Restoring or blurring focus before setting aria-hidden on the backdrop
avoids the browser warning when a control inside the modal (e.g. SSH
Disconnect) still had focus.
Remove folder-level package.json files from dashboard data directories in both repos.
Those overrides caused esm-wrap parsing of plain script data files
(tlds.js, hostname-validator.js, install-commands.js), triggering
"Unexpected token 'export'" at runtime.
- Add syncServers setting (default false) to extension and native host state
- Add "Sync Servers" toggle under Settings → Sync; when disabled, server
tunnels stay local and are not synced across linked devices
- On push: omit servers from snapshot when syncServers is false
- On apply: keep local servers and nextServerId when syncServers is false
(incremental and full restore)
- Stop calling closeSyncForBackup() during backup create so sync and
autopass keep running; backup already excludes autopass/ from the
archive.
- Restore still quiesces sync and removes autopass/ so storage can be
replaced safely; sync reconnects on next use.
- Clarify setSyncManager comment (restore-only). Update BACKUP.md,
SYNC.md, and ARCHITECTURE.md accordingly.
When a device pairs with the master, the master's autopass can emit an update
and applyRemoteUpdate would sometimes apply an empty or weaker snapshot from the
merged view, overwriting the master's state. Skip applying remote state when
we're the master and the incoming snapshot has less content (servers + vhosts +
serviceTunnels) than current state.
- Delink: any peer can leave; removeWriter notifies others, local state reset to defaults.
- Disband: master only; push syncGroupDisbanded so peers reset; master exports state to
state.json, then reloads (cleanup + restorePersistedState + restorePersistedTunnels).
- Skip handleDisbandFromMaster when receiver is master so master state is not reset.
- Store syncMasterDeviceId in synced state so MASTER badge shows on all devices.
- UI: show Delink for peers, Disband for master only; confirm modals for both.
- state.js: add lastLoadedDeviceNames cache, getDeviceNames(),
setDeviceNames(); saveStateSync() always merges and writes
deviceNames so saves never strip them.
- holesail-manager: include deviceNames in saveState() and
getStateSnapshot(); applySnapshotData() updates cache from
synced snapshot. buildDefaultState and legacy migration
include deviceNames: {}.
Prevents hostnames reverting to "Device 1" etc. after saves or sync.
When reopening with existing identity, do not pass discovery key to
Autopass. That makes Autobase bootstrap from this device's local core
(name: 'local') instead of bootstrap.getUserData('autobase/local'),
which can point at another device's writer and open it read-only.
- Device that creates sync group is the Master; MASTER label in Linked devices table
- Create invite when already linked generates invite for same sync group (no wipe)
- Any peer can create invites so devices can be added when Master is offline
- Identity file stores isMaster; same sync group reused across native host restarts
- Update SYNC.md, NATIVE-HOST.md, ARCHITECTURE.md, CHANGELOG.md
- Add getStateSnapshot, applySnapshotData, setStateSaveSuppressed to holesail-manager
- Sync diffs snapshot vs current state and only removes/adds/updates changed tunnels
- Suppress saves during apply and write state.json once at the end
- Fall back to full cleanup + restore when incremental APIs are unavailable
- Backup: do not include autopass/ (may be in use); always include
autopass-identity.json so sync identity is never lost
- Restore: remove autopass/ after extract so autopass can recreate from
restored identity
- Docs: BACKUP.md, SYNC.md, ARCHITECTURE.md updated
- pairWithInvite: await store.ready() before pair; await pass.ready()
after pair.finished(); on error call pair.close() then closePass()
- createSyncInvite: on error await closePass() instead of nulling refs
- Remove autopass dir before createSyncInvite/pairWithInvite so Corestore
gets a fresh device-file (device-file throws when inode/mtime changes)
- Await sync/rdp/holesail cleanup on host shutdown so corestore closes
before process exit
- Reset initPromise on init failure so Create invite can retry after
removing corrupt autopass dir
- getSyncStatus: fire-and-forget push device hostname when missing so
linked peers see names after opening Sync page
- Backup/restore: close sync (corestore) before copy/extract so autopass
data is consistent; backup includes autopass/ and autopass-identity.json
- Installer: preserve sync data on re-run (comments and messages)
- Docs: BACKUP.md sync-in-backup and pause behaviour; SYNC.md backups
include sync data
- Sync: use OS hostname for each device in Linked devices table; persist
deviceNames in state and merge on save/apply so peers see each other's names
- Docs: expand SYNC.md (linked devices table, replace-state modal, multi-device,
offline); NATIVE-HOST getSyncStatus (deviceId, syncGroupId, linkedDevices,
deviceName/name); ARCHITECTURE sync-manager and autopass paths; README
features/dashboard/file locations/doc link; BACKUP and SECURITY cross-refs
- getSyncStatus() now iterates pass.base.activeWriters and returns
linkedDevices: [{ id, isCurrent }] for each writer in the sync group
- Dashboard Linked devices table shows every device: "This device" plus
"Device 2", "Device 3", etc. with their IDs; rows sorted by id
- Fallback to single "This device" row when activeWriters is missing
- Await restorePersistedTunnels so applyingSync stays true for full restore,
preventing saveState() during tunnel startup from pushing back and looping
- Debounce onRemoteUpdate (600ms) and skip apply when state unchanged
(canonical fingerprint) to avoid redundant restarts
- Add confirm modal before "Link device": warns that current state will be
replaced and suggests creating a backup first
- Add Linked devices table when linked: show This device ID (writerKey) and
Sync group ID (discoveryKey); getSyncStatus returns deviceId and syncGroupId
- Await restorePersistedTunnels in applySyncedState so applyingSync stays
true for the full restore. Prevents saveState() during tunnel startup
from pushing back to autopass and causing a feedback loop.
