v0.5.5: Remote RPC Routing and Light Media
v0.5.5 fixes authenticated remote WebUI calls that could receive HTTP 403 and refreshes the documentation's memory-space screenshots and recordings. It includes PR #197 and PR #196.
Remote pages use the authenticated Gateway
Remote browser calls for status, Source catalogs, settings, Views, activation and management now use DSH's namespaced API Gateway. Local loopback clients retain the existing RPC channels. Detection also handles remote-desktop connections whose isLoopback flag describes Host ownership while the page has a remote origin.
DSH continues to own Host/Origin checks and browser authentication or pairing. Mnemon separately requires the startup configuration remoteAccess: trusted-host for Gateway writes, ZIP operations, View mutations and settings mutations. Without that grant, settings remain readable but report writable: false; ordinary reads and narrow activation remain available. Existing writeEnabled restrictions still apply. See remote deployment and configuration.
The new Gateway projection uses the published Typert protocol peer contract. It reuses existing handlers, preserves cancellation and validates returned RPC envelopes; it does not change Provider contracts or storage formats.
Light screenshots and recordings
The bilingual Light gallery contains 60 original JPEGs and two continuous demonstrations of about 42 seconds each. A Mnemon Pack was safely imported into disposable storage before capture. It covers memory spaces, recall, entities, the graph, dialogs, npm CLI guidance, expandable subpackages, settings, backup preview and narrow layouts.
The packaged READMEs and current guides use this gallery. Its screenshots honestly retain their v0.5.4 capture version; they do not claim to show the v0.5.5 remote transport fix. All 142 historical media files keep their original hashes. The source ZIP, databases, credentials and raw logs are not distributed.
Packages and upgrade
Only dsh-mnemon advances to 0.5.5. All sixteen official plugins remain at 0.5.4, pinned exactly by the Starter; unchanged plugin packages are not republished.
dsh plugin --profile web add dsh-mnemon@0.5.5Restart DSH and reload the browser so the new Client and Host routing are both active. Use headless instead of web for that Profile. Mnemon CLI remains separately installed and maintained through @mnemon-dev/mnemon on npm.
No memory-data migration is required. Existing IDs, Provider connections, configuration formats and stored data remain compatible. Remote management needs the explicit grant described above, even though earlier 0.1.2 Host guidance treated remoteAccess only as a rollback option. Rollback installs dsh-mnemon@0.5.4 in the same Profile and restarts DSH; the sixteen pinned plugin versions already match.
Verification and limits
The merged RPC fix passed local, paired-remote, denied-management and trusted-management tests. Its redacted live paired-HTTPS smoke test reported successful status, Source catalog and settings requests through the Gateway; see #197 for the exact environment. The media audit checked all 60 screenshots and all 333 source video frames with zero legacy-label OCR matches, and decoded both MP4s successfully.
Release gates cover the versioned workspace, independent plugin artifacts, the complete mixed-version Starter installation, frozen artifact integrity, npm read-back and an upgrade from v0.4.7. Tests of transport and UI mechanics do not establish model quality or live cloud-Provider behavior. Documented narrow-layout and Host-settings limits remain in scope as described in the gallery.
Previous release: v0.5.4.