Releases: burakgon/roamcode
Releases · burakgon/roamcode
Release list
RoamCode v2.1.0
Added
- Add a complete product showcase across the website and repository, with product-true desktop and mobile views of
Sessions, persistent split terminals, Automations, Agents, mobile terminal controls, and file exchange. - Add focused getting-started, documentation index, and remote-access guides that take a new standalone installation
from prerequisites through one-use pairing, provider setup, private networking, and recovery.
Changed
- Rebuild the website and README around RoamCode's standalone mission-control model, with clearer installation paths,
product hierarchy, self-hosting boundaries, and contribution guidance. - Keep Sessions, Automations, and Agents available in the persistent mobile bottom navigation while working inside a
live terminal or its supporting panels. - Improve package descriptions, keywords, installer guidance, and first-run output so the published npm and Homebrew
paths lead into the same account-free setup flow.
Fixed
- Preserve the real product aspect ratio and complete desktop and mobile navigation chrome across showcase images,
including split-screen work, Automations, Agents, terminal controls, and file workflows.
Full changelog: v2.0.0...v2.1.0
RoamCode v2.0.0
Changed
- Return RoamCode to a standalone-only product: Sessions, Automations, Agents, direct device pairing, local team
policy, and direct peer federation now operate entirely on each self-hosted Node.
Removed
- Remove hosted accounts, managed Node enrollment, shared relay transport, cloud CLI commands, hosted application
shell, relay containers, and their release artifacts.
Full changelog: v1.4.5...v2.0.0
RoamCode v1.4.5
Fixed
- Keep Organization ownership metadata out of standalone navigation and avoid repeating a generic context fallback
as both its type and display name in Cloud.
Full changelog: v1.4.4...v1.4.5
RoamCode v1.4.4
Fixed
- Prevent a newly activated terminal service worker from deadlocking cold Sessions or Automations deep links while
their replacement document is still loading.
Full changelog: v1.4.3...v1.4.4
RoamCode v1.4.3
Changed
- Open hosted Sessions and Automations as the full RoamCode workspace instead of nesting the terminal inside a
second control-plane frame, keeping one navigation plane on desktop and mobile.
Full changelog: v1.4.2...v1.4.3
RoamCode v1.4.2
Fixed
- Keep managed Node enrollment and the persistent terminal transport from opening competing relay connections, so a
successfully verified Node proceeds to its Sessions instead of falling into a Couldn't reach the server loop.
Full changelog: v1.4.1...v1.4.2
RoamCode v1.4.1
Fixed
- Finish the managed-terminal handoff when reopening the Node that is already active, instead of leaving a successful
encrypted connection behind the Opening your Node… interstitial.
Full changelog: v1.4.0...v1.4.1
RoamCode v1.4.0
Added
- Add scheduled and signal-only webhook triggers to coding Automations, including IANA time zones, one-time bearer
credentials, secret rotation, durable activity history, and explicit missed-run reporting after Node downtime. - Add an integrated Cloud workbench that keeps Sessions and Automations inside the control center with direct Node
switching, plus Organization settings for editing shared names, URLs, and Node metadata.
Changed
- Focus the standalone Agents catalog on installed coding runtimes instead of exposing local computer inventory;
Cloud still shows the owning Node when that context is needed for team execution. - Synchronize only webhook routing identities and queued signals with the optional control plane; request bodies,
terminal output, repositories, provider credentials, and Automation instructions remain on the Node.
Fixed
- Deduplicate webhook redelivery while a durable invocation is already queued or running, bound concurrent Automation
launches, and resume accepted signals safely after a Node or control-plane restart. - Keep Cloud Node selection fail-closed for offline, outdated, or unauthorized targets while preserving the existing
same-origin encrypted terminal and its default terminal interaction model.
Full changelog: v1.3.0...v1.4.0
RoamCode v1.3.0
Added
- Add the Node-first Agents inventory, runtime authentication controls, and exact Node/runtime Session launch.
