What's New

Release notes for every version, newest first.

v1.8.4

GitHub Release ↗ Latest

New: built-in read-only MCP server for AI clients.

  • Read-only MCP (Model Context Protocol) server — Claude Code, Cursor and other AI clients can read Schwab account data, positions, orders, quotes, option chains and rebalance suggestions over HTTP (Streamable HTTP at /mcp). There is no tool that places, changes or cancels an order, and calculate_rebalance only computes suggestions.
  • Off by default — Mcp:Enabled is false; the endpoint is not mapped (404) and no token is generated unless the user enables it.
  • Bearer-token authentication — a random 32-byte token is generated on first enable and stored at {dataRoot}/config/mcp-token.txt (owner-only on macOS/Linux); requests must present Authorization: Bearer <token>. Comparison is constant-time and the token is never logged.
  • Origin / Host hardening — non-local Origin or Host headers are rejected (403) to block DNS rebinding and malicious web pages.
  • 10 tools: get_account, get_balances, get_positions, get_orders, get_order, get_quote, get_quotes, get_price_history, get_option_chain, calculate_rebalance. Every tool and parameter has a runtime description for the AI client, and list results are size-capped.
  • Release-build safe — MCP responses are built from named fields, not anonymous types, which Obfuscar would otherwise break (HTTP 500). MCP types are excluded from obfuscation so tool names stay readable. Verified against the obfuscated release build.
  • Privacy note — everything a tool returns is sent to the AI service your client uses.

新增:内置只读 MCP 服务,供 AI 客户端使用。

  • 只读 MCP(Model Context Protocol)服务 —— Claude Code、Cursor 等 AI 客户端可通过 HTTP (Streamable HTTP,端点 /mcp)读取 Schwab 账户、持仓、订单、报价、期权链与再平衡建议。 不存在任何下单、改单或撤单的工具,calculate_rebalance 仅计算建议。
  • 默认关闭 —— Mcp:Enabled 为 false;用户未启用时不映射端点(404)、不生成 token。 。
  • Bearer token 认证 —— 首次启用时生成 32 字节随机 token,存于 {dataRoot}/config/mcp-token.txt (macOS/Linux 上仅属主可读写);请求须携带 Authorization: Bearer <token>。 比较采用常量时间,token 绝不写入日志。
  • Origin / Host 加固 —— 非本机的 Origin 或 Host 头将被拒绝(403),防止 DNS 重绑定和恶意网页。
  • 10 个工具:get_account、get_balances、get_positions、get_orders、get_order、get_quote、 get_quotes、get_price_history、get_option_chain、calculate_rebalance。每个工具和参数都带运行时描述, 列表结果有大小上限。
  • 发布版安全 —— MCP 响应用具名字段而非匿名类型构造(否则会被 Obfuscar 破坏,返回 HTTP 500); MCP 类型已排除在混淆之外,工具名保持可读。已在混淆后的发布版上实测。
  • 隐私提示 —— 工具返回的所有内容都会发送给您的客户端所使用的 AI 服务。

v1.8.3

GitHub Release ↗

Fixes: fresh Linux installs now show "Secure" in the browser out of the box.

  • Correct NSS trust flag (the root cause of "not secure"). The local CA was imported into the user's NSS database with the C,, trust flag, which does not mark a certificate as trusted for TLS. Chrome/Chromium therefore still showed https://127.0.0.1:8443 as "not secure" on first launch. The CA is now imported with the CT,CT,CT flag, so a new install is trusted for SSL immediately.
  • PEM export for certutil. The CA is now converted to PEM before the NSS import, which keeps the stored NSS entry valid (this also works around builds whose quant-ca.cer is DER).

修复:全新 Linux 安装开箱即显示"安全"。

  • 正确的 NSS 信任标志("不安全"的根因)。 之前本地 CA 以 C,, 标志导入用户 NSS 库,该标志并未 将证书标记为"受信任的 TLS 根",导致 Chrome/Chromium 首次访问 https://127.0.0.1:8443 仍显示 "不安全"。现在以 CT,CT,CT 标志导入,新安装立即被信任。
  • PEM 导出。 导入 NSS 前先将 CA 转为 PEM,确保 NSS 条目有效(同时兼容 quant-ca.cer 为 DER 的构建)。

v1.8.2

GitHub Release ↗

Makes the local-CA HTTPS trust step fully automatic on Linux — no commands to type.

