• v0.1.1 c7a16d51e3

    CI / Gateway plugin tests (push) Successful in 4m55s
    CI / Kotlin tests (android host + desktop) (push) Successful in 6m58s
    Stable

    ARIA released this 2026-08-24 21:13:30 +00:00 | 12 commits to master since this release

    Changelog

    New features

    • Per-device tokens with revocation (#11) — Each paired device now receives its own token (delivered in hello.ack) instead of sharing the global IRIS_TOKEN. A leaked or compromised device can be isolated without rotating the shared token.
      • New operator CLI: tools/iris_devices.py (list / revoke / unrevoke / reissue)
      • hermes gateway setup now offers a "Remove a paired device?" menu
      • App stores the device token in the secure store and presents it from then on
    • TLS fingerprint-confirm flow for self-signed gateway certs (#14) — SSH-host-key-style flow: on first pairing against a self-signed cert, the app shows the SHA-256 fingerprint; "Confirm & pin" stores it (EncryptedSharedPreferences / desktop keyring) and allows the connection. Anything else is rejected. Pin is cleared on "forget device".
    • Self-signed TLS cert generation in hermes gateway setup — When IRIS_HTTP_CERT is not set, setup now offers to generate a 10-year RSA-2048 self-signed cert (with proper SANs) using hermes' existing cryptography dependency — no openssl needed. Prints the fingerprint in the format the app's confirm dialog expects; pairing URL/QR advertise https:// automatically.
    • Push backend defaults to ntfy (#10) — IRIS_PUSH_BACKEND now defaults to ntfy, keeping push metadata on your own infrastructure. FCM is opt-in (IRIS_PUSH_BACKEND=fcm) with a privacy warning during setup (metadata routed via Google's servers).

    Changes

    • HTTP-only transport cleanup — Renamed IRIS_WS_HOST → IRIS_HTTP_HOST (clean rename, no compat fallback); dropped dead DEFAULT_PORT=8790. ws_probe.py / e2e.py default to http://127.0.0.1:8791 and honor IRIS_HTTP_URL.
    • Refactor: split adapter.py monolith (#12) — The 3,493-line adapter.py is now ~857 lines plus focused modules (hooks, classify, pickers, commands, setup, secrets, and 7 frame-handler mixins). Ruff complexity ceilings restored to built-in defaults; genuinely complex functions carry explicit # noqa as frozen, reviewed exceptions.

    Fixes

    • README limit claims corrected to match reality (#13): uploads are 100 MB default (configurable via max_upload_bytes), and there is a 1 MiB hard frame-body cap (no 4,096-character limit like Telegram). Limits are set on the gateway side.

    Documentation

    • New end-to-end install guide (docs/install.md) for non-technical users: gateway install, app install, LAN/TLS/remote connection, push, options, troubleshooting.
    • README gained an "Install the gateway" section; pairing section updated for HTTP transport (port 8791, QR scan on Android).
    • Replaced stale "android" name mentions with "iris" across docs; fixed stale WS-era references in docs 03/09/12/19.
    • New docs/playstore-listing.md with the FCM/ntfy privacy note.

    Tests

    • 5 new Python tests for cert generation (incl. openssl fingerprint cross-check)
    • 8 new Python tests for per-device token issuance/revocation/isolation
    • New Kotlin TlsPinningTest + TlsPinningIntegrationTest (real TLS handshake: unpinned → confirm data, pinned → 200)
    • Live E2E verified on the phone: self-signed cert pairing, pinning, chat, auto-reconnect after gateway restart⏎
    Downloads