# Changelog All notable changes to EvoScientist WebUI are documented in this file. ## Unreleased ## [0.1.8] - 2026-07-10 ### Added - Optional single-user WebUI authentication. Credentials are read from `.env`, pages and API routes are protected by a signed HTTP-only session cookie, and successful logins record their latest timestamp and counter in the local EvoScientist data directory. - Added an authenticated change-password dialog. It verifies the current password, atomically updates `.env`, rotates the session signing key, and invalidates prior sessions while retaining the current session. ### Fixed - Prevented React's `Maximum update depth exceeded` error during chat runs. Reading LangGraph SDK `stream.values` or `stream.messages` implicitly enabled high-frequency stream modes, allowing repeated external-store notifications to nest React updates. ### Changed - Chat runs now use updates-only streaming and refresh the persisted thread record when a run completes or pauses for approval. The UI keeps the optimistic user message and loading state during a run, then renders the complete saved conversation, tasks, files, and interrupt state after the server persists it. - Removed SDK stream-object propagation into message and tool components so no downstream component can accidentally re-enable high-frequency value or message-tuple subscriptions.