Files
picpeak/CHANGELOG.md
T
github-actions[bot] 2ac6c51fe5
Build and Push Docker Images / build-backend (push) Failing after 3m42s
Build and Push Docker Images / build-frontend (push) Failing after 3m41s
Build and Push Docker Images / summary (push) Successful in 3s
chore(beta): release 3.21.1-beta.0 (#255)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-03-22 12:43:55 +01:00

106 KiB
Raw Blame History

Changelog

All notable changes to PicPeak will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

3.21.1-beta.0 (2026-03-22)

Bug Fixes

  • address Shannon security assessment findings (37 vulnerabilities) (#254) (23cd9cb)

3.21.0-beta.0 (2026-03-18)

Features

Bug Fixes

  • wrap test email with standard email template (#252) (954a011)

3.20.1-beta.0 (2026-03-17)

Bug Fixes

  • address beta feedback - gallery layout fixes, Russian locale, email logo (#249) (486239a)

3.20.0-beta.0 (2026-03-17)

Features

  • photo visibility control with client access (#172) (4a93e4e)
  • photo visibility control with client access (#172) (e1b6e43)

3.19.2-beta.0 (2026-03-16)

Bug Fixes

  • security: invalidate tokens on password change, enforce session timeout, fix role update (f362239)
  • security: token invalidation on password change, session timeout enforcement (7ca9631)

3.19.1-beta.0 (2026-03-16)

Bug Fixes

  • external media dimensions, theme race condition, email color customization (dfae2c2)
  • resolve external media dimensions, gallery theme race condition, and add email color customization (bbeedd1)

3.19.0-beta.0 (2026-03-16)

Features

  • add photo cap per event and Portuguese (pt-BR) locale (1fa222e)
  • add photo cap per event and Portuguese locale (088de43)

3.18.2-beta.0 (2026-03-16)

Bug Fixes

  • resolve code scanning security alerts (multer, tar, Node 22) (85a07fc)
  • update dependencies to resolve code scanning security alerts (1f524f2)

3.18.1-beta.0 (2026-03-16)

Bug Fixes

  • wrap email preview with full styled header/footer template (9a6d2e8)
  • wrap email preview with full styled header/footer template (fc0911a), closes #229

3.18.0-beta.0 (2026-03-16)

Features

  • add visual WYSIWYG email template editor (#229) (04a7ea8)
  • register Russian locale and add to language selector (6f95b8c)
  • visual WYSIWYG email template editor (703c03f)

Bug Fixes

  • shorten Save button label on email template editor (7250c42)

3.17.2-beta.0 (2026-03-11)

Bug Fixes

  • update security policy with private reporting channels (308e086)
  • update security policy with proper contact email and private reporting (67b0f32), closes #223
  • video upload media type, select all, and dimension repair (#203, #220, #180) (fc75bcd)
  • video upload, select all, and dimension repair (#203, #220, #180) (a0bb080)

3.17.1-beta.0 (2026-03-08)

Bug Fixes

  • respect optional email settings in event creation (831ea6a)
  • respect optional email settings in event creation (#217) (9c44a0e)

3.17.0-beta.0 (2026-03-05)

Features

  • configurable upload batch size for reverse proxy compatibility (9b7495e)

3.16.0-beta.0 (2026-03-05)

Features

  • add thumbnail settings UI to admin panel (3a30fea)
  • add thumbnail settings UI to admin settings page (#206) (7d6d2f5)

3.15.3-beta.0 (2026-03-02)

Bug Fixes

  • issue #203 file type validation + security CVE fixes (8017171)
  • respect allowed_file_types setting for upload validation (#203) (fe07a14)
  • security: resolve all npm audit vulnerabilities (4272618)
  • security: resolve Docker image CVEs for code scanning alerts (cbecb93)

2.6.0 (2026-03-11)

Features

  • add configurable upload batch size for reverse proxy compatibility (#208) (02a46e0)
  • configurable upload batch size for reverse proxy compatibility (4243363)

Bug Fixes

2.5.1 (2026-02-22)

Bug Fixes

2.5.0 (2026-02-21)

Features

  • add admin dark mode and SEO/robots.txt settings (9c2a0d2)
  • add bulk category editing for photos (#157) (eca36c7)
  • add category hero/cover photo selection (#163) (6c30e2c)
  • add customizable event types with admin management (f8881d5)
  • add Gallery Premium and Gallery Story layouts (Beta) (e179def)
  • add hero image focal point picker with anchor positioning (#162) (734868a)
  • add justified layout modes and aspect-ratio-aware mosaic (#146) (608bbd5)
  • Add justified layout modes and aspect-ratio-aware mosaic (#146) (ef2ae00)
  • add justified/rows layout mode to masonry gallery (#146) (e081b56)
  • add justified/rows layout mode to masonry gallery (#146) + security fixes (cd1d504)
  • add optional event date and expiration settings (3079eaa)
  • add optional event date and expiration settings (2151147), closes #118
  • add original filename preservation and Lightroom export support (a59f414)
  • add original filename preservation and Lightroom export support (9872ad3)
  • add per-event custom logo upload with bug fixes (85170b8)
  • add per-event hero logo customization options (0790a1d)
  • add quilted layout, fix mosaic, and backfill photo dimensions (#146) (46ed1bc)
  • add update instructions dialog, email notifications, and capture date sorting (50c0990), closes #181
  • decouple hero header from gallery layouts (#158) (7b8d8bd)
  • gallery layouts, bulk category editing, and hero header improvements (7037106)
  • gallery layouts, hero customization, bulk categories & event types (d9e00dc)
  • gallery layouts, hero customization, event types, and UX improvements (#146, #155-163, #170, #171) (4280444)
  • improve gallery layouts with aspect-ratio-aware masonry and mosaic modes (#146) (aacfcd5)
  • improve hero image UX and live preview (#163, #158) (d63f67a)
  • new features and bug fixes for beta release (151e1bf)
  • original filename in admin UI, update dialog, and security hardening (3ea9d5b)
  • original filename in admin UI, update dialog, security hardening, and bug fixes (bcf2745)
  • per-event custom logos, customizable event types, and multiple bug fixes (4c08160)
  • pre-generate watermarks for instant lightbox loading (1be974a), closes #112
  • pre-generated watermarks and mobile upload button improvements (c6fdd38)
  • show original filename in admin UI (#184) (0891be1)

