Persist active page-tab and Shell/Task sub-tab across soft refreshes and
rebuilds. Soft-update session list without wiping tab HTML. Give sub-tabs
and action rows flex-shrink:0 so the output box cannot crush Run/Shell UI.
Separate read-only aiosqlite connection so concurrent operators/beacons
do not serialize behind write lock. Busy timeout, NORMAL sync, batch
metric upserts, and in-memory counter flush loop.
Org Default runner group no longer allows public repos. Move CI/SquidGate
to ubuntu-latest/windows-latest and pin third-party actions to commit SHAs
(org sha_pinning_required). Document protected master + CI posture.
Remove personal OneDrive paths and wrong GitHub owner; document self-hosted
CI for external contributors; fix env prefix table, deploy lab script, UFW
guidance, pyproject URLs, and tighten gitignore for secrets.
Wire context handlers per mount so duplicate ctxRun IDs no longer leave
the Session-tab Run button dead (getElementById hit the hidden rail).
Grow session/console output space, right-align Close, restyle INKO close.
MCP needs SQUIDC5_MCP_ENABLED and feature mcp_enabled. Expose mcp.active
on meta/features/deep health; clearer 403 text; Ops Features warns when
feature is on but process env still blocks.
INKO flyout collapses connection/model into a one-line summary when set.
Assets: live verified/interactive hosts always surface (clear stale
bulk-hide). mark_verified merges metadata and unhides host key.
Bare pip on self-hosted Windows can target a different interpreter than
setup-python. Use python -m pip install -e ".[binaries]" and verify
import before build_binaries.py on Linux and Windows binary jobs.
- GET /api/v1/hosts groups sessions into host nodes with co-host edges
- Claim TTL (SQUIDC5_SESSION_CLAIM_TTL_SEC), renew on activity, force claim
- Ops Assets view: SVG graph, host table, session drill-down to lock rail
- claim field on session list/get; UI chips + Force claim for admin
- Tests for hosts API, claim_info, ops markers; user-guide update
- Install portable gh when missing on squidsec runners
- Drop curl|head under pipefail (exit 23 on healthy smoke)
- Use pwsh for Windows binary build steps (bash path break)
Shared squidsec runners collide on fixed :8443 and pip caches.
Use random host ports for docker/binary smoke, unique container names,
and disable actions/setup-python pip cache on self-hosted.
- Fix All non-admin button (was setting admin when granter is admin)
- Reshape presets: Full operator, Operator, Read-only+INKO, Read only, ...
- Expose non_admin_scopes in meta catalog
SQUIDC5_PUBLIC_HOST is for implant/OAST callbacks (e.g. oast.*).
Connection tickets and redeem now build URLs from the request Host /
X-Forwarded-* so links match the ops console hostname.
Admins can issue a unique /ops#sc5ticket= URL for any active token
without seeing the secret. Recipient redeems once; server rolls the
token and auto-loads the new secret. CLI: sc5 tokens link.
- After mint/roll, Admin shows dismissible banner with secret + /ops#sc5= link
- POST /api/v1/tokens/{id}/roll and sc5 tokens roll rotate the secret
- tokens:manage cannot roll privileged tokens (admin only)
Pin drawer to visualViewport instead of padding foot by kb height.
Drop smooth scrollIntoView on every resize; snap chat log instantly
once; disable overflow-anchor on the message list.
Replace em/en dashes, arrows, middots, smart quotes, ellipsis, and
emoji/icon glyphs with plain ASCII across docs, UI, source, and agents.
INKO branding is text-only; empty placeholder is "-"; nav icons removed.
- Custom select arrow + right padding so text never collides with chevron
- Expand CHAT_SYSTEM_PROMPT with C5 purpose, objects, workflows, tool map
- Greedy markdown list match so consecutive 1. lines share one <ol>
- Soft-render views on nav/poll so focused inputs keep values
- Listener kinds: smtp + https; port range + duplicate port checks
- INKO: resizable flyout, New chat, empty-state starter cards, mobile kb inset
- Actor rename via PUT /me; LLM Get API key links; Admin TLS upload/activate
- Operator assets library for INKO-saved payloads/profiles/implants
- INKO nav page shows capabilities/status/tools (chat only in flyout)
- Status/tools outbox is large and scrollable
- Dashboard Beacons counts active sessions only (not closed totals)
- Render GFM markdown tables in INKO replies
- Copy button on each INKO assistant response
Keep INKO history in localStorage across flyout/page views. Clear the
input as soon as send starts, show a thinking indicator while waiting,
block concurrent sends, and render assistant markdown safely.
Rename INK to INKO (Intelligent Neural Kinetic Operator) across ops UI,
chat system prompt, and docs. Replace floating FAB with a top-bar INKO
button that opens a right-side flyout panel (full-screen on mobile).
- Hamburger slide-out nav on mobile (full-height menu, not tiny strip)
- Brand operator AI as INK (neural operator); Enter-to-send on chat
- Remove legacy capability runner; LLM config only under Admin
- Drag-resize bottom dock height and event/console split (persisted)
- Pink/purple themed scrollbars across the ops chrome
Compact sticky top bar with safe-area; swipe-friendly nav.
Session context opens as a bottom sheet with touch scrolling
(instead of being hidden on mobile). Docs menu scrolls when long.
Add multi-turn Admin AI chat (POST /api/v1/ai/chat) that can answer
generally and call allow-listed tools: sessions, listeners, tasks,
payloads, metrics, events, audit. Policy + scopes enforced per tool;
bounded rounds; sanitized I/O. Offline intents for list/create listener
when no LLM is configured. Ops UI drawer and AI tab are free-form chat.
- Preserve /v1 path in LLM base_url SSRF validation (fixes 404 on api.x.ai/chat/completions)
- Legacy pathless bases get /v1 restored for known OpenAI-compatible hosts
- POST /api/v1/llm/models proxies provider model list (SSRF-guarded)
- Ops UI: full provider list, auto base URL, key→model select, override checkbox
- AI page + drawer: pick among configured LLMs
- Admin view: hide context/bottom panes, roomier stack layout
Add BYO LLM form (provider/model/base_url/api_key) on AI and Admin views.
Replace scattered Docs links with a single header Docs dropdown per page.
Allow http loopback LLM base URLs for local Ollama (SSRF still blocks private/non-loopback).
- Soft-update session/listener tables so poll refresh does not clear selection
- Persist selected session/listener in localStorage
- Soft-update context rail (preserve shell/task inputs)
- Doc links on every view and feature block (GitHub user-guide anchors)
- AI nav tab + global floating Admin AI chat (POST /ai/run capabilities)
Add top-bar Phone QR button that encodes /ops#sc5= payload (url+token)
client-side. Scan opens ops and auto-connects; token never leaves browser
to a third-party QR API.
Replace card/masonry layout with competitor-style shell: top bar,
sidebar nav, main workspace, session context rail, bottom event/output
consoles. Session-centric workflow for discoverability.
Replace absolute masonry/fixed-tile heights with CSS grid and natural
panel height. Multi-page nav stays compact. Add SquidC5 banner to
README, docs, and web assets (replace SquidSec logo hero).
- C08: SHA-256 audit chain_hash/prev_hash on insert (migration v3)
- B14: shell.interact requires team membership when session has team_id
- C06: agents/linux Go beacon using implant AEAD envelope