  • Automatic browser trust on Linux. The local CA is now imported directly into the current user's NSS certificate database (~/.pki/nssdb), which Chrome/Chromium read on Linux — no sudo required, since it is a per-user store. Previously this required manually running certutil commands copied from the startup log.
  • Self-healing retry. If the one dependency this needs (certutil, from the libnss3-tools package) isn't installed yet, the app now retries automatic trust on every subsequent startup instead of only once at CA creation time — installing the package and restarting is enough, with no need to regenerate the certificate or reconfigure anything.
  • Correct SSL trust flag + valid NSS entry. The CA is now imported into NSS with the CT,CT,CT (SSL-trusted) flag and fed as a PEM export. The previous C,, flag stored the CA in NSS without marking it as trusted for TLS, so Chrome still showed https://127.0.0.1:8443 as "not secure" on first launch; the new flag makes a fresh install show "Secure" out of the box.

让 Linux 上本地 CA 的 HTTPS 信任步骤完全自动化——不再需要手敲命令。

  • Linux 上自动信任浏览器。 本地 CA 现在会直接导入当前用户的 NSS 证书数据库 (~/.pki/nssdb),Chrome/Chromium 在 Linux 上正是读取该库——因为这是用户级存储,不需要 sudo。此前需要手动复制启动日志里的 certutil 命令来执行。
  • 自愈式重试。 如果所需的唯一依赖(certutil,来自 libnss3-tools 包)尚未安装,应用现在 会在此后每次启动时重试自动信任,而不仅仅是在 CA 创建那一刻尝试一次——只需安装该依赖包并重启 应用即可,无需重新生成证书或重新配置。
  • 正确的 SSL 信任标志 + 有效的 NSS 条目。 本地 CA 现在以 CT,CT,CT(受信任 TLS)标志导入, 并以 PEM 传入 certutil(它只接受 PEM)。旧的 C,, 标志只把 CA 存入 NSS 却未标记为受信任, 导致 Chrome 首次访问 https://127.0.0.1:8443 仍显示"不安全";新标志让全新安装直接显示"安全"。

v1.8.1

GitHub Release ↗

Fixes the "not private" HTTPS warning and the update-check failure from v1.8.0.

  • Local CA + CA-signed HTTPS certificate. Replaces the plain self-signed certificate with a local Certificate Authority that is trusted once (a one-time step per machine) and then signs the server certificate. If you later change Urls or the Schwab OAuth redirect URI to a different host, the server certificate is automatically re-issued and signed by the same, already-trusted CA — no second trust step required. If CA generation fails for any reason, the app falls back to the old plain self-signed certificate so HTTPS never blocks startup.
  • HTTP to HTTPS redirect. The app now recognizes X-Forwarded-Proto from reverse proxies (nginx, Apache) and forces any plain HTTP request to redirect to HTTPS, fixing the case where the address bar kept showing http:// even when the app was configured for https://.
  • Fixed: "The update check failed" on self-contained builds. Self-contained Release builds trim unused reflection metadata, which broke JSON parsing of the GitHub Releases API response and made the /update page always report a failed check. Update checking now works correctly in the published Setup.exe / AppImage builds.

修复 v1.8.0 中的 HTTPS"不安全"警告与更新检查失败问题。

  • 本地 CA + CA 签名 HTTPS 证书。 用本地证书颁发机构(CA)替换纯自签名证书;CA 只需在每台 机器上信任一次(一次性操作),之后由它签发服务器证书。之后如果修改 Urls 或 Schwab OAuth 重定向地址到不同的主机,服务器证书会自动用同一个已被信任的 CA 重新签发,不需要第二次信任 操作。如果 CA 生成因任何原因失败,会自动降级为旧的纯自签名证书,确保 HTTPS 问题不会阻塞启动。
  • HTTP 自动跳转 HTTPS。 应用现在能识别反向代理(nginx、Apache)传来的 X-Forwarded-Proto 头,并强制把普通 HTTP 请求重定向到 HTTPS,修复了即使配置了 https:// 地址栏仍然显示 http:// 的问题。
  • 修复:self-contained 构建中"The update check failed"。 self-contained 的 Release 构建会 裁剪未使用的反射元数据,导致解析 GitHub Releases API 响应的 JSON 时失败,/update 页面因此 总是报告检查失败。现在已发布的 Setup.exe / AppImage 构建中更新检查功能正常工作。

v1.8.0

GitHub Release ↗

One-click upgrade — update from inside the app; configuration and strategy data are never lost.