3.15.2-beta.0 (2026-02-22)

Bug Fixes

  • add allow_user_uploads to gallery API responses (691e3ab)
  • add STORAGE_PATH to production docker-compose (cdda709)
  • checkbox and toggle settings not persisting after page refresh (808ed1d), closes #117
  • correct invitation activation validation and add missing translations (991aa98), closes #129
  • correct invitation email link URL path (86fa104), closes #129
  • correct storage path resolution in multiple files (#96) (0e3674b)
  • correct storage path resolution in multiple files (#96) (3ccb815)
  • docker compose v2 syntax and add missing ADMIN_PASSWORD to .env.example (#189) (0817443)
  • event-specific custom CSS settings not being saved (dadef81), closes #136
  • events without expiration date incorrectly shown as expired (c4f16eb)
  • handle null dates in dashboard and gallery pages (c5a8ffc)
  • hero header state and preview in admin theme editor (#158) (f554f46)
  • improve ghost button visibility in admin dark mode (4912e2b)
  • improve password validation errors and event list UX (#170, #171) (171abb3)
  • improve photo serving, category filters, and upload chunking (#155, #156, #161) (fa4c838)
  • increase upload limit to 1GB and fix category filters (#155, #156) (397d33a)
  • mobile upload button not visible in gallery (#113) (cacaffa)
  • mobile upload button visibility in gallery (2a2c23d), closes #113
  • mobile upload button visibility in gallery (df7dbff), closes #113
  • mobile upload button visibility in gallery (#113) (05a5307)
  • mobile upload button visibility in gallery (#113) (6cb4342)
  • remove non-functional watermark toggle from Feature Toggles (d4a15db)
  • render minimal/none header styles, cap hero height, switch category hero images (#158, #162, #163) (bc6c48b)
  • resend gallery email fails for events without password (6b3ead7), closes #137
  • resolve admin invitation flow issues and improve STORAGE_PATH documentation (41bf6ff)
  • resolve code quality issues and add missing i18n keys (#162, #163) (329d224)
  • resolve mixed light/dark mode styling in admin UI (#175) (f8c8abd)
  • restore aspect-ratio layouts and improve hero image quality (#180) (3974ba5)
  • restore aspect-ratio layouts and improve hero image quality (#180) (5cef7fd)
  • show upload button in mobile topbar instead of sidebar (ae181cf), closes #113
  • sync header_style DB column with theme editor selections (#158) (2288309)
  • sync header_style DB column with theme editor selections (#158) (a19e7c4)
  • update docker-compose to docker compose and add ADMIN_PASSWORD to .env.example (#189) (a4c6248)
  • update packages to fix security vulnerabilities (8097a0c)
  • use actual photo aspect ratios in masonry columns mode (#146) (8711f96)
  • use CSS Columns for gap-free mosaic layout (#146) (821d329)
  • use photo dimensions for mosaic aspect ratios (#146) (27ff51e)

Documentation

3.15.1-beta.0 (2026-02-21)

Bug Fixes

  • docker compose v2 syntax and add missing ADMIN_PASSWORD to .env.example (#189) (0817443)
  • update docker-compose to docker compose and add ADMIN_PASSWORD to .env.example (#189) (a4c6248)

3.15.0-beta.0 (2026-02-17)

Features

  • original filename in admin UI, update dialog, security hardening, and bug fixes (bcf2745)

Bug Fixes

  • events without expiration date incorrectly shown as expired (c4f16eb)

3.14.0-beta.0 (2026-02-17)

Features

  • add update instructions dialog, email notifications, and capture date sorting (50c0990), closes #181
  • original filename in admin UI, update dialog, and security hardening (3ea9d5b)
  • show original filename in admin UI (#184) (0891be1)

3.13.1-beta.0 (2026-02-15)

Bug Fixes

  • restore aspect-ratio layouts and improve hero image quality (#180) (3974ba5)
  • restore aspect-ratio layouts and improve hero image quality (#180) (5cef7fd)

3.13.0-beta.0 (2026-02-06)

Features

3.12.0-beta.0 (2026-02-06)

Features

  • add admin dark mode and SEO/robots.txt settings (9c2a0d2)

Bug Fixes

  • improve ghost button visibility in admin dark mode (4912e2b)
  • resolve mixed light/dark mode styling in admin UI (#175) (f8c8abd)

3.11.0-beta.0 (2026-02-06)

Features

  • add Gallery Premium and Gallery Story layouts (Beta) (e179def)
  • gallery layouts, hero customization, event types, and UX improvements (#146, #155-163, #170, #171) (4280444)

Bug Fixes

  • improve password validation errors and event list UX (#170, #171) (171abb3)
  • render minimal/none header styles, cap hero height, switch category hero images (#158, #162, #163) (bc6c48b)

3.10.1-beta.0 (2026-02-03)

Bug Fixes

  • sync header_style DB column with theme editor selections (#158) (2288309)
  • sync header_style DB column with theme editor selections (#158) (a19e7c4)

3.10.0-beta.0 (2026-02-03)

Features

  • add category hero/cover photo selection (#163) (6c30e2c)
  • add hero image focal point picker with anchor positioning (#162) (734868a)
  • gallery layouts, hero customization, bulk categories & event types (d9e00dc)

Bug Fixes

  • hero header state and preview in admin theme editor (#158) (f554f46)
  • improve photo serving, category filters, and upload chunking (#155, #156, #161) (fa4c838)
  • resolve code quality issues and add missing i18n keys (#162, #163) (329d224)

3.9.0-beta.0 (2026-02-01)

Features

  • add bulk category editing for photos (#157) (eca36c7)
  • decouple hero header from gallery layouts (#158) (7b8d8bd)
  • gallery layouts, bulk category editing, and hero header improvements (7037106)

Bug Fixes

  • increase upload limit to 1GB and fix category filters (#155, #156) (397d33a)

3.8.0-beta.0 (2026-01-30)

Features

  • add quilted layout, fix mosaic, and backfill photo dimensions (#146) (46ed1bc)
  • improve gallery layouts with aspect-ratio-aware masonry and mosaic modes (#146) (aacfcd5)