- Add manual coding Automations pinned to one Node, runtime, working directory, and provider option set; every Run
opens a durable real terminal Session and keeps immutable history after its definition is deleted. - Add the same-origin RoamCode account surface with Personal and Organization contexts, Node inventory, People &
Access administration, access requests, and separate CLI and managed-browser device revocation. - Add managed browser enrollment from an authorized Organization Node into the existing end-to-end encrypted
terminal, plus browser-assistedroamcode cloud loginand account-bound Node connection commands.
Changed
- Package the website, account shell, and unchanged terminal PWA into one digest-pinned Caddy gateway for an ordinary
single-VM deployment, with no edge-worker or provider-specific runtime requirement. - Route the account API and bounded blind-relay compatibility surface through one canonical domain while keeping
root relay administration, metrics, internal handlers, and unknown API paths private. - Make Sessions, Automations, and Agents the complete primary navigation on desktop and mobile while
retaining legacy workspace and attention contracts for compatible integrations. - Keep self-hosted Nodes personally owned until an explicit managed-cloud transfer, persist managed ownership across
configuration loss, and make signed cloud Node grants a read-only projection of organization People & Access. - Serve account, public legal/security documents, and the installable terminal from one canonical web origin while
retaining a safe legacy app-host redirect and the unchanged open-source self-hosted path. - Keep hosted account creation and managed-terminal handoff behind a versioned, fail-closed control-plane capability
document while preserving sign-in, sign-out, and account recovery against older control planes.
Fixed
- Rebuild caller-controlled forwarding headers at the gateway, expose only the exact public relay method/path pairs,
and keep missing static assets from falling through to either application shell. - Let file-outbox self-hosted installations complete account creation without trapping users behind an email link
that the installation deliberately cannot deliver, while preserving operator-assisted password recovery. - Keep Node Admin access scoped to one Node, replace role downgrades atomically, revoke device and relay terminal
streams when local or cloud read access disappears, and reauthorize input-lease renewal after permission changes. - Make automation invocation identity durable across the HTTP response crash window, reconcile live Sessions after a
restart, reject unavailable runtime authentication before spawning, and wait for a real provider composer before
submitting a task. - Prevent one-use relay bootstrap credentials from entering idempotency replay storage and preserve failed Run and
started-Session recovery details without creating duplicate side effects. - Keep managed browser activation fail-closed across confirmation, broker promotion, authorization refresh, response
loss, restart, role or grant revocation, and explicit browser-device cleanup without storing raw relay credentials. - Preserve Codex thread identity across macOS
/tmppath aliases and detect a ready composer that rendered before the
first terminal subscriber, so fast launches and Automation Runs do not stall or duplicate work. - Keep context, role, invitation, and Node-access selectors at a consistent accessible hit size in Safari and
Chromium without replacing their native semantic form behavior.
Full changelog: v1.2.0...v1.3.0
RoamCode v1.2.0
Added
- Provision, inspect, update, rotate, suspend, and delete hosted relay accounts through secure
roamcode cloud
operator commands that read the root capability from a private file, generate account capabilities locally, send
only hashes to the relay, commit the raw capability atomically to a mode-0600 output file, and verify a retained
pending capability before recovery after an ambiguous result. - Add a no-public-IP GCP and Cloudflare Tunnel deployment profile with immutable container digests, least-privilege
Secret Manager access, an isolated network, bounded containers and logs, verified SQLite backups, and a documented
daily persistent-disk snapshot policy. - Show live cloud-relay health in Settings → Devices, distinguish setup, connecting, online, reconnecting, and
offline states, and prevent remote-pairing actions that cannot succeed. - Create the first remote browser enrollment directly from the host with
roamcode cloud pair, using a five-minute,
one-use terminal QR/app link and expiry-bounded broker cleanup instead of requiring an already-paired local browser. - Repair or change a managed host's trusted PWA origin with
roamcode cloud configure --app-urlwithout deleting and
re-provisioning its relay route. - Add external HTTPS and public WebSocket acceptance checks that verify permanent redirects, security/cache policy,
real bidirectional blind-frame forwarding, transient-route cleanup, regional uptime checks, and alert-policy drift.
