Make the Hermes dashboard the standard connection path with API fallback and optional Relay pairing. Redesign onboarding and connection management, add startup preference and route/security details, reconcile pinned profile identity and hostname discovery, and update tests, docs, and localized resources.
- "No reachable endpoint" subsection: what the diagnostic means and how to
check each saved route from the phone (LAN vs Tailscale, port 8642).
- Callout: never use localhost/127.0.0.1 as the server address on a phone.
- Tailscale checklist, including that the relay Tailscale helper serves
the relay + API ports but not the dashboard :9119 (Manage needs it
reachable separately).
- "Long turns with local models" entry: mid-turn stream drops recover the
finished answer automatically; screen-on/plugged-in reduces drops.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Implements the spec in docs/plans/2026-06-24-connection-security-indicator.md
(decisions: Tailscale=green, ship all surfaces, "Encrypted · <mechanism>").
Single source of truth: data/ConnectionSecurity.kt computes a per-surface +
rollup verdict (TLS / Overlay / Mixed / Plain) from the active route's
schemes; ConnectionViewModel exposes it as a StateFlow. Overlay transports
(Tailscale/WireGuard/plugin proxy) count as encrypted, not just TLS — so a
ws:// route over a tailnet reads "Encrypted · Tailscale" (green), fixing the
old badge's hardcoded "Secure — TLS" lie.
Surfaces (all read the one flow):
- Chat status chip: leading security glyph (RelayStatusStrip slot).
- Connection card: full-width badge promoted out of the Advanced fold.
- Route picker: per-route glyph on each candidate.
- New ConnectionSecuritySheet: tap any badge for the per-transport
breakdown + mechanism explainer + docs link.
Removed the duplicated, buried security computation from
ActiveConnectionSections (now delegates to the shared model).
Docs: new user-docs "Is my connection secure?" page; fixes the
Tailscale=TLS conflation in decisions.md / security.md / remote-access.md;
first user-facing mention of TOFU cert pinning.
Verified: ./gradlew :app:testSideloadDebugUnitTest (ConnectionSecurityTest
7/7) + :app:lintSideloadDebug both green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The repo is public and distributed; several files leaked real server
identifiers. Replace them with generic placeholders across docs, scripts,
source, and test fixtures:
- real LAN IP 172.16.24.250 -> 192.168.1.100 (blessed example)
- real Tailscale IP 100.71.8.56 -> 100.64.0.1
- real hostname docker-server / tail6f460 tailnet -> hermes-host(.tailnet.ts.net)
- ssh user@host targets -> you@hermes-host
- server home path /home/bailey/ -> $HOME/
- custom voice id -> <your-voice-id>
Test fixtures changed on both input and assertion sides so suites stay
green (plugin.tests.test_pairing_mint_schema + test_voice_routes pass;
Kotlin URL-deriver/normalization fixtures consistent). No behavior change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
"Standard" was overloaded — it read as both an app feature tier and the
unmodified-upstream server state, which was confusing. Rename all
user-visible strings, docs, onboarding copy, and the matching test
assertions to "Vanilla Hermes" so the no-plugin path reads unambiguously.
Code identifiers, enum constants, and the persisted "standard" route value
are unchanged — that is an internal name only.
Also lands this session's architecture work:
- docs/path-architecture.html — connection-path + chat-transport
resolution flowchart, plus the build-flavor (googlePlay/sideload)
capability axis.
- user-docs CombineModel "how the pieces combine" three-tier model and
the release-tracks/index wording that makes the plugin-vs-flavor
prerequisites explicit.
- Aligns docs/security.md, upstream-surface-matrix.md, and spec.md on the
device-control 403 codes (device_control_sideload_only / sideload_only).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
README: feature-banner hero + screenshot gallery, Google Play marked live, lean renamed CLI section; drop the stale embedded demo video (GitHub CSP won't render external/Pages video) in favor of a link to the docs demo.
user-docs (getting-started, quick-start): defer first-time server setup to upstream Hermes docs, annotate the API/dashboard config, frame the API key as a user-chosen value, add 0.0.0.0 security notes, document the LAN-scan / manual / agent-generated-QR connect paths, and add non-technical skip-path + 'dashboard is optional' signposts.
Remove orphaned assets/chat_demo.mp4 + poster; the user-docs/public copies the docs site serves are kept.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- getting-started.md: replace the flat wall of setup commands with a
three-step funnel (install -> point at Hermes -> connect). The
Get-it-on-Google-Play badge is the primary install action; all server
setup, sideload install + SHA256/cert verification, dashboard auth, and
build-from-source detail is preserved behind collapsible details blocks
and OS code-group tabs so new users aren't scared off.
- Add a self-hosted Google Play badge SVG and a reusable <StoreBadge>
component (registered globally), also slotted into the home hero.
- HeroDemo: rebuild the phone-mockup input bar to the redesigned chatbar
(no slash button, one morphing Send/Voice/Stop trailing slot, GraphicEq
waveform voice glyph).
- chat.md: document the new input bar, steering, edit-and-resend, the
context meter, subagent lanes, interactive ask cards, turn-complete
notifications, and the gateway mobile-preamble behavior.
- Normalize "Hermes Relay" -> "Hermes-Relay" in phone-control-tools/voice.
- CHANGELOG + DEVLOG entries.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Rechrome VitePress theme to the RelayRefresh cockpit palette: navy-black
base, warm-white ink + alpha hairlines, electric-indigo accent, grid/dot
home texture, warm-paper light mode; swept hardcoded old-palette colors
from HermesFlow/HermesFlowNode/HeroDemo/ExperimentalBadge/FeatureMatrix
- Reposition marketing: hero "Runs on your machine. Lives on your devices.",
quick-path-first funnel ("Just connect" no-server-install card above the
"Give it hands" relay-plugin power path), SurfaceCards + HowItWorks
components slotted into the home layout, benefit-led feature cards
- Rename "Desktop CLI" -> "CLI" across copy (binary is host-agnostic; path/
track rename deferred to code refactor); Windows-today / macOS-Linux-soon
status on every availability claim incl. hero subtext; drop "self-hosted"
qualifier in favor of plain "Hermes agent"
- desktop/index.md re-led with the remote-hands story; tray/chat copy
rescoped (chat & management belong to hermes-desktop); modes table
reordered Tools/Daemon first
- Sidebar: add voice, voice-intents, phone-control-tools, relay-server,
flavor-differences (existing pages previously unreachable); bump stale
version pins (app 0.8.1, desktop alpha.18)
- SphereMark: fix gaze drift/snap by pinning lightAngleBlend to exactly 1
(partial blends leak the unbounded natural light angle), ambient life
moved into proximity-eased fbm wander, mouse-only pointer tracking,
occlusion halo over the home dot grid, larger + tighter mobile sizing
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>