Bug Fixes

  • use actual photo aspect ratios in masonry columns mode (#146) (8711f96)
  • use CSS Columns for gap-free mosaic layout (#146) (821d329)
  • use photo dimensions for mosaic aspect ratios (#146) (27ff51e)

3.7.0-beta.0 (2026-01-28)

Features

  • add justified layout modes and aspect-ratio-aware mosaic (#146) (608bbd5)
  • Add justified layout modes and aspect-ratio-aware mosaic (#146) (ef2ae00)

3.6.0-beta.0 (2026-01-27)

Features

  • add justified/rows layout mode to masonry gallery (#146) (e081b56)
  • add justified/rows layout mode to masonry gallery (#146) + security fixes (cd1d504)

Bug Fixes

  • update packages to fix security vulnerabilities (8097a0c)

3.5.0-beta.0 (2026-01-25)

Features

  • add per-event custom logo upload with bug fixes (85170b8)
  • per-event custom logos, customizable event types, and multiple bug fixes (4c08160)

3.4.0-beta.0 (2026-01-22)

Features

  • add customizable event types with admin management (f8881d5)
  • add per-event hero logo customization options (0790a1d)
  • new features and bug fixes for beta release (151e1bf)

Bug Fixes

  • event-specific custom CSS settings not being saved (dadef81), closes #136
  • handle null dates in dashboard and gallery pages (c5a8ffc)
  • remove non-functional watermark toggle from Feature Toggles (d4a15db)
  • resend gallery email fails for events without password (6b3ead7), closes #137

3.3.0-beta.0 (2026-01-21)

Features

  • add original filename preservation and Lightroom export support (a59f414)
  • add original filename preservation and Lightroom export support (9872ad3)

3.2.5-beta.0 (2026-01-18)

Bug Fixes

  • add STORAGE_PATH to production docker-compose (cdda709)
  • correct invitation activation validation and add missing translations (991aa98), closes #129
  • correct invitation email link URL path (86fa104), closes #129
  • resolve admin invitation flow issues and improve STORAGE_PATH documentation (41bf6ff)

Documentation

  • emphasize importance of STORAGE_PATH in env example (3397807)

3.2.4-beta.0 (2026-01-17)

Bug Fixes

  • correct storage path resolution in multiple files (#96) (0e3674b)
  • correct storage path resolution in multiple files (#96) (3ccb815)

3.2.3-beta.0 (2026-01-16)

Bug Fixes

  • add allow_user_uploads to gallery API responses (691e3ab)
  • mobile upload button not visible in gallery (#113) (cacaffa)

3.2.2-beta.0 (2026-01-16)

Bug Fixes

  • mobile upload button visibility in gallery (2a2c23d), closes #113
  • mobile upload button visibility in gallery (#113) (05a5307)

3.2.1-beta.0 (2026-01-16)

Bug Fixes

  • mobile upload button visibility in gallery (df7dbff), closes #113
  • mobile upload button visibility in gallery (#113) (6cb4342)

3.2.0-beta.0 (2026-01-16)

Features

  • add optional event date and expiration settings (3079eaa)
  • add optional event date and expiration settings (2151147), closes #118

Bug Fixes

  • checkbox and toggle settings not persisting after page refresh (808ed1d), closes #117

Documentation

  • add API_URL environment variable to .env.example files (3e69579)

3.1.0-beta.0 (2026-01-15)

Features

  • dynamic website title from branding settings (d29aab7)
  • pre-generate watermarks for instant lightbox loading (1be974a), closes #112
  • pre-generated watermarks and mobile upload button improvements (c6fdd38)

Bug Fixes

  • add lightbox loading spinner and watermark cache invalidation (050ed37)
  • lightbox watermark loading, white label translations, and dynamic footer year (ce8587b)
  • prevent database migration restart failures (83a4344), closes #107
  • show upload button in mobile topbar instead of sidebar (ae181cf), closes #113
  • watermark thumbnails, custom logo display, and German translations (ea20446)

3.0.1-beta.0 (2026-01-15)

Bug Fixes

  • CI workflow fixes for protected branches (cb01218)
  • lightbox watermark loading, white label translations, and dynamic footer year (3b720ed)
  • lightbox watermark loading, white label translations, and dynamic footer year (ce8587b)
  • lightbox watermark loading, white label translations, and dynamic footer year (#108) (3b720ed)

2.3.2 (2026-01-15)

Bug Fixes

  • watermark thumbnails, custom logo display, and German translations (f843e4c)
  • watermark thumbnails, custom logo display, and German translations (ea20446)

2.3.1 (2026-01-15)

Bug Fixes

  • CI workflow fixes for protected branches (657c205)
  • use Release Please extra-files instead of sync-versions job (fe7d45d)

3.0.0-beta.0 (2026-01-15)