  • In-app updater (Velopack). The app checks GitHub Releases on startup and every 24 hours. When a new version is available a banner appears at the top of the page. One click downloads, applies and restarts into the new version on Windows, macOS and Linux.
  • /update page. Shows the installed version, the latest version, the release notes from this changelog and the download progress. Buttons: Check now, Download, Upgrade & Restart and Upgrade after market close.
  • Dismissible banner. Dismissing a version hides it until a newer version appears; the dismissal is stored in your user settings, not in the program folder.
  • Trading safety gate. An upgrade is refused while a rebalance is running, while orders are still working/pending/queued, or — with automatic mode enabled — during US market hours (09:30–16:00 ET on weekdays). Refusals explain the reason instead of silently doing nothing. Upgrade after market close retries the gate after 16:30 ET.
  • Pre-upgrade snapshot. config/ and Data/ are copied to backups/{UTC}-{old version}/ before every upgrade; the five most recent snapshots are kept. Tokens and credentials are never copied. If the post-upgrade data migration fails, the latest snapshot is restored automatically.
  • Post-upgrade feedback. After a restart into a new version the app opens the dashboard and shows Updated to vX.Y.Z.
  • Degraded mode for zip installations. If the app was not installed through the Velopack installer, it only compares versions against the public release repository and offers the installer download. Nothing on your disk is replaced automatically; after one manual installer run, every later upgrade is a single click.
  • Public release repository. Releases are published to a separate, public repository (memoryfraction/Quant.Infra.Net.Pro-Public) that holds nothing but release assets, so checking for an update and downloading the installer need no account at all. The source repository stays private. Its address is the Update:ReleaseRepoUrl setting, and all four consumers read it: the Velopack feed, the degraded-mode release check, the installer download link and the How to upgrade link.
  • How to upgrade link. The update banner and the /update page link to the upgrade instructions published with the release repository.
  • Version single source. This changelog is embedded into the app and drives the version history page; the git tag drives the build version. No more hand-copied version numbers.
  • Upgrade anyway (when open orders cannot be verified). If the open-orders check cannot be completed at all (for example Schwab is not connected, or the authorization has expired), the /update page offers an Upgrade anyway (I have no open orders) button with a warning. The confirmation only bypasses the "orders could not be verified" refusal; it can never bypass a running rebalance, clearly in-flight orders, or the market-hours rule, and Upgrade after market close never uses this bypass.
  • MVP scope. Windows is the fully supported one-click upgrade target; Linux ships an AppImage (packaged, not end-to-end verified in this cycle); macOS is not published in this cycle — its CI job runs only on a manual workflow_dispatch with the include_macos input set to true.

一键升级 —— 在应用内完成升级,配置与策略数据永不丢失。

  • 应用内升级器(Velopack)。 启动后检查一次 GitHub Releases,之后每 24 小时检查一次。 有新版本时页面顶部出现提示横幅。Windows、macOS、Linux 上点一下即完成下载、替换与重启。
  • /update 页面。 显示当前版本、最新版本、来自本变更记录的更新说明与下载进度。 按钮包括 Check now、Download、Upgrade & Restart、Upgrade after market close。
  • 可关闭的横幅。 关闭某个版本后不再提示该版本,出现更新版本时仍会提示; 关闭状态写入用户设置,而不是程序目录。
  • 交易安全闸门。 再平衡执行中、存在未完成订单、或开启自动模式且处于美股交易时段 (美东工作日 09:30–16:00)时拒绝升级,并明确说明原因。Upgrade after market close 会在美东 16:30 之后重新检查闸门再执行。
  • 升级前快照。 每次升级前把 config/ 与 Data/ 复制到 backups/{UTC}-{旧版本}/, 只保留最近 5 份;不复制 token 与凭据。升级后的数据迁移若失败,会自动从最近快照恢复。
  • 升级后反馈。 重启进入新版本后自动打开 Dashboard 并显示 Updated to vX.Y.Z。
  • zip 安装的降级模式。 如果不是通过 Velopack 安装器安装的,只与公开发布仓库比对版本 并提供安装器下载链接,不会自动替换磁盘上的任何内容。手动装一次安装器后,之后每次升级都只需一点。
  • 公开发布仓库。 发布投递到独立的公开仓库(memoryfraction/Quant.Infra.Net.Pro-Public), 只承载发布资产,因此检查更新与下载安装器都无需任何账号;源代码仓库保持私有。 该地址即 Update:ReleaseRepoUrl 设置,四个消费者全部读取它:Velopack 发布源、 降级模式的版本检查、安装器下载链接、How to upgrade 链接。
  • How to upgrade 链接。 升级横幅与 /update 页面均链接到随发布仓库一同发布的升级说明。
  • 版本单一来源。 本变更记录嵌入程序并驱动版本历史页;git tag 驱动构建版本号,不再手工复制版本号。
  • Upgrade anyway(无法核实在途订单)。 当在途订单查询完全无法核实时(例如 Schwab 未连接、 或授权已过期),/update 页面会提供 Upgrade anyway (I have no open orders) 按钮并附警示语。 该确认只绕过“无法核实”这一种拒绝 - 再平衡执行中、明确在途的订单、或交易时段规则永远无法绕过, Upgrade after market close 也不使用该绕过。
  • MVP 范围。 Windows 为完整支持的一键升级目标;Linux 仅交付 AppImage(只打包,本周期未做端到端 验证);macOS 本周期不发布,其 CI 任务仅在手动 workflow_dispatch 且 include_macos 输入为 true 时运行。

v1.7.0

Program / data separation — configuration and strategy data now survive every upgrade.

