v3.6.2 — Profile-Based Access Control & Windows Compatibility
Release date: 2026-06-28
A maintenance release focusing on two community-contributed improvements: profile-based access isolation for multi-agent deployments, and Windows compatibility fixes.
✨ Feature: Profile-Based Access Control (PR #78 by @sfalsin)
What it does: Restricts which Hermes agent profiles each HCI user can see and manage. In multi-agent setups where you run multiple Hermes profiles (e.g. "jorah", "varys", "production"), this prevents users from accessing profiles they shouldn't.
Backend changes:
- New
allowed_profilesfield on user records — an array of profile names, or['*']for unrestricted access requireProfileAccessExpress middleware applied to all profile-scoped endpoints:/api/gateway/:profile/*,/api/config/:profile,/api/keys/:profile/api/profilesendpoint now filters results per-user — users only see profiles they're authorized for/api/office/agent-statesalso filtered per-usercanAccessProfile(user, profileName)andupdateUserProfiles()helper functions exported from auth modulePOST /api/usersaccepts optionalallowed_profilesarray
Frontend changes:
- Create User form now includes an "Agent Access" section with live-loaded checkboxes for each available profile
- Admin role auto-sets full access (
['*']) — no checkbox interaction needed - Files tab hidden for users without
files.readpermission - Maintenance tab hidden for non-admin users
Compatibility: Fully backward compatible. Existing users without allowed_profiles see all profiles (fallback to ['*'] behavior). No migration required.
🐛 Fix: Windows Compatibility (PR #79 by @jpntw-dotcom)
Problem: process.getuid() is a Unix-only API. On Windows, it throws TypeError: process.getuid is not a function at startup, preventing HCI from running entirely.
Changes in server.js:
const IS_ROOT = process.getuid === 0→process.getuid ? process.getuid() === 0 : false(gracefully returnsfalseon Windows, which is correct — Windows has no root concept)- XDG_RUNTIME_DIR auto-detection block now guarded with
process.getuidcheck (Linux-only feature, safely skipped on Windows)
No functional impact on Linux/macOS — the guard is a no-op where process.getuid exists.
📦 Files changed since v3.6.1
| File | Changes |
|---|---|
README.md |
+18 lines — Profile-Based Access Control documentation |
auth.js |
+23 lines, -2 — new auth functions for profile access |
server.js |
+46 lines, -23 — middleware + route guards + Windows fix |
src/index.html |
+2 lines, -2 — id attributes for nav elements |
src/js/core/auth.js |
+9 lines, -1 — nav visibility based on permissions |
src/js/pages/users.js |
+32 lines, -3 — profile selection UI in Create User form |
package.json |
version 3.6.1 → 3.6.2 |