中文 | English
中文
OxideTerm 2.2.0 新增了通知与审计工作区、加密会话录制和可复用的 TOTP 验证码凭据,让连接、命令、文件操作及自动化任务可以在同一个应用中回顾。同时,本版本加入终端粘贴编辑,完善本地会话管理和快捷命令分组,提供 Linux Nix 安装方式,并修复云同步闪退、Windows 终端输出和 Linux 录制恢复等问题。
📋 通知与审计工作区
- 通知中心扩展为“通知与审计”,提供通知、审计记录、会话汇总和会话录制入口。审计开关直接显示在页面顶部,默认关闭;开启后记录后续操作,关闭后仍可查看已经保存的记录。
- 审计记录可以按时间、类别、级别、事件来源和结果筛选,并按内容、连接、会话、本机账号或远程账号等字段搜索。记录详情展示操作过程、耗时、结果依据,以及可获得的退出码或传输字节数。
- 会话视图汇总命令、文件操作、其他操作和连接次数,支持继续查看该会话的相关记录。操作详情可沿父子关系查看子操作,方便追踪一次请求触发的后续任务。
- 事件来源区分用户、命令栏、快捷命令、广播、AI、MCP、插件、命令行和系统。操作结果区分已发送、成功、失败、取消、部分完成、中断和未知,保留判断结果所依据的协议响应、退出码或生命周期事件。
- 操作记录的默认保留策略为 90 天、512 MiB。保留天数和容量均可直接输入,支持 1–3650 天和 1 MiB–64 GiB;达到保留条件后自动清理,也可手动清除记录。
- 支持按当前筛选范围导出 JSON 或 CSV 摘要。需要命令、路径、账号和端点等详情时,可单独选择“导出受保护详情”,确认后生成明文文件。
使用方法:打开侧栏的“通知与审计”,在顶部启用审计,再通过筛选和会话汇总查看操作。审计数据在本机保存,敏感详情加密存储。
🔎 覆盖连接、文件和自动化操作
- SSH 审计覆盖主机密钥验证、认证尝试、交互式认证、连接状态、共享连接使用关系和重连阶段。终端与文件浏览等功能共用连接时,记录仍保留各自的会话、通道和实际连接代次。
- 本地终端、Telnet、Mosh、串口以及远程桌面的连接和退出过程接入审计;串口控制、Telnet 控制、远程桌面剪贴板与文件传输等操作也有相应记录。
- 终端命令、快捷命令、广播发送和 tmux 操作可以追溯到发起入口。命令完成状态使用可获得的 Shell 集成或退出码信息,单纯发送输入会保留“已发送”这一结果。
- 文件审计覆盖本地和远程文件浏览、搜索、预览、打开、创建目录、复制、移动、重命名、删除、上传下载及编辑器保存,也记录传输的暂停、恢复、取消和中断,以及文件冲突处理。
- 端口转发的创建、启动、停止、暂停、恢复和规则变更接入审计;主机面板中的进程、服务、容器、计划任务及日志查询等操作保留对应目标和结果。
- 设置、连接配置、密钥与凭据管理、云同步、备份恢复、应用锁、便携保险库、更新和诊断报告等操作接入记录。凭据管理记录操作及结果,省略密码、私钥和令牌内容。
- AI 工具调用、后台任务、MCP 请求及权限变更、插件操作和知识库管理可以关联到具体请求。授权、拒绝、取消和执行结果保留各自状态,便于了解自动化任务执行到了哪一步。
🎞️ 加密会话录制与回放
- 新增本地终端、SSH、Telnet、Mosh 和串口的审计录制,保存终端显示的输出与尺寸变化。输出录制默认关闭,首次开启时会单独确认。
- 录制内容在本地加密保存,不参与云同步;不采集键盘输入和终端文件传输载荷。终端显示出的敏感内容仍可能进入录制,开启时会明确提示。
- 录制页面支持播放、暂停、从头播放、时间定位和倍速播放,并显示录制中、已结束、已中断、不完整或已过期等状态。回放按需读取内容,长录制无需一次载入全部输出。
- 录制使用有容量上限的队列与后台写入。存储处理不及时会向终端读取路径传递背压,输入、取消和关闭继续获得处理;输出及尺寸变化保持原有顺序,采集缺口会明确标记。
- 修复 Linux 在录制队列恢复容量后,PTY 读取未重新启用、持续输出停住的问题。
- 录制内容默认保留 7 天、2 GiB,可独立于操作记录设置保留时间和容量。
使用方法:先启用审计,再进入“会话录制”开启“记录终端输出”。需要回顾时,从录制列表打开对应会话。
🔐 可复用的 TOTP 验证码凭据
- “设置 → 凭据”统一放置提权凭据和动态验证码凭据。TOTP 支持 Base32 密钥及
otpauth://链接,并支持 SHA-1、SHA-256、SHA-512、6 位或 8 位验证码和自定义更新周期。 - 一个验证码凭据可以供多个 SSH 连接使用,目标主机和各级跳板分别选择自己的凭据。它可以配合已有密码、密钥或交互式认证使用。
- 自动填写仅处理 SSH 认证阶段的提示。默认识别
MFA CODE、Verification code、OTP等验证码提示,也支持自定义正则表达式;只有一个明确匹配的隐藏输入项时才自动填写。 - 同一轮认证包含其他问题时,先收集人工回答,再生成当前验证码。每次认证只自动提交一次,服务器继续追问时转为人工输入;多个连接需要人工验证时会排队显示。
- 密钥存入受保护存储,连接配置只保存凭据引用。凭据可编辑、停用并被多个连接共用,仍有连接绑定时会阻止删除。
- 加密连接文件和云同步保留凭据及连接之间的关系,仅在选择包含敏感凭据时携带密钥。接收端将密钥存入自己的受保护存储;仅同步元数据时,不会把旧密钥当成已经更新的新密钥。
使用方法:在“设置 → 凭据”中添加动态验证码凭据,然后在 SSH 连接或跳板的编辑页面选择它。
✍️ 终端粘贴前编辑
- 新增“编辑后粘贴”,使用应用现有编辑器修改剪贴板中的命令或脚本,支持多行编辑、选择和撤销。多行粘贴确认流程也可以进入编辑,确认后才发送到终端。
