Skip to content

Release 0.109

v0.109.3 — 2026-07-02

Completes the v0.109.2 sweep: the Tables grid’s row/column IDs also used crypto.randomUUID() bare (via @mantle/content’s table model), so table editing would fail on plain-HTTP installs. Same fallback applied.

v0.109.2 — 2026-07-02

Assistant works on plain-HTTP installs. Companion fix to v0.109.1: browsers also remove crypto.randomUUID, crypto.subtle, the clipboard API, and microphone access on non-HTTPS pages. The assistant composer generated its idempotency key with crypto.randomUUID() and threw before sending — pressing Submit silently did nothing. All client code now goes through lib/secure-context-fallbacks.ts (UUID, sha256, copy-to-clipboard fallbacks); voice input, which browsers hard-block over HTTP, shows a clear “needs HTTPS” message instead of failing silently.

v0.109.1 — 2026-07-02

Login works on plain-HTTP installs. On a no-domain install (MANTLE_SITE_ADDRESS=:80, browsing by bare IP) the session cookie was marked Secure, so browsers silently dropped it — login returned OK but bounced straight back to the login screen, forever. Cookies (session + Microsoft OAuth handshake) now take the Secure flag from the request’s actual scheme (X-Forwarded-Proto), so HTTPS installs behave exactly as before and HTTP installs can actually sign in. Found on the first plain-HTTP field install. HTTPS remains strongly recommended — see docs/installation.md for pointing a domain at the box.

v0.109.0 — 2026-07-02

One install path. The curl-able root install.sh now only bootstraps (fetches the deploy bundle) and delegates configuration, startup, and verification to the bundled scripts/install.sh — the same script used to reconfigure a box later (--domain, --check). The deploy bundle now ships scripts/install.sh + scripts/sanity.sh.

  • scripts/install.sh gains POSTGRES_PASSWORD generation (kept on re-runs) and 80/443 port-in-use warnings.
  • A release-tag MANTLE_CHANNEL now pins MANTLE_IMAGE_TAG to the same version, so bundle and image can’t drift apart.
  • Docs refreshed to match the product: online embedder default, the current onboarding wizard (system-status gate, Models, Memory), Sonnet 5 defaults, and this changelog added.