New Features:
- Time-based session lockout: Automatically lock at a specific time daily
- Active hours for lockout: Only enforce timeout during configured hours
- Password on boot: Require password when system powers on/reboots
- Enhanced lockout timeout: Now respects active hours configuration
Configuration Options:
- lockoutAtTime: Time to auto-lock (e.g., "17:00")
- lockoutActiveStart/End: Time range for lockout enforcement
- requirePasswordOnBoot: Boolean to require password on system boot
Technical Changes:
- Updated configure_password_protection() with new prompts
- Added lockout time validation (HH:MM format)
- Enhanced main.js with isWithinActiveHours() and checkScheduledLockTime()
- Added boot flag creation in openbox autostart
- Updated config.json schema with new fields
The session timeout (inactivityTimeout) continues to work as before,
returning to home page after inactivity. The lockout timeout provides
an additional security layer with password protection.
- Fixed missing closing brace in keyboard auto-close section
- Removed duplicate line in showKeyboardIcon function
- Corrects SyntaxError: missing ) after argument list at line 441
Based on v0.9.2-6 (includes enhanced Electron update tool)
Version 0.9.4 introduces configurable optional features and security:
New Features:
- Optional pause button: Can be disabled during install/rerun
* Disables functionality entirely, not just hides the UI
* Configured in Core Settings menu (option 7)
- Optional keyboard button: Can be disabled during install/rerun
* Disables on-screen keyboard functionality completely
* Configured in Core Settings menu (option 7)
- Password protection with session lockout:
* Customizable lockout timeout (in minutes of inactivity)
* Blank screen during lockout with no interaction allowed
* Password required to unlock after timeout
* Password required after display schedule wake-up
* SHA-256 password hashing for security
* Option to only require password after display wake (0 minute timeout)
Configuration:
- New configure_optional_features() function for pause/keyboard buttons
- New configure_password_protection() function for security setup
- Added to Core Settings menu (options 7 & 8)
- All settings saved to config.json and loaded on startup
Implementation:
- Main.js: Password lockout window with blank screen
- Main.js: Lockout timer check in master timer loop
- Main.js: Display wake flag detection (.display-wake file)
- Main.js: Conditional pause button visibility based on config
- Preload.js: Conditional keyboard button based on config
- Display-on script: Creates flag file to trigger password requirement
All features are configurable on first install or by rerunning the script.
Fixed two critical issues preventing Electron update from completing:
1. cd permission denied error
Problem: Script tried to `cd /home/kiosk/kiosk-app` which failed with
"Permission denied" because the directory has restricted permissions (drwxr-x---)
and the regular user can't enter it.
Fix: Use `sudo -u kiosk bash -c "cd '/home/kiosk/kiosk-app' && npm install ..."`
instead of separate cd + npm commands. This runs both commands as the kiosk
user in a single bash session, avoiding the permission issue.
2. Wrong service name (kiosk vs lightdm)
Problem: Scripts tried to stop/start "kiosk" service which doesn't exist on
the user's system. Their kiosk runs under lightdm service.
Fix: Changed all references from:
- `systemctl stop/start kiosk` → `systemctl stop/start lightdm`
- "Restart kiosk service" → "Restart kiosk display"
- `journalctl -u kiosk` → `journalctl -u lightdm`
Additional fixes:
- Updated file checks: `[ -d ]` → `sudo test -d` for restricted directories
- Applied fixes to both update paths: successful install and failure/restore
- Updated both update_electron.sh and install_kiosk_0.9.2-6.sh
Changes in both scripts:
- update_electron() function: removed cd, added bash -c wrapper, changed service name
- Backup restore paths: same fixes applied
- Success path: updated restart prompts and service checks
- Failure path: fixed restore process with proper directory access
The update should now complete successfully without permission errors.
