This release adds 2 notable features for engineering teams evaluating rollout.
Published 1mo
Communication & Email
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
chat
communication
gdpr-compliant
privacy-first
screensharing
video-calls
+1 more
voice-calls
Affected surfaces
auth
Summary
AI summaryUpdates Highlights, Upgrade Notes, and 0.1.0 across a mixed release.
Full changelog
Highlights
- Bearer-First Origin Sessions: Direct login and registration now store bearer tokens for the origin server and use them for GraphQL HTTP and WebSocket authentication, with cookie fallback kept for compatibility paths.
- More Predictable Chat Entry: Returning to Chatto now remembers the last DM room as well as channel rooms, so the default chat entry points reopen the conversation you were using.
- Fresh Sessions Show Navigation: Fixed an issue where persisted sidebar state could hide primary navigation or room panels on a fresh session.
Upgrade Notes
- Client Authentication: Client developers should expect origin GraphQL requests and subscriptions to prefer bearer-token authentication after direct login or registration. Existing cookie-compatible paths remain available where needed.
- 0.1 Data Model: Server operators should continue treating this as the 0.1 event-sourced architecture. Pre-0.1 boot import paths are not part of this release line.
Generated Changelog
0.1.0 (2026-06-16)
Features
Bug Fixes
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]