehi shahabsalehi released this 30 Aug 17:37

Fixes

  • First launch on Windows failed silently: under a windowless build
    (--noconsole) the process has no stderr/stdout; the HTTP server's request
    logger writes to stderr before sending any response bytes, so every request
    died before the client saw anything. The server now guards against that, and
    the launcher maps the missing streams to os.devnull as a second layer.
  • Visible error dialogs: launch failures (port in use, firewall block) now
    show a dialog instead of failing quietly. Failures are also appended to
    testpractice-error.log next to the executable.
  • The browser opens only after the server answers a health check on the same
    localhost name the browser uses.

Security posture

Loopback-only listener (127.0.0.1 + ::1), no outbound connections, no registry
access, no admin rights. Details in release/SECURITY-AUDIT.md.

Binaries are unsigned, so the usual SmartScreen/Gatekeeper prompt appears on
first run. SHA-256 checksum files ship inside each zip for verification.