Files
picpeak/CHANGELOG.md
T
Paul Nothaft 1f09ac2d0d
Build and Push Docker Images / build-frontend (linux/amd64, ubuntu-latest) (push) Successful in 10m56s
Build and Push Docker Images / build-backend (linux/amd64, ubuntu-latest) (push) Failing after 23m12s
Build and Push Docker Images / smoke-aio (push) Failing after 12m6s
Build and Push Docker Images / build-ml (linux/amd64, ubuntu-latest) (push) Has been skipped
Build and Push Docker Images / build-aio (linux/amd64, ubuntu-latest) (push) Successful in 13m13s
Build and Push Docker Images / dockerhub-descriptions (push) Has been cancelled
Build and Push Docker Images / build-backend (linux/arm64, ubuntu-24.04-arm) (push) Has been cancelled
Build and Push Docker Images / merge-backend (push) Has been cancelled
Build and Push Docker Images / build-frontend (linux/arm64, ubuntu-24.04-arm) (push) Has been cancelled
Build and Push Docker Images / merge-frontend (push) Has been cancelled
Build and Push Docker Images / build-aio (linux/arm64, ubuntu-24.04-arm) (push) Has been cancelled
Build and Push Docker Images / merge-aio (push) Has been cancelled
Build and Push Docker Images / build-ml (linux/arm64, ubuntu-24.04-arm) (push) Has been cancelled
Build and Push Docker Images / merge-ml (push) Has been cancelled
Build and Push Docker Images / summary (push) Has been cancelled
chore(main): release 3.127.0-beta.0 (#1331)
2026-09-07 07:29:24 +00:00

339 KiB
Raw Blame History

Changelog

All notable changes to PicPeak will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

3.127.0-beta.0 (2026-09-07)

Features

  • usage: open the portal signed in, and rewrite the German copy (a02fa08)
  • usage: open the portal signed in, with the credential never in a served URL (f114f3e)
  • usage: plain link to the public usage portal, German opt-in copy (a16ff85)
  • usage: plain link to the public usage portal, German opt-in copy (7e40579)

Bug Fixes

  • analytics: send Umami page views through track(), not the removed trackView() (5b8c13f)
  • gallery: honor canvas settings in the Premium lightbox (fde0558)
  • gallery: honor canvas settings in the Premium lightbox (9edce85)
  • gallery: keep canvas rendering in the lightbox, render tiles as <img> (0986f7f)
  • i18n: rewrite the German product-usage copy (35cbcef)
  • security: bump sanitize-html to 2.17.7 (7c968e7)
  • security: bump sanitize-html to 2.17.7 (6583178)
  • security: stop a gallery viewer's own image fetches spending the anonymous budget (ac24319)
  • security: stop a gallery viewer's own image fetches spending the anonymous budget (7b2dd3f)
  • setup: require Node 22.12 for sanitize-html (e06d0b4)

3.126.3-beta.0 (2026-09-06)

Bug Fixes

  • usage: introduce consented v4 download restriction reporting (5306fe3)
  • usage: introduce consented v4 without changing historical reports (ef8a52f)

3.126.2-beta.0 (2026-09-06)

Bug Fixes

  • gallery: release grid tiles once they are far enough out of view (b3937d0)
  • gallery: retry a failed image fetch once the tile is back on screen (c4b03a8)
  • gallery: retry a failed image fetch once the tile is back on screen (77ae94e)

3.126.1-beta.0 (2026-09-06)

Bug Fixes

  • usage: preserve compatibility with old and partial reports (b801f3a)
  • usage: preserve report contracts with compatible receiver validation (7ca783f)

3.126.0-beta.0 (2026-09-06)

Features

  • usage: add beta capabilities and gallery/photo totals with explicit consent (b0bb65d)

3.125.0-beta.0 (2026-09-06)

Features

  • add opt-in product usage and feedback (#1110) (35b42bb)
  • expand opt-in capability coverage with versioned consent (a738259)

Bug Fixes

  • usage: close the QA findings on opt-in product usage (1e8b6f1)
  • usage: let an operator clear a participation the collector never accepted (e40bc47)

Documentation

  • usage: state in the consent dialog that the connection only runs outwards (c741dc2)

3.124.1-beta.0 (2026-09-05)

Bug Fixes

  • remove the fragmentation handling stranded by #1303 (5dda14f)

3.124.0-beta.0 (2026-09-05)

Features

  • newsletters: warn about deliverability before a large send (0536c86)
  • newsletters: warn about deliverability before a large send (49197be)

Bug Fixes

  • gallery: give the Grid layout a lazy-loading pre-load band (#1287) (b1e5287)
  • gallery: image-loading follow-ups — pre-load band, decode release, sanitizer dedup (905fc59)
  • gallery: release the canvas decode when it is drawn, not at unmount (fbe9757), closes #1287
  • gallery: release the canvas-mode decode, and drop a now-duplicate sanitizer (be8d79e)
  • gallery: remove the inert image-protection prop surface from AuthenticatedImage (1f316ef)
  • gallery: remove the inert image-protection prop surface from AuthenticatedImage (e734e41), closes #1297
  • newsletters: make the warning's duration and queue claim honest (7b4a65e)
  • remove the image-fragmentation surface (ae23b1a)
  • remove the image-fragmentation surface (967224c)
  • security: apply image-security defaults on every creation path (ab6c33d), closes #1296
  • security: apply the Image-security defaults instead of storing them (#1296) (2e9bd54)
  • security: apply the Image-security defaults instead of storing them (#1296) (8ca3610)
  • security: check for an escaped identifier before consuming the escape (b6dc099), closes #1264
  • security: close the remaining image-security default gaps (19c518a), closes #1296
  • security: close two CSS url() bypasses the sanitizer dedup exposed (1cf8274)
  • security: decode settings at the API boundary and honour the transaction (0e560eb), closes #1296
  • security: one settings decoder, and the last creation path (0deef25), closes #1296
  • security: re-check inline CSS after template substitution (027afb6), closes #1264
  • security: reject array values for every field on the event update (933f2d8), closes #1296
  • security: reject array values on the event update route too (8f3436f), closes #1296
  • security: strip control characters before scanning CSS for url() (99f54a3), closes #1264
  • security: use CSS whitespace, not JavaScript's, in the url() reader (4196e83), closes #1264
  • security: validate CSS urls last, after every pass that moves text (1151e96), closes #1264

3.123.0-beta.0 (2026-09-04)

Features

  • crm: newsletter campaigns behind a newsletters flag (#1264) (fc59540)
  • email: global signature footer from the business profile (#1264) (b6e40b9)

Bug Fixes

  • cms: enable the Tailwind typography plugin so prose classes work (#1288) (de3a7f7)
  • gallery: bound concurrent image fetches and abort them on unmount (#1287) (4afe7a6)
  • gallery: show a guest their own likes when feedback sharing is off (#1286) (8f98f6b)
  • security: make the CSS sanitizer's remote-URL block actually block (a7d0972)

3.122.7-beta.0 (2026-09-03)

Bug Fixes

  • security: batch 1 — zxcvbn DoS, revocation forgery, unlink traversals, stored Content-Type, edge middleware (ea394b5)
  • security: bound password input before zxcvbn, and drop the legacy media mounts (14cd5ea)
  • security: chunked-upload init checks the size cap before the type allow-list (0ac006b)
  • security: close four middleware gaps around the API edge (839bf4e)
  • security: contain logo, favicon and PDF-logo unlinks to their upload directories (3e46530)
  • security: enforce the strength-endpoint validators, and stop the generator spinning (054cd6f)
  • security: harden four smaller gallery and contract paths, drop the unmounted photo auth middleware (835312e)
  • security: never serve a photo under its stored MIME, and stop trusting the chunked-upload type (063977d)
  • security: stop reflecting submitted passwords in validation errors (903e471)
  • security: stop reflecting submitted values in validation errors everywhere, cap credential lengths, close the login timing oracle (40a8a98)
  • security: verify the signature before writing a token to the revocation list (0ca0e4a)

Documentation

  • document the upload allow-list and the chunked-upload type rule (f3b062a)
  • move the upload file-types page to the docs repository (659aa77)

3.122.6-beta.0 (2026-09-03)

Bug Fixes

  • gallery: follow the input in use, not the device's primary pointer (#1275) (a87e688)

3.122.5-beta.0 (2026-09-02)

Bug Fixes

  • crm: label the two invitation conflicts and stop guessing after a 5xx (bc90b4d)
  • crm: stop the invitation UI claiming more than it can know (6bb12c6)
  • crm: tell the admin whether a customer's invitation actually went out (1b8e5f8)
  • crm: tell the admin whether a customer's invitation actually went out (#1261) (b9c29fc)
  • email: compare queue timestamps in JS, and make retry actually send (89db469)
  • email: make waiting rows read-only, and time the grace from when due (4deac22)
  • email: read naive SQLite timestamps as UTC, and page the candidates (98aa06a)
  • email: show a queue nobody is working instead of reporting all-clear (73d8675)
  • email: show a queue nobody is working instead of reporting all-clear (#1262) (ec1df70)
  • email: wire the settings status card, and cap-aware truncation (2d403f7)
  • gallery: decide the overlay by pointer capability, not viewport width (d027488)
  • gallery: stop invisible overlay controls swallowing mobile taps (c0d3479)
  • gallery: stop invisible overlay controls swallowing mobile taps (#1263) (db197e7)

3.122.4-beta.0 (2026-09-02)

Bug Fixes

  • guests: keep guest identity across a tab close (#1265) (f722bda)

3.122.3-beta.0 (2026-09-02)

Bug Fixes

  • accounting: allow creating a customer from the picker (be39929)
  • accounting: let "bill to a customer" work with the portal off (3790156)
  • admin: interpolate activity and notification message values (78b1ddd)
  • admin: portal the update-available modal to document.body (ac50f0b)
  • analytics: serve self-hosted trackers same-origin so CSP stops blocking (3468550)
  • analytics: warn about the CSP allowlist on every tracker provider (3489610)
  • archives: run search, filter and sort server-side (fc7cb22)
  • archives: sort and total on real archive sizes, escape LIKE wildcards (da6e34d)
  • calendar: don't put a fixed reference date in the month header (76a1453)
  • categories: validate category name length instead of 500ing (5fa04e6)
  • close the remaining 2026-09-01 QA items, warnings and follow-on defects (cad699a)
  • contracts: add tooltips to the ellipsized block-library names (d16137b)
  • contracts: widen the block-library list column (bd44708)
  • email: derive preview sample data from each template's variables (1be2740)
  • email: give every template a real display name in the config UI (355fe4f)
  • email: give gallery_created a real German translation (73b08a7)
  • email: repair and seed the gallery lifecycle templates (41e1de7)
  • events: add archive_size to the immutable column deny-set (57dd084)
  • events: guard create-event submit against re-entrant submissions (c19e944)
  • events: honour ?tab=, show a load error, and stop lying about uploads (504a8b6)
  • events: rename a shadowing local and bound the photo-cap input (758dc00)
  • events: render a not-found state instead of hanging on a 404 (c2428aa)
  • events: return 409 instead of 500 when a slug is taken (afc5779)
  • feedback: align word-filter severity vocabulary with the admin UI (6f7aa59)
  • feedback: make the "block" severity tier actually reject (814f205)
  • gallery: no-store private JSON, and give guest uploads a real status (a28f96b)
  • gallery: restore the download CTA under headerStyle "none" (4c6ca49)
  • gallery: show a guest's own upload without a hard reload (18715b5)
  • gallery: stop browser zoom tripping the devtools viewport heuristic (72894e2)
  • gallery: stop devtools protection from breaking the whole page (9d4bd7a)
  • i18n: make i18n:ci pass by fixing the extractor config (5dbb435)
  • middleware: log ownership lookup failures; drop dead auth surface (42ba835)
  • migrations: judge each German field on its own in migration 195 (4515632)
  • per-field template guard, LIKE escaping, wait for all uploads (da8fcc8)
  • photos: emit visibility and processing_status from the list mapper (fe5ac91)
  • photos: treat category_id 0 as uncategorized instead of storing it (3f6c81a)
  • quotes: enforce the status state machine, and correct the table (103863c)
  • resolve the 2026-09-01 QA run findings (#1-#21) and repo-health debt (9b63399)
  • search: match the original filename, and honour the date-format setting (15fdd70)
  • search: stop escapeLikePattern corrupting bound search values (a89057d)
  • security: actually apply the general API rate limiter (b0f33c1)
  • security: apply per-IP rate limiting to credential endpoints (50e8ed6)
  • security: close the case-sensitivity bypass in the API rate limiter (a929aff)
  • security: raise the general limiter's fallback budget to 300 (19e125d)
  • security: rate-limit the password-change endpoints per IP too (5a0c9f5)
  • settings: clear the accounting flag when its parent is turned off (3e16b81)
  • settings: derive the sidebar preview from the real sidebar declaration (c6cb018)
  • settings: don't crash on a fresh load before permissions resolve (673f055)
  • settings: remove the duplicated section heading on 11 tabs (3acb452)
  • types: resolve the TypeScript build:check backlog (6e5755d)
  • ui: drop themed text colours from the last three admin surfaces (22cada9)
  • ui: stop branding-theme text colour rendering headings invisible (da9ceb1)
  • upload: enforce the chunked-upload cap on bytes received, not declared (77b11ab)
  • upload: enforce the configured per-file size limit on admin uploads (e18ab0d)
  • upload: scope category ids, stop temp-file leaks, split the video cap (7c9baff)
  • users: give the cancel-invitation dialog a distinct confirm label (31ffbc8)
  • webhooks: write delivery timestamps as ISO strings (c5c5a6b)
  • workflows: restore the once-per-process seed guard (a7d45dd)

Documentation

  • analytics: state the tracker proxy's trust model (23a433f)

3.122.2-beta.0 (2026-09-01)

Bug Fixes

  • upload: let Android guests reach the camera without breaking video (#1244) (66989d7)

3.122.1-beta.0 (2026-09-01)

Bug Fixes

  • archives: restore categories for original-filename archives on main too (#1252) (a35d2ba)
  • events: apply the gallery password policy to publish and send-later (#1253) (6938bad)

3.122.0-beta.0 (2026-09-01)

Features

  • events: publish without notifying, and send the gallery email later (#1235) (#1241) (1ef2b3c)

Bug Fixes

  • events: delete stored objects when cascading an event delete (#1051) (202c553)
  • single-photo gallery downloads 404 on S3 storage backends (#1048) (bb2f709)

3.121.4-beta.0 (2026-09-01)

Bug Fixes

  • auth: treat zxcvbn suggestions as advice, not blocking errors (#1050) (4f352de)

3.121.3-beta.0 (2026-08-30)

Bug Fixes

  • archives: take the restored category from the manifest (#1240) (0d340f4)

3.121.2-beta.0 (2026-08-29)

Bug Fixes

  • watcher: stop re-importing a photo whose file was replaced (#1226) (#1237) (6ca8baa)

3.121.1-beta.0 (2026-08-29)

Bug Fixes

  • email: keep the webhook payload out of the logs, and bound the response read (#1225) (#1233) (0d41fe5)

3.121.0-beta.0 (2026-08-29)

Features

Bug Fixes

  • export: name the camera master in photo exports, not the delivered render (#1229) (#1230) (f4c054a)
  • feedback: name the camera original in the exports, not just the stored file (#1224) (#1228) (4f684eb)

3.120.0-beta.0 (2026-08-28)

Features

  • api: Lightroom round-trip — read proofing marks, put finished edits back (#745) (#1165) (8db8527)

3.119.0-beta.0 (2026-08-28)

Features

Bug Fixes

  • gallery: make the returning-guest recovery findable (#1210) (#1217) (1f3f7e9)
  • guests: surface duplicate guest registrations, and stop making so many (#1210) (#1216) (5c85e0c)

3.118.0-beta.0 (2026-08-28)

Features

  • feedback: a third identity mode with one shared colour tag per photo (#1197) (#1208) (22e00f8)

3.117.0-beta.0 (2026-08-28)

Features

  • gallery: folders that contain photos instead of filtering them (#1160) (#1161) (0a36ca6)

Bug Fixes

3.116.1-beta.0 (2026-08-27)

Bug Fixes

  • images: fence the capture-date backfill on the file it read (#1201) (#1204) (cec8eff)

3.116.0-beta.0 (2026-08-26)

Features

  • auth: make the admin "Remember me" checkbox actually do something (#1186) (#1195) (d3e9a7c)

Bug Fixes

3.115.4-beta.0 (2026-08-26)

Bug Fixes

  • images: backfill orientation for libraries that predate the fix (#1199) (edef4d7)
  • images: respect EXIF orientation in thumbnails, heroes and previews (#1194) (c18f54e)

3.115.3-beta.0 (2026-08-26)

Bug Fixes

  • admin: gate the dimension repair as system maintenance (#1182) (3991dc3)
  • admin: make "Storage used" report storage used (#1164) (#1170) (849a580)
  • admin: move the maintenance sweeps' run state into the database (#1181) (#1184) (05e23ef)
  • external-media: record capture dates on import, and backfill existing libraries (#1172) (#1179) (410b8f8)
  • gallery: show other guests' colour labels in the grid (#1178) (#1180) (51d20c5)
  • gallery: stop the lightbox loading originals to display a photo (#1166) (#1169) (77953c1)
  • previews: preserve alpha and animation in the preview tier (#1171) (1366d6d)

3.115.2-beta.0 (2026-08-26)

Bug Fixes

3.115.1-beta.0 (2026-08-26)

Bug Fixes

3.115.0-beta.0 (2026-08-23)

Features

Bug Fixes

  • gallery: a guest's own hidden feedback is hidden from them too (#1150) (#1153) (2c81888)
  • gallery: guest filters respect show_feedback_to_guests, and marks survive a mid-write clear (#1147) (00b20b2)
  • gallery: no Logout button on galleries that don't require a password (#1149) (#1152) (e4a8be8)
  • scripts: regenerate-thumbnails resolves external sources through ensureThumbnail (#1148) (#1151) (b581267)

3.114.0-beta.0 (2026-08-23)

Features

  • gallery: colour labels for client proofing, and one global default per feedback type (#1044) (#1137) (e2844d1)

3.113.0-beta.0 (2026-08-22)

Features

  • faces: consolidate look-alike clusters after a scan, and suggest the rest (#1107) (3583c92)

Bug Fixes

  • gallery: a missing thumbnail tier must not take the backend down (#1128) (f735d26)
  • gallery: give masonry tiles their real shape back (#1130, #1131) (87115b2)
  • thumbnails: regenerate external photos instead of dropping their tiers (#1129) (97d92f8)

Documentation

  • faces: link the face-recognition guidance from where people look (#1125) (25fbefc)

3.112.0-beta.0 (2026-08-22)

Features

  • deploy: make the all-in-one image installable without a shell (#1124) (7223118)

3.111.1-beta.0 (2026-08-22)

Bug Fixes

3.111.0-beta.0 (2026-08-21)

