Releases: zeikar/liveclaw
Release list
v1.4.1
One hardening change. Nothing about using the app should look different — if it does, that is a bug
worth reporting.
Hardening
- The renderer now runs inside Chromium's OS sandbox.
sandbox: falsecame from the
electron-vite project template rather than from a need: the preload imports nothing but electron's
contextBridgeandipcRenderer, both of which a sandboxed preload keeps. Since the renderer
displays markdown written by an LLM, confining it is worth the one line — a compromised renderer is
now held inside the sandbox instead of sitting beside it with Node reachable.
Verified in all three ways the app runs, since a sandbox is a runtime property no unit test can
observe: the dev server, the plain build, and the packaged .app — where a sandboxed preload has to
load from inside app.asar. In each, all eight bridge methods answer, the navigation guard still
refuses a foreign origin, and the page still sees no require, process or Buffer. WebGL, Web
Audio, WebRTC and getUserMedia all remain available, so Live2D and the voice paths keep the browser
APIs they need.
Full Changelog: v1.4.0...v1.4.1
v1.4.0
A hardening and bug-fix release. No new features — but two changes you will notice.
Behaviour changes
- Packaged builds no longer read
$OPENCLAW_CONFIG_PATH. It names the file your gateway token
and its origin are read from, which is the same power as theOPENCLAW_TOKENa packaged build
already refuses, so it is now development-only. Auto-detection in a shipped build always reads
~/.openclaw/openclaw.json. If your config lives elsewhere, enter the gateway URL and token once
in the in-app setup screen. - Replies are no longer capped at 1000 tokens. The ceiling is now 4000, so a long answer stops
being cut off mid-sentence. How long the character actually replies is still the character
prompt's job.
Hardening
- Every IPC channel now authenticates its caller as this app's own renderer. Previously only the two
channels that hand out a credential did, while chat (which reaches an operator-grade gateway) and
settings (which decides which gateway) did not. - The main process refuses any navigation away from the renderer entry. The preload bridge belongs to
whatever document the window holds, so this closes the condition the per-channel checks defend
against. - Both ways a URL can leave the app now share one scheme rule. A middle-clicked link reached the
window-open handler without the renderer's own validation, sinceauxclickfires no click handler. - The packaged config path resolves from your OS account rather than
$HOME, and fails closed —
falling back would have handed the redirection straight back to the environment. - The macOS bundle no longer declares camera, Documents or Downloads usage. The app asks for none of
them; the microphone description stays and now says what it is for.
Fixes
- The chat transcript no longer rebuilds itself on every turn. A key derived from the message count
remounted the whole list, which reset scrolling to a jump and re-parsed every message's markdown
each turn. - The settings panel is exposed as a modal dialog, so assistive tech can announce it.
Internal
- Removed the unused
electron-updaterdependency and its placeholder publish config, a dead
autoFadeprop and its animation, and a leftoverpingIPC handler. - Release pages now carry generated notes.
Verified on the packaged macOS bundle: every IPC channel resolves inside the asar bundle, the
navigation guard refuses a foreign origin, and a decoy OPENCLAW_CONFIG_PATH is ignored.
Full Changelog: v1.3.0...v1.4.0
v1.3.0
Voice input (STT) with live streaming transcription: - The composer fills live while you speak; sending stays manual. - The OpenAI ephemeral-secret mint and SDP exchange run in the main process behind a sender-authenticated IPC; the WebRTC session runs in the renderer. Security: - The preload no longer exposes a generic ipcRenderer bridge, so a document in the window can no longer invoke arbitrary main handlers by name.
v1.2.0
v1.1.0
v1.1.0 — in-app settings with OpenClaw auto-detection