Release notes — Version 2.0
What changed in each version 2.0 release, newest first, as published with the release.
v2.0.11
Released 2026-09-12
- Eight more glossy themes, in the same style as Glass: Frost (light), Onyx (dark), Ruby, Amber, Citrine, Jade, Amethyst and Rose.
- That makes 19 themes in total - 4 light and 15 dark, 9 of them glossy.
- Glass itself is unchanged.
- The theme menu is now sorted: light themes first, then dark, then the glossy family together, running through the colour wheel from red to pink.
- The theme menu scrolls now - with 19 entries the list was taller than a 768px screen, and the last themes could not be picked at all.
- Every new theme label is translated into all ten languages.
- Contrast for all new themes was calculated, including the worst corner of the gloss gradient - which sits at the light end on dark themes and at the dark end on light ones.
v2.0.10
Released 2026-09-12
- Theme 'Teal' is now dark - its surface was almost white before, so it barely differed from the light theme.
- Four new themes: Glass (dark, glossy), Plum (dark violet), Sand (light, warm) and Mint (light, cool).
- Glass has a real gloss: a gradient and a highlight edge on every card and popover, without any animation.
- Two of the four new themes are light on purpose - otherwise only one light theme would have been left.
- Every theme label is translated into all ten languages.
- The logo in the sidebar is twice as large (36 -> 72 px); the sidebar header grew from 48 to 96 px and now has its own surface.
- The collapsed sidebar shows the brand initial as a badge instead of an empty header.
- The top bar keeps its height, so no page loses vertical space.
- New: the robot from the login page can now also appear in the signed-in interface, bottom right.
- The robot is OFF by default and is switched on per browser in the theme menu.
- The robot is not loaded at all on narrow screens, and it stops rendering while the tab is hidden.
- Fixed: the ten robot phrases were never translated in the browser - they showed their internal key name in every language.
v2.0.9
Released 2026-09-12
- Dashboard refresh has a new "Live" step driven by socket.io; the expensive metrics deliberately stay at 10 seconds or slower.
- Themes "red" and "blue" are now real dark themes with their own background, built the same way as navy and graphite.
- DID bulk management can create the target number pool on the spot ("POOL +") using the full pool wizard - name, comment, CallerID selection, reputation and provider validity.
- Numbers, money, percentages and durations now follow the user's language instead of always using en-US. The external XML/API output is deliberately unchanged.
- Fixed: duration formatting depended on Intl.DurationFormat, which Node 20 does not provide - durations were English in every language.
- Added the missing interface translations for all nine non-English languages.
- Fixed: the recording permissions page printed the truncated row count as the customer total.
- The background worker now starts through a .mjs entry point, which removes a ts-node warning in the error log on PM2 7.0.4 and newer.
- New acceptance probes for theme integrity and for dashboard refresh behaviour.
v2.0.8
Released 2026-09-11
- Background service memory leak fixed: the call-state maps kept the whole AMI read buffer alive per entry (V8 sliced strings) and held entries for 24 h. Keys are now copied and entries are swept 10 minutes after hangup (measured 9,581 -> 175 bytes per entry).
- Auto-PCAP is now per device and off by default (device page, Debug; needs callinfo.view). The queue is capped at 500 jobs and skips jobs older than 30 minutes, with a log line. The .env switch VOIPLIX_AUTO_PCAP is no longer used.
- PM2 starts the background worker directly (node --import tsx) with max_memory_restart 1500M, so PM2 measures and restarts the real process instead of the tsx launcher.
- Alerts and automatic exports aggregate in the database instead of loading every call (same numbers). CDR exports load only the template columns; a capped file is named _partial.
- Calls that end in a voicemail get the hangup cause 901 Went to voicemail on every path (DID, internal, call flow). DID calls to a voicemail dial plan now appear in the call list.
- New voicemail boxes get a default greeting (unavailable + busy); existing boxes without one get it once. An existing greeting is never overwritten.
- Per-device Skip intro message: the beep follows the greeting directly.
- voicemail.conf: minsecs=1 instead of 2; silence detection aligned with the installer on every system.
- Security updates run only at night (download 01:00, install 02:00, no catch-up after a reboot) and needrestart never restarts Asterisk automatically.
- voiplix-doctor runs every 5 minutes as a watcher (journal only, repairs built but off) with corrected checks. voiplix-service refuses an Asterisk restart when the channel count is unknown.
- After updating, run the root setup step once from the installed tree: scripts/installer/setup_asterisk_pjsip.sh
v2.0.7
Released 2026-09-10
- End customers can no longer delete recordings in the portal - the capability was revoked for the user and guest roles.
- The portal recordings list now shows the call duration.
- Both recordings lists (operator and portal) now have page numbers instead of a hard 200 row limit.
- The recordings permission list no longer lists the operator account itself.