Features

  • faces: show a detected face in its source photo, outlined (#1120) (38c27d0)

3.110.0-beta.0 (2026-08-21)

Features

  • faces: let the photographer choose which photo represents a person (#1119) (bbce3cd)
  • gallery: responsive grid thumbnails (#1095) (#1109) (887bdbe)

Bug Fixes

  • security: let cors() own Access-Control-Allow-Origin on protected images (#1118) (0077623)
  • ui: stop iOS Safari zooming in on 14px form fields (#1113) (d241919)

3.109.0-beta.0 (2026-08-21)

Features

  • setup: configure the public address and SMTP in the wizard, not .env (#1104) (9431b9f)

3.108.1-beta.0 (2026-08-20)

Bug Fixes

  • faces: face avatars were cropped against a cropped rendition (#1100) (b3a7ab2)

3.108.0-beta.0 (2026-08-20)

Features

  • gallery: sized preview tiers so phones stop pulling 1920px (#1095) (#1099) (011f6ae)

Bug Fixes

  • faces: defer on unreachable storage, and commit the import path first (#1097) (0b886ed)

3.107.5-beta.0 (2026-08-20)

Documentation

  • readme: point the single-container install at a tag that exists (2a84efe)
  • readme: point the single-container install at a tag that exists (e47c103)

3.107.4-beta.0 (2026-08-20)

Documentation

  • docker: Hub pages for aio + ml, and the image table in the README (899c9b3)

3.107.3-beta.0 (2026-08-20)

Bug Fixes

  • faces: scan external/reference photos instead of skipping them (#1090) (#1091) (576924f)

3.107.2-beta.0 (2026-08-19)

Bug Fixes

  • faces: restore the :beta image tag and surface sidecar health (#1087) (37a15e3)

3.107.1-beta.0 (2026-08-19)

Bug Fixes

  • preview: generate lightbox previews for external/reference photos (#1078) (#1079) (af7970b)

3.107.0-beta.0 (2026-08-18)

Features

  • faces: People in this gallery — face recognition via an optional ML sidecar (#1074) (#1075) (b69dd13)

3.106.0-beta.0 (2026-08-18)

Features

3.105.1-beta.0 (2026-08-16)

Bug Fixes

  • gallery: make per-event banner overrides actually work, both banners (#440, #932) (#1064) (52db982)

3.105.0-beta.0 (2026-08-16)

Features

3.104.1-beta.0 (2026-08-16)

Bug Fixes

  • pdf: RFC 6266-encode Content-Disposition on quote/invoice PDFs (#1024) (#1055) (3a11e6e)

3.104.0-beta.0 (2026-08-16)

Features

  • backup: open sqlite → pg .picpeak restore as the supported upgrade direction (#1041) (#1043) (8809564)

3.103.1-beta.0 (2026-08-16)

Bug Fixes

  • storage: add S3 client timeouts so a dropped connection can't wedge uploads (#1049) (3600231)

3.103.0-beta.0 (2026-08-16)

Features

  • permissions: granular permission gating + role editor & presets (#747, phase 1 of #743) (#1045) (b118695)

3.102.2-beta.0 (2026-08-13)

Bug Fixes

  • docker: default NODE_ENV=production so non-compose deploys don't fall back to SQLite (#1038) (#1039) (6de30e5)
  • events: make event_date/expires_at nullable on SQLite (#1029) (#1035) (671c4db)
  • feedback: persist guest feedback settings, unshadow the guest route (#1030) (#1031) (89dc962)
  • gallery: coerce SQLite 0/1 booleans in the guest surface (#1028) (#1034) (34ee311)

3.102.1-beta.0 (2026-08-11)

Documentation

  • flip README links to docs.picpeak.app + delete docs/_to-migrate (#1000 phase 3) (#1023) (27dedb1)

3.102.0-beta.0 (2026-08-11)

Features

3.101.5-beta.0 (2026-08-10)

Bug Fixes

  • slideshow: stop "no crop" fit letterboxing a pre-cropped frame (#1015) (#1018) (75bfad2)

3.101.4-beta.0 (2026-08-10)

Bug Fixes

  • deps: bump nanoid and js-yaml out of two HIGH advisories (#1013) (e3830cd)

3.101.3-beta.0 (2026-08-10)

Bug Fixes

3.101.2-beta.0 (2026-08-10)

Bug Fixes

  • branding: route the gallery footer through <PoweredBy /> (#1008) (1bf19a7)

3.101.1-beta.0 (2026-08-10)

Documentation

  • slim README to a lean router, stage deep content for docs-site migration (#1001) (ddebd50)

3.101.0-beta.0 (2026-08-09)

Features

  • transfers: add PicTransfer — cross-event file transfers (#998) (2e495d7)

3.100.2-beta.0 (2026-08-09)

Bug Fixes

  • branding: hide "Powered by PicPeak" on every page, not only the gallery (#999) (3bb4f1a)

3.100.1-beta.0 (2026-08-04)

Documentation

  • the retired registry path freezes, it does not stop serving (#995) (b9e4259)

3.100.0-beta.0 (2026-08-04)

Features

  • admin: surface the registry move through the update check (#993) (137a42f)
  • gallery: admin preview skips the password on protected galleries (#981) (f006615)

Bug Fixes

  • security: vet the destination project when linking a deal (#991) (0c8ad6b)

3.99.2-beta.0 (2026-08-04)

Bug Fixes

  • deps: bump ip-address, brace-expansion and postcss for open CVEs (#987) (6c03fea)

3.99.1-beta.0 (2026-08-04)

Bug Fixes

  • accounting: gate cross-add counters on the permission their endpoint checks (#984) (4b53b64)

3.99.0-beta.0 (2026-08-03)

Features

  • accounting: re-bill proof attachment, CRM panel & hours↔re-bills cross-add (#979) (165cebd)

3.98.6-beta.0 (2026-08-03)

Bug Fixes

  • auth: fail closed when the adminAuth roles join errors (#974) (6699855)
  • projects: stop the cockpit offering email controls the API rejects (#976) (67592fc)

3.98.5-beta.0 (2026-08-02)

Bug Fixes

  • security: enforce project ownership on project + project-email routes (GHSA-wrg5, GHSA-93x4) (#960) (7c0c0a5)

3.98.4-beta.0 (2026-08-02)

Bug Fixes

  • security: backup/restore hardening — public-dir DB dump, restore path allowlist, gunzip bound, manifest keying (#956) (0d4c308)
  • security: bound inbound-mail resources, redact secrets from logs (GHSA-2qf9, pgmp, r794) (#959) (1b4e5fe)
  • security: enforce event ownership on the v1 API surface (GHSA-9697) (#957) (e2ce95e)
  • security: escape brand tokens, block tracker redirects, trim logo diagnostic (GHSA-j347, mw76, 29vm) (#961) (164129b)
  • security: scope dashboard stats/analytics/activity to the caller's events (GHSA-c2jj, gqx7, jhcf) (#958) (da855cf)

3.98.3-beta.0 (2026-08-02)

Bug Fixes

  • security: authz/ownership gaps (token binding, auth revocation, feedback/customer ownership, token logging) (#950) (c2ce12c)
  • security: neutralize spreadsheet formulas in all CSV/export cell-writers (CSV injection cluster) (#948) (8f91c2c)
  • security: redact gallery share tokens from analytics tracking (GHSA-7m6c) (#952) (1c8f7d5)
  • security: unauth share_token leak (HIGH) + restore path-traversal, logo file-read, branding path keys (#946) (9050aff)

3.98.2-beta.0 (2026-08-01)

Bug Fixes

  • security: block guest access to hidden/client-only photos across bulk + secure routes (#939) (8a87c92)
  • security: bump sanitize-html to 2.17.5 (CVE-2026-53606) (#937) (fe615c8)
  • security: close authorization/ownership gaps (token scope, mass-assignment, category hero, project docs) (#943) (82d6871)
  • security: resolve DNS before vetting external hostnames (SSRF cluster) (#941) (b700569)

3.98.1-beta.0 (2026-08-01)

Bug Fixes

  • uploads: prevent cross-photo contamination from filename collisions and non-atomic writes (#931) (#933) (defeae9)

3.98.0-beta.0 (2026-07-31)

Features

  • gallery: mouse-wheel zoom at cursor in the lightbox (#885) (#927) (926a4a5)
  • gallery: multi-select feedback filters + sort direction controls (#889) (#929) (3bcded7)
  • gallery: per-event toggle to hide the logo on the password page (#894) (#928) (08ff9f2)

3.97.6-beta.0 (2026-07-30)

Bug Fixes

  • security: close GHSA-g94x (cross-gallery photo read) + GHSA-pv6w (admin DB export) (#924) (03087c7)

3.97.5-beta.0 (2026-07-30)

Bug Fixes

  • admin: code-review follow-ups on #910/#916 (MIME resolver + expiry reactivity) (#921) (252475f)

3.97.4-beta.0 (2026-07-29)

Bug Fixes

  • admin: expose view/download counters in the admin photos list (#895 follow-up) (#914) (aca3c8e)
  • admin: stop marking events expired up to 24h early (#909) (#916) (487f55f)

3.97.3-beta.0 (2026-07-29)

Bug Fixes

  • admin: serve videos with their real MIME type in the admin photo view (#908) (#910) (67c56c5)

3.97.2-beta.0 (2026-07-29)

Bug Fixes

  • analytics: make per-photo view/download counters actually count (#895) (#904) (78116e2)

3.97.1-beta.0 (2026-07-29)

Bug Fixes

  • tests: raise migration-boot hook timeout pins to the 120s default (#900) (d9ad982)

3.97.0-beta.0 (2026-07-29)

Features

3.96.1-beta.0 (2026-07-29)

Bug Fixes

  • gallery: keep the lightbox toolbar from masking the photo (#888) (#892) (ec66cd2)

3.96.0-beta.0 (2026-07-29)

Features

  • gallery: quick return from zoomed to fit-to-screen in the lightbox (#886) (#891) (97f6889)

3.95.5-beta.0 (2026-07-29)

Bug Fixes

  • gallery: don't close the lightbox when clicking beside the photo (#883) (#890) (34c2992)

3.95.4-beta.0 (2026-07-27)

Bug Fixes

  • sync gallery feedback filters after lightbox like/rating in simple mode (#882) (33f1bc4)

3.95.3-beta.0 (2026-07-27)

Bug Fixes

  • security: close 5 Trivy alerts — postcss/tar bumps + drop npm from the runtime image (#878) (08be2b8)

3.95.2-beta.0 (2026-07-27)

Bug Fixes

3.95.1-beta.0 (2026-07-26)

Bug Fixes

  • security: bump backend deps to close all 14 open Trivy code-scanning alerts (#869) (38b8d47)

3.95.0-beta.0 (2026-07-24)

Features

3.94.2-beta.0 (2026-07-23)

Bug Fixes

  • gallery: block password form in Instagram in-app browser and unmask login errors (#863) (323dcae)

3.94.1-beta.0 (2026-07-22)

Bug Fixes

  • tests: raise jest timeouts to survive the growing migration chain (#860) (40eb03f)

3.94.0-beta.0 (2026-07-22)

Features

Bug Fixes

  • dates: normalize SQLite epoch timestamps at remaining API surfaces (#485 follow-up) (#857) (c6ec93e)

3.93.0-beta.0 (2026-07-19)

Features

  • events: gallery QR code + printable table-card/poster PDFs (#847) (60cdd07)
  • notifications: surface guest activity in the admin bell (#849) (cb5b319)
  • slideshow: guest-scannable share-link QR overlay (#848) (e8dad4b)

Bug Fixes

  • crm: pass trx to logActivity inside transactions — audit rows silently lost on SQLite (#851) (a6a3c9f)

3.92.2-beta.0 (2026-07-19)

Bug Fixes

  • file-watcher: bound concurrent photo processing (#846) (8337a71)
  • security: read the password-complexity key the settings UI writes (#843) (8060fed)
  • uploads: keep videos when thumbnail generation fails (#845) (0310c46)

3.92.1-beta.0 (2026-07-19)

Bug Fixes

  • uploads: support configured raw formats (f7fd893)

3.92.0-beta.0 (2026-07-18)

Features

  • uploads: DNG / camera-RAW support via embedded-preview extraction (#821) (8c260c4)

3.91.0-beta.0 (2026-07-18)

Features

  • uploads: HEIC/HEIF support + dynamic format hint on guest upload (#821) (ee9d2f7)

Bug Fixes

  • gallery: serve JPEG preview for non-displayable originals in lightbox (codex review of #832) (808d305)
  • uploads: register HEIC/HEIF with the file validator + fix admin format hint (codex review of #832) (c9b64d9)

3.90.2-beta.0 (2026-07-17)

Bug Fixes

  • events: accept hero_logo_visible: null on create/update (#822) (0245e44)
  • events: accept hero_logo_visible: null on create/update (#822) (b97b130)
  • update: target docker-compose.production.yml in dashboard update steps (51a505e)
  • update: target docker-compose.production.yml in dashboard update steps + gate mailhog (2a0361a)
  • uploads: apply configured max file size to guest uploads (#613 follow-up) (29f1d23)
  • uploads: apply configured max file size to guest uploads (#613 follow-up) (1e38d84)
  • uploads: tighten guest max-file-size setting (codex review of #823) (43c6d22)
  • uploads: tighten guest max-file-size setting (codex review of #823) (e03d13e)

3.90.1-beta.0 (2026-07-17)

Bug Fixes

  • security: remove unguarded legacy /api/events router (GHSA-4j34-x562-5vfq) (e7ca8bd)
  • security: remove unguarded legacy /api/events router (GHSA-4j34-x562-5vfq) (6cd546e)

3.90.0-beta.0 (2026-07-16)

Features

  • auth: OIDC SSO for admin users — phase 1 (f12606b)

3.89.0-beta.0 (2026-07-16)

Features

  • security: harden .picpeak restore robustness — sessions, roles, sequences (a77c2c2)
  • security: harden .picpeak restore robustness — sessions, roles, sequences (340d91b)

Bug Fixes

  • security: close 4 open security advisories (backup takeover, share-login bypass, ZIP slip, chunked-upload traversal) (7ebc232)
  • security: harden .picpeak restore operator-preservation (GHSA-qxfx follow-up) (38fd41a)
  • security: preserve current admin on .picpeak restore (GHSA-qxfx-4493-4v8f) (348894e)
  • security: reject ZIP-slip entries in archive/backup restore (GHSA-jfhw-fj23-fx6x) (9cd6b08)
  • security: sanitize chunked-upload filename (GHSA-pc72-jf53-w28j) (31bc01c)
  • security: share-login must not bypass gallery password (GHSA-9hmx-68vc-qpqw) (7dace04)

3.88.1-beta.0 (2026-07-16)

Bug Fixes

  • security: mask backup credentials on read + unblock MFA login during maintenance (eadf282)
  • security: mask backup credentials on read + unblock MFA login during maintenance (07f2c90)

3.88.0-beta.0 (2026-07-15)

Features

  • setup: event-types step in first-run wizard + un-hardcode event type dependencies (109aba8)
  • setup: event-types step in first-run wizard + un-hardcode event type deps (#800) (7eb6357)

Bug Fixes

  • event-types: harden setup window + catalog validation (codex review) (f8ba669)
  • event-types: un-hardcode event type dependencies in v1 API and CRM (d64eef8)
  • event-types: un-hardcode event type dependencies in v1 API and CRM (#800) (5da1c3a)
  • gallery: show feedback filter chips on desktop for galleries without categories (0751a08)
  • gallery: show feedback filter chips on desktop for galleries without categories (#802) (b928338)

3.87.0-beta.0 (2026-07-11)

Features

  • invoices: configurable VAT note under MwSt. line + fix multi-page page-number overlap (#794) (ffd4a7e)
  • invoices: configurable VAT/free-text note + fix multi-page page-number overlap (#794) (1476884)

3.86.0-beta.0 (2026-07-10)

Features

  • categories: per-event category ordering — global default + override (#782) (d51112e)
  • categories: per-event category ordering — global default + override (#782) (4698402)

Bug Fixes

  • categories: address PR #790 review — event ownership, migration renumber, nits (a4b4485)

3.85.0-beta.0 (2026-07-10)

Features

  • slideshow: per-event play order + category filter (#202) (5467642)

3.84.1-beta.0 (2026-07-10)

Bug Fixes

  • ci: publish v-prefixed image tags via type=ref,event=tag (#668) (1f3bc3c)
  • ci: publish v-prefixed image tags via type=ref,event=tag (#668) (39db7bf)

3.84.0-beta.0 (2026-07-10)

Features

  • admin: GitHub repo button in the sidebar footer (#778) (279e047)
  • admin: GitHub repo button in the sidebar footer (#778) (d3d7df4)

Bug Fixes

  • ci: publish v-prefixed image tags so :vX.Y.Z resolves (#668) (2ee4146)
  • ci: publish v-prefixed image tags so :vX.Y.Z resolves (#668) (784d059)

Documentation

  • releasing: align stable version to main on promote (Option A) (df5aeab)
  • releasing: align stable version to main on promote (Option A) (5dea0c9)

3.83.1-beta.0 (2026-07-09)

Bug Fixes

  • release: target stable in release-please + undo bogus 2.7.0 bump (274ef0c)
  • release: target stable in release-please.yml + undo the bogus 2.7.0 bump (65ac6ed)

3.83.0-beta.0 (2026-07-08)

Features

  • messages: create/select quote, contract, invoice, gallery from a message (0dbf863)
  • messages: search bar + Archive/Delete with Archived & Deleted folders (99d5996)
  • messages: unified Messages email client (flag-gated, default off) (a71b9b5)

Bug Fixes

  • messages: PR #769 nits — server-side search, bare-email recipient, DE i18n (1e08a4f)
  • messages: PR #769 review — escape reply sender (XSS), gate backend routes, exact customer match (bb235e7)
  • messages: show the resolved customer's name in the doc-action modal (2c5c1d5)

3.82.6-beta.0 (2026-07-07)

Bug Fixes

  • workflows: backfill existing invoices + anchor dunning grace to due date when enabled (#750) (9596342)
  • workflows: scope dunning backfill to its own flow via targetWorkflowId (da3a77d)

3.82.5-beta.0 (2026-07-07)

Bug Fixes

  • admin: stop the event-date field crashing the page on backspace (760a201)

3.82.4-beta.0 (2026-07-07)

Bug Fixes

  • email,ui: billing emails follow customer language + readable payment-check confirmation (0c2d319)
  • email,ui: billing emails follow customer language + readable payment-check confirmation (fcc3e91)
  • email: sibling billing emails follow customer language too (c0008be)

3.82.3-beta.0 (2026-07-06)

Bug Fixes

  • branding: make 'Show logo in hero' a true global toggle with per-event override (#756) (a88da99)
  • branding: make 'Show logo in hero' a true global toggle with per-event override (#756) (96fe478)
  • branding: unify hero logo SIZE the same way as visibility (#756) (60b03b1)