⚠ BREAKING CHANGES

  • Deployment now requires external reverse proxy for SSL/HTTPS

Features

  • add Apple Liquid Glass templates, image security settings, and automated releases (6033461)
  • add complete translation support for backup admin page (e9f92e6)
  • Add CSS template system with custom gallery styling support (0da45e6)
  • add event management, gallery customization, and release automationFeature/event rename (40ee671)
  • add feedback management enhancements (0064122)
  • add GitHub Actions workflow for Docker image builds (4029559)
  • add multi-administrator support with RBAC and fix backup/restore for S3 (892e47d)
  • admin: external media import modal + thumbnail fixes for reference events\n\n- Photos tab: replace inline external folder picker with a modal opened via "Import from External Folder" button next to "Upload Photos"; add info that all pictures in the selected folder will be imported.\n- Admin thumbnails: align list endpoint to /api/admin/photos/:eventId/photos and always return thumbnail_url to trigger on-demand generation; normalize external paths to avoid duplicated folder segments (e.g., individual/individual) that broke resolver; improve thumbnail logging.\n- Use authenticated image fetching on admin feedback pages to prevent 401s in automation.\n- i18n: add backup.external.warning strings; complete German backup/restore coverage; add common keys (notSet, of, up, select, selected).\n- Docs: add Local (npm) setup for EXTERNAL_MEDIA_ROOT in deployment guide.\n\nRefs #17 gallery feature request: https://github.com/the-luap/picpeak/issues/17 (49c7778)
  • admin: refine header layout and logo placement (d64e7d0)
  • allow admin email updates in UI (#36) (3c2a79a)
  • beta/stable release channels with update notifications and bug fixes (3c7dc20)
  • beta/stable release channels with update notifications and bug fixes (#98) (3c7dc20)
  • completely rewrite GitHub mirror to create new history from target commit (febacb7)
  • consolidate setup scripts and guides into unified solution (29a8ff9)
  • docker: add PUID/PGID and user mapping to avoid bind mount permission issues; feat(setup): prompt for admin email interactively; docs: PUID/PGID in .env.example (410a33f)
  • enhance mirror-to-github workflow with commit-based history filtering (b4b09c1)
  • events: add CSS template selector to event edit page (6a6c2cd)
  • exclude Claude contributor from GitHub mirror workflow (abbcdb1)
  • fix analytics dashboard and implement complete Umami integration (45ce988)
  • gallery/filters: add Rated and Commented filters (UI + backend).\n\n- UI: add star (Rated) and message (Commented) buttons to feedback filter bars (desktop + mobile)\n- Backend: support filter=rated, commented, and combinations via aggregate counts/queries (b03760a)
  • gallery: add quick Like/Favorite actions on thumbnails across layouts (6368f10)
  • gallery: always-visible feedback indicators on grid tiles; fallback image rendering in lightbox/hero; auto-auth from shared-link token; fix external photo resolver\n\n- GridGallery: bottom-left icons for like/rated/comment on every tile\n- Hero layout grid: added same indicators (non-intrusive icons)\n- Lightbox/Hero: add fallbackSrc to display thumbnail if original fails\n- GalleryAuth: auto-store token from /gallery/:slug/:token and hydrate event\n- Backend gallery photo route: use resolvePhotoFilePath for external-media\n\nfix(admin): move photo feedback badges to bottom-right on admin grid tiles\n\nfix(dashboard): add missing i18n keys for activity types + fallback to formatter\n\nfix(admin/feedback): correct thumbnail URL base + robust date parsing\n\nRefs: #19 (6948aaa)
  • gallery: compact vertical icon-only feedback filter in PhotoFilterBar; remove wide buttons to prevent overflow\n\n- Desktop: vertical icon stack (All/Grid, Likes, Favorites) outside scroll area\n- Mobile: vertical icon stack below categories\n- Keeps existing category bar layout and count\n\nRefs: #19 (465f997)
  • i18n: add translations for settings tabs (c030e87)
  • implement 4 new features with bug fixes and refactoring plan (77a4bfd)
  • implement beta/stable release channels with update notifications (617e778)
  • implement comprehensive backup and restore system with S3 support (f6a79c8)
  • implement feedback filter for liked/favorited photos (Issue #17) (41857ec)
  • implement gallery feedback system with version tracking for backups (dc1419c)
  • implement gallery logo customization (Issue #17) (909e760)
  • lightbox: keep feedback usable while navigating (6368f10), closes #19
  • Multi-administrator RBAC, CSS templates & security hardening (#78) (16b3ab0)
  • native: auto-serve SPA when dist exists (unless SERVE_FRONTEND=false); add clear logging; serve index.html for /admin (fb16b7b)
  • native: build frontend and serve SPA from backend (SERVE_FRONTEND); fix Cannot GET /admin on native installs (9fe10bc)
  • native: serve built frontend from backend; build frontend during install/update; ensure env flags (SERVE_FRONTEND, FRONTEND_DIR) (61ad2d6)
  • overhaul public landing page and backup tooling (2a4d388)
  • select: add per-tile checkbox selection in Admin grid and all gallery layouts; tile click opens viewer; checkbox toggles selection; auto-enable selection mode; add testids (9fda54b)
  • setup/docker: auto-set PUID/PGID from invoking user and chown bind-mount folders; create missing data/events dirs (0618b78)
  • setup: remove --admin-password; print admin credentials from ADMIN_CREDENTIALS.txt; fix ADMIN_URL to avoid /admin/admin; update native service commands (84d0f63)
  • support per-gallery password toggle (5d6c061)
  • update GitHub mirror workflow to start history from specific commit (08da01f)

