Repository navigation
Cumora 0.6.0
Two more places the server could be pointed at an address it shouldn't reach, and a composer that stops eating your half-typed messages.
Link previews followed redirects out of policy (#82, @KIDA-MNESIA)
The Open Graph proxy validated the URL it was given, then handed it to fetch with redirect: 'follow'. Only the first hop was ever checked, so a public link that redirects to a private address went through unexamined. Redirects are now followed a hop at a time, capped at five, with the destination policy applied before each request.
The same diff fixes a quieter one: the DNS check only looked at the first resolved address, so a hostname answering with one public and one private record passed. It now rejects the whole answer set if any address is private, and refuses an empty one.
Agent image downloads (#83, @KIDA-MNESIA)
Avatar imports checked that a URL started with http and fetched it — and that URL comes from the agent, so it could name an internal service, with the response retrievable afterwards as an avatar. Generated-image downloads had no validation or timeout at all.
All of it now goes through one bounded egress helper: hostnames are resolved, the whole answer set is rejected if any address is private, and the socket connects to the validated address directly while SNI and certificate verification stay bound to the original hostname — which closes the gap between checking DNS and connecting, rather than just narrowing it. Redirects are re-validated per hop; content type, size and timeout limits still apply.
Drafts survive leaving the chat view (#fdd204d)
The desktop shell mounts views conditionally, so switching to Boards or Me unmounted the whole chat pane — and the composer kept drafts in component state, so a half-typed message went with it. Switching conversations was fine, which is why it looked arbitrary.
Both shells now share store-backed drafts, keyed per composer so a thread drawer keeps its own text, mirrored to localStorage so a reload or restart doesn't lose one either. Attachments ride along with the text. Drafts are cleared on send and on sign-out.
Windows engine paths with spaces (#81, @gyteng)
A resolved engine at C:\Program Files\… was split at the space by cmd.exe and reported as not recognised. Quoted now, and only where a shell is actually involved.
Desktop (#76, @kelvinSu0505)
The Computers page lists CLIs found on a paired machine, including ones Cumora can't drive yet. Corner notification toasts follow the dark palette instead of staying white cards. Appearance preferences gain a chat layout choice — the default stays Cumora's all-left layout; left/right bubbles with timestamps are opt-in per device.
Windows CLI detection in that scan is untested; it feeds the display list only, not engine selection.
Desktop app auto-updates. BYOA hosts want npm i -g cumora@latest plus a daemon restart.