- 提供明确的代码围栏移除操作,方便处理从 Markdown 文档或对话中复制的代码块。仅在用户选择该操作时移除包裹代码的围栏。
- 打开编辑器后未修改内容,或撤销全部修改时,保留原始粘贴内容及换行;编辑后的内容保留来源的 CRLF 换行约定。
💻 本地会话与远程终端管理
- 已保存的本地终端配置在侧栏拥有独立的会话条目,按配置组织正在运行的终端;可以折叠、展开,并从该配置继续新建终端。(PR #631)
- 选择本地会话时可以聚焦其运行中的终端,移除会话会关闭该配置对应的终端并记住侧栏隐藏状态;从会话管理器重新打开配置后,会再次显示并获得焦点。(PR #631)
- 修复 Windows 将暂时没有输出的 PTY 读取误判为结束,导致后续终端输出不再显示的问题。(PR #631)
- SSH、Telnet、Mosh 和串口会话结束后保留终端窗格与已有输出,便于查看退出原因或最后的错误信息;本地命令行环境保留原有退出自动关闭行为。
- 打开会话不再改变用户选择的侧栏可见状态,退出专注模式时恢复原有侧栏选择。
🗂️ 快捷命令分组
- 支持删除“系统”“网络”“文件”“Docker”等预设分组,组内命令会移动到“自定义”分组。“自定义”作为接收命令的默认分组保留。
- 在快捷命令管理页拖动分组左侧的手柄即可调整顺序,重启后保持排序。
- 删除和排序在保存成功后生效;保存失败时保留原有分组及命令状态。
🛠️ 界面、输入与同步修复
- 修复云同步预览渲染中的状态借用冲突,解决相关同步及本地导出流程可能触发的闪退。
- 修复终端视口短暂改变后恢复原尺寸,仍应用过期尺寸请求的问题,避免侧栏动画等操作留下错误的终端行列数。
- 修复相邻滚动区域共用交互状态导致滚动异常的问题,让各区域保持独立滚动。
- 终端右键菜单和串口传输菜单会随焦点离开而关闭,打开串口传输菜单时先聚焦对应窗格。
- 手动 X/Y/ZMODEM 操作集中到串口控制栏的“二进制传输”;SSH 等终端继续在检测到远端传输程序后提示选择文件或目录。传输失败提示区分超时、协议错误、文件读写和文件过大等原因。
- 修复替换已保存密码时首个字符与光标位置不同步的问题,以及会话日志遇到连续回车或跨数据块回车时产生多余空行的问题。
- 终端与 IDE 的中文/CJK 字体设置均支持手动填写自定义字体名称。笔记页面未使用背景图片时恢复不透明背景。
- 审计事件、会话和录制列表的行背景及分隔线铺满可用宽度,搜索与保留策略字段使用现有输入框交互。
- Windows 安装脚本明确采用 UTF-8 编码,修复本地化安装提示在系统代码页下显示异常的问题。
🐧 Linux Nix 支持与项目文档
- 新增 Linux x86_64 和 aarch64 的 Nix Flake,提供应用包、命令行入口、开发环境、overlay 与 NixOS 模块,可使用
nix build .#oxideterm、nix run .#oxideterm或nix develop。(PR #623) - Nix 安装由应用识别,更新交由 Nix 管理;包内包含运行所需资源、辅助程序和桌面集成,并完善 Linux 视频预览依赖处理。(PR #623)
- 更新 Nix 使用的 SSH 依赖哈希,加入打包校验,并补充 Nix 构建、开发及依赖维护文档。(PR #632)
- Nix 校验现由独立工作流执行,按相关文件变更触发,也可手动运行。
- 各语言 README 增加贡献者墙及内存占用对比说明,更新了相关用户指南。
👥 贡献者
感谢以下外部贡献者参与本次更新:
- @dzzzc:完善已保存本地会话的侧栏管理、移除与聚焦行为,并修复 Windows PTY 后续输出丢失的问题。(PR #631)
- @sgnay:引入 Linux Nix 打包、NixOS 集成及 Nix 更新识别,并完善依赖哈希、打包校验和维护文档。(PR #623、PR #632)
📌 使用与升级说明
- 审计与会话输出录制均需主动开启。操作记录和输出录制的保留策略分别管理,关闭审计不会删除已有记录。
- 审计记录反映 OxideTerm 能观察到的操作及结果;本机账号表示操作系统会话,命令退出状态取决于对应协议或 Shell 集成提供的信息。
- 选择导出受保护详情会生成明文文件;会话录制则继续在本机加密保存,不随云同步上传。
- Nix 安装请通过 Nix 更新;其他安装方式继续使用对应平台的安装包或应用内更新。
English
OxideTerm 2.2.0 introduces a Notification & Audit workspace, encrypted session recordings, and reusable TOTP credentials, bringing connection history, commands, file operations, and automated tasks into one place. This release also adds editing before terminal paste, improves local session management and quick-command groups, introduces Linux Nix packaging, and fixes cloud-sync crashes, Windows terminal output, and Linux recording recovery.
📋 Notification & Audit Workspace