Fixed two issues preventing the Electron update from working properly:
1. Log messages appearing in version output
- get_latest_electron_version() was outputting log messages to stdout
- These messages were being captured along with the version number
- Result: "Target version: [INFO] Fetching...39.2.3" in output
- Fix: Redirect log_info and log_error to stderr with >&2
- Now only the version number is captured in the variable
2. Backup function permission errors
- stat command needed sudo to read owner of restricted directories
- File checks [ -f ] couldn't access files in drwxr-x--- directories
- mkdir failed with "cannot create directory '/home/kiosk': Permission denied"
- Fix: Use sudo for all file operations in create_backup():
* sudo stat -c '%U' to get directory owner
* sudo test -f/d for file/directory checks
* sudo -u owner for mkdir, cp, and file writes
Changes in both update_electron.sh and install_kiosk_0.9.2-6.sh:
- get_latest_electron_version functions: Added >&2 to log statements
- create_backup functions: Added sudo to stat and all file checks
- Ensures backup works with restricted /home/kiosk permissions
The update process should now complete successfully without permission errors
or garbled version output.
The scripts were failing to find the kiosk installation at /home/kiosk/kiosk-app
because the /home/kiosk directory has restricted permissions (drwxr-x---),
preventing regular users from reading it.
Changes in both update_electron.sh and install_kiosk_0.9.2-6.sh:
1. Updated find_kiosk_dir() to use sudo for all file checks
- sudo test -f for checking if main.js exists
- Prevents "permission denied" errors on restricted directories
2. Added Method 4: Detect from running electron process
- Parses ps output to find electron executable path
- Extracts app directory from the path
- Provides fallback when directory searches fail
3. Updated get_current_electron_version functions
- Use sudo test -f to check if package.json exists
- Use sudo grep to read package.json and get version
- Ensures version detection works with restricted permissions
4. Fixed directory existence checks
- Use sudo test -d for checking kiosk directory
These changes allow the scripts to:
- Find kiosk installations in directories with restricted permissions
- Detect installations even when run as a regular user
- Work correctly with the standard /home/kiosk setup (drwxr-x---)
- Provide better fallback detection using running processes
The scripts will now prompt for sudo password when needed to check
for files in restricted directories, then continue normally.
Changed the script to run as a regular user instead of requiring sudo.
The script now:
- Checks that it's NOT being run as root (prevents sudo usage)
- Uses sudo for individual commands that need elevated privileges
- Prompts for sudo password only when needed
Changes:
- Removed EUID check that required running with sudo
- Added check to prevent running as root
- Added sudo to backup operations (mkdir, cp, file writes)
- All systemctl and npm install commands already use sudo appropriately
This matches the behavior of install_kiosk scripts which should be run
as a regular user, not with sudo.
Usage: ./update_electron.sh (not sudo ./update_electron.sh)
This new version of the install script includes a completely rewritten
manual Electron update tool that fixes all the issues with the previous version:
NEW FEATURES:
- Smart installation detection across multiple locations
- Verifies Electron is actually running (not just installed)
- Gets current version from both package.json and node_modules
- Fetches latest stable version from npm with multiple fallback methods
- Clear version comparison display (current vs latest)
- Breaking changes warning with direct links to Electron documentation
- Automatic backup creation before any changes
- Provides clear restore instructions
- Multiple user confirmation prompts before making changes
- Automatic rollback if update fails
- Fixes chrome-sandbox permissions after installation
- Manages kiosk service stop/start automatically
FIXES:
- No more "no electron app found" errors
- No more "script just bails" - proper error handling throughout
- Proper detection of running Electron instances
- Network failure handling with multiple fallback methods
- Clear feedback at every step of the process
The enhanced update tool is accessible from:
Advanced Menu → Manual Electron Update
Version updated from 0.9.2 to 0.9.2-6 to reflect the enhancement.
This script addresses issues with the manual Electron update process by:
- Detecting kiosk installation across multiple methods (user home, systemd service)
- Checking if Electron is actually running (not just installed)
- Getting current Electron version from both package.json and node_modules
- Fetching latest stable Electron version from npm registry with fallbacks
- Displaying clear version comparison (current vs latest)
- Warning users to check for breaking changes with links to documentation
- Creating automatic backups of package.json, package-lock.json, and version info
- Providing clear restore instructions if something goes wrong
- Requiring user confirmation at multiple steps before making changes
- Automatically attempting rollback if the update fails
- Fixing chrome-sandbox permissions after installation
- Managing kiosk service stop/start around the update
The script handles edge cases like:
- Missing or moved installations
- Network failures when fetching versions
- Failed npm installations with automatic recovery
- Permission issues with proper sudo user handling
Users can now safely update Electron with confidence that they can restore
if needed, and with clear visibility into what versions are being used.