- Fixed: Hide all on the operator row could rewrite the visibility flag of every recording in the database.
- The capability parity guard now understands revocations, not only additions.
v2.0.6
Released 2026-09-09
- Devices can now set up their own mailbox from the customer portal: change the *97 PIN and manage the greetings.
- A new per-device switch "Mailbox setup" controls this. It is off for every existing device and only takes effect together with the Voicemail switch.
- Deleting voicemail messages stays with the operator and the account owner - a device may configure its mailbox, never erase it.
- The operator PIN field is now checked by the same rule as the self-service one (digits only, 4 to 10) instead of failing with a database error.
- A PIN containing a comma or semicolon is rejected instead of being silently changed on the phone system.
- The device API no longer returns the portal password hash or the last login IP address.
- Missing translations for the PIN and mailbox messages added in all ten languages.
v2.0.5
Released 2026-09-09
- Sidebar now shows only what the login can actually open.
- Invoices, payments and system metrics have their own view permissions.
- Dashboard refresh interval belongs to the system login instead of its anchor account.
- Devices can no longer change operator settings of sibling devices.
- Eight rejected pages now say so instead of silently returning to the overview.
- Update page and aggregate templates are reachable from the menu.
v2.0.4
Released 2026-09-08
- Nine more areas can now be switched on and off per staff account, instead of being tied to the account type. Until now the pages for e-mail templates, scheduled cron actions, the API settings, call tracing, bulk device creation, assigning a provider to a customer, the holiday calendar, the DID quick-forwards overview and the default-user template were open to whole account types and could not be taken away. Fourteen new permissions were added for this; every one of them starts out with exactly the account types that could reach the area before, so nothing changes until you clear a tick box yourself.
- Security: a staff account that was only meant to look at calls could reach the call-tracing page - and with it the buttons for listening in on, whispering into and barging into live conversations. That page was reachable with the general 'view calls' permission, and the page itself only asked for the account type, which a staff account inherits from the operator account. It now needs its own 'call tracing' permission. If one of your staff accounts is supposed to keep this page, tick the new box for it after the update.
- Thirteen pages were still deciding access by account type although the actions behind them had already been moved to the permission system two versions ago: the pages for directions, destinations and destination groups. Page and action could therefore disagree. They now both ask the same permission.
- The download of a network recording (PCAP) for a single call now really checks the 'call detail' permission. Before, it read the account type out of the login token, which meant clearing that tick box had no effect on the download.
- Logging in as another user is now a permission of its own ('log in as'), held by the same account types as before.
- For the operator nothing changes after the update unless a tick box is cleared. Ordinary customers, resellers, partners and accountants keep exactly the access they had.
v2.0.3.1
Released 2026-09-08
- Live displays no longer depend on the clock of the computer you are looking at. If your PC clock was ten seconds fast, active calls appeared ten seconds longer than they were. The server now sends the duration as a number, and the browser only adds the time that has passed since it received it - so an incorrect clock cancels out.
- The same fix applies to the call duration on the dashboard widget and to the sort order on the active calls page, which was based on the same wrong figure.
- The CPS and peak tiles no longer go blank because of a wrong clock. A clock more than 15 seconds off used to hide all three tiles, including the two stored daily peaks that were perfectly correct. The protection against a stalled data feed is unchanged: if the update stops arriving, the tiles still fall silent.
- The caller-ID pool countdown ("next switch") is no longer thrown off by the viewer's clock. Previously, a clock offset larger than the switch interval left the "overdue" marker permanently wrong.
- This release changes displays only. Billing was never affected: call durations are measured on the server from the telephony events, so an incorrect clock on a PC has never cost or saved anyone a cent.
v2.0.3
Released 2026-09-08
- A system login with no permissions could sign in and then open nothing at all - every page ended in a redirect loop (ERR_TOO_MANY_REDIRECTS). A newly created login is exactly that by default, because no permission is ticked yet. It now lands on a page that says it has no access, and offers a way back and a way out.
- Refusals are no longer silent. Until now, clicking a menu entry you were not allowed to open dropped you back on the dashboard without a word, which reads as "the page is missing". 64 such places now explain themselves.
- A system login anchored to an end-customer account ran into a second redirect loop. Customer accounts are no longer offered as an anchor, and the loop is closed in the code as well, so existing logins cannot hit it either.
- The route guard and the pages themselves demanded different permissions in 14 places. They now agree. Two of those were locking people out rather than letting them in - a read-only view of the PBX pools could not open the page at all.
- The dashboard greeted a system login with the name of the account it borrows its view from, while the header two centimetres away showed the correct name. It now uses the name of whoever is signed in.
- The action log shows who acted: the system login or the device, not just the account. Entries whose login has since been deleted are marked as such instead of appearing blank.
- A system login can change its own password. The setting "may change own password" existed since v2.0.0 but there was no page behind it, so it never did anything.
