Paul Nothaft
04a7ea80f9
feat: add visual WYSIWYG email template editor ( #229 )
...
Replace raw HTML textarea with TipTap-based rich text editor for email
templates. Includes formatting toolbar, variable insertion dropdown,
source/visual toggle, and dark mode support. Add Mailhog service to
docker-compose for local email testing.
2026-03-15 22:05:27 +01:00
Paul Nothaft
c0a5cd56c8
Merge pull request #232 from the-luap/i18n/ru-missing-keys
...
i18n: add missing Russian translations for thumbnails and photo dimensions
2026-03-15 20:12:22 +01:00
Paul Nothaft
908ab08815
Merge beta to resolve conflicts for PR #232
2026-03-15 20:02:27 +01:00
Paul Nothaft
52ab609597
i18n: add missing Russian translations for thumbnails and photo dimensions
...
Adds 38 missing keys for settings.thumbnails and settings.photoDimensions
that were added after the initial Russian localization PR (#216 ).
2026-03-15 19:48:41 +01:00
Paul Nothaft
fafcfbf4e6
Merge pull request #216 from Ih0rd/russian-localization
...
basic Russian localization
2026-03-15 19:47:25 +01:00
Paul Nothaft
f07602553c
Merge pull request #228 from the-luap/release-please--branches--beta
...
Build and Push Docker Images / build-backend (push) Failing after 3m24s
Build and Push Docker Images / build-frontend (push) Failing after 3m25s
Build and Push Docker Images / summary (push) Successful in 3s
chore(beta): release 3.17.2-beta.0
v3.17.2-beta.0
2026-03-11 21:54:58 +01:00
Paul Nothaft
56f497c5f1
Merge pull request #227 from the-luap/release-please--branches--main
...
Build and Push Docker Images / build-backend (push) Failing after 3m29s
Build and Push Docker Images / build-frontend (push) Failing after 3m40s
Build and Push Docker Images / summary (push) Successful in 3s
chore(main): release 2.6.1
v2.6.1
2026-03-11 21:54:39 +01:00
github-actions[bot]
d2663bff81
chore(beta): release 3.17.2-beta.0
2026-03-11 19:48:06 +00:00
github-actions[bot]
b52cf1f741
chore(main): release 2.6.1
2026-03-11 19:48:05 +00:00
Paul Nothaft
308e086263
Merge pull request #226 from the-luap/fix/security-reporting-policy
...
fix: update security policy with private reporting channels
2026-03-11 20:47:51 +01:00
Paul Nothaft
7f7736282f
Merge pull request #225 from the-luap/fix/security-reporting-policy
...
fix: update security policy with private reporting channels
2026-03-11 20:47:41 +01:00
Paul Nothaft
67b0f32456
fix: update security policy with proper contact email and private reporting
...
- Replace placeholder security@example.com with info@picpeak.app
- Add GitHub Private Vulnerability Reporting links
- Update supported versions table to 2.x.x
Closes #223
2026-03-11 20:21:32 +01:00
Paul Nothaft
25b40c03b0
Merge pull request #224 from the-luap/release/beta-to-main
...
Merge beta into main
2026-03-11 20:19:10 +01:00
Paul Nothaft
28793bba68
Merge main into beta for release/beta-to-main
2026-03-11 20:12:52 +01:00
Paul Nothaft
4ae91142f8
Merge pull request #222 from the-luap/release-please--branches--main
...
Build and Push Docker Images / build-backend (push) Failing after 3m23s
Build and Push Docker Images / build-frontend (push) Failing after 3m18s
Build and Push Docker Images / summary (push) Successful in 2s
chore(main): release 2.6.0
v2.6.0
2026-03-11 12:01:51 +01:00
github-actions[bot]
c92879fbd3
chore(main): release 2.6.0
2026-03-11 10:57:06 +00:00
Paul Nothaft
a0bb080586
Merge pull request #221 from the-luap/fix/video-upload-select-all-dimensions
...
fix: video upload, select all, and dimension repair (#203 , #220 , #180 )
2026-03-11 11:56:38 +01:00
Paul Nothaft
fc75bcdfc3
fix: video upload media type, select all, and dimension repair ( #203 , #220 , #180 )
...
