| [eb5f978] | 1 | # Changelog — Klonkt
|
|---|
| [90259da] | 2 |
|
|---|
| [eb5f978] | 3 | All notable changes to Klonkt. Newest at the top.
|
|---|
| [054b603] | 4 | Versions follow [SemVer](https://semver.org/).
|
|---|
| [90259da] | 5 |
|
|---|
| 6 | ## [Unreleased]
|
|---|
| 7 |
|
|---|
| [c8e3b98] | 8 | ## [1.7.0] · 2026-08-21
|
|---|
| [0d5bd2c] | 9 |
|
|---|
| [84ce988] | 10 | ### Added
|
|---|
| [c8e3b98] | 11 | - **Your music travels as music, not as a link to it.** A track used to federate
|
|---|
| 12 | as a note with a file hanging off it, so a remote server saw a text with an
|
|---|
| 13 | attachment and nothing that said "this is a release by this artist". Tracks are
|
|---|
| 14 | now first-class Audio objects, an album is its own object on the wire, and the
|
|---|
| 15 | outbox carries the discography. Playlists federate as ActivityPub collections
|
|---|
| 16 | and are discoverable as such. The shapes follow what Funkwhale already speaks,
|
|---|
| 17 | so a Klonkt release lands in a Funkwhale library instead of being dropped.
|
|---|
| 18 | - **A post is the release.** Loose tracks in one post are gathered into a
|
|---|
| 19 | collection, the release date and the MusicBrainz release id ride along, and the
|
|---|
| 20 | hashtags are read from the raw text rather than the rendered version — which is
|
|---|
| 21 | why they used to arrive as nonsense, or not at all.
|
|---|
| 22 | - **Claim yourself in MusicBrainz.** Under Admin → Audio you can look yourself up
|
|---|
| 23 | and confirm "this is me". The link goes on the wire as `schema:sameAs`, so
|
|---|
| 24 | other servers can tie your Klonkt to the artist you already are elsewhere.
|
|---|
| 25 | - **The whole site as a music channel.** `/tracks.xml` publishes everything you
|
|---|
| 26 | released as one feed, for players that speak RSS rather than ActivityPub.
|
|---|
| 27 | - **Take your account somewhere else, and take everything with you (FEP-1580).**
|
|---|
| 28 | Your posts, your audio, the covers, the playlists and the GUIDs all move, your
|
|---|
| 29 | following list travels as a CSV you can upload or paste, and the guardianship
|
|---|
| 30 | moves before the follow does — the other order left a ward briefly unwatched.
|
|---|
| 31 | A moved account locks on the outgoing side, so nothing new leaves an address
|
|---|
| 32 | you no longer use. It is one page now, in steps, instead of scattered options.
|
|---|
| 33 | - **A reading view, next to Timeline and Grid.** One post fills the screen, the
|
|---|
| 34 | neighbours stand ready on either side, and scrolling snaps to the top of the
|
|---|
| 35 | next post. Each site chooses for itself: reading, timeline, or timeline on
|
|---|
| 36 | desktop with reading on a phone.
|
|---|
| 37 | - **Guests can sign in with the account they already have (OpenWebAuth).** A fan
|
|---|
| 38 | logs in through their own Klonkt and becomes a follower here, not another
|
|---|
| 39 | account holder with another password. Two Klonkts can introduce each other, so
|
|---|
| 40 | this works in both directions.
|
|---|
| 41 | - **Eight guardianship gates that actually switch.** The gate panel is a cockpit:
|
|---|
| 42 | every gate visible, each chip carrying its own state, and the apps are told
|
|---|
| 43 | what is gated before they try. Replying is its own gate, follow requests are
|
|---|
| 44 | decided by majority when there are several guardians, a ward can raise a
|
|---|
| 45 | question itself, and a logbook keeps the reason a decision was made.
|
|---|
| 46 | - **Approve followers first, if you want to.** A follow request waits for your
|
|---|
| 47 | yes, and until then the requester sees none of your posts.
|
|---|
| 48 | - **Every collection paginates.** The outbox now serves `first` and `last` and
|
|---|
| 49 | really walks its pages. Funkwhale refused it outright without them, so an
|
|---|
| 50 | unpaginated collection was not a cosmetic issue but a closed door.
