Changelog
- 2026-09-091.24.19 — Correct AL2023 firewall proof paths
MojoSec now matches the firewall command paths used by the broker to the fixed executables AL2023 records in Audit, so proven cron-owned reconciliations stay local. Exact argv, digest, PID, receipt, and JobEngine checks remain required.
- 2026-09-091.24.18 — Quiet cron-owned firewall readiness
The root firewall broker now proves read-only readiness checks so MojoSec keeps exact cron-owned probes local. Failed or unproven calls still remain central; there are no migrations, configuration changes, or API changes.
- 2026-09-091.24.17 — Reliable firewall proof under reconcile bursts
MojoSec now keeps legitimate cron-owned firewall reconciliations locally classified even when a full reconcile produces a large burst of process and receipt evidence. It also follows the newest audit-health observation after deployment sequence resets. No migrations, configuration changes, or consum…
- 2026-09-091.24.16 — Unambiguous cron Jobman startup
Cron now invokes the installed Jobman module through a stable bash → Jobman → engine process chain. MojoSec can prove scheduled firewall work after deployments without treating the legitimate wrapper re-exec sequence as unexplained privileged activity. No migrations or configuration changes are requ…
- 2026-09-091.24.15 — Reliable cron-owned job restarts
API deploys now verify the real Jobman cron path, retire old job processes safely, and let cron start fresh replacements with provable lineage.
- 2026-09-091.24.14 — Canonical firewall broker lineage
Firewall broker launches now produce one canonical Audit exec generation so MojoSec can prove expected reconciliation work without weakening its fail-open checks.
- 2026-09-091.24.13 — Resilient MojoSec identity helper
MojoSec keeps its least-privilege process-identity resolver available when an individual client request times out, disconnects, or fails.
- 2026-09-091.24.12 — Reliable least-privilege identity helper startup
django-mojo 1.24.12 fixes MojoSec’s unprivileged identity helper startup on systemd: the helper can now read the live Yama safety setting while still hiding other users’ processes, keeping kernel tunables read-only, and retaining zero capabilities and no network. No migrations or consumer code chang…
- 2026-09-091.24.11 — Deployment-complete MojoSec identity proof
django-mojo 1.24.11 makes ordinary enrolled deployments fully converge MojoSec from the activated framework before firewall work, so newly shipped identity-helper assets actually reach hosts. It also persists a protected Yama ptrace policy without weakening stricter host settings. No migrations or c…
- 2026-09-091.24.10 — Least-privilege JobEngine identity proof
django-mojo 1.24.10 lets MojoSec prove a live JobEngine’s executable identity across the application/root UID boundary without granting process-tracing authority to the network-capable sensor. Proven firewall broker work can therefore remain local-only instead of flooding the central security stream…
- 2026-09-081.24.2 — Safe Markdown rendering and resilient address validation
django-mojo 1.24.2 raises Mistune to 3.3.3 to prevent recursive-emphasis Markdown inputs from exhausting Python recursion, and restores USPS-preferred address validation by falling back once to Google whenever USPS is unavailable or unsuccessful. No consumer action is required.
- 2026-09-081.24.1 — Chat online-members read gated like message history
django-mojo 1.24.1 closes an information disclosure in chat: the online-members endpoint answered any signed-in user for any room, private groupless rooms included, so who was online in a DM could be listed by trying room ids. It now applies the same gate as message history. No consumer action is ne…
- 2026-09-061.24.0 — Safe registration attribution across Bouncer
django-mojo 1.24.0 preserves schema-declared registration attribution through Bouncer and login/register navigation while keeping credentials, navigation controls, undeclared parameters, and non-registration destinations excluded. It also applies one bounded value policy to hosted forwarding and reg…
- 2026-09-051.23.0 — API-first Admin Security and verified fleet firewall state
django-mojo 1.23.0 adds a dedicated Admin Security workspace and exact-host firewall verification without breaking established REST administration. Authorized users and validated per-user API keys retain their existing global permissions, group credentials get exact-group read access, legacy rules k…
- 2026-09-031.22.0 — Fail-closed LLM safety and capture-only registration fields
django-mojo 1.22.0 adds a fail-closed, policy-driven LLM safety boundary with durable incident recovery, and adds capture-only, accessible hosted registration fields. LLM-enabled deployments must configure and activate the safety policy before upgrading.
- 2026-08-311.21.2 — Chat hardening and cards, truthful SMS auth failures, non-root job engine
django-mojo 1.21.2 hardens chat (join-time history cutoff on every non-channel room kind, banned members locked out of read state, a cross-tenant message-id oracle closed, idempotent sends and reactions) and adds the card message kind with a server-side send service; makes every SMS-sending auth end…
- 2026-08-281.21.1 — Working job requeue, honest SMS failures, test messaging isolation
django-mojo 1.21.1 repairs the operator recovery for stranded background jobs — it previously published where no worker looks and reported success — makes phone-verification send failures honest (retryable when the provider is unavailable, explicit when the number cannot receive texts, no more raw s…
- 2026-08-281.21.0 — Confirmation pages, honest email sends, and commit-safe job publishing
django-mojo 1.21.0 makes emailed account links safe to open — verification, email-change and deactivation links now land on a confirmation page and change nothing until the person presses the button — makes email endpoints report send failures honestly instead of claiming success, publishes backgrou…
- 2026-08-261.20.1 — Reliable last-login state after JWT authentication
django-mojo 1.20.1 makes successful JWT authentication persist the user’s last-login timestamp reliably, while failed token minting no longer records login-success state.
- 2026-08-261.20.0 — Unlimited-by-default ApiKeys with bounded abuse monitoring
django-mojo 1.20.0 lets ordinary ApiKey traffic fan out without inheriting consumer rate limits, while preserving explicit and strict hard ceilings and adding bounded per-key threshold and concentration signals for operator review.