Changed
- Keep a private pending capability recoverable when an account create or rotation response is ambiguous, including
server failures, while removing staged credentials after definitive rejection and preserving the legacy
server-generated credential API for compatibility. - Compensate an ambiguous host-credential rotation back to the previous remote hash before restoring local state; if
neither mutation can be confirmed, retain the new private local credential instead of silently stranding the host
on a credential that may already have been revoked. - Harden the relay with a global upgraded-socket ceiling, reconnect-resistant host/device rate windows, ping
accounting, bounded WebSocket envelopes, disabled compression, strict browser-origin checks, and automatic pruning
of expired bootstrap devices. - Keep current and previous root capabilities in owner-only mounted files, and enforce HTTPS redirects, HSTS, CSP,
anti-framing, no-sniff, referrer, permission, and cache policy at both the direct host and cloud edge. - Run the cloud edge image as a dedicated non-root UID by default, and bound both portable relay containers with
read-only roots, process and memory ceilings, no-new-privileges, and rotated local logs.
Fixed
- Keep Settings → Devices selected during smooth scrolling and pairing reflow, bring a newly created QR into view,
and preserve 44-pixel mobile category targets without horizontal overflow. - Make Cancel revoke unused direct and cloud pairing links instead of only hiding their QR codes; failed QR
rendering also cleans up the unadvertised capability, while a relay cancellation remains retryable until broker
revocation is confirmed and never silently revokes a device that won the enrollment race. - Resume an unfinished one-use relay pairing after an accidental same-tab reload without restoring the secret URL
fragment or keeping the temporary capability beyond its original expiry; cancelled, expired, and explicitly
removed relay devices now delete their browser identity, while startup hygiene preserves every active or in-flight
key and removes abandoned pairing identities. - Repair and verify the packaged macOS PTY helper during the startup capability probe, so an unrepairable install is
reported before a terminal session starts instead of failing after the user creates it. - Rotate the relay routing capability inside the encrypted device claim so a copied one-use pairing URL loses broker
access at its original expiry, while retaining a short overlap for safe retry after an ambiguous final response. - Return a real
404for missing cloud PWA assets and other file-like paths instead of serving the HTML shell with
a successful response or an immutable cache policy; extensionless client routes still receive the SPA fallback. - Purge every owned route when an account is deleted, reconcile routes whose owner is deleted or missing after a
restart, close live routes from their authenticated in-memory owner even if durable cleanup fails, and keep a
recovery-only credential check available to suspended accounts without restoring route access. - Preserve a verifiable private credential after an ambiguous account or host rotation instead of reporting success,
discarding the only usable key, or leaving recovery stuck indefinitely. - Preserve the generated route identity and host capability in a private recovery configuration when both initial
cloud provisioning and compensating cleanup are ambiguous, while never deleting a route after a definitive
provisioning rejection. - Surface the relay's bounded, control-character-safe pairing failure in the CLI after cleanup, so quota and service
errors remain actionable without echoing arbitrary proxy output or capabilities. - Open secret-bearing host configuration and relay identity files through verified non-following descriptors, fsync
their parent directories after durable mutations, verify visible local state after a late durability error so a
remote rollback cannot strand an already-committed host credential, require both hosted SQLite databases in
backups, and bound restore readiness probes so a wedged container cannot stall the recovery drill indefinitely. - Persist the host access token with atomic, fsynced replacement; reject links, oversized or corrupt token files
instead of silently rotating credentials; repair legacy permissions through the verified file descriptor; and make
concurrent first starts converge on one durable token without printing an unused secret. - Accept bracketed IPv6 loopback origins consistently for direct hosts, peer registration and one-use pairing, and
local relay app URLs instead of incorrectly requiring HTTPS forhttp://[::1]development endpoints. - Check that the configured cloud host is online before issuing a one-use CLI pairing enrollment, so an offline host
cannot consume a five-minute link that it is unable to complete. - Reset saturated relay transports when a pong or peer-close notice cannot be queued, so slow connections cannot
retain ghost devices or an out-of-sync host channel map.
Full changelog: v1.1.0...v1.2.0