-
released this
2026-08-24 21:13:30 +00:00 | 12 commits to master since this releaseChangelog
New features
- Per-device tokens with revocation (#11) — Each paired device now receives its own token (delivered in
hello.ack) instead of sharing the globalIRIS_TOKEN. A leaked or compromised device can be isolated without rotating the shared token.- New operator CLI:
tools/iris_devices.py(list / revoke / unrevoke / reissue) hermes gateway setupnow offers a "Remove a paired device?" menu- App stores the device token in the secure store and presents it from then on
- New operator CLI:
- TLS fingerprint-confirm flow for self-signed gateway certs (#14) — SSH-host-key-style flow: on first pairing against a self-signed cert, the app shows the SHA-256 fingerprint; "Confirm & pin" stores it (EncryptedSharedPreferences / desktop keyring) and allows the connection. Anything else is rejected. Pin is cleared on "forget device".
- Self-signed TLS cert generation in
hermes gateway setup— WhenIRIS_HTTP_CERTis not set, setup now offers to generate a 10-year RSA-2048 self-signed cert (with proper SANs) using hermes' existingcryptographydependency — noopensslneeded. Prints the fingerprint in the format the app's confirm dialog expects; pairing URL/QR advertisehttps://automatically. - Push backend defaults to ntfy (#10) —
IRIS_PUSH_BACKENDnow defaults tontfy, keeping push metadata on your own infrastructure. FCM is opt-in (IRIS_PUSH_BACKEND=fcm) with a privacy warning during setup (metadata routed via Google's servers).
Changes
- HTTP-only transport cleanup — Renamed
IRIS_WS_HOST→IRIS_HTTP_HOST(clean rename, no compat fallback); dropped deadDEFAULT_PORT=8790.ws_probe.py/e2e.pydefault tohttp://127.0.0.1:8791and honorIRIS_HTTP_URL. - Refactor: split
adapter.pymonolith (#12) — The 3,493-lineadapter.pyis now ~857 lines plus focused modules (hooks, classify, pickers, commands, setup, secrets, and 7 frame-handler mixins). Ruff complexity ceilings restored to built-in defaults; genuinely complex functions carry explicit# noqaas frozen, reviewed exceptions.
Fixes
- README limit claims corrected to match reality (#13): uploads are 100 MB default (configurable via
max_upload_bytes), and there is a 1 MiB hard frame-body cap (no 4,096-character limit like Telegram). Limits are set on the gateway side.
Documentation
- New end-to-end install guide (
docs/install.md) for non-technical users: gateway install, app install, LAN/TLS/remote connection, push, options, troubleshooting. - README gained an "Install the gateway" section; pairing section updated for HTTP transport (port 8791, QR scan on Android).
- Replaced stale "android" name mentions with "iris" across docs; fixed stale WS-era references in docs 03/09/12/19.
- New
docs/playstore-listing.mdwith the FCM/ntfy privacy note.
Tests
- 5 new Python tests for cert generation (incl. openssl fingerprint cross-check)
- 8 new Python tests for per-device token issuance/revocation/isolation
- New Kotlin
TlsPinningTest+TlsPinningIntegrationTest(real TLS handshake: unpinned → confirm data, pinned → 200) - Live E2E verified on the phone: self-signed cert pairing, pinning, chat, auto-reconnect after gateway restart⏎
Downloads
- Per-device tokens with revocation (#11) — Each paired device now receives its own token (delivered in