- Debounce onRemoteUpdate (600ms) so bursts of autopass 'update' events
trigger a single apply.
- Skip apply when remote state matches current state (canonical fingerprint)
to avoid redundant restarts and re-pushes.
- Clear remoteUpdateDebounceTimer in cleanup().
- Add install-command helper (getInstallCommand + platform detection)
with OS-specific one-liners and configurable base URL
- Show onboarding card on Overview when !hostConnected: copy button,
platform switcher (macOS/Linux / Windows), and "Check again" button
- "Check again" triggers refresh and shows success/disconnected toast
- refresh() returns state so callers can react to hostConnected
- Add unit tests for install-commands (all platforms, base URL)
- Document "Native host not found" flow in README and INSTALLATION
- CI: rename Test step to Unit tests
- README: add Testing and linting subsection, link to Contributing
- CONTRIBUTING: expand Testing with test layout table and CI note
- ARCHITECTURE: add Testing section
- INSTALLATION: add npm test to build-from-source steps
- Add unit tests (hostname-validator, TLDs, payload-schemas) and integration tests for message handler registry
- Refactor native host message router into handler registry (handlers/state, tunnels, ssh, rdp, backup, ca, connections)
- Add ESLint config and npm test + lint steps in CI
- Dashboard: visibility-based refresh pause, configurable refresh interval (2s/5s/10s/paused)
- Accessibility: ARIA on nav and modals, focus trap and restore, prefers-reduced-motion
- Empty states: primary action buttons for virtual hosts, servers, service tunnels
- Native host rate limiting for backup and CA operations; update SECURITY.md
- CONTRIBUTING: "Adding a new dashboard page", dev workflow; add npm run dev script
- Trigger getState + applyPAC after successful restoreBackup (same as setVirtualHost/removeVirtualHost)
- Always re-apply PAC when getState returns state so restored/different vhost TLDs are reflected
- Add kill-previous-instance.mjs with PID lock file under BASE_DIR; on
startup send SIGTERM to any existing native-host before binding ports
- Register removePidFile on shutdown and exit
- Run "stop any running native host" at the start of install.sh and
install.ps1
- Use ESM with static imports so bare-pack includes the module in the
bundle (dynamic require was not included and broke the built binary)
- Add kill-previous-instance.mjs to CI syntax check
- Add kill-previous-instance.js with PID lock file under BASE_DIR
- On startup, send SIGTERM to any existing native-host process before binding ports
- Register removePidFile on shutdown and exit so the lock is cleared
- Run "stop any running native host" at the start of install.sh and install.ps1
- Add kill-previous-instance.js to CI syntax check
- CONTRIBUTING: use holepunchto/bare repo URL
- NATIVE-HOST: getState servers use url (not hsUrl), no state field
- BACKUP/NATIVE-HOST: backup filenames use holesail-backup- prefix and _ timestamp
- NATIVE-HOST: document createBackup/listBackups path and createdAt
- SSH: clarify that saved password is stored as passwordB64 in state.json
- ARCHITECTURE: note extra state.json settings in SETTINGS_DEFAULTS
Write all path variants for every .json in the bundle when building
for win32 (backslash, with/without leading slash) so bundle.read()
returns content regardless of runtime key normalization. Refill empty
or invalid JSON from alternate key or disk before writing variants.
