v0.2.4: Trusted Remote Settings
v0.2.4 completes the trusted remote management path introduced in v0.2.3 and fixes the empty Settings → Memory System page.
Fixed
- A writable settings snapshot from the Host is now the browser's authoritative management capability. A remote connection is no longer treated as read-only merely because it is not loopback.
- Provider service settings and Mnemon Pack controls use the same Host-authorized management channels.
- When both settings namespaces are unavailable, the settings page shows an actionable authorization diagnostic instead of rendering nothing.
Security boundary
remoteAccessremainsread-onlyby default and cannot be changed through Web settings.- Explicit
remoteAccess: trusted-hostpromotes/dsh-mnemon-write,/dsh-mnemon-settings, and/dsh-mnemon-packtogether at Host startup. - The deployment must also authenticate the remote page, configure the DSH Connection
trustedHostsallowlist, remain same-origin, and restart the Host. Do not enable remote management on an unauthenticated public endpoint.
Upgrading
Update dsh-mnemon and restart the affected DSH profile. This patch does not migrate, rewrite, or delete Runtime Memory, Project Documents, Memory Spaces, Provider data, or saved credentials.
See the v0.2.2 release notes for the previous published patch release.