From ec059a7469debb33b7f2f419d00fab1f01617ace Mon Sep 17 00:00:00 2001 From: Henrik Tilly Date: Sat, 3 Oct 2026 13:09:18 +0200 Subject: [PATCH] Prepare v2.4.0 release Security release: removes the feature-request automation (LLM-written diffs pushed from a write-scoped CI job), redacts secrets in logs, fixes the login rate limit behind proxies, closes the password-setup overwrite, adds audit logging and per-user chat rate limits, keeps AI chat on topic, and runs the container (release and local images) as an unprivileged user with an allowlisted build context. Co-Authored-By: Claude Sonnet 5.5 --- docs/CHANGELOG.md | 12 +++++++++++- package-lock.json | 4 ++-- package.json | 2 +- 3 files changed, 14 insertions(+), 4 deletions(-) diff --git a/docs/CHANGELOG.md b/docs/CHANGELOG.md index 1dc5834..a6cd867 100644 --- a/docs/CHANGELOG.md +++ b/docs/CHANGELOG.md @@ -5,7 +5,7 @@ All notable changes to SlackONOS will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). -## [Unreleased] +## [2.4.0] - 2026-10-03 ### Removed - **Feature-request automation** - The `featurerequest`/`fr` command, the `feature-request-enhance.yml` workflow and its `.github/agent/` LLM tooling are gone. The pipeline fed issue titles through OpenAI/Claude and committed and pushed the resulting diff from a write-scoped CI job, so a prompt-injected title could land arbitrary code on a branch. The `githubToken`/`githubApp*` config keys and `lib/github-app.js` went with it. Ideas and bugs go to GitHub issues as usual. @@ -20,6 +20,16 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - **AI chat stays on topic** - The AI's free-text `chat` replies are limited to short, music-related DJ lines. The prompt forbids code, technical help, homework and long answers, and the server replaces replies that contain code or run over several lines and truncates anything over 240 characters, so the bot can't be used as a free general-purpose assistant on the operator's OpenAI key. - **Per-user chat rate limits** - Non-admins are limited to 30 commands and 10 AI requests per minute (`userCommandRateLimit`, `aiRateLimitPerUser`; `0` disables). The user is told once per window, further messages are dropped. Admins are not limited. Stops one user from flooding the queue or running up the OpenAI bill. +### Upgrade notes +- **Config folder ownership:** the container now runs as the unprivileged `node` user (uid/gid 1000). On first start it takes ownership of the mounted `/app/config`, so existing installs keep working; set `PUID`/`PGID` to run as another user. +- **Ports below 1024:** a `webPort`/`httpsPort` below 1024 now needs a port mapping (e.g. `80:8080`) instead. +- **`featurerequest` is removed:** also drop `githubToken` and `githubApp*` from your `config.json`, and revoke any GitHub token or App key that was only used for it. + +### Verification +- npm test: 891 passing (up from 796 in 2.3.7) +- Full Slack + Sonos end-to-end integration suite: 111/111 passing +- Docker image (release and local) built and started as `node` against a root-owned config volume; CodeQL: no open alerts + ## [2.3.7] - 2026-08-30 ### Security diff --git a/package-lock.json b/package-lock.json index 7407e3e..680742b 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "slackonos", - "version": "2.3.7", + "version": "2.4.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "slackonos", - "version": "2.3.7", + "version": "2.4.0", "license": "ISC", "dependencies": { "@sefinek/google-tts-api": "^2.1.15", diff --git a/package.json b/package.json index 2561e32..7bcc94c 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "slackonos", - "version": "2.3.7", + "version": "2.4.0", "description": "Democratic Slack bot for controlling Sonos speakers with community voting", "main": "index.js", "scripts": {