- Fix admin video upload missing media_type/mime_type and video processing (#203 )
- Fix Gallery-Premium Select All using atomic callbacks instead of stale closure loop (#220 )
- Add photo dimension repair endpoint and admin UI (#180 )
- Add E2E tests for all three fixes
2026-03-11 11:50:43 +01:00
Paul Nothaft
9877f63aed
Merge pull request #219 from the-luap/release-please--branches--beta
...
Build and Push Docker Images / build-frontend (push) Failing after 3m20s
Build and Push Docker Images / build-backend (push) Failing after 3m20s
Build and Push Docker Images / summary (push) Successful in 2s
chore(beta): release 3.17.1-beta.0
v3.17.1-beta.0
2026-03-08 15:47:06 +01:00
github-actions[bot]
0c98c6b453
chore(beta): release 3.17.1-beta.0
2026-03-08 14:42:28 +00:00
Paul Nothaft
831ea6a3bc
Merge pull request #218 from the-luap/fix/optional-email-event-creation
...
fix: respect optional email settings in event creation
2026-03-08 15:42:14 +01:00
Paul Nothaft
9c44a0ebfa
fix: respect optional email settings in event creation ( #217 )
...
When admin/customer emails were configured as optional in Settings >
Event Creation, the backend still rejected empty values because:
1. express-validator .optional() only skips undefined, not empty strings
— changed to .optional({ values: 'falsy' }) so "" is treated as
absent
2. DB columns host_email and admin_email had NOT NULL constraints
— added migration to make them nullable
3. Email queue insert crashed on null recipient_email
— skip queuing when no customer email is provided
2026-03-08 15:36:38 +01:00
Ih0rd
a840ad4594
basic Russian localization
2026-03-06 06:17:30 +03:00
Paul Nothaft
08ac238d0a
Merge pull request #215 from the-luap/release-please--branches--beta
...
Build and Push Docker Images / build-backend (push) Failing after 3m31s
Build and Push Docker Images / build-frontend (push) Failing after 3m31s
Build and Push Docker Images / summary (push) Successful in 3s
chore(beta): release 3.17.0-beta.0
v3.17.0-beta.0
2026-03-05 22:22:58 +01:00
github-actions[bot]
7d967a47ae
chore(beta): release 3.17.0-beta.0
2026-03-05 21:21:48 +00:00
Paul Nothaft
9b7495e005
Merge pull request #214 from the-luap/feat/configurable-upload-batch-size
...
feat: configurable upload batch size for reverse proxy compatibility
2026-03-05 22:21:29 +01:00
Paul Nothaft
e1ad4219a5
Merge pull request #212 from the-luap/revert-210-feat/configurable-upload-batch-size
...
Revert "feat: configurable upload batch size for reverse proxy compatibility"
2026-03-05 22:16:43 +01:00
Paul Nothaft
cc4503ad28
Revert "feat: configurable upload batch size for reverse proxy compatibility"
2026-03-05 22:16:28 +01:00
Paul Nothaft
424336340b
Merge pull request #210 from the-luap/feat/configurable-upload-batch-size
...
feat: configurable upload batch size for reverse proxy compatibility
2026-03-05 22:14:41 +01:00
Paul Nothaft
a8308a5c02
Merge pull request #209 from the-luap/release-please--branches--beta
...
Build and Push Docker Images / build-frontend (push) Failing after 3m37s
Build and Push Docker Images / build-backend (push) Failing after 3m38s
Build and Push Docker Images / summary (push) Successful in 3s
chore(beta): release 3.16.0-beta.0
v3.16.0-beta.0
2026-03-05 22:14:28 +01:00
Paul Nothaft
02a46e083d
feat: add configurable upload batch size for reverse proxy compatibility ( #208 )
...
