Highlights
- Close the posting access gap reported in #287. Non-authenticated users can no longer post chat, WX, WCY, or WWV by default, and telnet checks access before storing or relaying those messages. A SysOp can still grant an explicit per-user exception.
- Add Web Activity to the System Operator Telemetry audit (#288). Public-web logins, logouts, accepted posts, and posts denied by the access policy appear without message bodies or session tokens.
- Keep PC and PY protocol state history independently bounded, with scrollable history and a selectable 20/50/100/200-row limit (#282, #283).
- Refresh CTY.DAT and WPXLOC indicators without overwriting unsaved settings, distinguish dataset release dates from local file update times, and show KEPS element age and count (#284, #285).
- Correct MUF solar-angle labeling, destination-hour rounding, and double daylight attenuation; prefer the saved registry grid over stale preference copies (#286).
- Offer named DXCC entity selectors for DX and spotter filters (#280), and make
show/dxccshow recent spots for the whole entity (#281). - Redact credentials from telnet command logging.
Operational notes
- Existing non-authenticated accounts that relied on chat, WX, WCY, or WWV posting need a SysOp privilege change or an explicit per-user access override to continue posting.
- Web Activity uses the existing bounded runtime audit buffer and resets on restart. Message bodies and session tokens are excluded.
- MUF signal labels remain heuristic and are not DXSpider path-loss predictions.
PY15remains reserved for the distributed security advisory proposal in #276; that feature is not part of this release.
Verification
- 762 default tests and 49 socket listener tests passed: 811 total.
- This release was not deployed or validated against a live peer network before publication.