What's New
Features
- Breeze Assist launcher — Windows Session 0 support with crash recovery, partner lifecycle hooks, and desktop performance optimizations (#225)
- AI Script Builder — AI-assisted script authoring with SSE streaming, MCP tool use, and approval workflow (#223)
- Hostname/OS version tracking — Agent heartbeat now reports hostname, OS version, and build so the dashboard reflects post-enrollment changes
Fixes
- macOS terminal PTY — Fixed PTY initialization in nocgo builds (all CI/release binaries) that caused terminal to show "Connected!" but never produce a shell prompt
- Terminal text color — Fixed inherited CSS
color: blackoverriding xterm.js theme, causing invisible text in remote terminal - macOS hostname — Agent now uses
LocalHostName(e.g. "MacBook-Pro-3") instead of short DNS hostname (e.g. "Mac") - Desktop capture on locked machines — Attaches thread to input desktop before DXGI/GDI init (#222)
- Display name edit — DeviceSettingsModal now initializes from
displayNameinstead ofhostname - Viewer warning UX — "Breeze Viewer not detected" changed to "Viewer didn't open?"
- Tab overflow dropdown — Device detail tabs use responsive overflow menu instead of horizontal scroll
- Agent WS pong timeout — Agent responds to server-side pings, force-upgrades unparseable dev versions (#224)
- Hono 4.12.5 type update — Non-null assertions for updated param types (#226)
- macOS nocgo metrics — CPU and disk IO metrics working in nocgo builds (#227)
- Docker compose configs — Fixed YAML indentation in all override files
- Migration 0003 — Made fully idempotent for existing databases (no manual SQL needed)
Security Hardening
- Partner guard verifies JWT signature before reading claims
- Device enrollment limit check moved inside transaction (TOCTOU fix)
- HMAC-SHA256 webhook signing for partner hooks (
PARTNER_HOOKS_SECRET) - Per-session spawn mutex instead of global lock
- Binary hash enforcement for helper connections
- Reduced token impersonation from SecurityDelegation to SecurityImpersonation