Releases: wanderwildwood/kotozute
Release list
v1.11.2
The first launch after this update takes longer than usual, once. The message database is
being rewritten as an encrypted one. Nothing is asked of you while it happens, and every
launch after it is normal.
Messages are stored encrypted on the phone
The database was in the clear before this — anything that could read the file off the device
could read the messages. It now has a key of its own, held in the phone's keystore. It is not
a passphrase and it does not lock the app; it means the messages are not readable by lifting
the file off the phone.
Signal used to stop silently
A bridge that refuses the phone — a rotated token, a pairing revoked — now says so: on the
settings line, above the message box, and in a notification. Before, Signal simply went quiet
and there was nothing anywhere saying why.
A catch-up that stops short of what the bridge is holding now comes back for the rest instead
of leaving the phone behind until the next round.
Lists turn a page everywhere
Not only on the texts. The Signal list, Signal threads and the contact list step a screen at a
time now, as the conversation list already did.
Full Changelog: v1.11.1...v1.11.2
v1.11.1
Deleting a conversation crashed the app.
It crashed from the inbox and from the archive alike, and on every delete rather
than now and then. The conversation was in fact deleted — reopening the app showed
the right list — but the app went down each time.
Nothing else changed.
Full Changelog: v1.11.0...v1.11.1
v1.11.0
Links in messages are links.
A web address or an email in a Signal message used to be text you retyped, and in the
browser it was text on both rails. Now it is something you tap, in all four places — the SMS
thread, the Signal thread, and both of them in Desktop Sync.
The three ways of handling a link are unchanged and now mean the same thing everywhere.
Ask before opening, which is the default, shows you the address and waits. Never open
leaves the text exactly as it arrived. Always open hands it to the browser.
That last one was broken. Links were only ever made clickable on the Ask path, so choosing
"Always open links" — the setting that sounds most permissive — quietly produced no links at
all. If you picked it and wondered why nothing was tappable, that is why, and it works now.
In the browser the links are built out of text, never out of markup, and only a web or email
address is allowed to become one. A message body is the one thing on that page written by
somebody else, and a page that parses it as markup is a page where a text someone sends you
can run code. A <script> tag or a javascript: address in a message stays visible text and
does nothing.
Two smaller things from the same read-through. The Signal account screen used to describe the
device that is the account as "unnamed" — a registered bridge has no name, because Signal
only asks for one when a device is linked — and now says "this bridge". And Mark all read has
left the settings list, since the selection menu already has it, while Storage and privacy
has moved above Desktop Sync and Signal.
Full Changelog: v1.10.0...v1.11.0
v1.10.0
Keep Signal connected — a new switch in Settings → Signal, off by default.
Until now the Signal connection lived only as long as the app's process, and nothing owned
that process. It existed because you opened the app, or a text arrived, or the phone
booted; when Android reclaimed it the connection went too, and the next Signal message
waited until something woke the app again. That it worked in the background at all was an
accident: Desktop Sync runs a foreground service, which kept the process alive and the
Signal connection with it. With Desktop Sync off, nothing did.
With the switch on, a service holds the connection open and messages arrive as they are
sent. The price is a permanent notification — quiet, no badge, with a Stop on it that turns
the setting off rather than leaving the next reboot to bring it back.
With it off, which is how it ships, there is no notification and Signal catches up every
fifteen minutes and whenever you open the app. That bounds how long a message can sit
unseen rather than leaving it to chance.
On a phone chosen partly for not having notifications on it, that seemed a choice to leave
with the person holding the phone rather than make for them.
Both halves are re-established whenever the app's process starts, including the one Android
creates at boot — so Signal comes back on its own after a flat battery.
Full Changelog: v1.9.0...v1.10.0
v1.9.0
Setting Signal up used to take three runs of the installer, four things installed
beforehand, and a QR code drawn by a tool the script never checked you had. Most of that
is gone.
It is one run now. What it needs is checked before anything happens and handed back as a
single apt install line, rather than discovered one piece at a time — the last of which
used to announce itself only after signal-cli was already installed. It offers to link
this computer to your Signal account where you stand, draws that QR itself, waits for you
to scan it, and then carries on and finishes. Registering is still only explained, never
done for you: it makes the computer become the account and ends Signal on your phone for
that number, which is not a thing to do behind a yes-or-no prompt.
Go is no longer among the things you need. The bridge is built here and published with the
release, and the installer fetches it, checking it against the checksum published beside
it, when Go is absent. Where Go is present it still builds from the source you cloned,
which is the better answer and the reason the download says plainly what it does and does
not prove.
Pairing the phone no longer goes through a browser. Two thirds of the pairing link is a
certificate fingerprint, and that single fact was why you had to pair a browser to the
phone first, purely to have somewhere to paste 140 characters. The installer draws the
link as a QR and Connect a bridge has a Scan button. Point the phone at the terminal. The
paste path is untouched for anyone already in Desktop Sync.
