github Yeraze/meshmonitor v4.17.0-rc6

pre-release3 hours ago

MeshMonitor v4.17.0-rc6

Warning

This is a pre-release for testing. It is not tagged latest. Use it on a test install or with a recent backup.

Summary

This release candidate is mostly a permissions release. Until now, many routes checked a per-source permission on any source, so a grant on one source could read, change or transmit on another. Every such route now checks the source it acts on: device configuration, mesh requests, messages, channels, nodes, settings, the poll, the v1 API, public embeds and the live WebSocket feed. Admins are unaffected apart from a few replies that now name one source instead of all of them; users with limited grants will see less than before, by design. On the feature side, every number field can now be cleared while editing, the sender's name in a channel or DM opens the node popup with its status, TAK team and role are configurable, and the Reticulum source page works on phones. Saving a config section no longer turns a node's "firmware default" position interval into a 32-second broadcast.

Features

  • UI: number fields can be cleared; blank is outlined and blocks Save (#5652)
  • Chat: sender name opens the node popup with status; status emoji badge on the avatar (#5651)
  • Config: TAK team and role module settings (#5641)
  • MQTT: source-card warning when client proxy has no linked broker (#5663)

Bug Fixes

  • Permissions: device-config routes check the target source (#5655)
  • Permissions: nodes, settings and message routes check the target source (#5656)
  • Permissions: mesh-request, announce, connection and channel routes check the target source (#5657)
  • Permissions: optional-sourceId reads limited to the caller's sources; install-wide jobs are admin only (#5658)
  • Permissions: private positions checked per source; telemetry reads and /api/status scoped; one rule for a source's address (#5660)
  • Permissions: every section of GET /api/poll gated on its own source (#5661)
  • Permissions: embeds and the v1 API scoped per source; MeshCore telemetry ids; restart is admin only (#5664)
  • Permissions: WebSocket events filtered per source and per grant (#5665)
  • Config: a stored 0 interval is sent as 0; one channel read-back; dead desktop Virtual Node checkboxes removed (#5662)
  • Admin: a stored 0 is explained; one request per Owner/Channels Load; dead Virtual Node env vars removed (#5659)
  • Admin: per-section Load for Status Message, Traffic Management and MeshBeacon, local and remote (#5644)
  • Reticulum: phone tab bar docks under the content (#5648)

Docs

  • MQTT: "Why don't I see MQTT traffic?" (#5663)
  • Add-ons: Virtual Node sidecars and REST API clients described separately (#5653)
  • Add-ons: Mesh Screensaver and Mesh Widget (Zebar) listed (#5650)

Issues Resolved

#5613, #5645, #5646, #5647, #5649

Upgrade Notes

  • No new migrations.
  • Permissions are now enforced per source everywhere. A user needs the grant on the source a request acts on; with no sourceId, on the primary source. If a non-admin loses access after upgrading, grant the permission on that source under Users.
    • A request naming an unknown sourceId returns 404; it used to act on the primary source.
    • A request with different sourceId values in the query and body returns 400.
    • Lists read with no sourceId return only the sources the caller may read.
  • Admin only now: the Auto-Enrichment and Position Estimation "run now" jobs, and Restart Container.
  • Public and anonymous access:
    • GET /api/status no longer returns install-wide statistics without an admin login; connection.localNode needs nodes:read on the primary source. connection.connected still needs no login.
    • The poll returns traceroutes only with traceroute:read on the source. Grant it to the anonymous account if a public map should draw route lines.
    • Embeds leave out a node that has a private position override, is hidden from the map, or reports its position on a channel outside the profile.
  • WebSocket: live events are filtered per source and per grant. A non-admin API-token client that listened without joining must now emit join-source (or the new join-all-sources) to receive anything. Firmware status and automation-engine events go to admins only. A revoked grant, a deactivated user and a logout take effect on the open socket.
  • GET /api/config no longer returns the local node's identity or firmware version without a grant on that source. GET /api/traceroutes/recent follows traceroute:read.
  • v1 API: private override columns, topology edges and private position telemetry are withheld from tokens without the matching grant; /status for an MQTT or MeshCore source reports that source; 403 bodies on a few routes now carry the message in error.
  • MeshCore: telemetry and Device Info graphs for a MeshCore contact need nodes:viewOnMap on that source.
  • Node address: shown to users with sources:read, everywhere.
  • Config saves: a position broadcast interval of 0 ("firmware default") is saved as 0. Earlier versions turned it into 32 seconds. The server now rejects a position interval of 1–31 s and a node-info interval of 1–3599 s.
  • Number fields: blank no longer means 0; type 0 where 0 means "off". A stored value outside a field's range shows red and blocks that form's Save until fixed.
  • Admin Commands: Load sends one request per click; on a lossy link, click Load again.
  • Purge node database with no sourceId now purges the primary source only.
  • Hide from map in a cross-source view hides the node only on sources the user may write.
  • Desktop app: the two Virtual Node checkboxes are gone; Virtual Node is set per source under Dashboard → Edit Source.

Thanks

Thanks to @maxhayim for the two add-on submissions.

Full changelog: v4.17.0-rc5...v4.17.0-rc6

🚀 MeshMonitor v4.17.0-rc6

📦 Installation

Docker (recommended):

docker run -d \
  --name meshmonitor \
  -p 8080:3001 \
  -v meshmonitor-data:/data \
  ghcr.io/Yeraze/meshmonitor:4.17.0-rc6

🧪 Testing

✅ All tests passed
✅ TypeScript checks passed
✅ Docker images built for linux/amd64, linux/arm64, linux/arm/v7

📋 Changes

See commit history for detailed changes.

Don't miss a new meshmonitor release

NewReleases is sending notifications on new releases.