v3.5.4

QwenLM/Qwen3-VLv3.5.4Aug 1, 2026by UNITRONIX

AI Summary

Patch release fixing security vulnerabilities in Address Book ACLs, legacy SQLite role checks, and MeshAgent MeshID generation.

Key Highlights

  • Fixed Address Book ACL bypass for restricted users
  • Fixed legacy SQLite role CHECK blocking Phase 52 sync
  • Fixed MeshAgent `.msh` bad size issue (now emits SHA-384 MeshID)

Full Release Notes

## [3.5.4] — 2026-08-01

### Fixed
- **Address Book ACL bypass (restricted users) (#342):** `GET /api/ab` (and personal AB / tags) now filters peers and fleet tags through the same device-group / folder ACL as `/api/peers/list`, so org shared address-book merge and stale entries no longer expose out-of-scope machines. Unscoped `GET /api/peers` (without `accessible`/`pageSize`) applies the same ACL for non-admin roles. Ships via panel update (Go server + console).
- **Legacy SQLite role CHECK blocking Phase 52 sync (#342):** upgraded `users` tables that still had `CHECK (role IN ('admin','operator','viewer'))` are rebuilt on Go `Migrate()` so `super_admin` / `global_admin` / `server_admin` / `pro` sync correctly. Installer/docs creators no longer add the old CHECK. Ships via panel update (Go server restart/migrate).
- **MeshAgent `.msh` `bad size` (#336):** `GET /api/mesh/download.msh` no longer embeds the static 40-hex MeshID placeholder. Panel/API now emit a stable per-group 96-hex (SHA-384) `MeshID`. Ships via panel update (Go restart).

Stable channel: `main`. Update via Settings → Updates.

## What's Changed
* sync: main 3.5.0 → dev (post-release baseline) by @UNITRONIX in https://github.com/UNITRONIX/BetterDesk/pull/338
* docs: sync sponsors list (Redspin, MyNameisStitch) to dev by @UNITRONIX in https://github.com/UNITRONIX/BetterDesk/pull/339
* hotfix: BetterDesk 3.5.4 — Address Book ACL and role CHECK (#342) by @UNITRONIX in https://github.com/UNITRONIX/BetterDesk/pull/343


**Full Changelog**: https://github.com/UNITRONIX/BetterDesk/compare/v3.5.0...v3.5.4