- Expanded the notification center into Notification & Audit, with views for notifications, audit records, session summaries, and session recordings. The audit switch is visible at the top of the page and is off by default. Enabling it captures subsequent operations; existing records remain readable after it is turned off.
- Added filtering by time, category, severity, source, and outcome, plus searches for content, connections, sessions, local accounts, and remote accounts. Record details show operation history, duration, the basis for an outcome, and exit codes or transferred bytes when available.
- Added session summaries with command, file-operation, other-operation, and connection counts. Open a session's related records or follow parent and child operations to trace the work triggered by a request.
- Distinguished user actions, the command bar, quick commands, broadcasts, AI, MCP, plugins, CLI commands, and system activity. Outcomes distinguish sent, succeeded, failed, cancelled, partially completed, interrupted, and unknown, with their supporting protocol response, exit code, or lifecycle event.
- Set default operation retention to 90 days and 512 MiB. Days and capacity accept direct numeric input, from 1–3650 days and 1 MiB–64 GiB. Records are pruned according to these limits and can also be cleared manually.
- Added JSON and CSV summary export for the current filters. A separate protected-details export includes commands, paths, accounts, and endpoints in a plaintext file after confirmation.
To use it, open Notification & Audit from the sidebar, enable auditing at the top, and use filters or session summaries to review activity. Audit data stays on the device, with sensitive details stored encrypted.
🔎 Connection, File, and Automation Coverage
- Added SSH auditing for host-key verification, authentication attempts, interactive authentication, connection state, shared-connection consumers, and reconnect stages. Terminals and file browsers sharing a connection retain their own session, channel, and physical-connection identities.
- Added connection and exit records for local terminals, Telnet, Mosh, serial sessions, and remote desktops, along with serial controls, Telnet controls, and remote-desktop clipboard and file transfers.
- Traced terminal commands, quick commands, broadcasts, and tmux operations back to their entry point. Command completion uses available shell integration or exit-code evidence; sending input alone retains a sent outcome.
