Repository navigation
Releases: shahabsalehi/testonini
Releases · shahabsalehi/testonini
Release list
v0.1.8 — scoring fix, security hardening, brand-free AI instructions
What changed since v0.1.7
Fixes
- Tests written without a per-question
pointsvalue (common in AI-authored tests) now score one point per question instead of showing0 / 0. Explicit values — including0for self-marked questions — are still honored. - Untimed practice mode truly never submits: the hidden 60-minute auto-submit countdown is gone.
- The AI authoring instructions embedded in the app no longer mention any exam brand. The app is and remains 100% exam-agnostic.
Security hardening (full model in release/SECURITY-AUDIT.md)
- DNS-rebinding protection: the
Hostheader is validated on every route — a foreign domain resolving to 127.0.0.1 is rejected before any file access. - Cross-origin (CSRF) rejection now applies to GET requests too: a web page from another site cannot read your
tests/orpdfs/folders. - Request body-size caps and atomic file writes on every write path.
Build
- CI: dropped the retired
macos-13runner leg that left releases hanging for 24 h. Intel macOS: build locally (seePLATFORMS.md).
Install
| Platform | File |
|---|---|
| Windows 10/11 x64 | TestPractice-windows-x64.zip |
| Linux x64 | TestPractice-linux-x64.zip |
| Apple Silicon (M1–M3) | TestPractice-macos-arm64.zip |
Binaries are unsigned: expect a SmartScreen / Gatekeeper prompt on first run (right-click → Open on macOS). Each zip carries a .sha256 sidecar to verify the download. Runs 100% locally — no accounts, no telemetry, no outbound connections.
v0.1.7 — fix silent first-launch failure on Windows
Fixes
- First launch on Windows failed silently: under a windowless build
(--noconsole) the process has nostderr/stdout; the HTTP server's request
logger writes tostderrbefore sending any response bytes, so every request
died before the client saw anything. The server now guards against that, and
the launcher maps the missing streams toos.devnullas a second layer. - Visible error dialogs: launch failures (port in use, firewall block) now
show a dialog instead of failing quietly. Failures are also appended to
testpractice-error.lognext to the executable. - The browser opens only after the server answers a health check on the same
localhostname the browser uses.
Security posture
Loopback-only listener (127.0.0.1 + ::1), no outbound connections, no registry
access, no admin rights. Details in release/SECURITY-AUDIT.md.
Binaries are unsigned, so the usual SmartScreen/Gatekeeper prompt appears on
first run. SHA-256 checksum files ship inside each zip for verification.