Back to list

News

Tactic Remote v1.5 Beta: Security Hardening and Multi-Server Architecture

Tactic Remote v1.5 focuses on making the server safer and giving you more ways to work with sessions — including connecting to multiple servers at once.

Published Tags: Launch news / security / announcement
News

Follow product and engineering updates from this channel.

Browse category

Hi there! Here's what's new in v1.5 — thanks for helping us test!

New Features

Multi-Server Support — You can now connect to multiple servers at the same time, each running independently with its own state. This is great for developers who work across different machines or want to keep projects separate. Each connection maintains its own isolated session state, so there's no cross-talk between servers.

Session History Auto-Save — No more losing terminal output! Sessions are now saved automatically when you disconnect, switch sessions, or put the app in the background. A 30-second debounce auto-save also kicks in during normal use, with smart deduplication so it won't thrash your disk. The history UI supports pull-to-refresh, shows which session is currently active with a green "Active" badge, and keeps relative timestamps fresh automatically.

Voice Dictation (Whisper) — On-device speech recognition is here! Pick a Whisper model and it preloads immediately so there's no delay when you start recording. The recording interface uses the app's theme orange for a clean, consistent look.

Security Improvements

This release significantly hardens the server across all platforms:

  • Path traversal protection: A new isPathWithinBase() check replaces the previous startsWith approach. This properly handles symbolic links and path normalization edge cases that could previously be exploited to escape the allowed directory.
  • Sensitive directory blocklist expanded: 1Password vaults and Linux keyring directories are now blocked on all platforms, in addition to the existing protections for .ssh, .gnupg, and system keychains.
  • Command execution safety: execSafe now enforces a 30-second timeout by default and a 2 MB buffer limit per output stream. Runaway processes can no longer consume unbounded memory or hang indefinitely.
  • Rate limiting and auth middleware: Server-side request throttling and authentication middleware added across Mac, Linux, and Windows servers.

Performance

  • ANSI parser results are cached, so unchanged terminal content doesn't get re-parsed on every render.
  • Terminal buffer updates are deduplicated with lazy line counting, reducing unnecessary re-renders during high-output sessions.
  • WebSocket broadcast is now backpressure-aware — it only sends to active subscribers and respects per-connection buffer limits.

iOS Polish

  • The Settings view is simpler — the redundant Connection tab has been removed since connection management lives in the server list now.
  • Fixed several retain cycles ([weak self] in Task closures) that could cause memory leaks during long sessions.
  • Recording state indicator matches the app's theme orange.

Testing and CI

We've added Jest test suites covering path safety validation and WebSocket handler behavior for all three server platforms (Mac, Linux, Windows), along with a GitHub Actions CI workflow for automated testing on every push.


To update, download the latest DMG from our Download page. Please report any issues you run into. Happy testing!

Try Tactic Remote

Control your coding Agents from your phone

Connect to Claude Code, Codex, and other Agents on your Mac, Windows, or Linux computer. Check progress and send the next instruction from iPhone or iPad.