May 22, 2026

TLS Peer Verification, Everywhere

TLS Verification on All Outbound HTTP (#182)

Both HTTP clients (the main curl wrapper and the parallel fetcher) had defaulted to skipping TLS peer verification since the project's early days. That exposed scraper traffic -- including cruise-line login POSTs that carry real user passwords -- to man-in-the-middle interception via a compromised proxy, DNS hijack, or hostile network.

Verification is now on everywhere. Tested against all 10 cruise-line domains plus Discord, both direct and through the scraping proxy -- zero certificate failures. The proxy uses HTTP CONNECT tunneling, so TLS stays end-to-end and peer verification works through it unchanged.

Lowest-Seen Package Price: Most Recent Date

The dashboard package tooltip's "Lowest seen" date showed the first time that price was ever observed. When the same low price recurs, what you actually want to know is how recently -- the tiebreaker now surfaces the most recent sighting.