- Covered local and remote file browsing, search, preview, opening, directory creation, copying, moving, renaming, deletion, uploads, downloads, and editor saves. Records also include transfer pause, resume, cancellation, interruption, and file-conflict decisions.
- Added auditing for port-forward creation, start, stop, suspension, restoration, and rule changes, plus host-panel operations involving processes, services, containers, scheduled tasks, and log queries.
- Added records for settings, connection profiles, keys and credentials, cloud sync, backup and restore, app lock, the portable vault, updates, and support reports. Credential management records actions and outcomes while omitting passwords, private keys, and tokens.
- Associated AI tool calls, background tasks, MCP requests and permission changes, plugin operations, and knowledge-base management with their originating requests. Authorization, denial, cancellation, and execution outcomes retain distinct states.
🎞️ Encrypted Session Recording and Playback
- Added audit recordings for local terminals, SSH, Telnet, Mosh, and serial sessions, capturing displayed terminal output and size changes. Output recording is off by default and requires a separate confirmation when enabled.
- Stored recordings locally with encryption and excluded them from cloud sync. Keyboard input and terminal file-transfer payloads are not captured. Sensitive information displayed in terminal output can appear in recordings, as explained when recording is enabled.
- Added play, pause, restart, seeking, and playback-speed controls, with active, finished, interrupted, partial, and expired states. Playback reads content as needed instead of loading an entire long recording at once.
- Used bounded recording queues and background writes. Slow storage applies backpressure to terminal reads while input, cancellation, and closure continue to be serviced. Output and resize events retain their order, and capture gaps are identified explicitly.
- Fixed Linux PTY reads remaining disabled after recording capacity became available again, which could leave sustained output stalled.
- Set default recording retention to 7 days and 2 GiB, configurable independently of operation-record retention.
To use it, enable auditing, open Session Recordings, and enable Record Terminal Output. Open a recorded session from the list to review it.
🔐 Reusable TOTP Credentials
- Brought privilege credentials and TOTP credentials together under Settings → Credentials. TOTP accepts Base32 secrets and
otpauth://URIs, with SHA-1, SHA-256, SHA-512, six or eight digits, and a configurable period. - Allowed multiple SSH connections to share one TOTP credential, with an explicit selection for the target host and each jump host. TOTP works alongside existing password, key, or interactive authentication.
- Limited autofill to SSH authentication prompts. Defaults recognize prompts such as
MFA CODE,Verification code, andOTP; custom regular expressions are supported. Autofill requires exactly one matching hidden input. - Collected manual answers to other questions before generating a current code. Each authentication attempt submits a code automatically once, then uses manual input for further challenges. Concurrent manual authentication prompts are queued.
- Stored secrets in protected storage and kept credential references in connection profiles. Credentials can be edited, disabled, and shared, with deletion blocked while a saved connection still uses them.
- Preserved credential bindings in encrypted connection archives and cloud sync. Secrets are included only when sensitive credentials are selected and are restored into the receiving device's protected storage. Metadata-only synchronization does not reuse an old seed as though it were a newly rotated one.
To use it, add a TOTP credential under Settings → Credentials, then select it when editing an SSH connection or jump host.
✍️ Edit Before Terminal Paste
- Added Edit Before Paste using the existing editor, with multiline editing, selection, and undo. The multiline paste-confirmation flow can also open the editor; content is sent only after confirmation.
- Added an explicit code-fence removal action for code copied from Markdown documents or conversations. Surrounding fences are removed only when that action is selected.
- Preserved original clipboard content and line endings when no edits remain, including after undoing all changes. Edited content retains the source's CRLF convention.
💻 Local Sessions and Remote Terminal Management
- Gave saved local terminal profiles persistent sidebar session entries that group their running terminals, support expand and collapse, and can open additional terminals with the same startup configuration. (PR #631)
- Focused a running terminal when selecting its local session. Removing a session closes that profile's terminals and remembers its hidden sidebar state; reopening the profile from the session manager restores visibility and focus. (PR #631)
- Fixed Windows treating a temporarily empty PTY read as end-of-file, which prevented later terminal output from appearing. (PR #631)
- Kept SSH, Telnet, Mosh, and serial terminal panes and their output available after a session ends, making final errors and exit messages readable. Local shells retain their existing automatic close-on-exit behavior.
- Preserved the chosen sidebar visibility when opening sessions and restored that choice when leaving Zen mode.
🗂️ Quick-Command Groups
- Allowed removal of preset groups such as System, Network, Files, and Docker. Their commands move into Custom, which remains the default destination group.
