MeshMonitor v4.17.0-rc6
Warning
This is a pre-release for testing. It is not tagged latest. Use it on a test install or with a recent backup.
Summary
This release candidate is mostly a permissions release. Until now, many routes checked a per-source permission on any source, so a grant on one source could read, change or transmit on another. Every such route now checks the source it acts on: device configuration, mesh requests, messages, channels, nodes, settings, the poll, the v1 API, public embeds and the live WebSocket feed. Admins are unaffected apart from a few replies that now name one source instead of all of them; users with limited grants will see less than before, by design. On the feature side, every number field can now be cleared while editing, the sender's name in a channel or DM opens the node popup with its status, TAK team and role are configurable, and the Reticulum source page works on phones. Saving a config section no longer turns a node's "firmware default" position interval into a 32-second broadcast.
Features
- UI: number fields can be cleared; blank is outlined and blocks Save (#5652)
- Chat: sender name opens the node popup with status; status emoji badge on the avatar (#5651)
- Config: TAK team and role module settings (#5641)
- MQTT: source-card warning when client proxy has no linked broker (#5663)
Bug Fixes
- Permissions: device-config routes check the target source (#5655)
- Permissions: nodes, settings and message routes check the target source (#5656)
- Permissions: mesh-request, announce, connection and channel routes check the target source (#5657)
- Permissions: optional-
sourceIdreads limited to the caller's sources; install-wide jobs are admin only (#5658) - Permissions: private positions checked per source; telemetry reads and
/api/statusscoped; one rule for a source's address (#5660) - Permissions: every section of
GET /api/pollgated on its own source (#5661) - Permissions: embeds and the v1 API scoped per source; MeshCore telemetry ids; restart is admin only (#5664)
- Permissions: WebSocket events filtered per source and per grant (#5665)
- Config: a stored 0 interval is sent as 0; one channel read-back; dead desktop Virtual Node checkboxes removed (#5662)
- Admin: a stored 0 is explained; one request per Owner/Channels Load; dead Virtual Node env vars removed (#5659)
- Admin: per-section Load for Status Message, Traffic Management and MeshBeacon, local and remote (#5644)
- Reticulum: phone tab bar docks under the content (#5648)
Docs
- MQTT: "Why don't I see MQTT traffic?" (#5663)
- Add-ons: Virtual Node sidecars and REST API clients described separately (#5653)
- Add-ons: Mesh Screensaver and Mesh Widget (Zebar) listed (#5650)
Issues Resolved
#5613, #5645, #5646, #5647, #5649
Upgrade Notes
- No new migrations.
- Permissions are now enforced per source everywhere. A user needs the grant on the source a request acts on; with no
sourceId, on the primary source. If a non-admin loses access after upgrading, grant the permission on that source under Users.- A request naming an unknown
sourceIdreturns 404; it used to act on the primary source. - A request with different
sourceIdvalues in the query and body returns 400. - Lists read with no
sourceIdreturn only the sources the caller may read.
- A request naming an unknown
- Admin only now: the Auto-Enrichment and Position Estimation "run now" jobs, and Restart Container.
- Public and anonymous access:
GET /api/statusno longer returns install-widestatisticswithout an admin login;connection.localNodeneedsnodes:readon the primary source.connection.connectedstill needs no login.- The poll returns traceroutes only with
traceroute:readon the source. Grant it to the anonymous account if a public map should draw route lines. - Embeds leave out a node that has a private position override, is hidden from the map, or reports its position on a channel outside the profile.
- WebSocket: live events are filtered per source and per grant. A non-admin API-token client that listened without joining must now emit
join-source(or the newjoin-all-sources) to receive anything. Firmware status and automation-engine events go to admins only. A revoked grant, a deactivated user and a logout take effect on the open socket. GET /api/configno longer returns the local node's identity or firmware version without a grant on that source.GET /api/traceroutes/recentfollowstraceroute:read.- v1 API: private override columns, topology edges and private position telemetry are withheld from tokens without the matching grant;
/statusfor an MQTT or MeshCore source reports that source; 403 bodies on a few routes now carry the message inerror. - MeshCore: telemetry and Device Info graphs for a MeshCore contact need
nodes:viewOnMapon that source. - Node address: shown to users with
sources:read, everywhere. - Config saves: a position broadcast interval of 0 ("firmware default") is saved as 0. Earlier versions turned it into 32 seconds. The server now rejects a position interval of 1–31 s and a node-info interval of 1–3599 s.
- Number fields: blank no longer means 0; type 0 where 0 means "off". A stored value outside a field's range shows red and blocks that form's Save until fixed.
- Admin Commands: Load sends one request per click; on a lossy link, click Load again.
- Purge node database with no
sourceIdnow purges the primary source only. - Hide from map in a cross-source view hides the node only on sources the user may write.
- Desktop app: the two Virtual Node checkboxes are gone; Virtual Node is set per source under Dashboard → Edit Source.
Thanks
Thanks to @maxhayim for the two add-on submissions.
Full changelog: v4.17.0-rc5...v4.17.0-rc6
🚀 MeshMonitor v4.17.0-rc6
📦 Installation
Docker (recommended):
docker run -d \
--name meshmonitor \
-p 8080:3001 \
-v meshmonitor-data:/data \
ghcr.io/Yeraze/meshmonitor:4.17.0-rc6🧪 Testing
✅ All tests passed
✅ TypeScript checks passed
✅ Docker images built for linux/amd64, linux/arm64, linux/arm/v7
📋 Changes
See commit history for detailed changes.