3.82.2-beta.0 (2026-07-05)

Bug Fixes

  • og: broaden social-crawler coverage (Bluesky Cardyb, WeChat-scraper, fediverse, etc.) (a0a28a4)
  • og: route branded short URLs + slideshow links to OG, add Viber (#699) (0dffe0c)
  • og: route branded short URLs + slideshow to OG handler, add Viber (#699) (a87ad77)

3.82.1-beta.0 (2026-07-05)

Bug Fixes

  • invoices: correct payment-check email template key so dunning email sends (9a76333)
  • invoices: correct payment-check email template key so dunning email sends (3682de1)

3.82.0-beta.0 (2026-07-03)

Features

  • setup: final community step (#732) + fix create-admin button overflow (#730) (a5f49e3)
  • setup: final community/thank-you step (#732); fix create-admin button overflow (#730) (dadaaee)

3.81.0-beta.0 (2026-07-03)

Features

  • admin two-factor authentication (TOTP) with recovery codes + CLI reset (cf07361)
  • admin-ui: TOTP MFA enrollment + two-step login; remove stub 2FA toggle (96e3c68)
  • auth: admin TOTP MFA — enrollment, login challenge, recovery, CLI reset (72e2ef6)

Bug Fixes

  • event creation 500s on PostgreSQL (NaN slideshow seed) + stray "0" boolean renders (b187f58)
  • security: close cross-event thumbnail leak, bulk-op ownership bypass, + hardening (081f3ed)
  • security: cross-event thumbnail leak, bulk-op ownership bypass + auth hardening (b732974)

3.80.0-beta.0 (2026-07-03)

Features

  • backup: fold .picpeak restore into the Restore wizard's Upload source (86324e7)
  • first-run setup wizard (feature selection + config) and portable .picpeak backup roundtrip (e513e83)
  • setup: add restore-from-backup branch to the first-run wizard (a95ee47)
  • setup: per-feature config step after feature selection (07b450a)

Bug Fixes

  • backup: address .picpeak review — table filter, superuser guard, tests (fa7665c)
  • setup: keep the first-run wizard light regardless of dark mode (d4b143f)

3.79.1-beta.0 (2026-07-02)

Bug Fixes

  • settings: remove duplicate Mail import that broke the dev server (5b535f8)
  • settings: remove duplicate Mail import that crashes the dev server (4aa6583)

3.79.0-beta.0 (2026-07-02)

Features

  • setup wizard + argument-driven unattended install (681619f)
  • setup: step-by-step wizard + argument-driven unattended install (d35c413)

3.78.0-beta.0 (2026-07-02)

Features

  • zero-config first run — in-browser admin bootstrap + auto-generated secrets (bafc96f)

Bug Fixes

  • ci: enable release-PR auto-merge with the PAT, not GITHUB_TOKEN (e08a33d)
  • enable release-PR auto-merge with the PAT so releases actually publish (97b9853)

3.77.3-beta.0 (2026-07-02)

Bug Fixes

  • set GH_REPO in release-please auto-merge step (d00d52a)

3.77.2-beta.0 (2026-07-02)

Bug Fixes

  • auto-publish release-please PRs without manual approval (fb64ec0)
  • ci: auto-publish release-please PRs without manual approval (#719) (a3e7232)

3.77.1-beta.0 (2026-07-02)

Documentation

  • require screenshots for UI changes in PRs (f5b4aa7)
  • require screenshots for UI changes in PRs (8ca7477)

3.77.0-beta.0 (2026-07-01)

Features

  • admin photos list/grid toggle + upload failure report (#707, #708) (e873f7c)
  • admin photos list/grid toggle + upload failure report (#707, #708) (6f95796)

3.76.2-beta.0 (2026-06-30)

Bug Fixes

  • ci: whatsnew highlights — set GH_REPO so gh runs without a checkout (3feed0f)
  • ci: whatsnew highlights — set GH_REPO so gh runs without a checkout (2a5f0a8)

3.76.1-beta.0 (2026-06-30)

Bug Fixes

  • whatsnew: decode HTML entities and trim em-dash detail in fallback bullets (5582644)

3.76.0-beta.0 (2026-06-30)

Features

  • gallery: branded URL shortener — /s/<slug> with OG injection (#699) (a0f7033)

3.75.1-beta.0 (2026-06-30)

Bug Fixes

  • og: rich social previews for share-token + slideshow URLs (#699) (25bf7bb)
  • og: rich social previews for share-token + slideshow URLs (#699) (1b8747d)

3.75.0-beta.0 (2026-06-30)

Features

  • updates: "What's New" highlights after update + pre-update teaser (a1a73bf)
  • updates: "What's New" highlights after update + pre-update teaser (500cf85)

Documentation

3.74.0-beta.0 (2026-06-29)

Features

  • admin: in-app migration banner for the org rename (0213347)
  • admin: in-app migration banner for the org rename (#669) (2a4bf3b)

Documentation

  • branch model + migration-to-org guide + PR template (166ef47)
  • branch model + migration-to-org guide + PR-template target hint (d606fcd)
  • prominent migration banner at the top of README (14bd3e1)
  • prominent migration banner at the top of README (#669) (5839bba)

3.73.0-beta.0 (2026-06-29)

Features

  • dashboard: revenue "year" tile toggles 365 days ↔ calendar YTD (d1c9e02)
  • invoices: surface monthly/manual accumulator drafts in the Bills list (e457656)

Bug Fixes

  • invoices: add bank transfer to the mark-paid method list (e96ef4c)
  • invoices: badge held (unsent, no send date) invoices as "Draft" (e4367e0)
  • invoices: show "Draft" on the invoice detail page for accumulator drafts (ca09442)
  • reminders: wrap is_active/is_archived wheres in formatBoolean (b9d9138)

3.72.0-beta.0 (2026-06-28)

Features

  • workflows: booking cutover — wire booking actions + hold documents behind approval gates (ec33ec7)

Bug Fixes

  • workflows: defer quote.accepted/declined emit until the 15-min response window locks (539a837)
  • workflows: make the dashboard pending-approvals card items clickable too (6e20d58)

3.71.3-beta.0 (2026-06-27)

Bug Fixes

  • events: wire customer notifications into both public API entry points (#647) (f017542)

3.71.2-beta.0 (2026-06-27)

Bug Fixes

  • event-reminder, email-language & gallery-publish bugs surfaced during workflow testing (c8714ca)

3.71.1-beta.0 (2026-06-26)

Bug Fixes

  • admin: stack publish-gallery dialog CTAs so the German label fits (#670) (748af98)

3.71.0-beta.0 (2026-06-25)

Features

  • admin-configurable workflow engine + dunning/Mahngebühr rework (RFC — feedback welcome) (15be3b8)
  • workflows: per-quote booking-workflow picker + quote→invoice (no gallery) built-in (d14f1d8)
  • workflows: pre-event reminder picks the template GROUP on the block, type stays automatic (10d091b)
  • workflows: route webhook node through the delivery pipeline (full Option 1) (675e41a)
  • workflows: warn when disabling a built-in (reverts to legacy, not off) (c5f131c)

Bug Fixes

  • crm: pre-event reminder resolves recipient from the event row, not a non-existent column (5fbe514)
  • event-types: renaming a type's slug cascades to events, quotes + reminder template (415c93a)
  • workflows: close review blockers — prefetch-safe approvals + loud gate-edge failure (98ab717)
  • workflows: harden graph validation + refuse enabling unimplemented flows (d927464)
  • workflows: matchFilter strict equality + accurate comment (dee8d40)
  • workflows: ship built-ins disabled for first beta + enabled-based mutex + admin sentinel (5893ecb)
  • workflows: wire a real, SSRF-guarded webhook action (was a silent no-op) (af7eea8)

3.70.0-beta.0 (2026-06-23)

Features

  • analytics: pluggable trackers — Umami + Rybbit + Custom (#663 Phase 1) (83461fe)

3.69.1-beta.0 (2026-06-23)

Bug Fixes

  • analytics: admin dashboard reads correct fields + Umami device API (#661) (349f566)
  • analytics: admin dashboard reads correct fields + Umami device API (#661) (7534447)

3.69.0-beta.0 (2026-06-22)

Features

  • feedback: per-guest favorite + like caps with mobile-friendly limit modal (#655) (3ac7017)
  • feedback: per-guest favorite + like caps with mobile-friendly limit modal (#655) (f2814e4)

Bug Fixes

  • i18n: replace ASCII quote with U+201D in DE perGuestLimitsDesc (98e97e3)

3.68.1-beta.0 (2026-06-22)

Bug Fixes

  • gallery: unbreak password entry in Instagram in-app browser (#654) (6193ab7)
  • gallery: unbreak password entry in Instagram in-app browser (#654) (b1bfd48)
  • test: raise bootCrmDb beforeAll timeout on slideshow suites (f4b6b89)

3.68.0-beta.0 (2026-06-21)

Features

  • whatsapp: admin-selectable template parameters + reorder (#647 follow-up) (80e8ec5)

3.67.1-beta.0 (2026-06-21)

Bug Fixes

  • branding+whatsapp: preserve customCss through preset switches (#645) + admin-pinned WhatsApp template language (#647) (cde028e)

3.67.0-beta.0 (2026-06-21)

Features

  • Live Slideshow ("Diashow") — fullscreen, auto-updating projector view for live events (4356393)
  • slideshow: add image fit setting (fill vs black bars) (b5c73e0)
  • slideshow: admin ui for live slideshow (385b05a)
  • slideshow: backend api for live slideshow (dea5e0f)
  • slideshow: db columns for live slideshow (1029dd0)
  • slideshow: en/de strings for live slideshow (cb761ee)
  • slideshow: gate behind a feature flag + move globals to a Settings tab (69367b4)
  • slideshow: public fullscreen slideshow viewer (fd02254)

Bug Fixes

  • slideshow: deny display-only token on download/upload/feedback (PR #646 review) (e36b330)
  • slideshow: dip-to-white/black no longer flickers the image (db8388c)
  • slideshow: drop updated_at from event writes (1e40f82)
  • slideshow: feature flag is a master kill-switch, not just admin UI (759784a)
  • slideshow: fill the viewport instead of black bars (6ec46de)
  • slideshow: read globals from app_settings, not the missing settings table (0f4388d)
  • slideshow: surface backend error in the live slideshow card (056f938)

Performance Improvements

  • slideshow: cache global settings to cut /state DB reads (PR #646 review) (a995131)

Documentation

  • slideshow: add Live Slideshow guide + README entries (16013d1)

3.66.1-beta.0 (2026-06-19)

Bug Fixes

  • deps: bump qs/brace-expansion overrides + add uuid override for node-cron (d705059)
  • security: close BOLA on photo-export + NAT64 SSRF in URL guard (b8211e9)
  • security: close NAT64 SSRF + photo-export BOLA + sweep Trivy alerts (GHSA-wmjx-pc37-272r, GHSA-9v4w-jrhx-g5wr) (6f40db8)

3.66.0-beta.0 (2026-06-19)

Features

  • categories: per-category download permissions (#640 part B) (820f483)
  • common: generic Promise-based ConfirmDialog primitive (#640 part C) (a3fcb5b)
  • feedback: export shape toggle — per-action vs per-guest pivot (#640 part E) (fabd67a)
  • whatsapp: WhatsApp Business API notification channel (#640 part D) (78c8e9d)

Bug Fixes

  • archives: stream-extract restore for >2 GiB + preserve original_filename via manifest (#640) (e4e79a0)
  • i18n: wrap WhatsApp token show/hide aria-label through t() (a8bb7b4)
  • settings: hoist tab-visibility useEffect above isLoading early return (49bfb45)

3.65.1-beta.0 (2026-06-18)

Bug Fixes

  • i18n: sweep activity-type translations + Events / API Tokens / Webhooks settings tabs (f17c654)

3.65.0-beta.0 (2026-06-18)

Features

  • accounting: consolidate VAT/financial config into Settings → Accounting (dc7b87b)
  • accounting: explain dispositions inline, drop markup from pass-through (9a023c0)
  • accounting: incoming-invoice workflow v2 + VAT/financial settings consolidation (b527915)
  • accounting: invoices force-enable the Accounting master (51837c3)
  • accounting: re-categorize incoming invoices, note field, pending re-bill pool (36a8e42)
  • accounting: supplier-country tax default + configurable default output VAT code (267b121)

Bug Fixes

  • accounting: address the-luap PR #636 review (707c5d0)
  • accounting: tax-report storno totals + hours-line date on Postgres (db9e41d)
  • crm: editor totals box computed VAT 100× too small (e9b297c)
  • hours: move logActivity out of the entry transactions (SQLite deadlock) (348955b)

3.64.0-beta.0 (2026-06-18)

Features

  • admin/exports: inline preview modal with copy-to-clipboard (#631) (fc5c1ae)
  • admin/exports: inline preview modal with copy-to-clipboard (#631) (27b5f7e)

3.63.0-beta.0 (2026-06-17)

Features

Bug Fixes

  • events: publish-from-draft email carries the real password (#627) (83b568e)
  • gallery: admin edits to welcome_message land for returning guests (#625) (ea6245c)
  • upload: auto-throttle on low-memory hosts + correct documented RAM minimum (#628) (714a9f6)

3.62.0-beta.0 (2026-06-17)

Features

  • accounting: add a Banana "Income & Expense" (cash-book) export format (445d6d7)
  • accounting: bill editor VAT dropdown + GET returns vat_code snapshot (2479d87)
  • accounting: clearer tax-export window + gate journal export on accounting flag (3edd832)
  • accounting: data-driven revenue-rate VAT map (multi-country) (873be91)
  • accounting: move Chart of accounts into Settings → Accounting (97795f6)
  • accounting: move Treuhänder export onto the Tax page (b1f73c1)
  • accounting: relocate VAT codes + rate maps into Settings → Accounting (4ff5b84)
  • accounting: scope the tax-report export to income-only or cost-only (9f3b286)
  • accounting: snapshot the chosen VAT code on quote/invoice create + storno (5b52969)
  • accounting: snapshot vat_code on quotes/invoices + export prefers it (foundation) (0a7dc1c)
  • accounting: tax report VAT-payable honours registration + reclaim (d7107aa)
  • accounting: unify tax report into one signed, typed, sortable ledger (fd1dd81)
  • accounting: VAT registration + reclaim-country settings in the Accounting tab (4d87684)
  • accounting: VAT registration/reclaim settings + un-gated VAT-codes read (fbbbb8a)
  • accounting: VAT-code dropdown in the quote editor (+ reusable VatRateSelect) (6e1924b)
  • branding: force color mode = standard look; hide overridden theme controls (4749e22)

Bug Fixes

  • accounting: Banana export is now a tab-separated .txt (actually importable) (a195067)
  • accounting: Banana I&E export uses the 'Category' column (not 'ContraAccount') (53a16f9)
  • accounting: emit ISO dates in exports (Postgres returns Date objects) (0c0fb29)
  • accounting: label the outgoing-invoice totals block in the tax summary (f3e77e7)
  • accounting: PR #622 blockers — CSV formula injection + IMAP double-ingest race (cd6d578)
  • accounting: PR #622 concerns — flag-cache, customer master gate, VAT-unconfigured, helpers, page cap (a93b6dc)
  • accounting: tax report cost side queried a non-existent column (ab65a47)
  • accounting: tidy the tax-export scope selector styling (8deb7e0)
  • accounting: UTF-8 BOM on the ledger export so Banana reads it correctly (74144da)
  • branding: force lock = light/dark only; Branding stays the full preset, galleries hide color+mode (a7c1913)
  • branding: when a force lock is active, collapse the theme customizer to just the Force control (1ac653a)
  • crm: admin surfaces follow the admin light/dark toggle, not the gallery theme (#620) (d3266a0)
  • flags: close CRM/accounting feature-gating gaps from the audit (03fa3d8)
  • settings: don't insert non-existent created_at into app_settings (8621338)

Documentation

  • readme: add CRM + accounting to features, tax disclaimer, update contributor (116743b)

3.61.0-beta.0 (2026-06-13)

Features

  • projects: Project Overview cockpit — link (multiple) quotes/contracts/hours into projects (58f93ae)

Bug Fixes

  • projects: "one customer matches" rule for deal-lineage attach (f74d8d4)
  • projects: address review — cross-customer guards + email/queue hardening (9d13880)
  • projects: enforce single-customer projects (guard event attach + re-label) (4b1e85c)

3.60.6-beta.0 (2026-06-10)

Bug Fixes

  • gallery: guest upload honours general_max_files_per_upload + i18n placeholder interpolates (#613) (40a4aa2)
  • gallery: guest upload honours general_max_files_per_upload + i18n placeholder interpolates (#613) (69b5186)

3.60.5-beta.0 (2026-06-09)

Bug Fixes

  • admin/events: delete cascade orphaned photo folders because it read a non-existent column (#608) (284680e)
  • admin/events: delete cascade orphaned photo folders because it read a non-existent column (#608) (457c956)

3.60.4-beta.0 (2026-06-08)

Bug Fixes

  • admin: graceful logo-img fallback + show sidebar widgets during perm hydration (#523 follow-up 2) (f51b9cf)
  • admin: logo-img fallback + sidebar perm hydration + filename NFD transliteration (#523 follow-up 2, #607) (fcd3ca3)
  • downloads: transliterate accented characters in filename via NFD instead of dropping them (#607) (620163f)

3.60.3-beta.0 (2026-06-04)

Bug Fixes

  • security: re-apply SVG CSP on the direct favicon route (PR #603 blocker) (1214b6b)

3.60.2-beta.0 (2026-06-04)

Bug Fixes

  • admin-header: skeleton brand block + move LanguageSelector into profile menu on <sm (#523 follow-up) (b48b5b0)
  • admin-header: skeleton brand block + move LanguageSelector into profile menu on <sm (#523 follow-up) (fe10191)

3.60.1-beta.0 (2026-06-02)

Bug Fixes

  • notifications: restore /clear-all route the frontend already calls (#597) (940fc60)

3.60.0-beta.0 (2026-06-02)

Features

  • restore: docker-logs visibility + ADMIN_CREDENTIALS.txt restore notice (3322a1d)

Bug Fixes

  • backup-ui: respect general_date_format + general_time_format (09f6a1a)
  • restore: coerce pg bigint counts to Number before comparing (PR #596 round 2) (354fbed)
  • restore: hoist preservedMeta above SQLite/PG split (PR #596 blocker) (a23fa3b)
  • restore: move operator-meta replay after post-restore verification (PR #596 round 3) (20e3092)
  • restore: set was_successful=true on the completed update (7988c18)

Documentation

  • consolidate disaster-recovery into Backup & Restore guide (43cb0ea)

3.59.1-beta.0 (2026-05-31)