This release is the prerequisite stage of the one-click upgrade plan. It does not yet add an in-application updater; it removes the root cause of "my settings disappeared after upgrading".

  • User data moved out of the program folder. Configuration, strategy data, trigger settings, execution mode, logs and the HTTPS certificate now live under %APPDATA%\Quant.Infra.Net.Pro\ (~/.config/Quant.Infra.Net.Pro/ on macOS/Linux). Overwriting the program folder — by zip or by installer — can no longer destroy user data.
  • Configuration layering. Shipped appsettings.json (read-only defaults) → config/appsettings.user.json (your overrides) → environment variables → User Secrets. New settings introduced by a release arrive automatically as defaults; your edited values stay yours.
  • One-time automatic migration. On first launch the app moves License Key, Urls, RedirectUri, advanced overrides, the trigger configuration, the HTTPS certificate and the EULA acceptance record out of the old install folder. Idempotent: running it again changes nothing, and it never overwrites an existing file.
  • Fixed trigger configuration bug. The rebalance trigger settings were written into the program folder but read from the user data folder, so saved trigger settings were never read back and were lost on upgrade. Read and write now use the same path.
  • Manual / automatic execution mode is persisted. Previously it reset to Manual every time the Rebalance page was opened.
  • SchemaVersion + migration pipeline. User data files carry a schema version and are upgraded by an ordered IUserDataMigration pipeline. Deserialization tolerates unknown fields, so installing an older version back remains possible.
  • Export / import all settings (Settings page). Download a zip with your configuration and strategy data for machine migration or manual backup. Schwab credentials are excluded by default and require an explicit opt-in; authorization tokens are never exported.
  • Data root override. The QUANT_INFRA_DATA_DIR environment variable overrides the user data root, which is required for Linux service accounts running as root or under systemd.
  • Documentation corrected. The deployment guide claimed configuration files were preserved across an upgrade; that was not true before this release. README now documents where data lives.

程序与数据分离 —— 配置和策略数据从此不会被升级破坏。

本版本是一键升级方案的前置阶段。它尚未引入应用内升级器,而是先消除"升级后设置丢失"的根因。

  • 用户数据移出程序目录。 配置、策略数据、触发配置、执行模式、日志与 HTTPS 证书统一迁移到 %APPDATA%\Quant.Infra.Net.Pro\(macOS/Linux 为 ~/.config/Quant.Infra.Net.Pro/)。 无论用 zip 覆盖还是安装器升级程序目录,都不会再破坏用户数据。
  • 配置分层。 随程序发布的 appsettings.json(只读默认值)→ config/appsettings.user.json (你的覆盖项)→ 环境变量 → User Secrets。新版本新增的配置项自动获得默认值,你改过的值保持不动。
  • 一次性自动迁移。 首次启动时自动把旧目录里的 License Key、Urls、RedirectUri、高级覆盖项、 触发配置、HTTPS 证书与 EULA 接受记录搬到用户数据区。幂等:重复运行不会产生变化,且绝不覆盖已存在的文件。
  • 修复触发配置 Bug。 再平衡触发配置过去写入程序目录、却从用户数据区读取,导致保存的设置永远读不回来、 且升级即丢失。现读写使用同一路径。
  • 手动/自动执行模式持久化。 此前每次打开再平衡页面都会重置为手动模式。
  • SchemaVersion 与迁移管线。 用户数据文件带架构版本,由有序的 IUserDataMigration 管线升级。 反序列化容忍未知字段,因此仍可装回旧版本。
  • 导出/导入全部设置(Settings 页面)。下载包含配置与策略数据的 zip,用于换机器或人工备份。 Schwab 凭据默认不包含、需明确勾选;授权 token 永不导出。
  • 数据根目录可覆盖。 环境变量 QUANT_INFRA_DATA_DIR 可覆盖用户数据根目录, 这是 Linux 以 root/systemd 运行服务账号所必需的。
  • 文档修正。 部署指南过去声称"配置文件会保留",在本版本之前该说法并不成立。 README 现已补充数据存放位置说明。

v1.6.3

Privacy mask for financial data: eye-toggle on Dashboard and Rebalance pages. Sensitive amounts and account numbers masked as **** by default.

财务数据隐私脱敏:Dashboard 与 Rebalance 页面增加眼睛图标开关,敏感金额与账户号码默认遮盖为 ****。

Versions 1.6.2 and earlier: README version history · All GitHub releases