TautWeekly for Plex v0.18.2
v0.18.2 makes Config > Validate, save, and verify the primary, scoped
validation workflow. The Manager compares normalized old and new values in
memory and returns a typed save-impact plan without exposing secret values.
Only affected work runs:
- Tautulli connection changes refresh choices, verify Tautulli/Plex, and
regenerate previews. - Direct Plex changes rerun integration verification and regenerate previews.
- SMTP-card changes rerun only the non-sending SMTP preflight.
- Identity, newsletter-content, custom-card, and library/exclusion changes
preserve sanitized connection evidence and regenerate previews through the
established renderer. - Cache, email, schedule, and delivery-delay-only changes run no discovery,
integration, SMTP, or preview work. Cache saves retain the existing concise
enabled, disabled, or settings-saved confirmation. - Exact no-op saves create no backup, make no service request, and start no
preview operation.
Unchanged sanitized discovery and verification evidence is safely rebased to
the new full configuration revision. Revision conflicts, external-edit
protection, private backups, restore behavior, schedules, and secret handling
remain unchanged. Verify remains available for secondary detailed
diagnostics. A successful manual Refresh or Verify can resume a preview that
was waiting on repaired choices without another configuration save.
Discovery failures now say that preview generation was skipped because
Tautulli choices could not be refreshed. The missing-owner message is used only
after successful discovery proves there is no unambiguous owner or
administrator.
Origin hardening
Same-origin checks now compare canonical authorities: DNS is case-insensitive,
one trailing dot is normalized, and omitted :80 or :443 is equivalent to
the matching explicit default port. Authentication, CSRF, Host allowlisting,
exact scheme/host matching, secure cookies, and private Tailscale HTTPS remain
required. Malformed origins, genuine cross-origin requests, Tailscale HTTP,
and spoofed Forwarded or X-Forwarded-* headers remain rejected. Sanitized
support codes distinguish invalid origins, host or scheme mismatches, and
remote HTTP without logging private hostnames.
Default macOS http://localhost:8787 and exact private .ts.net HTTPS access
are covered by regression tests. The reported default localhost failure was not
reproduced; if it persists, only the sanitized browser scheme, Host shape, and
trusted-proxy presence are needed for follow-up. Private hostnames and
credentials should not be posted.
Update existing installations
Back up private data, then use the documented update path for the installed
package. No configuration migration is required. Existing credentials,
schedules, generated newsletters, backups, history, Tailscale settings,
Manager access settings, package ownership, and recovery behavior remain
unchanged.
Validation
The release is covered by Manager unit and integration tests for every
maintained package kind, field-by-field save-impact and retained-evidence
contracts, no-op saves, discovery-failure status, canonical localhost and
Tailscale authorities, rejected cross-origin and HTTP mutations, and ignored
forwarding headers. Production and synthetic GUI behavior, renderer output,
cross-builds, platform packages, documentation, accessibility, privacy,
release payloads, checksums, reproducibility, CI, and desktop/mobile browser
behavior are validated as part of the release workflow.