Bug Fixes

  • admin-header: hide wordmark on <sm when logo also shows (#523) (c246fd3)
  • admin-header: truncate long company names on narrow widths (#523 regression) (e7cf834)
  • api/v1/events: also honour require_password + branding defaults (#592 follow-up) (2d44b1a)
  • api/v1/events: honour global devtools-detection default on create (#592) (2304b25)
  • bug-batch: #523 #564 #590 #591 #592 (c68a03c)
  • csp: external bootstrap script to survive strict reverse-proxy CSP (#564) (dcc629c)
  • gallery: preserve per-viewer is_liked across hard refresh (#590 follow-up) (791e997)
  • gallery: toggle (not add) the local liked set on click (#590) (d292b9f)
  • nginx: defensive large_client_header_buffers bump (#591) (c83e883)

3.59.0-beta.0 (2026-05-29)

Features

  • admin/users: reactivate + delete actions for deactivated admin users (c4a9b36)
  • admin/users: reactivate + delete actions for deactivated admin users (dfcebcc)

3.58.0-beta.0 (2026-05-29)

Features

  • i18n: add Slovenian (sl) language support (433af15)

3.57.2-beta.0 (2026-05-29)

Documentation

  • list CRM under Beta Features + note dev-compose rebuild gotcha (1ed4804)

3.57.1-beta.0 (2026-05-29)

Bug Fixes

  • email: preserve dots + subaddresses across all normalization sites (de9a924)

3.57.0-beta.0 (2026-05-29)

Features

  • admin: clickable version links + update-available modal with changelog & upgrade command (48cf112)

Documentation

  • release: establish stable-channel cadence + promotion process (e537923)

3.56.0-beta.0 (2026-05-29)

Features

  • CRM module — quotes, contracts, invoices, hours, calendar, tax (5f0fcc2)

Bug Fixes

  • crm: thread trx through sequence-claim sites to unblock SQLite (d1aecaa)
  • quote-response: compute minutes-remaining for the DE changeWithin string (5ce0b6e)

3.55.0-beta.0 (2026-05-27)

Features

  • lightbox: multi-photo Web Share save-to-Photos on iOS (#557) (d5823c7)

Bug Fixes

  • events: preserve branding inheritance when saving events with null color_theme (d5a37df)
  • lightbox+events: Android download lag, multi-photo Web Share re-land, theme branding inheritance (e016f51)
  • lightbox: eliminate download lag on Android by skipping the blob round-trip (0479521)

3.54.7-beta.0 (2026-05-26)

Bug Fixes

  • lightbox: restrict Web Share save-to-Photos path to iOS (#554) (578397b)
  • lightbox: restrict Web Share save-to-Photos path to iOS (#554) (2a309c7)

3.54.6-beta.0 (2026-05-25)

Bug Fixes

  • api/v1: accept color_theme + create feedback row on event create (#550) (7ef0e40)
  • api/v1: accept color_theme + create feedback row on event create (#550) (1b521e7)

3.54.5-beta.0 (2026-05-22)

Bug Fixes

  • nginx: honour outer X-Forwarded-Proto when behind a reverse proxy (#547) (b351d17)
  • nginx: honour outer X-Forwarded-Proto when behind a reverse proxy (#547) (5488de3)

3.54.4-beta.0 (2026-05-21)

Bug Fixes

  • recover three orphaned commits from #527 (BRAND_TITLE runtime, Web Share, pan zoom) (9607b46)

3.54.3-beta.0 (2026-05-21)

Bug Fixes

  • lightbox: fill the heart icon when liked (#538 follow-up) (3e39112)
  • lightbox: fill the heart icon when liked (#538 follow-up) (600c29d)

3.54.2-beta.0 (2026-05-20)

Bug Fixes

  • feedback: three guest-mode bugs from #538 (filter, like state, count leak) (c900be9)
  • feedback: three guest-mode bugs reported in #538 (5311588)

3.54.1-beta.0 (2026-05-20)

Bug Fixes

  • public-site: honor dark theme surface colors (8b72721)

3.54.0-beta.0 (2026-05-20)

Features

  • install: skip legacy chain when modern bootstrap fingerprint detected (#530) (8f0108c)

Bug Fixes

  • install: skip legacy chain on recovery-state DBs + schema-drift CI (#530) (a0ebc97)

3.53.0-beta.0 (2026-05-19)

Features

  • events: default Guest Feedback ON via admin setting (#520) (3465b55)

Bug Fixes

  • bug-batch-518: lightbox comments toggle + further fixes (633a2ae)
  • header: hide language name on mobile to free the title (#523) (4b4ecfd)
  • lightbox: hide comments toggle when allow_comments=false (#518) (d44e1ad)
  • og: brandable static title + wider crawler UA coverage (#521) (b960639)

3.52.1-beta.0 (2026-05-18)

Bug Fixes

  • install: self-chowning entrypoint kills fresh-install restart loop (#484) (42c5cda)

3.52.0-beta.0 (2026-05-18)

Features

  • api/v1: accept category_id on POST /events/:id/photos (2d5a2ad)
  • api/v1: accept category_id on POST /events/:id/photos (6901e26)

Bug Fixes

  • api/v1: scope category lookup to event_owned or global (92bb9e1)

3.51.5-beta.0 (2026-05-17)

Bug Fixes

  • email: parse JSON-encoded language setting before using as locale (ebc7da2)

3.51.4-beta.0 (2026-05-17)

Bug Fixes

  • categories: strip diacritics from auto-generated slugs (a747eb3)

3.51.3-beta.0 (2026-05-16)

Bug Fixes

  • i18n: settings page resets UI language to server default (482e91b)

3.51.2-beta.0 (2026-05-16)

Bug Fixes

  • i18n: drive customer "Preferred language" select from SUPPORTED_LANGUAGES (#510) (51890e1)

3.51.1-beta.0 (2026-05-16)

Bug Fixes

  • install: silence clean-install postgres log noise (#484) (99e60a2)
  • install: silence clean-install postgres log noise (#484) (86b33d4)

3.51.0-beta.0 (2026-05-14)

Features

  • downloads: preserve original camera filenames on download (opt-in) (#493) (826e43e)

3.50.0-beta.0 (2026-05-14)

Features

  • lightbox: medium-resolution preview tier (#492) (3083c74)
  • lightbox: medium-resolution preview tier (#492) (61f1d13)

3.49.6-beta.0 (2026-05-14)

Bug Fixes

  • install: defer events.hero_photo_id FK to break circular reference (#484) (62b3ed6)
  • install: defer events.hero_photo_id FK to break circular reference (#484) (87834a7)

3.49.5-beta.0 (2026-05-14)

Bug Fixes

  • admin-users: normalise date fields to ISO across DB drivers (#485) (d300426)
  • admin-users: normalise date fields to ISO across DB drivers (#485) (b6b58d0)

3.49.4-beta.0 (2026-05-14)

Bug Fixes

  • install: drop racy migration step + add missing frontend container (#484) (d4155c4)
  • install: silence pg healthcheck noise + drop legacy workers container (#484) (d39406b)
  • install: silence pg healthcheck noise + drop legacy workers container (#484) (0b0b1bb)

3.49.3-beta.0 (2026-05-14)

Bug Fixes

  • promo-banner: center by default + admin alignment selector (#482) (d1034ce)
  • promo-banner: center by default + admin alignment selector (#482) (a803491)

3.49.2-beta.0 (2026-05-13)

Bug Fixes

  • ci: pin TRIVY_PLATFORM per matrix arch (post-#477 follow-up) (6750f5d)
  • ci: pin TRIVY_PLATFORM per matrix arch (post-#477 follow-up) (c3256dc)

3.49.1-beta.0 (2026-05-13)

Bug Fixes

  • ci: scan multi-arch images per-arch by digest, pin trivy-action (#476) (1144e9d)

3.49.0-beta.0 (2026-05-13)

Features

  • og: per-event opt-in to use hero photo as social-share preview (#474) (d856340)
  • og: per-event opt-in to use hero photo as social-share preview (#474) (0bc7e2a)

3.48.1-beta.0 (2026-05-12)

Bug Fixes

  • customer-routes: Cache-Control: no-store on customer endpoints (#470) (3122dd0)

3.48.0-beta.0 (2026-05-12)

Features

  • customers: "Manage galleries" dialog on customer detail page (6d1af7a)
  • customers: "Manage galleries" dialog with immediate access revocation + section reorder + portal-flag revert (9be9296)
  • customers: email customer when admin adds new gallery access (c02c947)
  • customers: replace-assignments endpoint for a single customer (5377b88)
  • gallery: revoke customer-minted JWTs when assignment is removed (55a5846)

Bug Fixes

  • customer: don't log customer out on transient session-refresh errors (9e418c7)

Reverts

  • customer-portal: make the global flag UI-only, drop the kill-switch middleware (3f44193)

3.47.2-beta.0 (2026-05-11)

Bug Fixes

  • activity-log: smart feature_flags_updated rendering + 33 missing activity types (4703fd5)

3.47.1-beta.0 (2026-05-11)

Bug Fixes

  • features: customer-portal card uses 'Clients' to match sidebar wording (441cc41)
  • features: customer-portal card uses 'Clients' to match sidebar wording (dec2f5d)

3.47.0-beta.0 (2026-05-11)

Features

  • email-templates: categorise + link to feature flags (84c06af)
  • email-templates: categorise + sub-categorise + link to feature flags (2cae3fe)
  • email-templates: group Templates UI by category + Feature off chip (5ec26fc)
  • email-templates: group Templates UI by category with core sub-sections (53eecb6)
  • email-templates: seed missing locale translations + post-075 templates (e3150e4)
  • email-templates: seed missing nl/pt/ru/fr translations (358f7ee)

Bug Fixes

  • email-templates: backfill subcategory + customer password reset translations (2343a16)

3.46.3-beta.0 (2026-05-11)

Bug Fixes

  • branding: socials + promo round-trip from DB to form (#460) (bd2288e)
  • branding: socials + promo round-trip from DB to form (#460) (ae64a6a)

3.46.2-beta.0 (2026-05-11)

Bug Fixes

  • customer-portal: post-merge fixes for event save, theme fonts, and customer→gallery handoff (9776d8a)
  • events: CustomerAccountPicker hooks order crashed /admin/events/new (2a7ae07)

3.46.1-beta.0 (2026-05-11)

Bug Fixes

  • import: capture photo dimensions in fileWatcher + s3AutoImporter (#447) (5b14854)

3.46.0-beta.0 (2026-05-11)

Features

  • branding: Customer dashboard header toggles in Branding page (b252cb6)
  • customer accounts (#354) — recurring logins, profile, password reset, branded customer surface (fe52953)
  • customers: customer portal (#354) on top of feature-flags reorg (087ef45)

Bug Fixes

  • auth: restore COOKIE_SECURE='auto' default for production (adfa29e)
  • customer: unwrap /customer/* from RequireFeature gate (da08a58)
  • server: drop missing requireCustomerPortal middleware import (4fa7225)
  • server: mount /api/admin/feature-flags route (f048011)

3.45.1-beta.0 (2026-05-10)

Bug Fixes

  • create-event: branding-default theme survives eventTypes refetch (d62c529)
  • create-event: branding-default theme survives eventTypes refetch (#323-B) (37d487d)

3.45.0-beta.0 (2026-05-10)

Features

  • footer: hideable legal links + socials + promo banner (#441 + #440) (f3505c2)

3.44.2-beta.0 (2026-05-10)

Bug Fixes

  • events: clamp page state when totalPages drops below current page (#442) (b4e30a4)
  • events: clamp page state when totalPages drops below current page (#442) (9c4a96f)

3.44.1-beta.0 (2026-05-10)

Bug Fixes

  • events: admins can clear expiration on edit even when 'Require expiration' is ON (#426) (3fd8af3)
  • events: admins can clear expiration on edit even when "Require expiration" is ON (#426) (e544561)

3.44.0-beta.0 (2026-05-10)

Features

  • settings: Features tab + sidebar reorg with feature-flag gating (c3798e1)
  • settings: Features tab + sidebar reorg with feature-flag gating (15e3336)

3.43.3-beta.0 (2026-05-09)

Bug Fixes

  • gallery: serve thumbnails / photos / hero via storage abstraction (#432) (d3007b0)

3.43.2-beta.0 (2026-05-09)

Documentation

  • contributing: update branch reference from main to beta (ed37caf)

3.43.1-beta.0 (2026-05-09)

Bug Fixes

  • event: correct updating client access (d00f6fa)
  • event: ensure client share token is generated only when necessary (916580a)

3.43.0-beta.0 (2026-05-09)

Features

  • localization: add French translations for fit options in thumbnails (2c12885)
  • localization: add i18next configuration and CLI commands for localization management (74e87b9)
  • localization: add i18next extraction helper & refactor backup configuration component to tsx (e7228b0)
  • localization: add missing translations (86ee6c8)
  • localization: improve English translations for clarity and consistency (46b99c6)
  • localization: update thumbnail settings and add fit options translations (5fc427c)
  • translations: add French language support and improve localization handling (a5db4bd)

Documentation

  • localization: enhance French language support and improve i18next configuration (d1bc5e0)

[Unreleased]

Bug Fixes

  • event: fix updating client access (ee85e1d)

Features

  • i18n: add French (fr) language support with full translation coverage
  • i18n: add i18next configuration with language detection and namespace setup
  • i18n: add CLI commands for localization management (extraction, validation)
  • i18n: add i18nextExtractionHelper developer script for auditing missing translation keys
  • i18n: complete and restructure translation files for EN, DE, NL, PT, RU with consistent key naming

Code Refactoring

  • admin: convert BackupConfiguration, BackupDashboard, and BackupManagement from JSX to TSX with full i18n support
  • admin: remove stale .d.ts declaration files replaced by TSX components
  • i18n: clean up useLocalizedTimeAgo hook and update useLocalizedDate

3.42.7-beta.0 (2026-05-09)

Bug Fixes

  • auth: default COOKIE_SECURE to 'auto' in production + first-install UX (#427) (e1c9382)

3.42.6-beta.0 (2026-05-09)

Bug Fixes

  • external-media: pre-generate thumbnails so reference-mode galleries load fast (#423) (e2ffd9f)
  • external-media: pre-generate thumbnails so reference-mode galleries load fast (#423) (f3d0f16)

3.42.5-beta.0 (2026-05-08)

Bug Fixes

  • admin: test email always sends, regardless of update availability (#418) (9326a42)

3.42.4-beta.0 (2026-05-08)

Bug Fixes

  • events: typed-DELETE confirmation for bulk delete (#417) (e165ee5)
  • events: typed-DELETE confirmation for bulk delete (#417) (99e420b)

3.42.3-beta.0 (2026-05-07)

Bug Fixes

  • create-event: re-apply Branding theme on stale→fresh settings (#323-B) (401abf7)
  • security: scan triage cleanup — drop dead deps, harden Docker/nginx/postMessage (7abfeb9)
  • security: scan triage cleanup — drop dead deps, harden Docker/nginx/postMessage (6b6191a)

3.42.2-beta.0 (2026-05-07)

Bug Fixes

  • security: patch 18 dependency CVEs (axios + transitives + nodemailer + i18next-http-backend) (b7d6ca0)
  • security: patch 18 dependency CVEs (axios + transitives) (523f499)

3.42.1-beta.0 (2026-05-07)

Bug Fixes

  • gallery: WCAG-safe Download button text + extract HeaderDownloadButton (#401 follow-ups) (04e928d)
  • gallery: WCAG-safe Download button text + extract HeaderDownloadButton (#401 follow-ups) (0c80abd)

3.42.0-beta.0 (2026-05-07)

Features

  • gallery: icon-only menu, accent Download CTA (#386) (876b35b)

3.41.0-beta.0 (2026-05-06)

Features

  • branding: 8-token CI palette + force color mode + dark-mode consistency (8050927)
  • branding: force color mode (dark or light) site-wide (5a162fc)
  • branding: inline force color mode with auto-save + clearer palette help text (67d7d8d)
  • email: expand email palette to 8 tokens + Sync from Branding button (47b6b39)
  • events: Sync from Branding button in gallery theme customizer + clarified default inheritance (bdbe7b8)
  • i18n: add Brazilian Portuguese (pt-BR) locale (375f512)
  • i18n: improve pt locale with pt-BR phrasings, remove duplicate pt-BR file (f25559c)
  • theme: expand color settings to 8-token CI palette + alt button (114aab5)

Bug Fixes

  • admin: tab underlines use accent (not accent-dark) for proper highlight color (565ae45)
  • branding: admin sidebar uses accent-dark, primary buttons follow CI token (fc2bce3)
  • branding: comprehensive sweep — replace remaining primary-* legacy colors with accent tokens (578a174)
  • branding: selected-state accent colors, force-mode actually flips galleries, compact color picker layout (5b410ed)
  • branding: working tooltips, high-contrast selected states, gallery chrome follows accent (b19bb0c)
  • cms: apply dark mode to CMS editor, public CMS, and admin modals (d2a10f6)
  • theme: centralise force-mode enforcement inside ThemeContext so every gallery flips (21188f4)

3.40.1-beta.0 (2026-05-04)

Bug Fixes

  • auth: /auth/session must enforce session timeout symmetrically (#350 recurrence) (c8e09c2)
  • auth: /auth/session must enforce session timeout symmetrically (#350 recurrence) (b106da1)

3.40.0-beta.0 (2026-05-04)

Features

  • branding: per-family generic fallback via meta.json (dcff451)
  • branding: self-hosted webfonts with filesystem scanner (d04bf28)

Bug Fixes

  • fonts: drop immutable Cache-Control to allow font replacement rollout (5703fcb)

Documentation

  • fonts: cache rollout, stale-list note, meta.json (bd0e052)

3.39.1-beta.0 (2026-05-04)

Documentation

  • readme: add Contributors section with @Luca-Timo and @Rekoo-PS (c60ab74)
  • readme: add Contributors section with @Luca-Timo and @Rekoo-PS (dbe0a30)

3.39.0-beta.0 (2026-05-04)

Features

  • gallery: decouple header style from layout, add banner option (1f1a856)

3.38.0-beta.0 (2026-05-04)

Features

  • events: bulk delete with password confirmation (#384) (647aea2)

3.37.0-beta.0 (2026-05-04)

Features

  • events: add Photos column to admin events list (#384) (d561db8)
  • events: add Photos column to admin events list (#384) (ffb4318)

3.36.0-beta.0 (2026-05-04)

Features

  • events: prefill admin email + admin picker on event creation (3fe8e61)

3.35.0-beta.0 (2026-05-04)

Features

  • events: tree view for external media folder picker (cdd40ac)
  • events: tree view for external media folder picker (f927b09)

Bug Fixes

  • events: match scrollbar to theme in external folder tree picker (bd42ee1)

3.34.2-beta.0 (2026-05-04)

Bug Fixes

  • docker: install system ffmpeg on Alpine, drop broken bundled binary (3ab8a64)
  • docker: install system ffmpeg on Alpine, drop broken bundled binary (96818c7)

3.34.1-beta.0 (2026-05-03)

Bug Fixes

  • cms: nl/pt/ru i18n + gate external_url in public response (08d0462)
  • cms: nl/pt/ru i18n + gate external_url in public response (bce5c1f)

