ScreenTinker v1.9.34-alpha1
Changes
- chore(release): v1.9.34-alpha1
- Keep the widget editor's Preview isolated, whatever the org setting says
- Escape user-controlled data at the HTML sinks it actually reaches
- Close the third QA round: limiter bypass, stored XSS, break-glass, org placement
- Fix: per-organization SSO was blocked by our own CSP and had never worked in a browser
- Fix a login-page dead end, an enumeration oracle, and three boot/limiter defects
- SSO-only: enforce per-domain, cover invited members, and stop the admin locking themselves out
- SSO: build the operator approval screen, and close the last of the QA findings
- SSO-only: close the backdoor, the unilateral disable, and the fresh-install fail-open
- Fix: the router discarded every SSO return, so single sign-on could never complete
- Boot: install missing dependencies and rebuild the native module before starting
- README: nest the SSO subsections under their parent headings
- README: document SSO-only, and correct two claims that stopped being true
- SSO-only: an org may require its own identity provider, operator approves removal
- SSO settings: show a verification outcome once, not twice
- SSO: refuse delegated proof names, release lapsed and deleted claims
- SSO: TXT only for domain proof, drop the CNAME form
- Fix RSS ticker so scroll speed is content-independent
- SSO: prove domain ownership by DNS, and fix what the second review found
- SSO: fix an account takeover, a remote crash, and login CSRF found in review
- Remove focus timeout for input element
- SSO: per-organization providers, configured by the customer
- Prevent input focus from scrolling
- SSO: one OIDC flow for every provider, and verify the token properly
- Fix main content width shrinking to narrow column
- Fix banner shifting whole dashboard layout
- Fix banner persistence across view switches and modal scroll on open
- Fix banners: prepend inside #app instead of inserting before it as sibling
- Fix banners overlapping sidebar by adding margin-left matching sidebar width
- Add org-level widget sandbox isolation toggle with warnings
- Initial plan
- BrightSign: report IPv6, the attached display and the active video mode
- BrightSign: report the LAN address, real disk, memory and load
- BrightSign: find the LAN address on any interface, and say when there is none
- Pi installer: stop advertising what was never installed (#245)
- Stop Android panels losing controls when they update
Artifacts
screentinker-1.9.34-alpha1.tar.gz- bundle: server + frontend source + the Tizen .wgt (the signed Android APK is added at the root during release finalization).ScreenTinker.wgt- Tizen TV web app, unsigned - for inspection only.
Sign it with your own Samsung certificate (Tizen Studio + a profile that includes
your TV's DUID) to install, or - easiest - point a Tizen TV browser / URL Launcher
athttps://<your-instance>/player(no signing needed).autorun.zip- BrightSign player installer. Drop it on the root of a player's
storage (microSD, USB, or internal flash) and power-cycle: it unpacks itself and
reboots into the player. Editscreentinker.jsoninside the archive first to
point it at your own server.- Docker image:
ghcr.io/screentinker/screentinker:1.9.34-alpha1(pre-release -:latestis NOT moved). ScreenTinker.apk- signed Android player (attached during release finalization).