The pause button wasn't appearing because preload.js variables were being
reset when pages reloaded/navigated, but the visibility message was only
sent once in attachView().
Now sends pause-button-visibility on EVERY page load (did-finish-load event)
to ensure the button state persists across page reloads and navigation.
Major UX improvement: Replaced problematic home return popup on timed sites
with an on-demand pause button that appears on user interaction.
Changes:
- NEW: Pause button appears in bottom-left corner on user interaction
- Shows only on timed rotation sites (duration > 0)
- Auto-hides after 5 seconds of inactivity
- Reuses existing inactivity prompt logic for pause dialog
- Pause durations: 15 min, 30 min, 1 hour, 2 hours
- Home return popup now ONLY appears on manual sites (duration = 0)
- Timed sites use pause button instead (cleaner UX)
Implementation details:
- Added pause button state/functions to preload.js (outside DOMContentLoaded)
- Added pause-dialog.html with time selection UI
- Added showPauseDialog() function and IPC handler in main.js
- Modified attachView() to send pause-button-visibility based on site duration
- Modified HOME RETURN CHECK to skip timed sites (line 3622-3625)
- Button creation reuses keyboard icon pattern for consistency
This fixes the issue where the home return popup would appear but sites
could rotate under it on timed rotation sites. Now users get a clean,
on-demand pause control that doesn't interfere with normal browsing.
The home return inactivity popup was only working on manual sites (duration=0)
and hidden sites, but not on timed rotation sites (duration>0). This was because
the site rotation logic had an early return statement that prevented the home
return check from ever executing.
Changes:
- Removed early return after rotateToNextSite() call (line 3605)
- Now both auto-rotation AND home return checking work together
- Home popup will appear on ALL site types after inactivity period
- Updated version to 0.9.1-1 with changelog
Technical details:
The master timer had two sections - section 6 for site rotation and section 7
for home return checking. When a timed site rotated, section 6 would return
early, preventing section 7 from executing. Removing the return allows both
features to work in harmony.
Root cause: Pause button state variables and IPC listener were declared inside
DOMContentLoaded, causing them to reset every time a page loaded.
Symptoms:
- Main process sends shouldShow=true when switching to rotation site
- Preload receives it and sets pauseButtonShouldShow=true
- Page loads → DOMContentLoaded fires → variables reset to false
- User taps screen → sees shouldShow=false → no button appears
Fix:
- Moved pause button variables outside DOMContentLoaded (persist across page loads)
- Moved pause button functions outside DOMContentLoaded (called by IPC listener)
- Moved IPC listener outside DOMContentLoaded (registers once, not per page)
- Kept only user interaction handlers inside DOMContentLoaded
This ensures pause button state persists across page navigations within a tab.