3.34.0-beta.0 (2026-05-03)

Features

  • cms: add external URL toggle for imprint and privacy pages (b2c8161)
  • cms: add per-page external URL override — backend (66423bb)
  • cms: admin UI for external imprint/privacy URL (a4e3d10)
  • cms: redirect legal links to external URL when configured (c5bba50)

3.33.2-beta.0 (2026-05-03)

Bug Fixes

  • events: admin-set password on reset, full-URL gallery_link in all emails (0d1f82d)
  • events: admin-set password on reset, full-URL gallery_link in all emails (ff50c74)

3.33.1-beta.0 (2026-05-03)

Bug Fixes

  • email: render conditionals, localise password placeholders, fix caller/template variable drift (0767203)
  • email: render conditionals, localise password placeholders, fix caller/template variable drift (e8052ad)

3.33.0-beta.0 (2026-05-02)

Features

  • native multi-arch Docker images (Apple Silicon, ARM64 Linux) (df30618)

3.32.5-beta.0 (2026-05-02)

Bug Fixes

  • theme: kill initial white frame + theme-aware skeleton tiles (#358 follow-up) (f529c9e)
  • theme: kill initial white frame + theme-aware skeleton tiles (#358 follow-up) (1a530ae)

3.32.4-beta.0 (2026-05-01)

Bug Fixes

  • events: stop mapping branding_logo_position onto hero_logo_position (af2b062)
  • events: stop mapping branding_logo_position onto hero_logo_position (ef1c875)
  • theme: pre-React bootstrap to kill white-flash on dark galleries (#358) (07b41e6)
  • theme: pre-React bootstrap to kill white-flash on dark galleries (#358) (f81a872)

3.32.3-beta.0 (2026-05-01)

Bug Fixes

  • auth: /auth/session must verify issuer claim like adminAuth (#350) (83dedbc)
  • auth: make /auth/session verify the issuer claim like adminAuth (#350) (88a6c6a)
  • events: coerce expires_in_days to Number before addDays (e5712d8)
  • events: coerce expires_in_days to Number before addDays (db29d0e)

3.32.2-beta.0 (2026-05-01)

Bug Fixes

  • events search/counters (#346), lazy gallery skeleton (#321), smooth lightbox swipe (#348) (6229b38)
  • events: server-side search/pagination to remove first-100 cap (#346) (a5b20ca)
  • gallery: lazy-render skeleton grid for fast loads (#321 follow-up) (d9d8137)
  • lightbox: smooth carousel swipe + drop instructional hint (#348) (743086d)

3.32.1-beta.0 (2026-04-30)

Documentation

  • move documentation to docs.picpeak.app, drop in-repo copies (02ed5d4)
  • move documentation to docs.picpeak.app, drop in-repo copies (0faf9b3)

3.32.0-beta.0 (2026-04-29)

Features

  • webhooks: enrich event.* payloads with customer contact + share_token (#341) (7ea4801)
  • webhooks: enrich event.* payloads with customer contact + share_token (#341) (1e69d5f)

3.31.1-beta.0 (2026-04-28)

Bug Fixes

  • events: show customer phone in event details view (#331) (4c73d22)
  • gallery: single-finger swipe nav in mobile lightbox (#332) (4c8eba0)
  • gallery: use ref for swipe-start to avoid stale-closure miss (#332) (fcddfe0)
  • lightbox: mobile toolbar clipping + iOS safe-area + viewport-fit (#336) (42a7ae4)
  • mobile lightbox + share previews + customer phone bug triage (1e40677)
  • share: OG/Twitter-card metadata for gallery share URLs (#333) (5275621)

3.31.0-beta.0 (2026-04-28)

Features

  • frontend: dedupe /public/settings via shared usePublicSettings hook (#325) (3d4ae4d)
  • native S3 storage backend (#328) + presigned download follow-up (1b717ce)
  • outbound webhooks for event/photo lifecycle (#327) (c488f48)
  • presigned download UI + S3 prefix walker auto-importer (follow-ups) (446d80a)
  • S3 storage + webhooks + settings dedupe + backup fixes (06d54be)

Bug Fixes

  • backup: cron schedule mapping + manifest format detection + bigint coerce (ab4095f)
  • backup: incremental backups against S3 + jsonb stats parsing (e232f9f)

3.30.0-beta.0 (2026-04-27)

Features

  • customisable 404 + gallery-not-found pages via CMS (#324) (4f77905)
  • optional customer phone field gated by global toggle (#322) (be6cb28)
  • public v1 API + token management + OpenAPI docs (#322) (808b15b)

Bug Fixes

  • dedupe parallel admin 401 redirects to /admin/login (038e84c)
  • floor password_changed_at when comparing against JWT iat (793e410)
  • theme picker buttons no longer submit the parent form (#326) (2eead52)
  • theme save without Live Preview, Branding default on new events, gallery loading flicker (#323, #321) (822be9a)
  • theme-preset match loop ignores extra fields like logoUrl (#323) (b63a877)

Documentation

  • add Buy Me a Coffee badge + Support section (46bc894)

3.29.1-beta.0 (2026-04-26)

Bug Fixes

  • address bugs and feature requests from discussion #317 (6cfff6f)
  • discussion #317 issues and #318 archive crash (2f2f405)
  • prevent backend crash on archive when admin_email is null (#318) (e4b0f96)

3.29.0-beta.0 (2026-04-23)

Features

3.28.3-beta.0 (2026-04-13)

Bug Fixes

  • revert /api prefix in adminPhotos.js to avoid double-prefix (094276d)
  • revert /api prefix in adminPhotos.js to avoid double-prefix (#307) (ceb2a09)

3.28.2-beta.0 (2026-04-12)

Bug Fixes

  • display welcome message in gallery and fix guest thumbnail URLs (#306, #307) (b05c36a)
  • display welcome message in gallery and fix guest thumbnail URLs (#306, #307) (9323bef)

3.28.1-beta.0 (2026-04-12)

Bug Fixes

  • apply sort direction in gallery and respect show_feedback_to_guests (#302, #303) (3716ff5)
  • apply sort direction in gallery view and respect show_feedback_to_guests (#302, #303) (dffe057)

3.28.0-beta.0 (2026-04-11)

Features

  • add COOKIE_SECURE=auto for mixed HTTPS/HTTP deployments (#298) (b1dfbe4)
  • add COOKIE_SECURE=auto for mixed HTTPS/HTTP deployments (#298) (15a8ab4)

Bug Fixes

  • guest feedback flow bugs in Masonry grid and PhotoLightbox (#292) (54badef)
  • guest feedback flow bugs in Masonry grid and PhotoLightbox (#292) (77f07e9)

3.27.0-beta.0 (2026-04-11)

Features

  • add admin dark mode and SEO/robots.txt settings (9c2a0d2)
  • add Apple Liquid Glass templates, image security settings, and automated releases (6033461)
  • add bulk category editing for photos (#157) (eca36c7)
  • add category hero/cover photo selection (#163) (6c30e2c)
  • add configurable upload batch size for reverse proxy compatibility (#208) (02a46e0)
  • Add CSS template system with custom gallery styling support (0da45e6)
  • add customizable event types with admin management (f8881d5)
  • add Dutch (nl) locale and fix missing translation keys across all locales (b54a80d)
  • add Dutch locale and fix missing translation keys (e32da68)
  • add event management, gallery customization, and release automationFeature/event rename (40ee671)
  • add Gallery Premium and Gallery Story layouts (Beta) (e179def)
  • add hero image focal point picker with anchor positioning (#162) (734868a)
  • add justified layout modes and aspect-ratio-aware mosaic (#146) (608bbd5)
  • Add justified layout modes and aspect-ratio-aware mosaic (#146) (ef2ae00)
  • add justified/rows layout mode to masonry gallery (#146) (e081b56)
  • add justified/rows layout mode to masonry gallery (#146) + security fixes (cd1d504)
  • add multi-administrator support with RBAC and fix backup/restore for S3 (892e47d)
  • add optional event date and expiration settings (3079eaa)
  • add optional event date and expiration settings (2151147), closes #118
  • add original filename preservation and Lightroom export support (a59f414)
  • add original filename preservation and Lightroom export support (9872ad3)
  • add per-event custom logo upload with bug fixes (85170b8)
  • add per-event hero logo customization options (0790a1d)
  • add per-gallery thumbnail scale setting (#172) (#251) (ee46088)
  • add photo cap per event and Portuguese (pt-BR) locale (1fa222e)
  • add photo cap per event and Portuguese locale (088de43)
  • add quilted layout, fix mosaic, and backfill photo dimensions (#146) (46ed1bc)
  • add thumbnail settings UI to admin panel (3a30fea)
  • add thumbnail settings UI to admin settings page (#206) (7d6d2f5)
  • add update instructions dialog, email notifications, and capture date sorting (50c0990), closes #181
  • add visual WYSIWYG email template editor (#229) (04a7ea8)
  • admin: refine header layout and logo placement (d64e7d0)
  • allow admin email updates in UI (#36) (3c2a79a)
  • beta/stable release channels with update notifications and bug fixes (3c7dc20)
  • beta/stable release channels with update notifications and bug fixes (#98) (3c7dc20)
  • configurable upload batch size for reverse proxy compatibility (9b7495e)
  • configurable upload batch size for reverse proxy compatibility (4243363)
  • decouple hero header from gallery layouts (#158) (7b8d8bd)
  • docker: add PUID/PGID and user mapping to avoid bind mount permission issues; feat(setup): prompt for admin email interactively; docs: PUID/PGID in .env.example (410a33f)
  • draft mode, admin branding, and workflow improvements (dc98206)
  • draft mode, admin branding, and workflow improvements (40332a7)
  • dynamic website title from branding settings (d29aab7)
  • events: add CSS template selector to event edit page (6a6c2cd)
  • gallery layouts, bulk category editing, and hero header improvements (7037106)
  • gallery layouts, hero customization, bulk categories & event types (d9e00dc)
  • gallery layouts, hero customization, event types, and UX improvements (#146, #155-163, #170, #171) (4280444)
  • gallery/filters: add Rated and Commented filters (UI + backend).\n\n- UI: add star (Rated) and message (Commented) buttons to feedback filter bars (desktop + mobile)\n- Backend: support filter=rated, commented, and combinations via aggregate counts/queries (b03760a)
  • gallery: add quick Like/Favorite actions on thumbnails across layouts (6368f10)
  • gallery: always-visible feedback indicators on grid tiles; fallback image rendering in lightbox/hero; auto-auth from shared-link token; fix external photo resolver\n\n- GridGallery: bottom-left icons for like/rated/comment on every tile\n- Hero layout grid: added same indicators (non-intrusive icons)\n- Lightbox/Hero: add fallbackSrc to display thumbnail if original fails\n- GalleryAuth: auto-store token from /gallery/:slug/:token and hydrate event\n- Backend gallery photo route: use resolvePhotoFilePath for external-media\n\nfix(admin): move photo feedback badges to bottom-right on admin grid tiles\n\nfix(dashboard): add missing i18n keys for activity types + fallback to formatter\n\nfix(admin/feedback): correct thumbnail URL base + robust date parsing\n\nRefs: #19 (6948aaa)
  • gallery: compact vertical icon-only feedback filter in PhotoFilterBar; remove wide buttons to prevent overflow\n\n- Desktop: vertical icon stack (All/Grid, Likes, Favorites) outside scroll area\n- Mobile: vertical icon stack below categories\n- Keeps existing category bar layout and count\n\nRefs: #19 (465f997)
  • i18n: add translations for settings tabs (c030e87)
  • implement 4 new features with bug fixes and refactoring plan (77a4bfd)
  • implement beta/stable release channels with update notifications (617e778)
  • improve gallery layouts with aspect-ratio-aware masonry and mosaic modes (#146) (aacfcd5)
  • improve hero image UX and live preview (#163, #158) (d63f67a)
  • lightbox: keep feedback usable while navigating (6368f10), closes #19
  • Multi-administrator RBAC, CSS templates & security hardening (#78) (16b3ab0)
  • multilingual email templates with translations table (8c5996e)
  • multilingual email templates with translations table (f50d7c0)
  • native: auto-serve SPA when dist exists (unless SERVE_FRONTEND=false); add clear logging; serve index.html for /admin (fb16b7b)
  • native: build frontend and serve SPA from backend (SERVE_FRONTEND); fix Cannot GET /admin on native installs (9fe10bc)
  • native: serve built frontend from backend; build frontend during install/update; ensure env flags (SERVE_FRONTEND, FRONTEND_DIR) (61ad2d6)
  • new features and bug fixes for beta release (151e1bf)
  • original filename in admin UI, update dialog, and security hardening (3ea9d5b)
  • original filename in admin UI, update dialog, security hardening, and bug fixes (bcf2745)
  • overhaul public landing page and backup tooling (2a4d388)
  • per-event custom logos, customizable event types, and multiple bug fixes (4c08160)
  • photo visibility control with client access (#172) (4a93e4e)
  • photo visibility control with client access (#172) (e1b6e43)
  • pre-generate watermarks for instant lightbox loading (1be974a), closes #112
  • pre-generated watermarks and mobile upload button improvements (c6fdd38)
  • register Russian locale and add to language selector (6f95b8c)
  • select: add per-tile checkbox selection in Admin grid and all gallery layouts; tile click opens viewer; checkbox toggles selection; auto-enable selection mode; add testids (9fda54b)
  • setup/docker: auto-set PUID/PGID from invoking user and chown bind-mount folders; create missing data/events dirs (0618b78)
  • setup: remove --admin-password; print admin credentials from ADMIN_CREDENTIALS.txt; fix ADMIN_URL to avoid /admin/admin; update native service commands (84d0f63)
  • show original filename in admin UI (#184) (0891be1)
  • sort photos by capture date with configurable default sort (#283) (8805fa5)
  • sort photos by capture date with configurable default sort (#283) (633d4a0)
  • support per-gallery password toggle (5d6c061)
  • visual WYSIWYG email template editor (703c03f)
  • warn about low thumbnail resolution when selecting beta themes (ee3f6ae)
  • warn about low thumbnail resolution with beta themes (aef9b4e)

