v1.1.6
stableA security release. Authenticating with `plakar login` now requires a confirmation code typed into the terminal that started it, and the API server stops accepting the previous flow on 18 September 2026.
Security
plakar loginauthenticates through a hardened flow. The confirmation page served by the Plakar API displays a code that has to be typed into the terminal the login was started from, so an authentication request can only be approved by whoever holds that terminal. This closes phishing attacks that rely on someone else approving the confirmation.
Warning
From Friday 18 September 2026, the API rejects authentication requests that do
not use the new flow. Upgrade to v1.1.6 before then to keep plakar login
working.