Bug Fixes

  • add missing route for feedback management page (517128f)
  • add missing translations and fix BackupHistory useTranslation error (99e4778)
  • Add settings translations and fix manual backup process (#82) (476fcce)
  • admin/feedback: use correct event id when rendering photo thumbnails (4c7b49a), closes #19
  • admin: prevent category badge overlap in grid (d64e7d0)
  • align backend port to 3000 across all configurations (3a8d53f)
  • Align nginx backend port for production Docker deployments (v2.2.2) (#88) (e0bd19a)
  • auto-convert old date formats to new date-fns syntax (e1aca6b)
  • backup: add lastBackup alias and totalBackups for frontend compatibility (749100c)
  • backup: allow manual backups when automated backups are disabled (e6dd89e)
  • ci: add QEMU setup for multi-arch builds and skip for PRs (0d36a27)
  • clear notifications via API (#35) (013be18)
  • complete backup page translations and improve UI (7387a5e)
  • complete restore page translations and fix structure (618e269)
  • configure github-release plugin to use GitHub API instead of Gitea (2624ea6)
  • correct GitHub repository path in Drone CI release config (247e154)
  • correct import statements for api in backup JSX files (30f6780)
  • correct malformed gallery URLs in admin panel View Gallery links (3074748)
  • correct password generator function name in reset password route (65d796b)
  • correct script name in Gitea mirror workflow (828d6bc)
  • cors: scope CORS to /api only and avoid throwing on disallowed origins; prevents static asset 500s on native (90bb21e)
  • critical database connection pool exhaustion issues (8588133)
  • db: improve PostgreSQL connection check in wait-for-db.sh (e85a68a)
  • display new password after admin password reset (bd8b885)
  • Docker Swarm DNS resolution and backup status display (v2.2.3) (082d8ab)
  • Docker Swarm DNS resolution and backup status display (v2.2.3) (082d8ab)
  • force github-release plugin to use GitHub API instead of Gitea (558a966)
  • frontend: add missing externalMedia service and mount admin external-media routes; verify Vite build (ab324f1)
  • gallery thumbnails not loading (404 errors) #96 (e3c3c4c)
  • gallery/filters: always apply global liked/favorited filters by aggregate counts (ignore guest_id); resolves mismatch between client guest_id and server identifier (526dcd8)
  • gallery/filters: make feedback filters work globally when no guest_id is provided; remove guest_id from client photos query\n\n- Backend /api/gallery/:slug/photos: if filter present and guest_id missing, filter by like_count/favorite_count\n- Frontend useGalleryPhotos: stop passing random guestId (does not match server guest_identifier)\n\nThis makes Liked/Favorited filters reflect photos with aggregate feedback counts as expected. (5b2561b)
  • gallery/sidebar: compact icon-only feedback filter in sidebar (vertical, small) to avoid overflow; use GalleryFilter variant=compact (ff89f96)
  • gallery: feedback filter headline + horizontal icons in sidebar (compact variant); ensure sidebar content scrolls (flex-col container) (3a6d061)
  • handle auth errors and JSON parsing in admin panel (b2ae5f1)
  • handle legacy non-JSON logo paths when replacing logo (0d5ce48)
  • harden gallery downloads and per-gallery auth (fc1bf53)
  • implement 9 production enhancements and security fixes (c584369)
  • improve admin credentials display and configuration (ad495a9)
  • improve version bump workflow with better conflict resolution (c787510)
  • JSON serialize favicon and logo URLs for PostgreSQL storage (b83f427)
  • Multi-administrator RBAC, CSS templates & security hardening (#80) (37d4e1c)
  • multiple improvements and CI/CD updates (bf70567)
  • native/http: disable CSP upgrade-insecure-requests and HSTS unless ENABLE_HSTS=true; prevents HTTPS upgrades on HTTP installs (24b4a31)
  • native: correct setup paths to /opt/picpeak/app, update repo URL, add sqlite prod support; docs path fixes (b992b15)
  • native: remove obsolete workers service; restart only backend; add API request logging and preflight handler; keep static assets outside CORS (f3604b4)
  • nginx: add Docker DNS resolver for Swarm/dynamic service discovery (049837f)
  • nginx: Add Docker DNS resolver for Swarm/dynamic service discovery (v2.2.3) (cc1ddfd)
  • photos: category changes now persist and display correctly (#77) (d9da98c)
  • photos: resolve upload category selection and improve feedback buttons (#77) (856d533)
  • prefer admin token on admin routes (#23 #28) (d4404e3)
  • prevent unnecessary image recompression and fix SQLite migration #95 (3cdc0ea)
  • remove description field from migration 035 app_settings inserts (22cc406)
  • remove file requirement from GitHub release in Drone CI (8335916)
  • remove formatBoolean calls from migration 032 - critical production fix (0502ed3)
  • remove unnecessary publish-manifest job from Docker workflow (986b101)
  • remove unused formatBoolean import from migration 033 (1238db5)
  • remove updated_at field from password reset query (ed0243e)
  • remove updated_at from app_settings inserts in multiple migrations (4c42b4c)
  • replace github-release plugin with direct curl API call (76a466c)
  • resolve backend startup errors in development (f8fb1c3)
  • resolve branding display issues and invitation parsing errors (1931d73)
  • Resolve branding display issues and invitation parsing errors (v2.2.1) (#86) (d7ecf83)
  • resolve CI/CD version bump race condition (0bf4764)
  • resolve database connection error for analytics settings (95939d5)
  • resolve date formatting error in event creation (c51d756)
  • resolve development environment issues (61299a3)
  • resolve duplicate logger declaration and syntax error in rate limit service (0fe6d73)
  • resolve feedback validation issues from GitHub issue #16 (f26beca)
  • resolve feedback validation issues from GitHub issue #16 (67ff415)
  • resolve GitHub issues #4, #8, #9, and #10 (934d6dd)
  • resolve GitHub mirror workflow cherry-pick failure with merge commits (d6adde4)
  • resolve language-specific column issues in core migrations (62617f6)
  • resolve migration conflicts and duplicate numbering (a401fbd)
  • resolve multiple feedback management issues (ad75818)
  • resolve multiple issues from GitHub issue #14 (e91209f)
  • resolve port configuration issues and database column mismatch (6de64a1)
  • resolve PostgreSQL migration issues for development environment (ee855a3)
  • resolve production UI and API issues (d5790ad)
  • resolve SIGPIPE error in GitHub mirror workflow file cleanup (b7c8953)
  • resolve translation interpolation issue for download button (c1e10f1)
  • security: upgrade Alpine base image to fix libpng and c-ares CVEs (b706eeb)
  • setup/native: correct repo URL, paths, and systemd for native install; support sqlite in production knex config (87b8414)
  • setup/native: Debian 12 compatibility (reliable RAM detection, sudo-less run_as_user, git safe.directory); ensure SQLite data dir; use user for migrate (dc482e6)
  • setup/native: handle forced updates safely by fetch+checkout/reset instead of pull; stable on rewritten histories (3697344)
  • setup/update: detect native installs first (/opt/picpeak/app/backend or systemd unit); avoid false docker updates on root (adf576f)
  • simplify Drone github-release step to avoid shell parsing issues (94f10e1)
  • stabilize uploads and guest feedback filters (aaaf598)
  • update all deployment guide links in README.md (6389b9d)
  • update deployment guide with critical URL configuration and nginx port fixes (1cadce1)
  • update form-data and multer to address security vulnerabilities (7750170)
  • update Gitea mirror workflow to selectively remove scripts (296430e)
  • update GitHub mirror action to support fine-grained personal access tokens (827eb48)
  • use admin API for Umami config in analytics page (a54a2c0)
  • use plugins/gitea-release for Drone CI/CD (0c783c6)
  • use plugins/github-release for Drone CI/CD (f926cd3)
  • watermark upload JSON parsing and image quality preservation (0e3b50d)

