Ghost FTP v0.91.1 — cross-platform reliability and diagnostic privacy
Patch release following the verified published v0.91.0 source. These changes address real edge cases while leaving existing Windows/Linux, Android and macOS product architecture and image assets intact.
Fixes
- Windows/Linux Site Manager: clicking another saved site while a draft is being edited no longer destroys it. The active draft stays associated with its original profile even if a search/filter hides the row. Escape is guarded, an explicit Cancel restores the persisted profile, switching to New Site/Import is disabled while editing, and in-flight actions cannot accidentally close it.
- Android: FTP/FTPS/SFTP URL userinfo in user-facing errors is now fully redacted, including username-only URLs and user/password URLs. Non-credential URL hosts and useful server messages remain visible within existing bounded diagnostics.
- macOS: unreadable, over-limit or invalid saved-profile JSON is never silently discarded before subsequent saves; its original bytes are preserved under a dedicated recovery key. Backup imports with duplicate profile UUIDs reject atomically instead of silently overwriting entries.
- QA: new/expanded Android JVM, macOS XCTest and desktop source-interaction regressions cover the affected failures.
Scope and release acceptance
All six required workflows must pass on the exact PR HEAD SHA and again on merged main, followed by the canonical signed/unsigned asset inventory and SHA-256 verification before publication. The release process must never move the v0.91.0 tag or substitute concept renderings for genuine application screenshots.
The provided ZIP has 75 Windows/Linux/Android design concepts (30 Windows, 29 Linux, 16 Android), not installed-app evidence. The ZIP includes no macOS concept reference. Installed-screen 1:1, real-device full click acceptance, Android production-signing continuity, macOS notarization and macOS FTPS/SFTP verified identities remain separate blocking work; none is claimed complete by this patch.