Skip to content

v0.4.1

Choose a tag to compare

@github-actions github-actions released this 21 Sep 07:11
· 33 commits to main since this release

What changed

Take this one if you have ever edited config.yaml by hand. A file without
an ack_key brought up a daemon with no interface on any port and said nothing
about why. Everything else here is the interface being less tiring to use.

Changed

  • The tabs stay with you down a long page. Settings runs past eight
    thousand pixels and Help is longer; changing tab meant scrolling all the way
    back to the top first. The tab bar is now stuck beneath the header, and on a
    phone — where three stacked bars would eat a quarter of the screen — the
    header scrolls away instead and the tabs take the top.

    The Settings section rail, the chip strip a phone shows in its place, and
    every anchored heading were all offset by the height of the header alone;
    they now key off the height of everything stuck above them, so a section you
    jump to lands below the chrome rather than behind it. That last part was
    already slightly wrong at phone width before this change.

Fixed

  • A configuration without an acknowledgement key started a daemon with no
    interface, and said nothing about it.

    The key is normally generated the first time notifymatrix writes its own
    configuration file, so an installation that went through setup has always had
    one. A config.yaml written by hand — or restored from a backup taken before
    the key existed — did not, and the entire web surface was conditional on it:
    no settings page, no status board, no acknowledgement endpoint, no peer link.

    The daemon started anyway. It reported itself running, watched the site, and
    sent alerts carrying acknowledgement links that pointed at a port nothing was
    listening on. The only symptom was a browser that could not connect to a
    service the service manager said was up.

    The key is now generated when the configuration is opened rather than only
    when it is written, and it is kept, so links already sent keep working across
    a restart. If one still cannot be generated — a data directory that is not
    writable — the daemon now refuses to start and says so, instead of running
    headless and looking healthy.

Verifying this release

Every binary is signed. Verification instructions, including how to
rebuild from source and compare hashes, are in
docs/RELEASING.md.

Linux / macOS — cosign (keyless, no key to trust in advance):

cosign verify-blob notifymatrix-linux-amd64 \
  --bundle notifymatrix-linux-amd64.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/suburbazine/Unifi-Notification-Matrix/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Download the .sigstore.json next to the binary; it carries the
signature, the certificate and the transparency-log proof. Keep
--certificate-identity-regexp — without it cosign verifies a
signature from anyone.

Build provenance (any platform):

gh attestation verify notifymatrix-linux-amd64 --repo suburbazine/Unifi-Notification-Matrix

Windows: the .exe is Authenticode-signed and timestamped.
Right-click → Properties → Digital Signatures, or:

Get-AuthenticodeSignature .\notifymatrix-windows-amd64.exe

This is source-available software under the
PolyForm Noncommercial License 1.0.0. Commercial use
requires a licence: licensing@xtremission.com

Full Changelog: v0.4.0...v0.4.1