|
|---|
| 51 | - **Conversations know what you have read.** Unread is counted per conversation,
|
|---|
| 52 | a read is an event rather than a guess, and a waiting read answers with the
|
|---|
| 53 | difference — no more polling for a whole list to find one new line.
|
|---|
| 54 | - **Apple Music and YouTube playlists embed properly**, with the same parsing the
|
|---|
| 55 | hub uses and a height that matches what you actually embedded.
|
|---|
| [84ce988] | 56 | - **Messages is one conversation view.** Messages, Conversations and Sent were
|
|---|
| 57 | three separate filters, so a single exchange fell apart: what you sent sat
|
|---|
| 58 | under Sent, what came back under one of the other two, and you had to switch
|
|---|
| 59 | filters to follow a thread. They are now one Conversations view in which sent
|
|---|
| 60 | and received sit in the same thread, oldest at the top, with your own
|
|---|
| 61 | contributions marked. Four filters remain: All, Conversations, Activity and
|
|---|
| 62 | Moderation.
|
|---|
| 63 | - **A conversation says what it is about.** When a thread hangs off one of your
|
|---|
| 64 | posts, its header links to that post. Without it a reply in a list is
|
|---|
| 65 | impossible to place. Threads that are not about a post run per person instead.
|
|---|
| 66 | - **Posts in Messages look like posts.** Formatting, images, audio, video, quote
|
|---|
| 67 | cards and link previews now render the same way they do in News, including on
|
|---|
| 68 | the messages you sent yourself — a photo you attached used to arrive as bare
|
|---|
| 69 | text on your own screen while everyone else saw the picture.
|
|---|
| 70 | - **The Guardian app shows a ward's posts in full.** The same gap sat in the
|
|---|
| 71 | guardian view: a post from your ward arrived without its media, quote card or
|
|---|
| 72 | emoji, which is exactly the post a guardian needs to be able to judge. A
|
|---|
| 73 | content warning still stays collapsed there, as before.
|
|---|
| 74 | - **Reply from inside a conversation.** A thread has its own reply editor, the
|
|---|
| 75 | rich one with formatting, media and a language picker. Waving stays a separate
|
|---|
| 76 | button next to it: a wave is a nudge, not an answer.
|
|---|
| 77 |
|
|---|
| 78 | ### Fixed
|
|---|
| [c8e3b98] | 79 | - **The thread under a remote post is fetched through your own server and never
|
|---|
| 80 | stored.** Replies, like and boost status and the FEP-9098 emoji now come along,
|
|---|
| 81 | and the next page is read too — before, a long thread stopped halfway.
|
|---|
| 82 | - **The rate limiter counted the whole site instead of the caller**, so a busy
|
|---|
| 83 | site handed out 429s to everyone. Related: whether to trust a proxy belongs to
|
|---|
| 84 | where you run, not to whether you are in development or production.
|
|---|
| 85 | - **A live clock in the response turned the long poll into a loop.** The answer
|
|---|
| 86 | changed every second, so it never waited — it just kept coming back.
|
|---|
| 87 | - **The editor survives a page change.** Modules wired to elements restart on
|
|---|
| 88 | every navigation, so the edit page loads its editor again after a back button,
|
|---|
| 89 | and saving without a module no longer wiped what you wrote.
|
|---|
| 90 | - **A slug is a local key, not a name on the wire.** Half names, missing names
|
|---|
| 91 | and three spellings of the same name all came from treating one as the other.
|
|---|
| 92 | - **The circle fell over on a media field that was not a list**, which took the
|
|---|
| 93 | whole page with it rather than the one post.
|
|---|
| [5d0d41d] | 94 | - **People on privacy-strict servers can follow you again.** Some servers only
|
|---|
| 95 | hand out an account's public key to a signed request. Klonkt asked without
|
|---|
| 96 | signing, got turned away, and could therefore not check the follow request that
|
|---|
| 97 | had just arrived — so it was refused, and the other server kept retrying for
|
|---|
| 98 | days. Klonkt now signs that lookup, and those follows go through. This also
|
|---|
| 99 | affected everything else fetched from such a server: profiles, posts and
|
|---|
| 100 | replies.
|
|---|
| [57aee3b] | 101 | - **Replies from other people now arrive in threads.** When someone replied to a
|
|---|
| 102 | post in a conversation you were part of, their server forwarded that reply to
|
|---|
| 103 | you — and it was turned away, because the forwarding server signs with its own
|
|---|
| 104 | key rather than the author's. Threads were quietly incomplete on your side.