- Caller-ID pool rotation is now race-free. Under simultaneous calls a single switch was booked many times over, and the usage counters drifted upwards accordingly. Measured on the old code: ten concurrent calls booked ten switches instead of one.
- The pool usage counter now counts when a pool is put into service, not when it is left. Until now the pool actually in use always displayed "0 uses today".
- Number usage counters no longer lose updates under load. Measured on the old code: 16 of 20 simultaneous draws went missing.
- The device portal has paging and a filter for date and number. It showed the last 100 calls with no way to search and no way to go further back.
- The portal heading now says these are outgoing calls, because that is all it has ever been able to show. The same was true for the end-customer view, without saying so.
- The pool pages used the word "counter" for three different quantities. Each now has its own wording, and the explanation matches what the number actually does.
- fail2ban: an operator IP entered by hand into the jail configuration file has no effect, because the generated whitelist replaces that value rather than adding to it. Such entries are now reported in the log instead of being lost in silence. Trusted addresses belong in the GUI whitelist under Monitoring - that is the only place that survives a repair run.
v2.0.2
Released 2026-09-07
- Devices can now sign in to the customer portal themselves. Five switches per device decide what the phone sees: portal login, recordings, voicemail, calls and DIDs. All are off for every existing device, so nothing changes until you turn them on.
- The portal password is a separate password, set by hand under Devices. It is deliberately NOT the SIP secret: that one stands in clear text in the Asterisk configuration file, and on IP-authenticated peers it is empty, so a login built on it would be both unsafe and impossible.
- New page "My voicemail" in the customer portal. The message list existed only in the operator area until now and no link led to it, so end customers could not reach their own messages at all.
- A signed-in device sees only its own calls, DIDs, recordings and mailbox - not those of the other extensions on the same account, and never the account balance, invoices, payments or the owner's address.
- A device gets its own small set of rights instead of inheriting the account's. Inheriting would have let a phone delete its owner's recordings and send SMS on the owner's bill, because the customer role carries those rights.
- The login page had no rate limit at all - every account could be guessed at without any delay. It now allows 10 failed attempts per user name and 60 per address in 15 minutes; a successful login clears the counter.
- The rate limit on the WebRTC device check could be switched off by the caller, because it trusted a header the client controls. It now uses the address the web server itself records.
- A provider trunk that had been assigned to a user could pass the WebRTC device check, which hands out the upstream carrier's password. Trunks are now excluded.
- Signing out wrote a log entry that did not say who signed out - a system user's logout looked exactly like the logout of the customer whose view it borrows. The action log now also records which device acted.
- Two dashboard endpoints answered without going through the page guard and would have handed a signed-in phone the account-wide call statistics of its owner.
- Faster: the calls and recordings tables are now indexed on the device column, which the new portal pages filter on.
v2.0.1
Released 2026-09-07
- System users can finally be limited area by area. Until now 111 built-in administrator checks never asked the capability catalogue, so unchecking a section had no effect for backups, servers, licence, updates, callback, global routing and the update API. They now ask it.
- Closed a privilege escalation: a system user whose anchor account is the administrator passed every protective check in user management, no matter which boxes were ticked. Holding "manage users" was enough to block, rename or delete the operator account itself. User management now asks four separate administrator-only rights.
- Closed a data leak in the invoice bulk actions: hide-all, unhide-all and queue-for-e-mail ignored the per-user restriction of a system user and acted on every invoice of the tenant. The e-mail queue is sent by the hourly cron, so this could not be recalled afterwards.
- Four pages were reachable through a capability that was too broad: the callback settings, the global cause rules, the LCR cloning between resellers and the quick-forward defaults could be opened by an account that only held PBX or routing rights. They now require the operator-wide rights they belong to.
- New rights, all granted to the administrator only, so nothing changes for existing roles: convert tariff, weak-password list, raw PJSIP block, purge live calls, and four for user management (edit any, delete any, manage staff accounts, grant administrator).
v2.0.0
Released 2026-09-06
- System users: a separate kind of account for your own staff and for customer requests. You pick exactly which areas the account may reach and which users it may see - it is not a row in the customer list, uses no licence seat, and customers can neither see nor manage it.
- Permissions are now split into separate verbs where it matters: recordings view / download / delete, DIDs view / assign, plus new areas for invoices, payments, devices and users. Every new verb is checked in the code, not just listed in the form.
- Leaving the user selection empty means the account sees all users; ticking users restricts it to exactly those - in lists, in detail views and in downloads alike.
- The action log now tells a system user apart from a customer with the same id, which it could not do before.
- Anything not ticked stays closed for a system user, including pages that are still tied to the built-in admin check.
- Known limitation: backups, servers, licence and settings cannot yet be granted individually - they stay closed for system users until version 2.0.1.
- Two long-standing type errors in the background service are fixed, so its type check is now clean.