Perspective Server 1.1.0 Beta 2
Pre-release
Pre-release
·
10 commits
to main
since this release
Perspective Server 1.1.0 Beta 2
This beta is a targeted security release for GitHub issue #1, [Bug] Open web server manipulable by any web page.
What changed
- Restricts the local server to loopback access while preserving both IPv4 and IPv6 localhost connectivity
- Adds bearer-token protection for local clients and repairs the in-app chat, dashboard test, and copied client setup flows to work with that requirement
- Returns readable auth failures to localhost web clients so browser-based integrations see proper 401 responses instead of opaque CORS errors
- Fails startup if the auth token cannot be safely persisted, avoiding an unrecoverable local auth state
Security issue reported by Brian Sniffen.
Assets
PerspectiveServer-1.1.0-beta.2.dmg: notarized DMG for manual installPerspectiveServer-1.1.0-beta.2.zip: notarized Sparkle update artifact
If you install from the DMG, the app can still receive future Sparkle updates after launch.