Users behind Cloudflare Tunnel and other reverse proxies cannot upload
batches >100MB. The upload chunking previously used a hardcoded 500MB
limit. This adds a configurable `max_upload_batch_size_mb` setting
(default 95MB) to the admin General settings, leaving headroom below
Cloudflare's 100MB limit.
2026-03-05 22:12:37 +01:00
github-actions[bot]
98fd6dd8e1
chore(beta): release 3.16.0-beta.0
2026-03-05 20:38:56 +00:00
Paul Nothaft
3a30fea862
Merge pull request #207 from the-luap/fix/github-issues-194-197-main
...
feat: add thumbnail settings UI to admin panel
2026-03-05 21:38:41 +01:00
Paul Nothaft
7d6d2f5688
feat: add thumbnail settings UI to admin settings page ( #206 )
...
Add a new "Thumbnails" tab in the admin settings page allowing users to
configure thumbnail dimensions, quality, format, and fit mode from the UI.
Also fix backend route column name mismatch (key/value → setting_key/setting_value)
that caused a 500 error, and add a button to regenerate all thumbnails.
2026-03-04 22:55:14 +01:00
Paul Nothaft
b5074e4e46
Merge pull request #205 from the-luap/release-please--branches--beta
...
Build and Push Docker Images / build-frontend (push) Failing after 3m24s
Build and Push Docker Images / build-backend (push) Failing after 3m25s
Build and Push Docker Images / summary (push) Successful in 4s
chore(beta): release 3.15.3-beta.0
v3.15.3-beta.0
2026-03-02 23:18:27 +01:00
github-actions[bot]
a1d941f049
chore(beta): release 3.15.3-beta.0
2026-03-02 22:18:06 +00:00
Paul Nothaft
80171713e0
Merge pull request #204 from the-luap/fix/github-issues-194-197-main
...
fix: issue #203 file type validation + security CVE fixes
2026-03-02 23:17:50 +01:00
Paul Nothaft
c0301dcbf4
Merge branch 'beta' into fix/github-issues-194-197-main
2026-03-02 23:15:37 +01:00
Paul Nothaft
cbecb9323c
fix(security): resolve Docker image CVEs for code scanning alerts
...
- Upgrade nginx base from 1.27-alpine to 1.28-alpine (Alpine 3.23, OpenSSL 3.5.5)
- Upgrade npm to latest in backend production stage to fix tar, minimatch, brace-expansion CVEs
- Add brace-expansion and minimatch overrides for app-level transitive deps
- Remove incompatible body-parser v2 override (breaks Express 4 JSON parsing)
- Remove npm upgrade from builder stages (npm 11 breaks npm ci with existing lockfile)
2026-03-02 23:06:15 +01:00
Paul Nothaft
4272618b3f
fix(security): resolve all npm audit vulnerabilities
...
Frontend (6 → 0 vulnerabilities):
- axios: update to fix DoS via __proto__ key in mergeConfig (CVE-2026-25639)
- swiper: update to fix prototype pollution (critical)
- rollup: update to fix arbitrary file write via path traversal
- minimatch: update to fix multiple ReDoS vulnerabilities
- ajv: update to fix ReDoS with $data option
- markdown-it: update to fix ReDoS
Backend (32 → 0 vulnerabilities):
- multer: update to fix DoS via incomplete cleanup and resource exhaustion
- minimatch: update to fix multiple ReDoS vulnerabilities
- Add npm overrides for transitive dependencies:
- fast-xml-parser >=5.3.8 (fixes XSS, DoS, stack overflow via AWS SDK)
- qs >=6.14.2 (fixes arrayLimit bypass DoS via Express)
- tar >=7.5.8 (fixes path traversal and hardlink attacks via sqlite3)
Docker:
- Pin nginx base image to 1.27-alpine in Dockerfile.prod
- Update security comments in backend Dockerfile
- Existing apk upgrade --no-cache ensures OpenSSL/libexpat CVEs are
patched at build time (OpenSSL 3.5.5, Alpine 3.23.3)
2026-03-02 10:36:47 +01:00
Paul Nothaft
fe07a148f1
fix: respect allowed_file_types setting for upload validation ( #203 )
...
