Patch shipped: v1.6.709 — Sharing an AI answer no longer publishes anything you pasted into the chat, and reset-password really lets you back in
Posted by Chris
These SparkBox updates are now available: v1.6.709 — Sharing an AI answer no longer publishes anything you pasted into the chat, and reset-password really lets you back in - Share to demox no longer publishes secrets. If you pasted an .env excerpt, a licence key, a Plex claim token, an API key or a password into the chat while asking your question, the pre-filled public post carried it word for word into the forum, the address bar and your browser history. Both your question and the AI reply are now filtered before the post is prepared, and each removed value is labelled so you can see which credential it was. If you shared a chat before this update, treat anything you pasted into it as public and rotate it. - sparkbox reset-password now really gets you back in. On a box updated from an older version the reset could report success and the new password be accepted, and the dashboard would still bounce you straight back to the login form, because the folder it keeps your session in was left owned by root and it could not write a session file. Resetting the password now repairs that folder before it restarts the dashboard. - The built-in assistant now gives the right details for connecting Sonarr, Radarr or Prowlarr to SABnzbd by hand. It used to leave people chasing DNS and Docker networks after "Unable to connect to SABnzbd"; it now tells you the host and port those apps actually need (localhost, port 8081) and warns that 8186 is the browser port only. Update from the SparkBox dashboard, or run sudo sparkbox upgrade on your SparkBox host. If a problem remains after updating, submit a private support ticket or reply here. Include your SparkBox version and what you see; leave passwords and licence keys out.