The installer also learned the difference between an operating system and a processor. It
would have told a Mac there was no Signal library for it, which is untrue — macOS is fine,
on both Intel and Apple Silicon. What macOS and Windows lack is systemd, which is a
different problem with a different answer. It says which one is in the way, and says it
before asking for sudo.
Full Changelog: v1.8.1...v1.9.0
v1.8.1
Back from a conversation goes to the conversation list.
Crossing between someone's SMS and Signal threads used to leave the screen you
came from underneath the one you went to, so hopping between the two a few times
buried the list under a stack of thread screens and the back arrow walked down
through every one of them. Crossing replaces the screen it leaves.
A reply now shows what it is replying to. The bridge has always known — Signal
names the message a reply answers, and it was kept and carried all the way to
the phone — but nothing drew it, so a reply arrived as an ordinary message and,
in a group, answered nothing you could see. It sits above the message in the
quieter colour, on the phone and in the browser alike. A conversation fills from
the day the bridge was paired, so what a reply answers is sometimes older than
anything here; that says so rather than showing nothing.
The conversation list has no overflow button any more. It held one item, and on
this screen that button costs the filter tabs their full names. Mark all read is
in Settings now, at the top with Archived and Scheduled, and it still appears
with the other actions when conversations are selected. The settings cog has
moved to the right edge, where the overflow used to be.
Full Changelog: v1.8.0...v1.8.1
v1.8.0
Signal is here. It sits in the same conversation list as your texts, with a badge
on the rows that came over it; unmarked still means SMS. It needs a bridge running
on a computer that stays on — see the README, and bridge/install.sh sets it up.
Hold a Signal message to react to it, and hold it again to take yours back. The
browser does the same on a right-click. Six emoji rather than a picker: a reaction
is a quick thing, and a grid of a thousand glyphs on this screen is not quick.
Mute works on SMS conversations now. The app could always silence one — it was
three screens down, under that conversation's own notification settings, which is
not where anyone looks for something they want to do in a hurry. Same switch, now
in the thread's menu, in the list's selection, and in the browser.
Write a message now and send it later, on either rail and from either place. Hold
Send in a Signal thread to pick a time; the browser has a clock beside its Send
button. The phone holds it and the phone's own alarm sends it, so it goes out
whether or not the browser is still open. Text only, and it says so.
The installer checks what it downloads against a known checksum instead of running
whatever arrived.
Removed: a store listing and an F-Droid config that were both QUIK's, inherited
whole and never touched — the title said "QUIK SMS" and all five languages sent
readers to QUIK's support room. A stray contact string sent French-locale users to
that project's maintainer's email. None of it was ever ours to hand out.
Full Changelog: https://github.com/wanderwildwood/kotozute/commits/v1.8.0
v1.6.4
Desktop Sync gives you an address a computer can reach, and a link you can copy.
With mobile data on alongside Wi-Fi, the link could name the carrier's address
instead of the phone's. The relay was listening correctly the whole time, so
everything looked right except the one address you were handed, and the browser
simply timed out. It asks the system which network is Wi-Fi now rather than
taking whichever address it found first — and where there is no such network it
says so instead of offering one that cannot work.
The link can be copied. It had to be read off the phone and typed into a
computer, and the token was drawn from an alphabet holding both l and I and 1.
New links avoid every character that can be mistaken for another, and a link
typed by hand is no longer refused for its capitals. Existing links keep
working; Reset Desktop Sync link issues one in the new alphabet.
On a phone with two SIMs, a conversation now says which one the newest message
went out on. It was marked only where the SIM changed, which on a thread that
never changes meant a single mark at the very top, far from anything you were
looking at.
Thanks to those who reported the address bug and asked for the rest.
Full Changelog: v1.6.3...v1.6.4
v1.6.3
A swipe reaches the end of a thread.
The last page of a conversation stopped a line or two short: the newest message
was cut off behind the compose bar, and swiping again landed in exactly the same
place, so the end of it could not be read at all. A message taller than the
screen — a long one, or a photo — halted a thread the same way on the way past
it. Both turn now.
Full Changelog: v1.6.2...v1.6.3
v1.6.2
The app crashed the moment you opened a conversation, if it wasn't your default SMS app.
Android grants the message permissions to whichever app holds the default-SMS role and takes
them back when it doesn't, so an app that isn't the default can't read the message database at
all. This one was asking to be your default instead of asking for those permissions, rather
than as well — so if you declined that first prompt, or just backed out of it, the next
recipient you tapped took the app down. No dialog, nothing in the way of an explanation.
It asks for both now, the default-app prompt first, because saying yes to that one grants
everything at once. Saying no to all of it is no longer fatal either: the conversation opens
empty rather than sitting on Loading or dying.
Found by a Kompakt user on Reddit. It could only ever happen to someone who hadn't made this
their default app, which is why it stood as long as it did.
Full Changelog: v1.6.1...v1.6.2