Added
- Duplicate a profile together with its browser state.
POST /api/profiles/{id}/duplicatenow accepts{"include_browser_state": true}, which copies the source profile's cookies, logged-in sessions, history and local storage into the clone alongside its settings and fingerprint — so the copy launches as the same identity and the same session. The source is held stopped for the whole copy — a launch, reset or delete of it is refused with 409 until the copy finishes, and a source that is still launching or closing is refused too — and the clone only appears in the list once its directory is complete, so a half-built clone can never be launched or deleted. Chromium's single-instance lock files and the source's preview frame are left behind; a failed copy leaves nothing behind. Reset and Delete now also refuse (409) a profile whose browser is still launching or closing, instead of touching a directory Chrome is using, and Launch refuses (409) a profile whose previous browser is still closing instead of starting a second Chrome on the same directory. In the profile editor, Duplicate becomes a split button: the button itself still makes a config-only copy, and its menu offers With browser state (disabled until the profile is stopped). Without the flag the endpoint behaves exactly as before. - Send files to a profile, and keep what it downloads. A profile now has files of its own:
POST /api/profiles/{id}/filesuploads one,GETlists them or fetches the bytes,DELETEremoves one. Under Docker the browser cannot see your filesystem, so an upload also appears in the guest's own file dialog under Uploads — , letting a website's "Choose file" button reach it, and files the browser downloads are captured automatically instead of being trapped in the container — published only once the transfer completes, so a half-written download is never served. The live viewer gains a files button: upload, drop a file onto the screen, fetch one back, or remove one. Files are stored beside the profile rather than inside it, so duplicating a profile's browser state never copies its documents, and deleting a profile deletes them with it. Per-profile limits are configurable (ARTIFACT_MAX_BYTES,ARTIFACT_MAX_COUNT,ARTIFACT_MAX_TOTAL_BYTES). On the native macOS and Windows builds the browser already shares your filesystem and its own Downloads folder, so download capture and the sidebar shortcut do not apply there.
Changed
- Bundles the CloakBrowser 0.6.0 engine.
macOS (universal — Apple Silicon + Intel): not notarized yet, so macOS blocks the first launch. Run xattr -rc "/Applications/CloakBrowser Manager.app" once, or use System Settings → Privacy & Security → Open Anyway.
Windows: if SmartScreen warns, click More info → Run anyway.
The stealth Chromium engine downloads on first launch.
Verify your download against SHA256SUMS (attached): shasum -a 256 -c SHA256SUMS.