New Features
- Added a capture subscription API to support more transports (#699).
- Added support for restricting OAuth login by user email, along with a new
emailOAuth scope. - Added OIDC-only member authentication (#686).
- Enabled automatic video quality (bandwidth estimation) for legacy (v2) clients (#693).
- Added a mouse pointer visibility toggle via
capture.video.show_pointer(#691). - Added multi-file selection and bulk deletion to file transfer (#687).
- Added file deletion support and a user delete config option to file transfer (#683).
- Added a
?scrollquery param to set scroll sensitivity on load (#681). - Added an arm64 Google Chrome image (#685).
- Added example Docker Compose configurations for simple browser, TURN server, GPU-accelerated browser, and OAuth setups (#684).
- Added an "open in app" plugin to open chat links in a shared neko instance (#682).
Fixes
- Fixed missing clipboard fallback button in Safari (#709).
- Fixed a XSS vulnerability by sanitizing attribute values and preventing Vue template compilation in rendered markdown.
- Fixed video pipeline configuration to accept a bare pipeline string (#701).
- Fixed a goroutine leak in the RTCP PLI ticker (#697).
- Fixed a memory leak by freeing
CStringallocations andGFilereferences in drag URI handling (#700). - Fixed a nil pointer panic when destroying the WebRTC peer during a profile change (#695).
- Fixed file transfer to allow non-admin uploads and downloads (#679).
- Fixed the TOR browser image to fetch it from the latest download source.
Misc
- Removed the default configuration file bundled with the image; defaults are now built into the server, preventing accidental overrides when providing a custom config.
- Updated persistent data policies for Firefox-based browsers.