Skip to content
LibxaFrame
Sign In
Release 12 August 2026 6 min read

Libxa Desktop 0.3.0: HTTPS, preview and a terminal

A certificate authority on your own machine signs certificates for your .test domains, because no public one ever can. Plus a preview window at three viewports, a terminal that opens where the project is, and a TLS toggle that finally does something.

Libxa Desktop 0.3.0 adds HTTPS for local sites, a preview window, and a terminal that opens where a project actually lives.

HTTPS on a .test domain

Some things only reproduce over HTTPS. Service workers, secure cookies, SameSite=None, the clipboard API, geolocation, anything behind a mixed-content warning. Testing them locally has generally meant either a self-signed certificate your browser refuses in a way you have to click past every session, or a tunnel to somewhere public.

Neither is necessary. A certificate authority is not a special kind of organisation; it is a key pair whose public half is in a trust store. So 0.3.0 creates one on your machine, and one button puts its root in the Windows user trust store.

That button does not ask for administrator rights, which surprises people. The per-user certificate store does not need elevation. Only the machine-wide one does, and there is no reason to install a development root there.

Each certificate covers the domain, its wildcard, localhost and 127.0.0.1, and is valid for 396 days. That number is not arbitrary: Chrome rejects any certificate with a lifetime over 398 days, and renewal runs a month before expiry, so a certificate is replaced before anything notices.

Worth being explicit about why this is a local CA rather than Let's Encrypt. .test is reserved by RFC 6761 for exactly this purpose, and reserved means no public certificate authority can ever issue for it. Not "does not currently". Cannot. ACME needs to verify you control a domain, and nobody controls .test.

The root stays on your machine, and one button removes it again.

The toggle that did nothing

Switching HTTPS on for a site was already possible in 0.1.0. It was in the data model, it was in the IPC surface, and the interface showed it.

nginx ignored it completely. A site marked secure was served over plain HTTP, with nothing anywhere indicating that the setting had not taken effect. The config generator simply never emitted a TLS block.

This is the second setting in two releases found to be recorded, displayed and unused, after per-site PHP versions in 0.2.0. Both had the same shape: the interface and the data model agreed with each other, and neither was talking to the thing that generates the config.

Preview

Clicking a site opens it in a window at a desktop, tablet or mobile viewport. It runs in its own session partition, so a preview logged in as a test user does not disturb the browser session you were already working in, and when a site will not load you get an explanation of what went wrong rather than the browser's generic error page.

A terminal, already in the right directory

Opening a shell at a project is a small thing done many times a day. 0.3.0 opens one: Windows Terminal, PowerShell or cmd on Windows, Terminal on macOS, and the common emulators on Linux, tried in order so a missing one falls through to the next instead of failing.

Removed

System information no longer lists the versions of the shell the app is built on. They describe the application itself, not the environment it manages, and sitting in a list beside the PHP and nginx versions they read as though they were part of the stack being managed. It now shows the platform, the architecture, the app version and where its data lives.

Updating

Existing installations update themselves. The download is verified against the SHA-512 in latest.yml and installed when you ask for it, not behind your back.

Installers are still not code-signed, so Windows SmartScreen warns on a fresh install. Choose More info, then Run anyway.

Keep reading