Documentation

  • add minimum system requirements section to README (4615a5d)
  • add PUID/PGID note for Docker bind mounts to avoid permission issues (0178e71)
  • add transparency note about AI-assisted development (35e360d)
  • add warnings about $ character in Docker Compose passwords (87d1761)
  • clarify VITE_API_URL usage; remove FRONTEND_API_URL; add storage vars; simplify compose mounts and external DB example (refs #18) (758c085)
  • compose: fix backend healthcheck path; remove frontend VITE_API_URL env and document /api proxy (refs #18) (ecbc488)
  • fix deployment/admin routing and CORS guidance; add AGENTS.md; ignore AGENTS.md (refs #18) (dad1787)
  • follow-up on PR #15 — clarify VITE_API_URL usage, compose mounts, and admin routing (refs #15) (e9171c7)
  • readme: reflect new External Media reference mode and update roadmap (gallery feedback status) (ee13556)
  • replace email addresses with GitHub issue links (0c989ce)
  • update deployment guide with GitHub Container Registry images (2c9a56f)

Code Refactoring

  • simplify deployment structure with direct port exposure (6492cb9)

2.3.0 (2026-01-15)

Features

  • beta/stable release channels with update notifications and bug fixes (3c7dc20)
  • beta/stable release channels with update notifications and bug fixes (#98) (3c7dc20)
  • implement beta/stable release channels with update notifications (617e778)

Bug Fixes

  • display new password after admin password reset (bd8b885)
  • gallery thumbnails not loading (404 errors) #96 (e3c3c4c)
  • prevent unnecessary image recompression and fix SQLite migration #95 (3cdc0ea)
  • watermark upload JSON parsing and image quality preservation (0e3b50d)

2.2.4 (2026-01-08)

Bug Fixes

  • backup: add lastBackup alias and totalBackups for frontend compatibility (749100c)
  • Docker Swarm DNS resolution and backup status display (v2.2.3) (082d8ab)
  • Docker Swarm DNS resolution and backup status display (v2.2.3) (082d8ab)

2.2.3 (2026-01-08)

Bug Fixes

  • nginx: add Docker DNS resolver for Swarm/dynamic service discovery (049837f)
  • nginx: Add Docker DNS resolver for Swarm/dynamic service discovery (v2.2.3) (cc1ddfd)

2.2.2 (2026-01-08)

Bug Fixes

  • align backend port to 3000 across all configurations (3a8d53f)
  • Align nginx backend port for production Docker deployments (v2.2.2) (#88) (e0bd19a)

2.2.1 (2026-01-08)

Bug Fixes

  • handle legacy non-JSON logo paths when replacing logo (0d5ce48)
  • JSON serialize favicon and logo URLs for PostgreSQL storage (b83f427)
  • resolve branding display issues and invitation parsing errors (1931d73)
  • Resolve branding display issues and invitation parsing errors (v2.2.1) (#86) (d7ecf83)

2.2.0 (2026-01-08)

Features

  • i18n: add translations for settings tabs (c030e87)

Bug Fixes

  • Add settings translations and fix manual backup process (#82) (476fcce)
  • backup: allow manual backups when automated backups are disabled (e6dd89e)
  • db: improve PostgreSQL connection check in wait-for-db.sh (e85a68a)

2.1.1 (2026-01-07)

Bug Fixes

  • ci: add QEMU setup for multi-arch builds and skip for PRs (0d36a27)
  • Multi-administrator RBAC, CSS templates & security hardening (#80) (37d4e1c)

2.1.0 (2026-01-07)

Features

  • add multi-administrator support with RBAC and fix backup/restore for S3 (892e47d)
  • events: add CSS template selector to event edit page (6a6c2cd)
  • Multi-administrator RBAC, CSS templates & security hardening (#78) (16b3ab0)

Bug Fixes

  • photos: category changes now persist and display correctly (#77) (d9da98c)
  • photos: resolve upload category selection and improve feedback buttons (#77) (856d533)

2.0.0 (2026-01-03)

⚠ BREAKING CHANGES

  • Deployment now requires external reverse proxy for SSL/HTTPS

Features

  • add Apple Liquid Glass templates, image security settings, and automated releases (6033461)
  • add complete translation support for backup admin page (e9f92e6)
  • Add CSS template system with custom gallery styling support (0da45e6)
  • add event management, gallery customization, and release automationFeature/event rename (40ee671)
  • add feedback management enhancements (0064122)
  • add GitHub Actions workflow for Docker image builds (4029559)
  • admin: external media import modal + thumbnail fixes for reference events\n\n- Photos tab: replace inline external folder picker with a modal opened via "Import from External Folder" button next to "Upload Photos"; add info that all pictures in the selected folder will be imported.\n- Admin thumbnails: align list endpoint to /api/admin/photos/:eventId/photos and always return thumbnail_url to trigger on-demand generation; normalize external paths to avoid duplicated folder segments (e.g., individual/individual) that broke resolver; improve thumbnail logging.\n- Use authenticated image fetching on admin feedback pages to prevent 401s in automation.\n- i18n: add backup.external.warning strings; complete German backup/restore coverage; add common keys (notSet, of, up, select, selected).\n- Docs: add Local (npm) setup for EXTERNAL_MEDIA_ROOT in deployment guide.\n\nRefs #17 gallery feature request: https://github.com/the-luap/picpeak/issues/17 (49c7778)
  • admin: refine header layout and logo placement (d64e7d0)
  • allow admin email updates in UI (#36) (3c2a79a)
  • completely rewrite GitHub mirror to create new history from target commit (febacb7)
  • consolidate setup scripts and guides into unified solution (29a8ff9)
  • docker: add PUID/PGID and user mapping to avoid bind mount permission issues; feat(setup): prompt for admin email interactively; docs: PUID/PGID in .env.example (410a33f)
  • enhance mirror-to-github workflow with commit-based history filtering (b4b09c1)
  • exclude Claude contributor from GitHub mirror workflow (abbcdb1)
  • fix analytics dashboard and implement complete Umami integration (45ce988)
  • gallery/filters: add Rated and Commented filters (UI + backend).\n\n- UI: add star (Rated) and message (Commented) buttons to feedback filter bars (desktop + mobile)\n- Backend: support filter=rated, commented, and combinations via aggregate counts/queries (b03760a)
  • gallery: add quick Like/Favorite actions on thumbnails across layouts (6368f10)
  • gallery: always-visible feedback indicators on grid tiles; fallback image rendering in lightbox/hero; auto-auth from shared-link token; fix external photo resolver\n\n- GridGallery: bottom-left icons for like/rated/comment on every tile\n- Hero layout grid: added same indicators (non-intrusive icons)\n- Lightbox/Hero: add fallbackSrc to display thumbnail if original fails\n- GalleryAuth: auto-store token from /gallery/:slug/:token and hydrate event\n- Backend gallery photo route: use resolvePhotoFilePath for external-media\n\nfix(admin): move photo feedback badges to bottom-right on admin grid tiles\n\nfix(dashboard): add missing i18n keys for activity types + fallback to formatter\n\nfix(admin/feedback): correct thumbnail URL base + robust date parsing\n\nRefs: #19 (6948aaa)
  • gallery: compact vertical icon-only feedback filter in PhotoFilterBar; remove wide buttons to prevent overflow\n\n- Desktop: vertical icon stack (All/Grid, Likes, Favorites) outside scroll area\n- Mobile: vertical icon stack below categories\n- Keeps existing category bar layout and count\n\nRefs: #19 (465f997)
  • implement 4 new features with bug fixes and refactoring plan (77a4bfd)
  • implement comprehensive backup and restore system with S3 support (f6a79c8)
  • implement feedback filter for liked/favorited photos (Issue #17) (41857ec)
  • implement gallery feedback system with version tracking for backups (dc1419c)
  • implement gallery logo customization (Issue #17) (909e760)
  • lightbox: keep feedback usable while navigating (6368f10), closes #19
  • native: auto-serve SPA when dist exists (unless SERVE_FRONTEND=false); add clear logging; serve index.html for /admin (fb16b7b)
  • native: build frontend and serve SPA from backend (SERVE_FRONTEND); fix Cannot GET /admin on native installs (9fe10bc)
  • native: serve built frontend from backend; build frontend during install/update; ensure env flags (SERVE_FRONTEND, FRONTEND_DIR) (61ad2d6)
  • overhaul public landing page and backup tooling (2a4d388)
  • select: add per-tile checkbox selection in Admin grid and all gallery layouts; tile click opens viewer; checkbox toggles selection; auto-enable selection mode; add testids (9fda54b)
  • setup/docker: auto-set PUID/PGID from invoking user and chown bind-mount folders; create missing data/events dirs (0618b78)
  • setup: remove --admin-password; print admin credentials from ADMIN_CREDENTIALS.txt; fix ADMIN_URL to avoid /admin/admin; update native service commands (84d0f63)
  • support per-gallery password toggle (5d6c061)
  • update GitHub mirror workflow to start history from specific commit (08da01f)