Bug Fixes

  • add allow_user_uploads to gallery API responses (691e3ab)
  • add lightbox loading spinner and watermark cache invalidation (050ed37)
  • Add settings translations and fix manual backup process (#82) (476fcce)
  • add STORAGE_PATH to production docker-compose (cdda709)
  • address beta feedback - gallery layout fixes, Russian locale, email logo (#249) (486239a)
  • address Shannon security assessment findings (37 vulnerabilities) (#254) (23cd9cb)
  • admin photo feedback filters have no effect (#293) (9ed8a2b)
  • admin/feedback: use correct event id when rendering photo thumbnails (4c7b49a), closes #19
  • admin: prevent category badge overlap in grid (d64e7d0)
  • align backend port to 3000 across all configurations (3a8d53f)
  • Align nginx backend port for production Docker deployments (v2.2.2) (#88) (e0bd19a)
  • apply password change fix to regular modal + longer toast delay (#263) (c63bc47)
  • apply password change redirect fix to regular modal too (#263) (147dc28)
  • backup: add lastBackup alias and totalBackups for frontend compatibility (749100c)
  • backup: allow manual backups when automated backups are disabled (e6dd89e)
  • checkbox and toggle settings not persisting after page refresh (808ed1d), closes #117
  • CI workflow fixes for protected branches (657c205)
  • CI workflow fixes for protected branches (cb01218)
  • ci: add QEMU setup for multi-arch builds and skip for PRs (0d36a27)
  • clear notifications via API (#35) (013be18)
  • correct invitation activation validation and add missing translations (991aa98), closes #129
  • correct invitation email link URL path (86fa104), closes #129
  • correct storage path resolution in multiple files (#96) (0e3674b)
  • correct storage path resolution in multiple files (#96) (3ccb815)
  • cors: scope CORS to /api only and avoid throwing on disallowed origins; prevents static asset 500s on native (90bb21e)
  • database migration restart bug, lightbox loading spinner, and watermark cache invalidation (7c58749)
  • db: improve PostgreSQL connection check in wait-for-db.sh (e85a68a)
  • display new password after admin password reset (bd8b885)
  • docker compose v2 syntax and add missing ADMIN_PASSWORD to .env.example (#189) (0817443)
  • Docker Swarm DNS resolution and backup status display (v2.2.3) (082d8ab)
  • Docker Swarm DNS resolution and backup status display (v2.2.3) (082d8ab)
  • dynamic website title from branding settings (4701edc)
  • event-specific custom CSS settings not being saved (dadef81), closes #136
  • events without expiration date incorrectly shown as expired (c4f16eb)
  • external media dimensions, theme race condition, email color customization (dfae2c2)
  • frontend: add missing externalMedia service and mount admin external-media routes; verify Vite build (ab324f1)
  • gallery thumbnails not loading (404 errors) #96 (e3c3c4c)
  • gallery/filters: always apply global liked/favorited filters by aggregate counts (ignore guest_id); resolves mismatch between client guest_id and server identifier (526dcd8)
  • gallery/filters: make feedback filters work globally when no guest_id is provided; remove guest_id from client photos query\n\n- Backend /api/gallery/:slug/photos: if filter present and guest_id missing, filter by like_count/favorite_count\n- Frontend useGalleryPhotos: stop passing random guestId (does not match server guest_identifier)\n\nThis makes Liked/Favorited filters reflect photos with aggregate feedback counts as expected. (5b2561b)
  • gallery/sidebar: compact icon-only feedback filter in sidebar (vertical, small) to avoid overflow; use GalleryFilter variant=compact (ff89f96)
  • gallery: feedback filter headline + horizontal icons in sidebar (compact variant); ensure sidebar content scrolls (flex-col container) (3a6d061)
  • handle legacy non-JSON logo paths when replacing logo (0d5ce48)
  • handle null dates in dashboard and gallery pages (c5a8ffc)
  • harden gallery downloads and per-gallery auth (fc1bf53)
  • hero header state and preview in admin theme editor (#158) (f554f46)
  • improve ghost button visibility in admin dark mode (4912e2b)
  • improve password validation errors and event list UX (#170, #171) (171abb3)
  • improve photo serving, category filters, and upload chunking (#155, #156, #161) (fa4c838)
  • increase upload limit to 1GB and fix category filters (#155, #156) (397d33a)
  • issue #203 file type validation + security CVE fixes (8017171)
  • JSON serialize favicon and logo URLs for PostgreSQL storage (b83f427)
  • lightbox watermark loading, white label translations, and dynamic footer year (3b720ed)
  • lightbox watermark loading, white label translations, and dynamic footer year (ce8587b)
  • lightbox watermark loading, white label translations, and dynamic footer year (#108) (3b720ed)
  • mobile upload button not visible in gallery (#113) (cacaffa)
  • mobile upload button visibility in gallery (2a2c23d), closes #113
  • mobile upload button visibility in gallery (df7dbff), closes #113
  • mobile upload button visibility in gallery (#113) (05a5307)
  • mobile upload button visibility in gallery (#113) (6cb4342)
  • Multi-administrator RBAC, CSS templates & security hardening (#80) (37d4e1c)
  • native/http: disable CSP upgrade-insecure-requests and HSTS unless ENABLE_HSTS=true; prevents HTTPS upgrades on HTTP installs (24b4a31)
  • native: correct setup paths to /opt/picpeak/app, update repo URL, add sqlite prod support; docs path fixes (b992b15)
  • native: remove obsolete workers service; restart only backend; add API request logging and preflight handler; keep static assets outside CORS (f3604b4)
  • nginx: add Docker DNS resolver for Swarm/dynamic service discovery (049837f)
  • nginx: Add Docker DNS resolver for Swarm/dynamic service discovery (v2.2.3) (cc1ddfd)
  • photos: category changes now persist and display correctly (#77) (d9da98c)
  • photos: resolve upload category selection and improve feedback buttons (#77) (856d533)
  • pin npm to v10 in backend Dockerfile (ddefd3a)
  • pin npm upgrade to v10 in backend Dockerfile (978e447)
  • prefer admin token on admin routes (#23 #28) (d4404e3)
  • prevent database migration restart failures (83a4344), closes #107
  • prevent unnecessary image recompression and fix SQLite migration #95 (3cdc0ea)
  • remove non-functional watermark toggle from Feature Toggles (d4a15db)
  • render minimal/none header styles, cap hero height, switch category hero images (#158, #162, #163) (bc6c48b)
  • resend gallery email fails for events without password (6b3ead7), closes #137
  • resolve admin invitation flow issues and improve STORAGE_PATH documentation (41bf6ff)
  • resolve branding display issues and invitation parsing errors (1931d73)
  • Resolve branding display issues and invitation parsing errors (v2.2.1) (#86) (d7ecf83)
  • resolve code quality issues and add missing i18n keys (#162, #163) (329d224)
  • resolve code scanning security alerts (multer, tar, Node 22) (85a07fc)
  • resolve external media dimensions, gallery theme race condition, and add email color customization (bbeedd1)
  • resolve issues #194, #195, #196, #197 (33af088)
  • resolve issues #194, #195, #196, #197 (5ea4ef3)
  • resolve issues #194, #195, #196, #197 (33483cf)
  • resolve issues #194, #195, #196, #197 (cd00bc1)
  • resolve JWT iat timing issue in password change (#263) (c031b1e)
  • resolve mixed light/dark mode styling in admin UI (#175) (f8c8abd)
  • resolve password change redirect loop (#263) and file watcher crash (#269) (b23c51b)
  • resolve password change redirect loop and file watcher crash (835bdf5), closes #269
  • resolve redirect loop after mandatory password change (#263) (07fc5e6)
  • resolve redirect loop after mandatory password change (#263) (3c8d344)
  • respect allowed_file_types setting for upload validation (#203) (fe07a14)
  • respect optional email settings in event creation (831ea6a)
  • respect optional email settings in event creation (#217) (9c44a0e)
  • restore aspect-ratio layouts and improve hero image quality (#180) (3974ba5)
  • restore aspect-ratio layouts and improve hero image quality (#180) (5cef7fd)
  • security: invalidate tokens on password change, enforce session timeout, fix role update (f362239)
  • security: resolve all npm audit vulnerabilities (4272618)
  • security: resolve Docker image CVEs for code scanning alerts (cbecb93)
  • security: token invalidation on password change, session timeout enforcement (7ca9631)
  • security: upgrade Alpine base image to fix libpng and c-ares CVEs (b706eeb)
  • set JWT iat after password_changed_at to prevent token rejection (#263) (b1d1667)
  • setup/native: correct repo URL, paths, and systemd for native install; support sqlite in production knex config (87b8414)
  • setup/native: Debian 12 compatibility (reliable RAM detection, sudo-less run_as_user, git safe.directory); ensure SQLite data dir; use user for migrate (dc482e6)
  • setup/native: handle forced updates safely by fetch+checkout/reset instead of pull; stable on rewritten histories (3697344)
  • setup/update: detect native installs first (/opt/picpeak/app/backend or systemd unit); avoid false docker updates on root (adf576f)
  • shorten Save button label on email template editor (7250c42)
  • show upload button in mobile topbar instead of sidebar (ae181cf), closes #113
  • stabilize uploads and guest feedback filters (aaaf598)
  • sync header_style DB column with theme editor selections (#158) (2288309)
  • sync header_style DB column with theme editor selections (#158) (a19e7c4)
  • update dependencies to resolve code scanning security alerts (1f524f2)
  • update docker-compose to docker compose and add ADMIN_PASSWORD to .env.example (#189) (a4c6248)
  • update packages to fix security vulnerabilities (8097a0c)
  • update security policy with private reporting channels (308e086)
  • update security policy with private reporting channels (7f77362)
  • update security policy with proper contact email and private reporting (67b0f32), closes #223
  • use actual photo aspect ratios in masonry columns mode (#146) (8711f96)
  • use CSS Columns for gap-free mosaic layout (#146) (821d329)
  • use photo dimensions for mosaic aspect ratios (#146) (27ff51e)
  • use Release Please extra-files instead of sync-versions job (fe7d45d)
  • video upload media type, select all, and dimension repair (#203, #220, #180) (fc75bcd)
  • video upload, select all, and dimension repair (#203, #220, #180) (a0bb080)
  • watermark thumbnails, custom logo display, and German translations (f843e4c)
  • watermark thumbnails, custom logo display, and German translations (ea20446)
  • watermark upload JSON parsing and image quality preservation (0e3b50d)
  • wire admin photo feedback filters into grid query (#293) (d4b4dc6)
  • wrap email preview with full styled header/footer template (9a6d2e8)
  • wrap email preview with full styled header/footer template (fc0911a), closes #229
  • wrap test email with standard email template (#252) (954a011)

Documentation

  • add API_URL environment variable to .env.example files (3e69579)
  • add PUID/PGID note for Docker bind mounts to avoid permission issues (0178e71)
  • clarify file system photo import requires existing event (#269) (5295516)
  • clarify file system photo import requires existing event (#269) (ee0baaf)
  • emphasize importance of STORAGE_PATH in env example (3397807)
  • readme: reflect new External Media reference mode and update roadmap (gallery feedback status) (ee13556)

3.26.2-beta.0 (2026-04-11)

Bug Fixes

  • admin photo feedback filters have no effect (#293) (9ed8a2b)
  • wire admin photo feedback filters into grid query (#293) (d4b4dc6)

3.26.1-beta.0 (2026-04-09)

Bug Fixes

  • apply password change fix to regular modal + longer toast delay (#263) (c63bc47)
  • apply password change redirect fix to regular modal too (#263) (147dc28)
  • resolve JWT iat timing issue in password change (#263) (c031b1e)
  • set JWT iat after password_changed_at to prevent token rejection (#263) (b1d1667)

Documentation

  • clarify file system photo import requires existing event (#269) (5295516)
  • clarify file system photo import requires existing event (#269) (ee0baaf)

3.26.0-beta.0 (2026-04-09)

Features

  • sort photos by capture date with configurable default sort (#283) (8805fa5)
  • sort photos by capture date with configurable default sort (#283) (633d4a0)

Bug Fixes

  • resolve password change redirect loop (#263) and file watcher crash (#269) (b23c51b)
  • resolve password change redirect loop and file watcher crash (835bdf5), closes #269

3.25.0-beta.0 (2026-04-08)

Features

  • draft mode, admin branding, and workflow improvements (dc98206)
  • draft mode, admin branding, and workflow improvements (40332a7)

3.24.1-beta.0 (2026-04-05)

Bug Fixes

  • resolve redirect loop after mandatory password change (#263) (07fc5e6)
  • resolve redirect loop after mandatory password change (#263) (3c8d344)

3.24.0-beta.0 (2026-04-04)

Features

  • warn about low thumbnail resolution when selecting beta themes (ee3f6ae)
  • warn about low thumbnail resolution with beta themes (aef9b4e)

3.23.0-beta.0 (2026-04-04)

Features

  • multilingual email templates with translations table (8c5996e)
  • multilingual email templates with translations table (f50d7c0)

Bug Fixes

  • pin npm to v10 in backend Dockerfile (ddefd3a)
  • pin npm upgrade to v10 in backend Dockerfile (978e447)

3.22.0-beta.0 (2026-03-25)

Features

  • add Dutch (nl) locale and fix missing translation keys across all locales (b54a80d)
  • add Dutch locale and fix missing translation keys (e32da68)

3.21.1-beta.0 (2026-03-22)

Bug Fixes

  • address Shannon security assessment findings (37 vulnerabilities) (#254) (23cd9cb)

3.21.0-beta.0 (2026-03-18)

Features

Bug Fixes

  • wrap test email with standard email template (#252) (954a011)

3.20.1-beta.0 (2026-03-17)

Bug Fixes

  • address beta feedback - gallery layout fixes, Russian locale, email logo (#249) (486239a)

3.20.0-beta.0 (2026-03-17)

Features

  • photo visibility control with client access (#172) (4a93e4e)
  • photo visibility control with client access (#172) (e1b6e43)

3.19.2-beta.0 (2026-03-16)

Bug Fixes

  • security: invalidate tokens on password change, enforce session timeout, fix role update (f362239)
  • security: token invalidation on password change, session timeout enforcement (7ca9631)

3.19.1-beta.0 (2026-03-16)

Bug Fixes

  • external media dimensions, theme race condition, email color customization (dfae2c2)
  • resolve external media dimensions, gallery theme race condition, and add email color customization (bbeedd1)

3.19.0-beta.0 (2026-03-16)

Features

  • add photo cap per event and Portuguese (pt-BR) locale (1fa222e)
  • add photo cap per event and Portuguese locale (088de43)

3.18.2-beta.0 (2026-03-16)

Bug Fixes

  • resolve code scanning security alerts (multer, tar, Node 22) (85a07fc)
  • update dependencies to resolve code scanning security alerts (1f524f2)

3.18.1-beta.0 (2026-03-16)

Bug Fixes

  • wrap email preview with full styled header/footer template (9a6d2e8)
  • wrap email preview with full styled header/footer template (fc0911a), closes #229

3.18.0-beta.0 (2026-03-16)

Features

  • add visual WYSIWYG email template editor (#229) (04a7ea8)
  • register Russian locale and add to language selector (6f95b8c)
  • visual WYSIWYG email template editor (703c03f)

Bug Fixes

  • shorten Save button label on email template editor (7250c42)

3.17.2-beta.0 (2026-03-11)

Bug Fixes

  • update security policy with private reporting channels (308e086)
  • update security policy with proper contact email and private reporting (67b0f32), closes #223
  • video upload media type, select all, and dimension repair (#203, #220, #180) (fc75bcd)
  • video upload, select all, and dimension repair (#203, #220, #180) (a0bb080)

3.17.1-beta.0 (2026-03-08)

Bug Fixes

  • respect optional email settings in event creation (831ea6a)
  • respect optional email settings in event creation (#217) (9c44a0e)

3.17.0-beta.0 (2026-03-05)

Features

  • configurable upload batch size for reverse proxy compatibility (9b7495e)

3.16.0-beta.0 (2026-03-05)

Features

  • add thumbnail settings UI to admin panel (3a30fea)
  • add thumbnail settings UI to admin settings page (#206) (7d6d2f5)

3.15.3-beta.0 (2026-03-02)

Bug Fixes

  • issue #203 file type validation + security CVE fixes (8017171)
  • respect allowed_file_types setting for upload validation (#203) (fe07a14)
  • security: resolve all npm audit vulnerabilities (4272618)
  • security: resolve Docker image CVEs for code scanning alerts (cbecb93)

2.6.0 (2026-03-11)

Features

  • add configurable upload batch size for reverse proxy compatibility (#208) (02a46e0)
  • configurable upload batch size for reverse proxy compatibility (4243363)

Bug Fixes

2.5.1 (2026-02-22)

Bug Fixes

2.5.0 (2026-02-21)

Features

  • add admin dark mode and SEO/robots.txt settings (9c2a0d2)
  • add bulk category editing for photos (#157) (eca36c7)
  • add category hero/cover photo selection (#163) (6c30e2c)
  • add customizable event types with admin management (f8881d5)
  • add Gallery Premium and Gallery Story layouts (Beta) (e179def)
  • add hero image focal point picker with anchor positioning (#162) (734868a)
  • add justified layout modes and aspect-ratio-aware mosaic (#146) (608bbd5)
  • Add justified layout modes and aspect-ratio-aware mosaic (#146) (ef2ae00)
  • add justified/rows layout mode to masonry gallery (#146) (e081b56)
  • add justified/rows layout mode to masonry gallery (#146) + security fixes (cd1d504)
  • add optional event date and expiration settings (3079eaa)
  • add optional event date and expiration settings (2151147), closes #118
  • add original filename preservation and Lightroom export support (a59f414)
  • add original filename preservation and Lightroom export support (9872ad3)
  • add per-event custom logo upload with bug fixes (85170b8)
  • add per-event hero logo customization options (0790a1d)
  • add quilted layout, fix mosaic, and backfill photo dimensions (#146) (46ed1bc)
  • add update instructions dialog, email notifications, and capture date sorting (50c0990), closes #181
  • decouple hero header from gallery layouts (#158) (7b8d8bd)
  • gallery layouts, bulk category editing, and hero header improvements (7037106)
  • gallery layouts, hero customization, bulk categories & event types (d9e00dc)
  • gallery layouts, hero customization, event types, and UX improvements (#146, #155-163, #170, #171) (4280444)
  • improve gallery layouts with aspect-ratio-aware masonry and mosaic modes (#146) (aacfcd5)
  • improve hero image UX and live preview (#163, #158) (d63f67a)
  • new features and bug fixes for beta release (151e1bf)
  • original filename in admin UI, update dialog, and security hardening (3ea9d5b)
  • original filename in admin UI, update dialog, security hardening, and bug fixes (bcf2745)
  • per-event custom logos, customizable event types, and multiple bug fixes (4c08160)
  • pre-generate watermarks for instant lightbox loading (1be974a), closes #112
  • pre-generated watermarks and mobile upload button improvements (c6fdd38)
  • show original filename in admin UI (#184) (0891be1)

3.15.2-beta.0 (2026-02-22)

Bug Fixes

  • add allow_user_uploads to gallery API responses (691e3ab)
  • add STORAGE_PATH to production docker-compose (cdda709)
  • checkbox and toggle settings not persisting after page refresh (808ed1d), closes #117
  • correct invitation activation validation and add missing translations (991aa98), closes #129
  • correct invitation email link URL path (86fa104), closes #129
  • correct storage path resolution in multiple files (#96) (0e3674b)
  • correct storage path resolution in multiple files (#96) (3ccb815)
  • docker compose v2 syntax and add missing ADMIN_PASSWORD to .env.example (#189) (0817443)
  • event-specific custom CSS settings not being saved (dadef81), closes #136
  • events without expiration date incorrectly shown as expired (c4f16eb)
  • handle null dates in dashboard and gallery pages (c5a8ffc)
  • hero header state and preview in admin theme editor (#158) (f554f46)
  • improve ghost button visibility in admin dark mode (4912e2b)
  • improve password validation errors and event list UX (#170, #171) (171abb3)
  • improve photo serving, category filters, and upload chunking (#155, #156, #161) (fa4c838)
  • increase upload limit to 1GB and fix category filters (#155, #156) (397d33a)
  • mobile upload button not visible in gallery (#113) (cacaffa)
  • mobile upload button visibility in gallery (2a2c23d), closes #113
  • mobile upload button visibility in gallery (df7dbff), closes #113
  • mobile upload button visibility in gallery (#113) (05a5307)
  • mobile upload button visibility in gallery (#113) (6cb4342)
  • remove non-functional watermark toggle from Feature Toggles (d4a15db)
  • render minimal/none header styles, cap hero height, switch category hero images (#158, #162, #163) (bc6c48b)
  • resend gallery email fails for events without password (6b3ead7), closes #137
  • resolve admin invitation flow issues and improve STORAGE_PATH documentation (41bf6ff)
  • resolve code quality issues and add missing i18n keys (#162, #163) (329d224)
  • resolve mixed light/dark mode styling in admin UI (#175) (f8c8abd)
  • restore aspect-ratio layouts and improve hero image quality (#180) (3974ba5)
  • restore aspect-ratio layouts and improve hero image quality (#180) (5cef7fd)
  • show upload button in mobile topbar instead of sidebar (ae181cf), closes #113
  • sync header_style DB column with theme editor selections (#158) (2288309)
  • sync header_style DB column with theme editor selections (#158) (a19e7c4)
  • update docker-compose to docker compose and add ADMIN_PASSWORD to .env.example (#189) (a4c6248)
  • update packages to fix security vulnerabilities (8097a0c)
  • use actual photo aspect ratios in masonry columns mode (#146) (8711f96)
  • use CSS Columns for gap-free mosaic layout (#146) (821d329)
  • use photo dimensions for mosaic aspect ratios (#146) (27ff51e)

Documentation

3.15.1-beta.0 (2026-02-21)

Bug Fixes

  • docker compose v2 syntax and add missing ADMIN_PASSWORD to .env.example (#189) (0817443)
  • update docker-compose to docker compose and add ADMIN_PASSWORD to .env.example (#189) (a4c6248)

3.15.0-beta.0 (2026-02-17)

Features

  • original filename in admin UI, update dialog, security hardening, and bug fixes (bcf2745)

Bug Fixes

  • events without expiration date incorrectly shown as expired (c4f16eb)

3.14.0-beta.0 (2026-02-17)

Features

  • add update instructions dialog, email notifications, and capture date sorting (50c0990), closes #181
  • original filename in admin UI, update dialog, and security hardening (3ea9d5b)
  • show original filename in admin UI (#184) (0891be1)

3.13.1-beta.0 (2026-02-15)

Bug Fixes

  • restore aspect-ratio layouts and improve hero image quality (#180) (3974ba5)
  • restore aspect-ratio layouts and improve hero image quality (#180) (5cef7fd)

3.13.0-beta.0 (2026-02-06)

Features

3.12.0-beta.0 (2026-02-06)

Features

  • add admin dark mode and SEO/robots.txt settings (9c2a0d2)

Bug Fixes

  • improve ghost button visibility in admin dark mode (4912e2b)
  • resolve mixed light/dark mode styling in admin UI (#175) (f8c8abd)

3.11.0-beta.0 (2026-02-06)

Features

  • add Gallery Premium and Gallery Story layouts (Beta) (e179def)
  • gallery layouts, hero customization, event types, and UX improvements (#146, #155-163, #170, #171) (4280444)

Bug Fixes

  • improve password validation errors and event list UX (#170, #171) (171abb3)
  • render minimal/none header styles, cap hero height, switch category hero images (#158, #162, #163) (bc6c48b)

3.10.1-beta.0 (2026-02-03)