- Added drag handles for reordering groups in the quick-command manager, with the order retained after restart.
- Applied deletion and reordering only after saving succeeds. A failed save preserves the previous groups and commands.
🛠️ Interface, Input, and Sync Fixes
- Fixed a state-borrow conflict while rendering cloud-sync previews that could crash related synchronization and local-export flows.
- Cancelled obsolete terminal resize requests when the viewport returned to its original size, preventing sidebar animations and similar changes from leaving the terminal with incorrect dimensions.
- Fixed adjacent scroll areas sharing interaction state, keeping their scrolling independent.
- Dismissed terminal context menus and serial-transfer menus when focus leaves the pane, and focused the relevant serial pane before opening its transfer menu.
- Consolidated manual X/Y/ZMODEM actions under Binary Transfer in the serial toolbar. SSH and other terminals continue to prompt for files or directories after detecting a remote transfer program. Failure notices now distinguish timeouts, protocol errors, file I/O, and oversized files.
- Fixed first-character caret positioning when replacing saved passwords, and extra session-log lines caused by repeated or chunk-split carriage returns.
- Added custom Chinese/CJK font names to both terminal and IDE settings. Restored an opaque notes background when no background image is configured.
- Made audit-event, session, and recording rows and separators fill the available width, and used the existing input controls for audit search and retention settings.
- Explicitly encoded Windows installer scripts as UTF-8 to preserve localized prompts across system code pages.
🐧 Linux Nix Support and Documentation
- Added a Linux x86_64 and aarch64 Nix flake with application packages, a CLI entry point, a development shell, an overlay, and a NixOS module. Use
nix build .#oxideterm,nix run .#oxideterm, ornix develop. (PR #623) - Recognized Nix installations and delegated updates to Nix. Packages include runtime resources, helpers, and desktop integration, with improved Linux video-preview dependency handling. (PR #623)
- Updated the Nix SSH dependency hash, added package verification, and documented Nix builds, development, and dependency maintenance. (PR #632)
- Moved Nix validation into a dedicated workflow triggered by relevant file changes or manual dispatch.
- Added contributor walls and idle-memory comparisons to the localized READMEs and updated related user guides.
👥 Contributors
Thank you to the external contributors to this release:
- @dzzzc: Improved saved local-session sidebar management, removal, and focus, and fixed missing Windows PTY output after an empty read. (PR #631)
- @sgnay: Introduced Linux Nix packaging, NixOS integration, and Nix update detection, then improved dependency hashes, package verification, and maintenance documentation. (PR #623, PR #632)
📌 Usage and Upgrade Notes
- Auditing and session-output recording require explicit activation. Operation records and recordings have separate retention settings; turning auditing off preserves existing records.
- Audit records describe operations and outcomes observable by OxideTerm. The local account identifies the operating-system session, and command completion depends on information available from the protocol or shell integration.
- Exporting protected details creates a plaintext file. Session recordings remain encrypted on the device and are excluded from cloud sync.
- Update Nix installations through Nix. Other installations continue to use their platform packages or the in-app updater.
📥 Download for your system
| Operating system | x64 | ARM64 |
|---|---|---|
| Windows | Setup (.exe) | Setup (.exe) |
| macOS | DMG (Intel) | DMG (Apple Silicon) |
| Linux | AppImage · DEB · RPM | AppImage · DEB · RPM |
Portable archives, signatures, and Downloaded If SmartScreen warns, click More info -> Run anyway.
若 SmartScreen 弹出警告,点击 更多信息 -> 仍要运行。
sha256sums.txt remain available in the release assets below.
📌 Installation Tips / 安装提示
macOS
.dmg files may be quarantined by Gatekeeper. Run in Terminal:
xattr -cr ~/Downloads/OxideTerm_*.dmg
# or after install / 或安装后
xattr -cr /Applications/OxideTerm.app
Windows
Linux
# AppImage
chmod +x OxideTerm_*_linux_*.AppImage && ./OxideTerm_*_linux_*.AppImage
# Debian/Ubuntu
sudo dpkg -i OxideTerm_*_linux_*.deb && sudo apt-get install -f
# Fedora/RHEL-compatible systems
sudo dnf install ./OxideTerm_*_linux_*.rpm
🔗 Links
- Documentation: https://oxideterm.app
- GitHub Issues: https://github.com/AnalyseDeCircuit/oxideterm/issues
- Changelog: https://github.com/AnalyseDeCircuit/oxideterm/blob/main/.github/release-notes/stable-changelog.md