Explicitly write tt-native package.json under Windows path variants
in Fix 1. Document in CHANGELOG.
Use forward-slash addon resolution key for all platforms in the
distributable build so the runtime finds the tt-native prebuild when
the bundle normalizes paths on Windows. Update CHANGELOG and
CONTRIBUTING to document the fix.
After unmount, the runtime may resolve #package with or without a
leading slash. Write the same content to both keys so the .json
loader never gets an empty entry and the host no longer crashes with
"Unexpected end of JSON input" on Windows.
patchBundle so the runtime never gets empty content for that key
(fixes "Unexpected end of JSON input" in Module._extensions..json
when the host is started by the extension on Windows).
- State: treat empty or whitespace-only state.json (and legacy
persist file) as missing and return default state instead of
throwing in JSON.parse.
- State: add ensureStorageDir() and call it from message-router
after setStoragePath so the storage directory exists on fresh
install before any state is loaded or saved.
- SECURITY.md: Note that we install to system store and run
update-ca-certificates; add that Chrome/Firefox may not use it.
- Add step-by-step instructions to manually import the CA into
Chrome/Chromium and Firefox on Linux (path to ca.cert.pem).
- INSTALLATION.md: In first-time setup, add Linux note and link
to SECURITY.md for manual import.
- Replace sudo with pkexec so PolicyKit shows a graphical auth dialog
when the native host is launched by the browser (no terminal).
- Pass DISPLAY and XAUTHORITY into the pkexec env so the polkit
agent can display the dialog in the current session.
- Keep copy + update-ca-certificates in a single pkexec sh -c for
one password prompt.
- Update SECURITY.md and JSDoc to describe pkexec / PolicyKit.
When building with --all, the bundle used a single addon resolution (darwin-arm64),
so the Linux binary tried to load the wrong prebuild and tt-native failed. Patch
tt-native binding with a nested resolution map (addon → bare → node → platform →
arch) so the runtime selects the correct prebuild per platform; SSH PTY then works
on Linux.
- scripts/build-distributable.js: build host-specific addonResolutions, write
binding with full map; update comments
- docs/ARCHITECTURE.md, CONTRIBUTING.md: document addon resolution patch
- CHANGELOG.md: add entry under bug fixes
When building with --all, the bundle used a single addon resolution (darwin-arm64),
so the Linux binary tried to load the wrong prebuild and tt-native failed. Patch
tt-native binding with a nested resolution map (addon → bare → node → platform →
arch) so the runtime selects the correct prebuild per platform; SSH PTY then works
on Linux.
- Move connect-proxy and https-proxy into proxy/
- Move certificate-authority, backup-manager, ssh-manager, rdp-manager into managers/
- Move messenger.js into host/
- Move test-dirname.cjs into test/
- Update imports, CI lint paths, and ARCHITECTURE.md
- Import host/message-router.js and holesail-manager/index.js directly
- Delete host.js and holesail-manager.js
- Drop shim entries from CI syntax checks
- Update ARCHITECTURE.md diagram and file table
- Add "Use TLS (secure connection)" checkbox in Add Virtual Host modal
- Persist and restore useTls in state; show TLS badge in table
- When enabled, HTTPS proxy connects to tunnel backend over TLS (SNI =
hostname) for HTTP and WebSocket; supports services on port 443
- CHANGELOG: add Firefox support subsection (manifest_firefox, background
scripts, proxy/native-messaging/CSP, installer, pack, extension-id)
- CONTRIBUTING: repo layout with background-boot/main, Firefox load steps
and private-windows note, install.sh Chrome vs Firefox manifests,
DEBUG_VERBOSE in background-boot.js
- ARCHITECTURE: manifest.json vs manifest_firefox.json, background.js
importScripts, background-boot/main and proxy/native-messaging notes,
native host lifecycle and separate manifests
- INSTALLATION: allowed_origins vs allowed_extensions, Allow in Private
Windows for Firefox, extension ID updates both manifests
- SECURITY: PAC scope Chrome vs Firefox (autoConfig/data URL), proxy
security and private-windows requirement
Firefox's default MV3 CSP includes upgrade-insecure-requests, which upgrades
ws://127.0.0.1 to wss:// and breaks SSH/RDP WebSocket connections to the
local native host. Add explicit content_security_policy to manifest_firefox.json
allowing ws://127.0.0.1:* and http://127.0.0.1:* on extension pages.