Bug Fixes

  • sync header_style DB column with theme editor selections (#158) (2288309)
  • sync header_style DB column with theme editor selections (#158) (a19e7c4)

3.10.0-beta.0 (2026-02-03)

Features

  • add category hero/cover photo selection (#163) (6c30e2c)
  • add hero image focal point picker with anchor positioning (#162) (734868a)
  • gallery layouts, hero customization, bulk categories & event types (d9e00dc)

Bug Fixes

  • hero header state and preview in admin theme editor (#158) (f554f46)
  • improve photo serving, category filters, and upload chunking (#155, #156, #161) (fa4c838)
  • resolve code quality issues and add missing i18n keys (#162, #163) (329d224)

3.9.0-beta.0 (2026-02-01)

Features

  • add bulk category editing for photos (#157) (eca36c7)
  • decouple hero header from gallery layouts (#158) (7b8d8bd)
  • gallery layouts, bulk category editing, and hero header improvements (7037106)

Bug Fixes

  • increase upload limit to 1GB and fix category filters (#155, #156) (397d33a)

3.8.0-beta.0 (2026-01-30)

Features

  • add quilted layout, fix mosaic, and backfill photo dimensions (#146) (46ed1bc)
  • improve gallery layouts with aspect-ratio-aware masonry and mosaic modes (#146) (aacfcd5)

Bug Fixes

  • use actual photo aspect ratios in masonry columns mode (#146) (8711f96)
  • use CSS Columns for gap-free mosaic layout (#146) (821d329)
  • use photo dimensions for mosaic aspect ratios (#146) (27ff51e)

3.7.0-beta.0 (2026-01-28)

Features

  • add justified layout modes and aspect-ratio-aware mosaic (#146) (608bbd5)
  • Add justified layout modes and aspect-ratio-aware mosaic (#146) (ef2ae00)

3.6.0-beta.0 (2026-01-27)

Features

  • add justified/rows layout mode to masonry gallery (#146) (e081b56)
  • add justified/rows layout mode to masonry gallery (#146) + security fixes (cd1d504)

Bug Fixes

  • update packages to fix security vulnerabilities (8097a0c)

3.5.0-beta.0 (2026-01-25)

Features

  • add per-event custom logo upload with bug fixes (85170b8)
  • per-event custom logos, customizable event types, and multiple bug fixes (4c08160)

3.4.0-beta.0 (2026-01-22)

Features

  • add customizable event types with admin management (f8881d5)
  • add per-event hero logo customization options (0790a1d)
  • new features and bug fixes for beta release (151e1bf)

Bug Fixes

  • event-specific custom CSS settings not being saved (dadef81), closes #136
  • handle null dates in dashboard and gallery pages (c5a8ffc)
  • remove non-functional watermark toggle from Feature Toggles (d4a15db)
  • resend gallery email fails for events without password (6b3ead7), closes #137

3.3.0-beta.0 (2026-01-21)

Features

  • add original filename preservation and Lightroom export support (a59f414)
  • add original filename preservation and Lightroom export support (9872ad3)

3.2.5-beta.0 (2026-01-18)

Bug Fixes

  • add STORAGE_PATH to production docker-compose (cdda709)
  • correct invitation activation validation and add missing translations (991aa98), closes #129
  • correct invitation email link URL path (86fa104), closes #129
  • resolve admin invitation flow issues and improve STORAGE_PATH documentation (41bf6ff)

Documentation

  • emphasize importance of STORAGE_PATH in env example (3397807)

3.2.4-beta.0 (2026-01-17)

Bug Fixes

  • correct storage path resolution in multiple files (#96) (0e3674b)
  • correct storage path resolution in multiple files (#96) (3ccb815)

3.2.3-beta.0 (2026-01-16)

Bug Fixes

  • add allow_user_uploads to gallery API responses (691e3ab)
  • mobile upload button not visible in gallery (#113) (cacaffa)

3.2.2-beta.0 (2026-01-16)

Bug Fixes

  • mobile upload button visibility in gallery (2a2c23d), closes #113
  • mobile upload button visibility in gallery (#113) (05a5307)

3.2.1-beta.0 (2026-01-16)

Bug Fixes

  • mobile upload button visibility in gallery (df7dbff), closes #113
  • mobile upload button visibility in gallery (#113) (6cb4342)

3.2.0-beta.0 (2026-01-16)

Features

  • add optional event date and expiration settings (3079eaa)
  • add optional event date and expiration settings (2151147), closes #118

Bug Fixes

  • checkbox and toggle settings not persisting after page refresh (808ed1d), closes #117

Documentation

  • add API_URL environment variable to .env.example files (3e69579)

3.1.0-beta.0 (2026-01-15)

Features

  • dynamic website title from branding settings (d29aab7)
  • pre-generate watermarks for instant lightbox loading (1be974a), closes #112
  • pre-generated watermarks and mobile upload button improvements (c6fdd38)

Bug Fixes

  • add lightbox loading spinner and watermark cache invalidation (050ed37)
  • lightbox watermark loading, white label translations, and dynamic footer year (ce8587b)
  • prevent database migration restart failures (83a4344), closes #107
  • show upload button in mobile topbar instead of sidebar (ae181cf), closes #113
  • watermark thumbnails, custom logo display, and German translations (ea20446)

3.0.1-beta.0 (2026-01-15)

Bug Fixes

  • CI workflow fixes for protected branches (cb01218)
  • lightbox watermark loading, white label translations, and dynamic footer year (3b720ed)
  • lightbox watermark loading, white label translations, and dynamic footer year (ce8587b)
  • lightbox watermark loading, white label translations, and dynamic footer year (#108) (3b720ed)

2.3.2 (2026-01-15)

Bug Fixes

  • watermark thumbnails, custom logo display, and German translations (f843e4c)
  • watermark thumbnails, custom logo display, and German translations (ea20446)

2.3.1 (2026-01-15)

Bug Fixes

  • CI workflow fixes for protected branches (657c205)
  • use Release Please extra-files instead of sync-versions job (fe7d45d)

3.0.0-beta.0 (2026-01-15)

⚠ BREAKING CHANGES

  • Deployment now requires external reverse proxy for SSL/HTTPS

Features

  • add Apple Liquid Glass templates, image security settings, and automated releases (6033461)
  • add complete translation support for backup admin page (e9f92e6)
  • Add CSS template system with custom gallery styling support (0da45e6)
  • add event management, gallery customization, and release automationFeature/event rename (40ee671)
  • add feedback management enhancements (0064122)
  • add GitHub Actions workflow for Docker image builds (4029559)
  • add multi-administrator support with RBAC and fix backup/restore for S3 (892e47d)
  • admin: external media import modal + thumbnail fixes for reference events\n\n- Photos tab: replace inline external folder picker with a modal opened via "Import from External Folder" button next to "Upload Photos"; add info that all pictures in the selected folder will be imported.\n- Admin thumbnails: align list endpoint to /api/admin/photos/:eventId/photos and always return thumbnail_url to trigger on-demand generation; normalize external paths to avoid duplicated folder segments (e.g., individual/individual) that broke resolver; improve thumbnail logging.\n- Use authenticated image fetching on admin feedback pages to prevent 401s in automation.\n- i18n: add backup.external.warning strings; complete German backup/restore coverage; add common keys (notSet, of, up, select, selected).\n- Docs: add Local (npm) setup for EXTERNAL_MEDIA_ROOT in deployment guide.\n\nRefs #17 gallery feature request: https://github.com/the-luap/picpeak/issues/17 (49c7778)
  • admin: refine header layout and logo placement (d64e7d0)
  • allow admin email updates in UI (#36) (3c2a79a)
  • beta/stable release channels with update notifications and bug fixes (3c7dc20)
  • beta/stable release channels with update notifications and bug fixes (#98) (3c7dc20)
  • completely rewrite GitHub mirror to create new history from target commit (febacb7)
  • consolidate setup scripts and guides into unified solution (29a8ff9)
  • docker: add PUID/PGID and user mapping to avoid bind mount permission issues; feat(setup): prompt for admin email interactively; docs: PUID/PGID in .env.example (410a33f)
  • enhance mirror-to-github workflow with commit-based history filtering (b4b09c1)
  • events: add CSS template selector to event edit page (6a6c2cd)
  • exclude Claude contributor from GitHub mirror workflow (abbcdb1)
  • fix analytics dashboard and implement complete Umami integration (45ce988)
  • gallery/filters: add Rated and Commented filters (UI + backend).\n\n- UI: add star (Rated) and message (Commented) buttons to feedback filter bars (desktop + mobile)\n- Backend: support filter=rated, commented, and combinations via aggregate counts/queries (b03760a)
  • gallery: add quick Like/Favorite actions on thumbnails across layouts (6368f10)
  • gallery: always-visible feedback indicators on grid tiles; fallback image rendering in lightbox/hero; auto-auth from shared-link token; fix external photo resolver\n\n- GridGallery: bottom-left icons for like/rated/comment on every tile\n- Hero layout grid: added same indicators (non-intrusive icons)\n- Lightbox/Hero: add fallbackSrc to display thumbnail if original fails\n- GalleryAuth: auto-store token from /gallery/:slug/:token and hydrate event\n- Backend gallery photo route: use resolvePhotoFilePath for external-media\n\nfix(admin): move photo feedback badges to bottom-right on admin grid tiles\n\nfix(dashboard): add missing i18n keys for activity types + fallback to formatter\n\nfix(admin/feedback): correct thumbnail URL base + robust date parsing\n\nRefs: #19 (6948aaa)
  • gallery: compact vertical icon-only feedback filter in PhotoFilterBar; remove wide buttons to prevent overflow\n\n- Desktop: vertical icon stack (All/Grid, Likes, Favorites) outside scroll area\n- Mobile: vertical icon stack below categories\n- Keeps existing category bar layout and count\n\nRefs: #19 (465f997)
  • i18n: add translations for settings tabs (c030e87)
  • implement 4 new features with bug fixes and refactoring plan (77a4bfd)
  • implement beta/stable release channels with update notifications (617e778)
  • implement comprehensive backup and restore system with S3 support (f6a79c8)
  • implement feedback filter for liked/favorited photos (Issue #17) (41857ec)
  • implement gallery feedback system with version tracking for backups (dc1419c)
  • implement gallery logo customization (Issue #17) (909e760)
  • lightbox: keep feedback usable while navigating (6368f10), closes #19
  • Multi-administrator RBAC, CSS templates & security hardening (#78) (16b3ab0)
  • native: auto-serve SPA when dist exists (unless SERVE_FRONTEND=false); add clear logging; serve index.html for /admin (fb16b7b)
  • native: build frontend and serve SPA from backend (SERVE_FRONTEND); fix Cannot GET /admin on native installs (9fe10bc)
  • native: serve built frontend from backend; build frontend during install/update; ensure env flags (SERVE_FRONTEND, FRONTEND_DIR) (61ad2d6)
  • overhaul public landing page and backup tooling (2a4d388)
  • select: add per-tile checkbox selection in Admin grid and all gallery layouts; tile click opens viewer; checkbox toggles selection; auto-enable selection mode; add testids (9fda54b)
  • setup/docker: auto-set PUID/PGID from invoking user and chown bind-mount folders; create missing data/events dirs (0618b78)
  • setup: remove --admin-password; print admin credentials from ADMIN_CREDENTIALS.txt; fix ADMIN_URL to avoid /admin/admin; update native service commands (84d0f63)
  • support per-gallery password toggle (5d6c061)
  • update GitHub mirror workflow to start history from specific commit (08da01f)

Bug Fixes

  • add missing route for feedback management page (517128f)
  • add missing translations and fix BackupHistory useTranslation error (99e4778)
  • Add settings translations and fix manual backup process (#82) (476fcce)
  • admin/feedback: use correct event id when rendering photo thumbnails (4c7b49a), closes #19
  • admin: prevent category badge overlap in grid (d64e7d0)
  • align backend port to 3000 across all configurations (3a8d53f)
  • Align nginx backend port for production Docker deployments (v2.2.2) (#88) (e0bd19a)
  • auto-convert old date formats to new date-fns syntax (e1aca6b)
  • backup: add lastBackup alias and totalBackups for frontend compatibility (749100c)
  • backup: allow manual backups when automated backups are disabled (e6dd89e)
  • ci: add QEMU setup for multi-arch builds and skip for PRs (0d36a27)
  • clear notifications via API (#35) (013be18)
  • complete backup page translations and improve UI (7387a5e)
  • complete restore page translations and fix structure (618e269)
  • configure github-release plugin to use GitHub API instead of Gitea (2624ea6)
  • correct GitHub repository path in Drone CI release config (247e154)
  • correct import statements for api in backup JSX files (30f6780)
  • correct malformed gallery URLs in admin panel View Gallery links (3074748)
  • correct password generator function name in reset password route (65d796b)
  • correct script name in Gitea mirror workflow (828d6bc)
  • cors: scope CORS to /api only and avoid throwing on disallowed origins; prevents static asset 500s on native (90bb21e)
  • critical database connection pool exhaustion issues (8588133)
  • db: improve PostgreSQL connection check in wait-for-db.sh (e85a68a)
  • display new password after admin password reset (bd8b885)
  • Docker Swarm DNS resolution and backup status display (v2.2.3) (082d8ab)
  • Docker Swarm DNS resolution and backup status display (v2.2.3) (082d8ab)
  • force github-release plugin to use GitHub API instead of Gitea (558a966)
  • frontend: add missing externalMedia service and mount admin external-media routes; verify Vite build (ab324f1)
  • gallery thumbnails not loading (404 errors) #96 (e3c3c4c)
  • gallery/filters: always apply global liked/favorited filters by aggregate counts (ignore guest_id); resolves mismatch between client guest_id and server identifier (526dcd8)
  • gallery/filters: make feedback filters work globally when no guest_id is provided; remove guest_id from client photos query\n\n- Backend /api/gallery/:slug/photos: if filter present and guest_id missing, filter by like_count/favorite_count\n- Frontend useGalleryPhotos: stop passing random guestId (does not match server guest_identifier)\n\nThis makes Liked/Favorited filters reflect photos with aggregate feedback counts as expected. (5b2561b)
  • gallery/sidebar: compact icon-only feedback filter in sidebar (vertical, small) to avoid overflow; use GalleryFilter variant=compact (ff89f96)
  • gallery: feedback filter headline + horizontal icons in sidebar (compact variant); ensure sidebar content scrolls (flex-col container) (3a6d061)
  • handle auth errors and JSON parsing in admin panel (b2ae5f1)
  • handle legacy non-JSON logo paths when replacing logo (0d5ce48)
  • harden gallery downloads and per-gallery auth (fc1bf53)
  • implement 9 production enhancements and security fixes (c584369)
  • improve admin credentials display and configuration (ad495a9)
  • improve version bump workflow with better conflict resolution (c787510)
  • JSON serialize favicon and logo URLs for PostgreSQL storage (b83f427)
  • Multi-administrator RBAC, CSS templates & security hardening (#80) (37d4e1c)
  • multiple improvements and CI/CD updates (bf70567)
  • native/http: disable CSP upgrade-insecure-requests and HSTS unless ENABLE_HSTS=true; prevents HTTPS upgrades on HTTP installs (24b4a31)
  • native: correct setup paths to /opt/picpeak/app, update repo URL, add sqlite prod support; docs path fixes (b992b15)
  • native: remove obsolete workers service; restart only backend; add API request logging and preflight handler; keep static assets outside CORS (f3604b4)
  • nginx: add Docker DNS resolver for Swarm/dynamic service discovery (049837f)
  • nginx: Add Docker DNS resolver for Swarm/dynamic service discovery (v2.2.3) (cc1ddfd)
  • photos: category changes now persist and display correctly (#77) (d9da98c)
  • photos: resolve upload category selection and improve feedback buttons (#77) (856d533)
  • prefer admin token on admin routes (#23 #28) (d4404e3)
  • prevent unnecessary image recompression and fix SQLite migration #95 (3cdc0ea)
  • remove description field from migration 035 app_settings inserts (22cc406)
  • remove file requirement from GitHub release in Drone CI (8335916)
  • remove formatBoolean calls from migration 032 - critical production fix (0502ed3)
  • remove unnecessary publish-manifest job from Docker workflow (986b101)
  • remove unused formatBoolean import from migration 033 (1238db5)
  • remove updated_at field from password reset query (ed0243e)
  • remove updated_at from app_settings inserts in multiple migrations (4c42b4c)
  • replace github-release plugin with direct curl API call (76a466c)
  • resolve backend startup errors in development (f8fb1c3)
  • resolve branding display issues and invitation parsing errors (1931d73)
  • Resolve branding display issues and invitation parsing errors (v2.2.1) (#86) (d7ecf83)
  • resolve CI/CD version bump race condition (0bf4764)
  • resolve database connection error for analytics settings (95939d5)
  • resolve date formatting error in event creation (c51d756)
  • resolve development environment issues (61299a3)
  • resolve duplicate logger declaration and syntax error in rate limit service (0fe6d73)
  • resolve feedback validation issues from GitHub issue #16 (f26beca)
  • resolve feedback validation issues from GitHub issue #16 (67ff415)
  • resolve GitHub issues #4, #8, #9, and #10 (934d6dd)
  • resolve GitHub mirror workflow cherry-pick failure with merge commits (d6adde4)
  • resolve language-specific column issues in core migrations (62617f6)
  • resolve migration conflicts and duplicate numbering (a401fbd)
  • resolve multiple feedback management issues (ad75818)
  • resolve multiple issues from GitHub issue #14 (e91209f)
  • resolve port configuration issues and database column mismatch (6de64a1)
  • resolve PostgreSQL migration issues for development environment (ee855a3)
  • resolve production UI and API issues (d5790ad)
  • resolve SIGPIPE error in GitHub mirror workflow file cleanup (b7c8953)
  • resolve translation interpolation issue for download button (c1e10f1)
  • security: upgrade Alpine base image to fix libpng and c-ares CVEs (b706eeb)
  • setup/native: correct repo URL, paths, and systemd for native install; support sqlite in production knex config (87b8414)
  • setup/native: Debian 12 compatibility (reliable RAM detection, sudo-less run_as_user, git safe.directory); ensure SQLite data dir; use user for migrate (dc482e6)
  • setup/native: handle forced updates safely by fetch+checkout/reset instead of pull; stable on rewritten histories (3697344)
  • setup/update: detect native installs first (/opt/picpeak/app/backend or systemd unit); avoid false docker updates on root (adf576f)
  • simplify Drone github-release step to avoid shell parsing issues (94f10e1)
  • stabilize uploads and guest feedback filters (aaaf598)
  • update all deployment guide links in README.md (6389b9d)
  • update deployment guide with critical URL configuration and nginx port fixes (1cadce1)
  • update form-data and multer to address security vulnerabilities (7750170)
  • update Gitea mirror workflow to selectively remove scripts (296430e)
  • update GitHub mirror action to support fine-grained personal access tokens (827eb48)
  • use admin API for Umami config in analytics page (a54a2c0)
  • use plugins/gitea-release for Drone CI/CD (0c783c6)
  • use plugins/github-release for Drone CI/CD (f926cd3)
  • watermark upload JSON parsing and image quality preservation (0e3b50d)