**Return-to-Home Popup Logic (CORRECTED):**
- FIXED: Return-to-home inactivity prompt now appears ONLY on manual sites (duration=0)
- Rotation sites (duration>0) skip return-to-home logic and use auto-rotation instead
- Previous commit had this backwards - now corrected
**Pause Button Auto-Hide:**
- Pause button now auto-hides after 5 seconds of inactivity (like keyboard icon)
- Each user interaction resets the 5-second timer
- Debug logging shows when button auto-hides
- Prevents button from staying on screen permanently
**Manual Electron Update Detection:**
- Added main.js file check to Method 1 (default kiosk user)
- Added Method 6: Check /opt/kiosk-app and /usr/local/kiosk-app
- Added Method 7: Query systemd kiosk.service for working directory
- Improved parent directory detection with cleaner variable usage
- Enhanced error message with numbered search locations and kiosk user home path
- Better debug output to help diagnose installation issues
**Display Schedule Logic (CRITICAL FIX):**
- FIXED: Reversed display off/on time comparison logic
- Overnight case (22:00 off, 06:00 on): Now correctly checks off_mins > on_mins
- Same-day case (08:00 off, 17:00 on): Now correctly checks off_mins < on_mins
- Display will now properly stay OFF during scheduled times
- Fixes issue where "keep display on" watchdog was too aggressive
All changes improve UX and fix critical scheduling bugs
- Add comprehensive console logging for pause button lifecycle:
* Main process logs when sending visibility updates with duration info
* Renderer logs visibility changes and user interaction events
* Helps diagnose why pause button may not appear on rotation sites
- Fix return-to-home inactivity prompt appearing on manual sites:
* Skip inactivity timeout logic when on manual sites (duration=0)
* Manual sites should not trigger return-to-home prompts
* Only rotation sites should show inactivity prompts
These changes help diagnose pause button issues and improve UX for manual sites
Major Fixes:
1. FIXED: Pause button visibility logic completely rewritten
- Pause button now properly hidden on duration=0 sites
- Shows ONLY on user interaction (mousedown/touchstart/keydown)
- Main process sends pause-button-visibility on tab switch
- Preload receives visibility state and enforces it
- Button hidden immediately when switching to manual sites
2. FIXED: Pause dialog window conflict resolved
- Created separate pauseWindow variable (was reusing promptWindow)
- Pause dialog no longer disappears immediately
- Prevents conflicts with inactivity prompt window
- Each dialog has its own window lifecycle
3. FIXED: Mixed header characters now uniform
- All =--- and =-- patterns replaced with ---
- Consistent use of dashes throughout script
- Better terminal display compatibility
4. FIXED: Manual Electron update detection improved
- Three-method detection strategy:
* Method 1: Check /home/kiosk/kiosk-app
* Method 2: Search all /home/*/kiosk-app with main.js verification
* Method 3: Check current directory for kiosk-app
- Added debug output showing search paths and current context
- More robust detection across different installation scenarios
Implementation Details:
- pauseButtonShouldShow tracks if button is allowed on current site
- pauseButtonShown tracks if button is currently displayed
- User interaction only shows button if pauseButtonShouldShow is true
- attachView() sends visibility message on every tab switch
- Throttled user interaction handling (100ms) prevents spam
Critical Fixes:
- FIXED: npm installation verification added
* Now explicitly checks if npm is installed after nodejs
* Falls back to installing npm separately if missing
* Displays npm version after installation
* Prevents "npm: command not found" error during Electron install
- FIXED: Pause button now appears only on user interaction
* Hidden by default (display:none)
* Shows on mousedown/touchstart/keydown events
* Similar behavior to keyboard icon
* Throttled to check every 5 seconds
* Better UX - less visual clutter
- FIXED: Pause button hidden on manual sites (duration=0)
* Main process checks site duration when visibility requested
* Sends pause-button-visibility message to views
* attachView() function controls visibility on tab switch
* Prevents confusion on sites where return-to-home popup appears
Implementation:
- Added 'request-pause-button-visibility' IPC message
- Main process responds with 'pause-button-visibility' based on duration
- Pause button automatically hidden/shown when switching tabs
- User interaction triggers visibility check
Key Changes:
- FIXED: All box drawing characters replaced with consistent standard chars
* Changed === to --- for better terminal compatibility
* Removed all special Unicode box drawing symbols
- FIXED: Pause button time options now match return-to-home dialog
* Changed from 5/15/30/60 to 15/30/60/120 minutes