The "Allowed File Types" admin setting was stored in the database but
never actually read during upload validation. Both frontend and backend
used hardcoded MIME type lists, causing video uploads (e.g. MP4) to be
rejected even when explicitly added to the setting.
Changes:
- Add getAllowedMimeTypes() to uploadSettings service that reads the
general_allowed_file_types DB setting and converts extensions to MIME types
- Backend admin upload route now resolves allowed types from settings
before multer processes files (via resolveAllowedTypes middleware)
- Backend gallery upload route uses dynamic allowed types from settings
- Expose allowed_file_types in public settings API for gallery clients
- Frontend PhotoUpload and UserPhotoUpload components now derive allowed
MIME types from settings instead of hardcoded image-only lists
- Add shared fileTypes.ts utility for extension-to-MIME conversion
Closes #203
2026-03-01 14:36:34 +01:00
Paul Nothaft
0ec4190e2e
Merge pull request #201 from the-luap/release-please--branches--main
...
Build and Push Docker Images / build-backend (push) Failing after 3m17s
Build and Push Docker Images / build-frontend (push) Failing after 3m17s
Build and Push Docker Images / summary (push) Successful in 2s
chore(main): release 2.5.1
v2.5.1
2026-02-23 20:10:21 +01:00
Paul Nothaft
0ec3787150
Merge pull request #200 from the-luap/release-please--branches--beta
...
Build and Push Docker Images / build-backend (push) Failing after 3m22s
Build and Push Docker Images / build-frontend (push) Failing after 3m22s
Build and Push Docker Images / summary (push) Successful in 3s
chore(beta): release 3.15.2-beta.0
v3.15.2-beta.0
2026-02-23 20:10:12 +01:00
github-actions[bot]
59faf73f04
chore(main): release 2.5.1
2026-02-22 21:37:40 +00:00
github-actions[bot]
3e0c4fd73e
chore(beta): release 3.15.2-beta.0
2026-02-22 21:37:26 +00:00
Paul Nothaft
33af088560
Merge pull request #199 from the-luap/fix/github-issues-194-197-main
...
fix: resolve issues #194 , #195 , #196 , #197
2026-02-22 22:37:21 +01:00
Paul Nothaft
5ea4ef3cf3
Merge pull request #198 from the-luap/fix/github-issues-194-197
...
fix: resolve issues #194 , #195 , #196 , #197
2026-02-22 22:37:11 +01:00
Paul Nothaft
33483cf32d
fix: resolve issues #194 , #195 , #196 , #197
...
- #194 : Send full date format object instead of just format string to prevent JSON parse errors
- #195 : Remove non-functional forgot password link, fix README port 3005 -> 3000
- #196 : Use ADMIN_PASSWORD env var in migration, update existing user in create-admin script instead of failing
- #197 : Convert camelCase filter keys to snake_case in photo export to match backend PhotoFilterBuilder
2026-02-22 22:34:44 +01:00
Paul Nothaft
cd00bc13d4
fix: resolve issues #194 , #195 , #196 , #197
...
- #194 : Send full date format object instead of just format string to prevent JSON parse errors
- #195 : Remove non-functional forgot password link, fix README port 3005 -> 3000
- #196 : Use ADMIN_PASSWORD env var in migration, update existing user in create-admin script instead of failing
- #197 : Convert camelCase filter keys to snake_case in photo export to match backend PhotoFilterBuilder
2026-02-22 22:27:21 +01:00
Paul Nothaft
26ec9666b9
Merge pull request #193 from the-luap/release-please--branches--main
...
Build and Push Docker Images / build-backend (push) Failing after 3m47s
Build and Push Docker Images / build-frontend (push) Failing after 3m40s
Build and Push Docker Images / summary (push) Successful in 3s
chore(main): release 2.5.0
v2.5.0
2026-02-21 20:52:30 +01:00