Documentation

  • add minimum system requirements section to README (4615a5d)
  • add PUID/PGID note for Docker bind mounts to avoid permission issues (0178e71)
  • add transparency note about AI-assisted development (35e360d)
  • add warnings about $ character in Docker Compose passwords (87d1761)
  • clarify VITE_API_URL usage; remove FRONTEND_API_URL; add storage vars; simplify compose mounts and external DB example (refs #18) (758c085)
  • compose: fix backend healthcheck path; remove frontend VITE_API_URL env and document /api proxy (refs #18) (ecbc488)
  • fix deployment/admin routing and CORS guidance; add AGENTS.md; ignore AGENTS.md (refs #18) (dad1787)
  • follow-up on PR #15 — clarify VITE_API_URL usage, compose mounts, and admin routing (refs #15) (e9171c7)
  • readme: reflect new External Media reference mode and update roadmap (gallery feedback status) (ee13556)
  • replace email addresses with GitHub issue links (0c989ce)
  • update deployment guide with GitHub Container Registry images (2c9a56f)

Code Refactoring

  • simplify deployment structure with direct port exposure (6492cb9)

2.3.0 (2026-01-15)

Features

  • beta/stable release channels with update notifications and bug fixes (3c7dc20)
  • beta/stable release channels with update notifications and bug fixes (#98) (3c7dc20)
  • implement beta/stable release channels with update notifications (617e778)

Bug Fixes

  • display new password after admin password reset (bd8b885)
  • gallery thumbnails not loading (404 errors) #96 (e3c3c4c)
  • prevent unnecessary image recompression and fix SQLite migration #95 (3cdc0ea)
  • watermark upload JSON parsing and image quality preservation (0e3b50d)

2.2.4 (2026-01-08)

Bug Fixes

  • backup: add lastBackup alias and totalBackups for frontend compatibility (749100c)
  • Docker Swarm DNS resolution and backup status display (v2.2.3) (082d8ab)
  • Docker Swarm DNS resolution and backup status display (v2.2.3) (082d8ab)

2.2.3 (2026-01-08)

Bug Fixes

  • nginx: add Docker DNS resolver for Swarm/dynamic service discovery (049837f)
  • nginx: Add Docker DNS resolver for Swarm/dynamic service discovery (v2.2.3) (cc1ddfd)

2.2.2 (2026-01-08)

Bug Fixes

  • align backend port to 3000 across all configurations (3a8d53f)
  • Align nginx backend port for production Docker deployments (v2.2.2) (#88) (e0bd19a)

2.2.1 (2026-01-08)

Bug Fixes

  • handle legacy non-JSON logo paths when replacing logo (0d5ce48)
  • JSON serialize favicon and logo URLs for PostgreSQL storage (b83f427)
  • resolve branding display issues and invitation parsing errors (1931d73)
  • Resolve branding display issues and invitation parsing errors (v2.2.1) (#86) (d7ecf83)

2.2.0 (2026-01-08)

Features

  • i18n: add translations for settings tabs (c030e87)

Bug Fixes

  • Add settings translations and fix manual backup process (#82) (476fcce)
  • backup: allow manual backups when automated backups are disabled (e6dd89e)
  • db: improve PostgreSQL connection check in wait-for-db.sh (e85a68a)

2.1.1 (2026-01-07)

Bug Fixes

  • ci: add QEMU setup for multi-arch builds and skip for PRs (0d36a27)
  • Multi-administrator RBAC, CSS templates & security hardening (#80) (37d4e1c)

2.1.0 (2026-01-07)

Features

  • add multi-administrator support with RBAC and fix backup/restore for S3 (892e47d)
  • events: add CSS template selector to event edit page (6a6c2cd)
  • Multi-administrator RBAC, CSS templates & security hardening (#78) (16b3ab0)

Bug Fixes

  • photos: category changes now persist and display correctly (#77) (d9da98c)
  • photos: resolve upload category selection and improve feedback buttons (#77) (856d533)

2.0.0 (2026-01-03)

⚠ BREAKING CHANGES

  • Deployment now requires external reverse proxy for SSL/HTTPS

Features

  • add Apple Liquid Glass templates, image security settings, and automated releases (6033461)
  • add complete translation support for backup admin page (e9f92e6)
  • Add CSS template system with custom gallery styling support (0da45e6)
  • add event management, gallery customization, and release automationFeature/event rename (40ee671)
  • add feedback management enhancements (0064122)
  • add GitHub Actions workflow for Docker image builds (4029559)
  • admin: external media import modal + thumbnail fixes for reference events\n\n- Photos tab: replace inline external folder picker with a modal opened via "Import from External Folder" button next to "Upload Photos"; add info that all pictures in the selected folder will be imported.\n- Admin thumbnails: align list endpoint to /api/admin/photos/:eventId/photos and always return thumbnail_url to trigger on-demand generation; normalize external paths to avoid duplicated folder segments (e.g., individual/individual) that broke resolver; improve thumbnail logging.\n- Use authenticated image fetching on admin feedback pages to prevent 401s in automation.\n- i18n: add backup.external.warning strings; complete German backup/restore coverage; add common keys (notSet, of, up, select, selected).\n- Docs: add Local (npm) setup for EXTERNAL_MEDIA_ROOT in deployment guide.\n\nRefs #17 gallery feature request: https://github.com/the-luap/picpeak/issues/17 (49c7778)
  • admin: refine header layout and logo placement (d64e7d0)
  • allow admin email updates in UI (#36) (3c2a79a)
  • completely rewrite GitHub mirror to create new history from target commit (febacb7)
  • consolidate setup scripts and guides into unified solution (29a8ff9)
  • docker: add PUID/PGID and user mapping to avoid bind mount permission issues; feat(setup): prompt for admin email interactively; docs: PUID/PGID in .env.example (410a33f)
  • enhance mirror-to-github workflow with commit-based history filtering (b4b09c1)
  • exclude Claude contributor from GitHub mirror workflow (abbcdb1)
  • fix analytics dashboard and implement complete Umami integration (45ce988)
  • gallery/filters: add Rated and Commented filters (UI + backend).\n\n- UI: add star (Rated) and message (Commented) buttons to feedback filter bars (desktop + mobile)\n- Backend: support filter=rated, commented, and combinations via aggregate counts/queries (b03760a)
  • gallery: add quick Like/Favorite actions on thumbnails across layouts (6368f10)
  • gallery: always-visible feedback indicators on grid tiles; fallback image rendering in lightbox/hero; auto-auth from shared-link token; fix external photo resolver\n\n- GridGallery: bottom-left icons for like/rated/comment on every tile\n- Hero layout grid: added same indicators (non-intrusive icons)\n- Lightbox/Hero: add fallbackSrc to display thumbnail if original fails\n- GalleryAuth: auto-store token from /gallery/:slug/:token and hydrate event\n- Backend gallery photo route: use resolvePhotoFilePath for external-media\n\nfix(admin): move photo feedback badges to bottom-right on admin grid tiles\n\nfix(dashboard): add missing i18n keys for activity types + fallback to formatter\n\nfix(admin/feedback): correct thumbnail URL base + robust date parsing\n\nRefs: #19 (6948aaa)
  • gallery: compact vertical icon-only feedback filter in PhotoFilterBar; remove wide buttons to prevent overflow\n\n- Desktop: vertical icon stack (All/Grid, Likes, Favorites) outside scroll area\n- Mobile: vertical icon stack below categories\n- Keeps existing category bar layout and count\n\nRefs: #19 (465f997)
  • implement 4 new features with bug fixes and refactoring plan (77a4bfd)
  • implement comprehensive backup and restore system with S3 support (f6a79c8)
  • implement feedback filter for liked/favorited photos (Issue #17) (41857ec)
  • implement gallery feedback system with version tracking for backups (dc1419c)
  • implement gallery logo customization (Issue #17) (909e760)
  • lightbox: keep feedback usable while navigating (6368f10), closes #19
  • native: auto-serve SPA when dist exists (unless SERVE_FRONTEND=false); add clear logging; serve index.html for /admin (fb16b7b)
  • native: build frontend and serve SPA from backend (SERVE_FRONTEND); fix Cannot GET /admin on native installs (9fe10bc)
  • native: serve built frontend from backend; build frontend during install/update; ensure env flags (SERVE_FRONTEND, FRONTEND_DIR) (61ad2d6)
  • overhaul public landing page and backup tooling (2a4d388)
  • select: add per-tile checkbox selection in Admin grid and all gallery layouts; tile click opens viewer; checkbox toggles selection; auto-enable selection mode; add testids (9fda54b)
  • setup/docker: auto-set PUID/PGID from invoking user and chown bind-mount folders; create missing data/events dirs (0618b78)
  • setup: remove --admin-password; print admin credentials from ADMIN_CREDENTIALS.txt; fix ADMIN_URL to avoid /admin/admin; update native service commands (84d0f63)
  • support per-gallery password toggle (5d6c061)
  • update GitHub mirror workflow to start history from specific commit (08da01f)

Bug Fixes

  • add missing route for feedback management page (517128f)
  • add missing translations and fix BackupHistory useTranslation error (99e4778)
  • admin/feedback: use correct event id when rendering photo thumbnails (4c7b49a), closes #19
  • admin: prevent category badge overlap in grid (d64e7d0)
  • auto-convert old date formats to new date-fns syntax (e1aca6b)
  • clear notifications via API (#35) (013be18)
  • complete backup page translations and improve UI (7387a5e)
  • complete restore page translations and fix structure (618e269)
  • configure github-release plugin to use GitHub API instead of Gitea (2624ea6)
  • correct GitHub repository path in Drone CI release config (247e154)
  • correct import statements for api in backup JSX files (30f6780)
  • correct malformed gallery URLs in admin panel View Gallery links (3074748)
  • correct password generator function name in reset password route (65d796b)
  • correct script name in Gitea mirror workflow (828d6bc)
  • cors: scope CORS to /api only and avoid throwing on disallowed origins; prevents static asset 500s on native (90bb21e)
  • critical database connection pool exhaustion issues (8588133)
  • force github-release plugin to use GitHub API instead of Gitea (558a966)
  • frontend: add missing externalMedia service and mount admin external-media routes; verify Vite build (ab324f1)
  • gallery/filters: always apply global liked/favorited filters by aggregate counts (ignore guest_id); resolves mismatch between client guest_id and server identifier (526dcd8)
  • gallery/filters: make feedback filters work globally when no guest_id is provided; remove guest_id from client photos query\n\n- Backend /api/gallery/:slug/photos: if filter present and guest_id missing, filter by like_count/favorite_count\n- Frontend useGalleryPhotos: stop passing random guestId (does not match server guest_identifier)\n\nThis makes Liked/Favorited filters reflect photos with aggregate feedback counts as expected. (5b2561b)
  • gallery/sidebar: compact icon-only feedback filter in sidebar (vertical, small) to avoid overflow; use GalleryFilter variant=compact (ff89f96)
  • gallery: feedback filter headline + horizontal icons in sidebar (compact variant); ensure sidebar content scrolls (flex-col container) (3a6d061)
  • handle auth errors and JSON parsing in admin panel (b2ae5f1)
  • harden gallery downloads and per-gallery auth (fc1bf53)
  • implement 9 production enhancements and security fixes (c584369)
  • improve admin credentials display and configuration (ad495a9)
  • improve version bump workflow with better conflict resolution (c787510)
  • multiple improvements and CI/CD updates (bf70567)
  • native/http: disable CSP upgrade-insecure-requests and HSTS unless ENABLE_HSTS=true; prevents HTTPS upgrades on HTTP installs (24b4a31)
  • native: correct setup paths to /opt/picpeak/app, update repo URL, add sqlite prod support; docs path fixes (b992b15)
  • native: remove obsolete workers service; restart only backend; add API request logging and preflight handler; keep static assets outside CORS (f3604b4)
  • prefer admin token on admin routes (#23 #28) (d4404e3)
  • remove description field from migration 035 app_settings inserts (22cc406)
  • remove file requirement from GitHub release in Drone CI (8335916)
  • remove formatBoolean calls from migration 032 - critical production fix (0502ed3)
  • remove unnecessary publish-manifest job from Docker workflow (986b101)
  • remove unused formatBoolean import from migration 033 (1238db5)
  • remove updated_at field from password reset query (ed0243e)
  • remove updated_at from app_settings inserts in multiple migrations (4c42b4c)
  • replace github-release plugin with direct curl API call (76a466c)
  • resolve backend startup errors in development (f8fb1c3)
  • resolve CI/CD version bump race condition (0bf4764)
  • resolve database connection error for analytics settings (95939d5)
  • resolve date formatting error in event creation (c51d756)
  • resolve development environment issues (61299a3)
  • resolve duplicate logger declaration and syntax error in rate limit service (0fe6d73)
  • resolve feedback validation issues from GitHub issue #16 (f26beca)
  • resolve feedback validation issues from GitHub issue #16 (67ff415)
  • resolve GitHub issues #4, #8, #9, and #10 (934d6dd)
  • resolve GitHub mirror workflow cherry-pick failure with merge commits (d6adde4)
  • resolve language-specific column issues in core migrations (62617f6)
  • resolve migration conflicts and duplicate numbering (a401fbd)
  • resolve multiple feedback management issues (ad75818)
  • resolve multiple issues from GitHub issue #14 (e91209f)
  • resolve port configuration issues and database column mismatch (6de64a1)
  • resolve PostgreSQL migration issues for development environment (ee855a3)
  • resolve production UI and API issues (d5790ad)
  • resolve SIGPIPE error in GitHub mirror workflow file cleanup (b7c8953)
  • resolve translation interpolation issue for download button (c1e10f1)
  • setup/native: correct repo URL, paths, and systemd for native install; support sqlite in production knex config (87b8414)
  • setup/native: Debian 12 compatibility (reliable RAM detection, sudo-less run_as_user, git safe.directory); ensure SQLite data dir; use user for migrate (dc482e6)
  • setup/native: handle forced updates safely by fetch+checkout/reset instead of pull; stable on rewritten histories (3697344)
  • setup/update: detect native installs first (/opt/picpeak/app/backend or systemd unit); avoid false docker updates on root (adf576f)
  • simplify Drone github-release step to avoid shell parsing issues (94f10e1)
  • stabilize uploads and guest feedback filters (aaaf598)
  • update all deployment guide links in README.md (6389b9d)
  • update deployment guide with critical URL configuration and nginx port fixes (1cadce1)
  • update form-data and multer to address security vulnerabilities (7750170)
  • update Gitea mirror workflow to selectively remove scripts (296430e)
  • update GitHub mirror action to support fine-grained personal access tokens (827eb48)
  • use admin API for Umami config in analytics page (a54a2c0)
  • use plugins/gitea-release for Drone CI/CD (0c783c6)
  • use plugins/github-release for Drone CI/CD (f926cd3)

Documentation

  • add minimum system requirements section to README (4615a5d)
  • add PUID/PGID note for Docker bind mounts to avoid permission issues (0178e71)
  • add transparency note about AI-assisted development (35e360d)
  • add warnings about $ character in Docker Compose passwords (87d1761)
  • clarify VITE_API_URL usage; remove FRONTEND_API_URL; add storage vars; simplify compose mounts and external DB example (refs #18) (758c085)
  • compose: fix backend healthcheck path; remove frontend VITE_API_URL env and document /api proxy (refs #18) (ecbc488)
  • fix deployment/admin routing and CORS guidance; add AGENTS.md; ignore AGENTS.md (refs #18) (dad1787)
  • follow-up on PR #15 — clarify VITE_API_URL usage, compose mounts, and admin routing (refs #15) (e9171c7)
  • readme: reflect new External Media reference mode and update roadmap (gallery feedback status) (ee13556)
  • replace email addresses with GitHub issue links (0c989ce)
  • update deployment guide with GitHub Container Registry images (2c9a56f)

Code Refactoring

  • simplify deployment structure with direct port exposure (6492cb9)

1.2.0 (2026-01-03)

Features

  • Event Rename: Safe event renaming with automatic slug updates, old URL redirects via slug_redirects table, and optional email notifications to clients
  • Optional Event Fields: Make customer name, email, and admin email fields optional via admin settings with "(optional)" labels in forms
  • Photo Filtering: Filter photos by rating, likes, favorites, and comments with a new PhotoFilterPanel component
  • Photo Export: Export filtered photo selections as ZIP, generate Capture One/Lightroom-compatible XMP sidecar files, or export metadata lists
  • Custom CSS Templates: 3 customizable CSS template slots with live preview, XSS-safe sanitization, and per-event template assignment
  • Apple Liquid Glass Theme: Starter CSS template inspired by iOS 26 / macOS Tahoe Liquid Glass design with glass morphism effects, Apple SF Pro fonts, and responsive layout
  • Liquid Glass Dark Theme: Neon-accented dark glass theme with animated gradient backgrounds
  • Image Security Settings: Per-event download protection with configurable protection levels (basic, standard, enhanced, maximum), canvas rendering, DevTools detection, and right-click prevention
  • Automated Releases: Release Please integration for automatic versioning, changelog generation, and GitHub releases that trigger Docker image builds

Bug Fixes

  • Date Parsing: Fix event date formatting in slugs (now uses YYYY-MM-DD format correctly)
  • Search Placeholder: Fix search field placeholder visibility in glass-styled sidebar
  • Vite Proxy: Fix Vite dev server proxy port configuration
  • Photo Export Button: Fix export button staying disabled when photos are selected
  • Boolean Parsing: Fix boolean parsing in publicSettings.js for optional fields
  • Translation Keys: Add missing common.optional translation key in locales

Security

  • Fix critical vulnerabilities and harden application security
  • Add CSS sanitizer utility blocking XSS vectors in custom templates
  • Implement secure gallery CSS endpoint for template delivery

Code Refactoring

  • Add Photo and Settings service layers for better code organization
  • Phase 1 code consolidation with service layer architecture
  • Modular settings page with feature-based tab components
  • Create photoFilterBuilder utility for query construction
  • Add eventRenameService for safe event operations

Documentation

  • Add comprehensive REFACTORING_PLAN.md for codebase improvement roadmap
  • Update README roadmap with implemented features (Download Protection, Gallery Templates, Filtering & Export)
  • Add test specification documents for all new features

Database Migrations

  • 049_add_slug_redirects.js - Store old slugs for URL redirects after rename
  • 050_add_optional_event_fields_settings.js - Settings for optional form fields
  • 051_add_photo_filter_indexes.js - Performance indexes for photo filtering
  • 052_add_css_templates.js - CSS template storage with 3 slots
  • 053_add_liquid_glass_templates.js - Apple Liquid Glass and Dark theme starter templates

[1.1.15] - Previous Release

Initial stable release with core functionality.