* Consistent user experience across both dialogs
* Icons match the inactivity prompt style
- FIXED: Site rotation now respects user interaction
* Rotation pauses for 1 minute after last user activity
* Prevents sites from rotating while user is actively using them
* Similar to keyboard auto-close behavior (30 sec inactivity)
* Provides better UX - no interruptions during use
- FIXED: Manual Electron update directory detection
* Now dynamically searches for kiosk installation
* Checks /home/kiosk/kiosk-app first
* Falls back to searching all /home/*/kiosk-app directories
* Displays detected user and directory path
* Fixes "directory not found" error
Implementation Details:
- Pause button works on all pages including home URL
- Rotation logic: respects both pause extension AND user activity
- Electron update creates backup before updating
- Verifies update completion and offers rollback if needed
Version 0.9.0:
- Renamed from v09.9.1_4 to use cleaner version numbering (0.9.0)
- Updated all internal version references
Version 0.9.1 - New Features and Fixes:
- NEW: Pause button feature (bottom-left, orange button)
* Allows users to pause rotation and inactivity timers
* Time extension options: 5, 15, 30, or 60 minutes
* After extension expires, normal rotation/home logic resumes
* Provides better user control without complex automation
- FIXED: Site rotation timing now more consistent
* Rotation now happens on schedule regardless of user interaction
* User activity only blocks return-to-home, not site rotation
* Sites will display for their configured duration more reliably
* Added logging to show rotation timing
- FIXED: Manual Electron update feature completely rewritten
* Added comprehensive error checking at each step
* Creates backup before updating
* Verifies update after completion
* Provides rollback instructions if update fails
* Shows current and new versions
* Logs update process to /tmp/electron-update.log
- IMPROVED: Removed all box drawing characters (╔╗╝╚) from output
* Replaced with standard characters for better compatibility
- IMPROVED: Code cleanup and better comments throughout
Modified the inactivity check to show the return to home popup on both
timed and manual websites by removing the manualNavigationMode condition.
Previously, the popup only appeared on manual (0-duration) websites.
CRITICAL FIXES:
- Removed userRecentlyActive early return that blocked ALL rotation
- v0.9.15 had bug where any interaction blocked rotation for 60 seconds
- Sites now rotate on schedule unless user specifically interacted with that site
BEHAVIOR NOW CORRECT:
- Sites with time rotate on schedule automatically
- User interaction pauses rotation ONLY on that specific site
- After 1 minute of inactivity, "Return to Rotation" popup appears
- Popup only appears on sites where user actually interacted
- No popup on home screen unless user interacted with home screen
- Media playback check every 3 seconds (good performance)
This fixes the issues where:
- No rotation was happening even with sites having time set
- Popup was appearing without user interaction
- Popup was appearing on home screen when there was no rotation
This commit fixes the initial v0.9.15 implementation to match the
actual vision:
CORRECTED BEHAVIOR:
- User interaction PAUSES rotation on that site
- After 1 minute of inactivity → popup appears
- Popup gives options: extend time or return to rotation
- No response (15 sec) → auto-return to rotation
- Works on ALL sites including home URL
- Media playback blocks popup and rotation
KEY FIXES:
1. Removed wrong "popup on first interaction" logic
2. Restored userInteractedWithCurrentSite flag (removed in v0.9.14)
3. markActivity() now sets interaction flag instead of showing popup
4. Rotation blocked when userInteractedWithCurrentSite=true
5. Inactivity check works on ANY site where user interacted
(not just home or manualNavigationMode)
6. Changed default timeout from 2 minutes to 1 minute
7. Prompt response clears interaction flag on "return to rotation"
8. Extension expiry clears interaction flag to resume rotation
9. Updated all bash script defaults from 120s to 60s
TECHNICAL CHANGES:
- Line 3639: Changed popupShownForCurrentSite → userInteractedWithCurrentSite
- Line 3706-3711: Set flag in markActivity() instead of showing popup
- Line 3937: Block rotation if userInteractedWithCurrentSite
- Line 3947-3989: Simplified inactivity check - works on ANY interacted site
- Line 3651: Default timeout 60000ms (was 120000ms)
- Line 3671: Config default 60s (was 120s)
- Line 3970: Clear flag when extension expires
- Line 4078: Reset flag when site changes
- Line 4179, 4197: Clear flag on return to rotation
- Bash section: Updated all 120s→60s, 2min→1min defaults
This matches the original vision: rotation pauses on interaction,
popup after inactivity gives control, auto-return prevents stuck kiosk.