Skip to content

v0.5.6

Latest

Choose a tag to compare

@github-actions github-actions released this 02 Oct 01:51

What changed

Added

  • The Web settings offer the Windows Firewall rule for the ports they
    choose.
    On a real site the acknowledgement address was right and the
    router forwarded the port, and every Acknowledge button still timed out:
    Windows Firewall dropped the connection before this program saw it. It took
    a rule typed by hand into Defender.

    Under Settings → Web, a Windows Firewall card now says, for the
    ack-only listener and the peer link listener, whether a rule lets them in:
    allowed, blocked, out of date (wrong port, switched off, or for
    another copy of the program), or not needed (not set, auto until its
    first start, or on this machine only). Allow through Windows Firewall
    creates or corrects the rules, and the Activity log records which ports it
    opened. Beside it is the exact PowerShell the button runs, to paste into an
    administrator terminal instead. That is the way when this program is
    running from an ordinary terminal without the rights, or when you would
    rather do it yourself.

    It works from the saved addresses, so a port changed and saved on this page
    gets its rule before the restart that opens it. It never opens Listen on,
    which is this page and its sign-in. Each rule allows one TCP port for this
    program only, and belongs to the NotifyMatrix group so it is easy to
    find. notifymatrix uninstall removes them. The router still needs its own
    forward for anything reached from outside the building.

  • A paired product's refused events are now impossible to miss. When a
    peer sends a kind of event its approved list does not include, which is
    usually its next release reporting something new, every one is refused
    until somebody approves it. All that said so was a card well down Settings
    → Peer link and a line in its receipts. At a real site, a new Rewards
    release's events were refused for as long as it took somebody to look
    there.

    Now a banner on every tab, the wall board included, says how many kinds of
    event are waiting and how many have been refused, and links to the
    decision. The Settings tab carries the count. In Peer link the decision
    comes first, as a warning, and every refusal in the receipts has a
    Decide now button that goes to it. The banner shows counts only; which
    product and which conditions stay behind the sign-in. Nothing changes for
    the paired product: refused events are answered exactly as before, and it
    keeps retrying until the decision is made.

Changed

  • The Ack-only listener's help now says the link needs the same port.
    http://your.name:50001 goes with 0.0.0.0:50001, unless the router
    deliberately forwards a different outside port to it. It used to say only
    "never your public hostname", which read as if the two should differ.

Fixed

  • An install fed only by paired products is no longer called "not set
    up".
    With Rewards, LSProtect or Sentry paired and no UniFi console, the
    header said not set up, Setup showed a red count, and a large box across
    the incident board said Nothing is being watched yet … nothing can raise
    one
    , while the paired products were raising incidents. A paired product
    now counts as something being watched. The board shows its usual Nothing
    open
    state, and the console and sources steps are marked optional ("not
    needed: 1 paired product raises incidents here") rather than to-do. A
    console that is configured but broken is still a to-do.

Verifying this release

Every binary is signed. Verification instructions, including how to
rebuild from source and compare hashes, are in
docs/RELEASING.md.

Linux / macOS — cosign (keyless, no key to trust in advance):

cosign verify-blob notifymatrix-linux-amd64 \
  --bundle notifymatrix-linux-amd64.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/suburbazine/Unifi-Notification-Matrix/' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Download the .sigstore.json next to the binary; it carries the
signature, the certificate and the transparency-log proof. Keep
--certificate-identity-regexp — without it cosign verifies a
signature from anyone.

Build provenance (any platform):

gh attestation verify notifymatrix-linux-amd64 --repo suburbazine/Unifi-Notification-Matrix

Windows: the .exe is Authenticode-signed and timestamped.
Right-click → Properties → Digital Signatures, or:

Get-AuthenticodeSignature .\notifymatrix-windows-amd64.exe

This is source-available software under the
PolyForm Noncommercial License 1.0.0. Commercial use
requires a licence: licensing@xtremission.com

Full Changelog: v0.5.5...v0.5.6