Bug Fixes

  • add missing route for feedback management page (517128f)
  • add missing translations and fix BackupHistory useTranslation error (99e4778)
  • admin/feedback: use correct event id when rendering photo thumbnails (4c7b49a), closes #19
  • admin: prevent category badge overlap in grid (d64e7d0)
  • auto-convert old date formats to new date-fns syntax (e1aca6b)
  • clear notifications via API (#35) (013be18)
  • complete backup page translations and improve UI (7387a5e)
  • complete restore page translations and fix structure (618e269)
  • configure github-release plugin to use GitHub API instead of Gitea (2624ea6)
  • correct GitHub repository path in Drone CI release config (247e154)
  • correct import statements for api in backup JSX files (30f6780)
  • correct malformed gallery URLs in admin panel View Gallery links (3074748)
  • correct password generator function name in reset password route (65d796b)
  • correct script name in Gitea mirror workflow (828d6bc)
  • cors: scope CORS to /api only and avoid throwing on disallowed origins; prevents static asset 500s on native (90bb21e)
  • critical database connection pool exhaustion issues (8588133)
  • force github-release plugin to use GitHub API instead of Gitea (558a966)
  • frontend: add missing externalMedia service and mount admin external-media routes; verify Vite build (ab324f1)
  • gallery/filters: always apply global liked/favorited filters by aggregate counts (ignore guest_id); resolves mismatch between client guest_id and server identifier (526dcd8)
  • gallery/filters: make feedback filters work globally when no guest_id is provided; remove guest_id from client photos query\n\n- Backend /api/gallery/:slug/photos: if filter present and guest_id missing, filter by like_count/favorite_count\n- Frontend useGalleryPhotos: stop passing random guestId (does not match server guest_identifier)\n\nThis makes Liked/Favorited filters reflect photos with aggregate feedback counts as expected. (5b2561b)
  • gallery/sidebar: compact icon-only feedback filter in sidebar (vertical, small) to avoid overflow; use GalleryFilter variant=compact (ff89f96)
  • gallery: feedback filter headline + horizontal icons in sidebar (compact variant); ensure sidebar content scrolls (flex-col container) (3a6d061)
  • handle auth errors and JSON parsing in admin panel (b2ae5f1)
  • harden gallery downloads and per-gallery auth (fc1bf53)
  • implement 9 production enhancements and security fixes (c584369)
  • improve admin credentials display and configuration (ad495a9)
  • improve version bump workflow with better conflict resolution (c787510)
  • multiple improvements and CI/CD updates (bf70567)
  • native/http: disable CSP upgrade-insecure-requests and HSTS unless ENABLE_HSTS=true; prevents HTTPS upgrades on HTTP installs (24b4a31)
  • native: correct setup paths to /opt/picpeak/app, update repo URL, add sqlite prod support; docs path fixes (b992b15)
  • native: remove obsolete workers service; restart only backend; add API request logging and preflight handler; keep static assets outside CORS (f3604b4)
  • prefer admin token on admin routes (#23 #28) (d4404e3)
  • remove description field from migration 035 app_settings inserts (22cc406)
  • remove file requirement from GitHub release in Drone CI (8335916)
  • remove formatBoolean calls from migration 032 - critical production fix (0502ed3)
  • remove unnecessary publish-manifest job from Docker workflow (986b101)
  • remove unused formatBoolean import from migration 033 (1238db5)
  • remove updated_at field from password reset query (ed0243e)
  • remove updated_at from app_settings inserts in multiple migrations (4c42b4c)
  • replace github-release plugin with direct curl API call (76a466c)
  • resolve backend startup errors in development (f8fb1c3)
  • resolve CI/CD version bump race condition (0bf4764)
  • resolve database connection error for analytics settings (95939d5)
  • resolve date formatting error in event creation (c51d756)
  • resolve development environment issues (61299a3)
  • resolve duplicate logger declaration and syntax error in rate limit service (0fe6d73)
  • resolve feedback validation issues from GitHub issue #16 (f26beca)
  • resolve feedback validation issues from GitHub issue #16 (67ff415)
  • resolve GitHub issues #4, #8, #9, and #10 (934d6dd)
  • resolve GitHub mirror workflow cherry-pick failure with merge commits (d6adde4)
  • resolve language-specific column issues in core migrations (62617f6)
  • resolve migration conflicts and duplicate numbering (a401fbd)
  • resolve multiple feedback management issues (ad75818)
  • resolve multiple issues from GitHub issue #14 (e91209f)
  • resolve port configuration issues and database column mismatch (6de64a1)
  • resolve PostgreSQL migration issues for development environment (ee855a3)
  • resolve production UI and API issues (d5790ad)
  • resolve SIGPIPE error in GitHub mirror workflow file cleanup (b7c8953)
  • resolve translation interpolation issue for download button (c1e10f1)
  • setup/native: correct repo URL, paths, and systemd for native install; support sqlite in production knex config (87b8414)
  • setup/native: Debian 12 compatibility (reliable RAM detection, sudo-less run_as_user, git safe.directory); ensure SQLite data dir; use user for migrate (dc482e6)
  • setup/native: handle forced updates safely by fetch+checkout/reset instead of pull; stable on rewritten histories (3697344)
  • setup/update: detect native installs first (/opt/picpeak/app/backend or systemd unit); avoid false docker updates on root (adf576f)
  • simplify Drone github-release step to avoid shell parsing issues (94f10e1)
  • stabilize uploads and guest feedback filters (aaaf598)
  • update all deployment guide links in README.md (6389b9d)
  • update deployment guide with critical URL configuration and nginx port fixes (1cadce1)
  • update form-data and multer to address security vulnerabilities (7750170)
  • update Gitea mirror workflow to selectively remove scripts (296430e)
  • update GitHub mirror action to support fine-grained personal access tokens (827eb48)
  • use admin API for Umami config in analytics page (a54a2c0)
  • use plugins/gitea-release for Drone CI/CD (0c783c6)
  • use plugins/github-release for Drone CI/CD (f926cd3)

