Full release notes · 2026-08-25

CartoVox 0.2.2

security, recovery, climate, and offline reliability

The application was called Atlas Studio until version 0.8.2. Builds are shared with invited testers on the Discord server; these notes are also readable offline inside the app.

Browse releases

This is the current invited technical-alpha build. It keeps the complete v0.2 worldbuilding workspace and adds the first broad post-release hardening pass: safer imported projects and local APIs, recoverable storage management, corrected Köppen aridity, persistent player presentation, resilient saved maps, and a less intrusive World workspace.

Security and private local operation

  • Lore from project backups is now treated as untrusted input. Markdown is rendered through an inert-document sanitizer with strict element, attribute, and URL allowlists before it can enter the live dashboard; dangerous HTML, event handlers, images, scripts, embedded documents, forms, styles, and executable URL schemes are removed.
  • Wiki links and Lore Editor option lists escape imported names instead of assembling live handlers or option markup from author text.
  • Every endpoint that resolves a world now shares one containment check. Crafted world IDs can no longer traverse out of the local library through map files, atlas styles, names, lore overrides, exports, plates, or re-simulation.
  • Re-simulation rejects unknown projects, malformed seeds and non-object override data, and refuses concurrent work on the same project instead of interleaving writes.
  • JSON writes and responses replace non-finite numbers with valid null values; configuration overrides reject NaN and infinity before they can silently corrupt sea level or other numerical fields.
  • Mutation requests have bounded bodies and malformed JSON, invalid numbers, negative or invalid Content-Length values, and over-large input now receive explicit 4xx responses rather than dropping the local connection.
  • Atlas no longer loads fonts or executable code from Google Fonts or public CDNs. All dashboard scripts are vendored; a damaged install reports its missing local assets clearly instead of contacting a third party.

Recoverable Trash and local storage

  • Library now includes a visible Trash with Restore, Delete permanently, Empty trash, disk usage, and expiry information.
  • Completed worlds are recoverable for 30 days; cancelled, failed, or incomplete projects are retained for seven days. Expiry is applied when Trash is opened, making deletion predictable rather than running as a hidden background task.
  • A 5 GB soft limit produces an explicit review warning but never silently destroys a recent completed world.
  • Restoring prefers the original project identity and safely creates a new identity if that ID has since been reused, without overwriting the newer project.
  • Update downloads are pruned only after the replacement installer has completed SHA-256 verification, preventing old installers from accumulating while preserving the last usable download if an update fails.

Corrected Köppen dry-climate classification

  • New and re-simulated worlds now apply Köppen's actual rainfall-seasonality rule: whether at least 70% of annual precipitation falls in the warm half-year, the cold half-year, or neither.
  • The warm and cold halves are ranked per cell from that location's own seasonal temperatures, so hemispheres resolve correctly, and precipitation is weighted by orbital residence time for eccentric orbits.
  • The previous classifier measured general seasonality instead of rainfall timing and could assign the cold-season constant to evenly watered ground. The corrected model produces more credible dry, grassland, forest, and Mediterranean transitions.
  • world_config.json records biome_model_version. Existing saved worlds are never silently reclassified on open; version 1 remains reproducible from its saved configuration, while version 2 is the default for new work.

Presentation, World workspace, and map recovery

  • Campaign player mode now survives a page reload, application restart, or crash for the same world and campaign. It returns to the saved player-visible layer without exposing the author dashboard.
  • Missing or deleted Campaign presentation data fails closed with a clear recovery screen. Player-region links are inert while presenting, and only an explicit Exit presentation action clears the saved state.
  • The World workspace's diagnostics and controls can be collapsed into a distraction-free map view. Expanding long health findings no longer pushes the globe below an unreachable viewport.
  • Saved worlds recover their generated map catalogue after a local-service interruption instead of remaining in a false “Maps unavailable” state. Project JSON and manifests are served with no-store caching so a restarted local process cannot be confused with a stale cached dashboard.
  • Library thumbnails try one known fallback and then show an honest “No preview rendered” state. Missing maps no longer trigger an infinite retry loop against the local server.

Robustness and edge cases

  • Completed generation jobs are retired from memory while recent logs and every running job remain available for reconnection and cancellation.
  • Empty-ocean seed scans no longer index a missing landmass; silhouette measurements use spherical coordinates rather than distorted map-sheet pixels.
  • Degenerate one-plate states safely fall back when no boundary anchor candidates exist.
  • Latitude-band summaries keep one stable schema even for empty bands and worlds without land.
  • Corrupt top-level author records in manifests, Campaign, Chronicle, regional projects, and related editable data degrade safely instead of breaking the whole project.
  • World-library, Trash, and HTTP paths now resolve through the same runtime data-root seam, improving portable builds and isolated tests.
  • Minor climate, topology documentation, settings-help, filename, and historical-map edge cases found in the audit were cleaned up and covered by regressions.

Cross-platform verification

  • The regular test workflow now runs on Ubuntu, Windows, and macOS for every push and pull request instead of discovering platform-specific failures only during a release build.
  • This release passes 283 automated tests, Python compilation, JavaScript syntax checks, release-version validation, and a reduced end-to-end world generation that produced 122 artifacts with finite core fields, 239 river reaches, seven lakes, and no simulation-health errors.

Compatibility and invited alpha access

Existing worlds, revisions, Campaigns, Chronicles, regional projects, beta keys, and author data remain compatible. The Köppen correction affects only worlds newly generated or deliberately re-simulated with biome model version 2. Older worlds that predate optional scientific layers remain readable; those layers require a deliberate re-simulation rather than being fabricated on open.

CartoVox remains limited to invited testers with an offline beta key. Verification uses no account, telemetry, hardware fingerprint, activation server, or network connection. Generated worlds and author data stay on the tester's machine.

Full generation is intentionally demanding and may take roughly 20–25 minutes on a current high-end Mac and 50–55 minutes on a current high-end Windows machine, depending on settings and selected atlas plates. Use Preview, Quick, Draft atlas finish, or selective plates while exploring.