Changelog
Safer sharing and a round of fixes
Aktar 0.12.1 is a maintenance release from a review of the whole app. It tightens what leaves your Mac, closes a few ways a web page or a crafted file could get Aktar to do something you didn't ask for, and fixes a set of smaller bugs. If you're on 0.3.0 or later, Aktar offers it automatically.
- Mac0.12.1
- Windowscoming soon
- iPhone & iPadcoming soon
- Androidcoming soon
Location removed from more files
Remove location and Remove all now also cover WebP, AVIF and GIF images, a PNG's text chunks (under Remove all), and .mov, .mp4 and .m4v videos. Videos are copied without re-encoding, just without their location (or all metadata), so it's quick and the picture is untouched. This applies inside folder ZIPs too, and a file that can't be cleaned isn't uploaded.
Links that can't be turned against you
HTML, SVG, XML and JavaScript files are uploaded so that opening their link downloads them instead of running them on your bucket's domain. An SVG in an <img> tag still shows. aktar://upload-clipboard and aktar://watch/pause links now ask first, since any web page can open them. Transfer links from Share to Another Device expire after an hour, and closing the window takes the copied link off the clipboard.
All changes in this release
Improved
- Remove location and Remove all cover WebP, AVIF and GIF images, PNG text chunks and .mov, .mp4 and .m4v videos, inside folder ZIPs too. A file that can't be cleaned isn't uploaded.
- HTML, SVG, XML and JavaScript uploads download when their link is opened instead of running on your bucket's domain.
aktar://upload-clipboardandaktar://watch/pauselinks ask before they act.- Transfer links expire after an hour. The transfer link and the local API token are hidden from clipboard managers, and closing the transfer window clears the copied link.
- Watched folder webhooks use https:// (plain http:// only for this Mac or the local network) and don't follow redirects to another host.
- HTML and Markdown output escape the file name, so a crafted name can't add markup to what you paste.
- Images over 100 megapixels are uploaded as they are instead of being converted, previewed or given a thumbnail, so a small file claiming huge dimensions can't use up all memory.
- Storage requests that carry no file data give up after 60 seconds instead of possibly waiting forever.
Fixed
- Reuse links for duplicate files no longer hands out a link that now serves a different file.
- A path without
{uuid},{random},{md5}or{sha256}no longer replaces a file that already has that name: the new one is numbered ("name 2.png"). - Deleting an older history entry whose name was uploaded again later no longer deletes the newer file.
- A large upload picked up where it stopped no longer keeps its old name after you rename the file or change the path.
- A Public Base URL that isn't a valid web address no longer crashes Aktar; Settings says what's wrong.
- An
aktar://watch/pauselink with a huge number of minutes no longer crashes Aktar. Pauses are capped at one year. - The bucket view in the Library shows new uploads and stays filled after a destination's settings change.
- Copying a web link no longer makes the clipboard upload shortcut try to upload the link as a file.
- Two images copied within the same second no longer overwrite each other, and Aktar's temporary files are cleaned up.
- Expiring uploads are only deleted by Aktar while the bucket still has its auto-delete rules.
- Text, code, Markdown and PDF previews skip files over 25 MB instead of downloading them whole.