Documentation

  • add minimum system requirements section to README (4615a5d)
  • add PUID/PGID note for Docker bind mounts to avoid permission issues (0178e71)
  • add transparency note about AI-assisted development (35e360d)
  • add warnings about $ character in Docker Compose passwords (87d1761)
  • clarify VITE_API_URL usage; remove FRONTEND_API_URL; add storage vars; simplify compose mounts and external DB example (refs #18) (758c085)
  • compose: fix backend healthcheck path; remove frontend VITE_API_URL env and document /api proxy (refs #18) (ecbc488)
  • fix deployment/admin routing and CORS guidance; add AGENTS.md; ignore AGENTS.md (refs #18) (dad1787)
  • follow-up on PR #15 — clarify VITE_API_URL usage, compose mounts, and admin routing (refs #15) (e9171c7)
  • readme: reflect new External Media reference mode and update roadmap (gallery feedback status) (ee13556)
  • replace email addresses with GitHub issue links (0c989ce)
  • update deployment guide with GitHub Container Registry images (2c9a56f)

Code Refactoring

  • simplify deployment structure with direct port exposure (6492cb9)

1.2.0 (2026-01-03)

Features

  • Event Rename: Safe event renaming with automatic slug updates, old URL redirects via slug_redirects table, and optional email notifications to clients
  • Optional Event Fields: Make customer name, email, and admin email fields optional via admin settings with "(optional)" labels in forms
  • Photo Filtering: Filter photos by rating, likes, favorites, and comments with a new PhotoFilterPanel component
  • Photo Export: Export filtered photo selections as ZIP, generate Capture One/Lightroom-compatible XMP sidecar files, or export metadata lists
  • Custom CSS Templates: 3 customizable CSS template slots with live preview, XSS-safe sanitization, and per-event template assignment
  • Apple Liquid Glass Theme: Starter CSS template inspired by iOS 26 / macOS Tahoe Liquid Glass design with glass morphism effects, Apple SF Pro fonts, and responsive layout
  • Liquid Glass Dark Theme: Neon-accented dark glass theme with animated gradient backgrounds
  • Image Security Settings: Per-event download protection with configurable protection levels (basic, standard, enhanced, maximum), canvas rendering, DevTools detection, and right-click prevention
  • Automated Releases: Release Please integration for automatic versioning, changelog generation, and GitHub releases that trigger Docker image builds

Bug Fixes

  • Date Parsing: Fix event date formatting in slugs (now uses YYYY-MM-DD format correctly)
  • Search Placeholder: Fix search field placeholder visibility in glass-styled sidebar
  • Vite Proxy: Fix Vite dev server proxy port configuration
  • Photo Export Button: Fix export button staying disabled when photos are selected
  • Boolean Parsing: Fix boolean parsing in publicSettings.js for optional fields
  • Translation Keys: Add missing common.optional translation key in locales

Security

  • Fix critical vulnerabilities and harden application security
  • Add CSS sanitizer utility blocking XSS vectors in custom templates
  • Implement secure gallery CSS endpoint for template delivery

Code Refactoring

  • Add Photo and Settings service layers for better code organization
  • Phase 1 code consolidation with service layer architecture
  • Modular settings page with feature-based tab components
  • Create photoFilterBuilder utility for query construction
  • Add eventRenameService for safe event operations

Documentation

  • Add comprehensive REFACTORING_PLAN.md for codebase improvement roadmap
  • Update README roadmap with implemented features (Download Protection, Gallery Templates, Filtering & Export)
  • Add test specification documents for all new features

Database Migrations

  • 049_add_slug_redirects.js - Store old slugs for URL redirects after rename
  • 050_add_optional_event_fields_settings.js - Settings for optional form fields
  • 051_add_photo_filter_indexes.js - Performance indexes for photo filtering
  • 052_add_css_templates.js - CSS template storage with 3 slots
  • 053_add_liquid_glass_templates.js - Apple Liquid Glass and Dark theme starter templates

[1.1.15] - Previous Release

Initial stable release with core functionality.