- deployServerBinary: use rename(2) for atomic replace, fixes ETXTBSY
when target Go binary is busy (Linux kernel handles inode swap).
Falls back to copyFileSync on cross-device rename or non-Linux.
Windows: rename target out of the way first, then move new in.
- settings.js: mark 'server' phase as error when build succeeded but
deploy failed (was incorrectly marking 'done' from build alone).
- settings.js: completion modal now shows error title, error message
and pre-formatted stderr when serverDeploy.success === false.
- i18n: added complete_with_errors, modal_done_with_errors_title in
en/pl.
Introduce a SessionManager for relay-based remote sessions in the Tauri MGMT client: new SessionCommand API, start/stop/session input routing, clipboard/recording/quality controls, and notification read/dismiss state. Wire AppState with new mutexes and show main window on startup. CI: add SBOM generation (anchore) and Trivy vulnerability scan steps. Misc: change console Docker DB path, large README/CHANGELOG updates (chat E2E, unattended access/WOL, i18n expansion, CDAP/SDK docs), and many web-nodejs assets/locales/routes/views/services and server-side changes.
Introduce a server-side API proxy and cookie-enabled HTTP client in the Tauri backend to bypass WebView CORS/mixed-content limitations and support session-based auth. Cargo.toml enables reqwest cookie_store; AppState and lib.rs build and expose a shared reqwest::Client and register api_proxy and api_clear_session commands. commands.rs implements api_proxy (forwards requests, returns JSON with __status and proper error reporting) and a stubbed api_clear_session.
Add a large set of frontend UI components and features: AutomationPanel, ChatPanel, DataGuardPanel, DeviceDetail, FileTransferPanel, HelpRequestsPanel, NotificationCenter, RemoteView, ServerPanel, SessionHistoryPanel, ToastContainer and a toast store. Update Dashboard and DeviceList to include recent sessions, help requests, device actions/WOL, retry buttons, and an actions menu. Also update layout/Sidebar/Settings, add locale strings (en/pl), and tweak global styles and some web-nodejs assets (desktop widgets, desktop-mode, tutorial, main layout) to support the new panels and behavior.
Add multiple security hardenings across the server and web console: enforce proof-of-possession for /ws/bd-mgmt using Ed25519-signed headers with timestamp/nonce and replay protection (public key binding, canonicalization, storage, verification, and tests); remove legacy API key query param and config-table fallback in favor of scoped api_keys (migrate bootstrap key into api_keys); tighten WebSocket origin handling for relay and signal servers to allow only localhost origins by default unless an explicit allowlist is set; update auth middleware public paths and test helpers to use X-API-Key header; add ensureScopedAPIKey migration and related helpers; add a GitHub Secret Scan workflow and an audit report. Misc: propagate audit logging on bd-mgmt connect/disconnect and validate enrollment public keys during device register.