- Firefox rejects native messaging manifest if allowed_origins is present.
Install script now writes Chrome-only manifest (allowed_origins) and
Firefox-only manifest (allowed_extensions) to their respective locations.
- Fix local Firefox manifest by removing allowed_origins.
- Log disconnect reason from port.error (Firefox) in addition to
runtime.lastError (Chrome) so native messaging failures are visible.
- Log getState failures on disconnect for easier debugging.
- Treat PAC as active when mode === 'pac_script' (Chrome) or proxyType ===
'autoConfig' (Firefox) so we don't mis-detect "not active" in Firefox.
- In proxy.settings.onChange, only call applyPAC() when levelOfControl !==
'controlled_by_this_extension'. When we still have control, return without
re-applying to stop the set -> onChange -> applyPAC loop.
Firefox's match pattern validator does not allow the moz-extension:// scheme
in matches. Use extension_ids: ["*"] so extension pages can load the
resources without invalid manifest error.
Firefox MV3 does not support background.service_worker. Split background
into background-boot.js (globals) and background-main.js (startup logic);
Chrome keeps using importScripts() in background.js, Firefox manifest uses
background.scripts with the same file list so the extension loads in both.
- Add extension/manifest_firefox.json (no key, moz-extension://*/* for
web_accessible_resources) for correct Firefox MV3 behavior
- Update pack-extension.js: zip excludes manifest_firefox.json; XPI
built separately with manifest_firefox.json as manifest.json
- Update generate-extension-id.js to set gecko.id in manifest_firefox.json
when present (no key in Firefox manifest)
- Document dual-manifest layout and pack/generate-id behavior in CONTRIBUTING.md
Use var(--bg) for btn-primary text color and color-mix for hover to
correctly adapt across themes. Add --terminal-bg CSS variable and
_getXtermTheme() helper so the SSH terminal picks up the correct
palette at connection time.
Normalize loadAvg to [0,0,0] fallback in both the native host handler
and the dashboard renderer to prevent TypeError when bare-node-os returns
a non-array value for loadavg().
- Add getProcessStats message handler to native host returning process
memory (rss, heap used/total, external), PID, uptime, OS memory,
CPU load averages, core count, platform/arch, and tunnel state counts
- Add stats-tracker.js to background SW tracking cumulative connections,
reconnect count, last disconnect time, and per-minute connection rate
ring buffer (30 buckets) for sparkline display
- Include statsHistory and activeConnections array in all getState responses
- Add Statistics dashboard page with six sections: Native Host Process,
System Resources, Tunnel Health, Proxy Traffic, Peer Connections
(with SVG sparkline), and Extension & Proxy Info
- Preserve checkbox selection across table re-renders on all bulk-action
tables (virtual hosts, servers, service tunnels)
- Add theme-aware custom checkbox styling for bulk selection rows using
design system tokens, with white checkmark override for light theme
Replace native browser checkbox appearance on table row and select-all
checkboxes with fully custom styled controls using design system tokens,
with a white checkmark override for the light theme's darker cyan.
Snapshot checked row IDs before each innerHTML swap in the virtual hosts,
service tunnels, and server tunnels tables so that periodic refresh cycles
no longer reset multi-selection state.
chrome.permissions.request() must be called synchronously within a user
gesture. Moving it from the background message-router (where the gesture
context has expired) into the addVhostSubmit click handler in virtual-hosts.js
fixes the "Unchecked runtime.lastError: This function must be called during
a user gesture" console error.
Most modern SSH servers disable plain password auth and only allow
keyboard-interactive. Excluding it from PreferredAuthentications caused
SSH to exhaust all auth methods and exit immediately.
Also scope SSH_ASKPASS_REQUIRE=force to only apply when a saved password
is provided. Setting it unconditionally broke keyboard-interactive auth
since that method ignores SSH_ASKPASS and reads from the PTY directly.
Reverts the experimental feature that attempted to serve the dashboard
via a local HTTP server registered as a hardcoded `my.dash.board` virtual
host, intended to satisfy Chrome's PWA "secure origin" installability
requirement. The approach caused proxy connection errors and file-not-found
issues that were not worth resolving.
Removed: native-host/dashboard-server.js, native-host/test-chain.mjs
Reverted: startup.js, message-router.js, virtual-hosts.js, index.js,
build-distributable.js, extension/pages/virtual-hosts.js,
CI workflows (ci.yml, release.yml)