|
|---|
| 105 | Such a reply is now checked at the source instead of being refused: the post is
|
|---|
| 106 | fetched from the server that hosts it, and only what comes back from there is
|
|---|
| 107 | stored. A forwarded delete is still refused, because a deleted post cannot be
|
|---|
| 108 | checked.
|
|---|
| 109 | - **A like or boost looks the same everywhere.** The same post could show as
|
|---|
| 110 | liked in News and as not liked on the interact page, because both kept their
|
|---|
| 111 | own record. There is one record now, so the buttons agree — including for
|
|---|
| 112 | everything you reacted to before this release, which is carried over
|
|---|
| 113 | automatically when the site updates.
|
|---|
| [84ce988] | 114 | - **A like from an app now sticks.** Liking a post from Shaer was stored, but
|
|---|
| 115 | the app never got that back, so the heart popped off again on the next reload
|
|---|
| 116 | — and because the app never saw the like, it could only offer "like" again and
|
|---|
| 117 | never undo it. Un-liking from an app now works.
|
|---|
| 118 |
|
|---|
| [0d5bd2c] | 119 | ### Security
|
|---|
| [c8e3b98] | 120 | - **Paid posts leaked their full content through the outbox and the follower
|
|---|
| 121 | backfill.** The redaction itself worked; the queries handed it a row without
|
|---|
| 122 | the `paid` column, so the gate read `undefined`, waved everything through and
|
|---|
| 123 | said nothing. Both queries now select what they decide on, and a test guards
|
|---|
| 124 | the class of mistake rather than this one instance of it.
|
|---|
| 125 | - **Fan-only posts went out with a public label.** They were addressed correctly
|
|---|
| 126 | but described as public, which is exactly the sort of contradiction a remote
|
|---|
| 127 | server resolves in the wrong direction.
|
|---|
| 128 | - **A cross-tenant leak in the tracker export.** One site could reach another
|
|---|
| 129 | site's rows through the exporter.
|
|---|
| 130 | - **The playlist gate now opens only files that belong to the site itself.**
|
|---|
| 131 | - **A key is bound to the actor it speaks for.** A signature is only accepted
|
|---|
| 132 | when the key, its owner and the actor agree; before, a key could vouch for
|
|---|
| 133 | someone it had no relationship with.
|
|---|
| 134 | - **OpenWebAuth unpacks PKCS#1 v1.5 itself**, without an early exit and with a
|
|---|
| 135 | cap on attempts. Node removed the padding mode that used to do this because it
|
|---|
| 136 | leaks timing (CVE-2023-46809, the Marvin attack); doing it by hand keeps the
|
|---|
| 137 | path constant-time and closes the oracle rather than reopening it.
|
|---|
| [0d5bd2c] | 138 |
|
|---|
| 139 | - **Updated components close seven security advisories.** The heaviest one sat
|
|---|
| 140 | in the library that cleans up posts arriving from elsewhere: a carefully built
|
|---|
| 141 | post could slip a script past it, and a script running on your page can act as
|
|---|
| 142 | if it were you. At the same time mail handling moved three major versions on,
|
|---|
| 143 | closing a cluster of holes around sending — among them one where a prepared
|
|---|
| 144 | name could smuggle commands into the conversation with the mail server, and
|
|---|
| 145 | one where a message could end up at a different domain than the one addressed.
|
|---|
| 146 | None of this changes how Klonkt looks or behaves. One advisory is knowingly
|
|---|
| 147 | left open: it concerns a way of generating identifiers that Klonkt does not
|
|---|
| 148 | use.
|
|---|
| 149 |
|
|---|
| [859b1707] | 150 | ## [1.6.0] · 2026-07-31
|
|---|
| 151 |
|
|---|
| [d49b60b] | 152 | ### Added
|
|---|
| [c502242] | 153 | - **Guardians (FEP-633c).** An account can now be watched over by one or more
|
|---|
| 154 | guardians, the way a child has parents. A guardian offers to look after
|
|---|
| 155 | someone; the ward accepts in their own Messages, and any existing guardians
|
|---|
| 156 | co-approve, so no one can attach themselves to a child on their own. Once
|
|---|
| 157 | agreed, the guardian appears on the ward's actor (`shaer:guardians`) and can
|
|---|
| 158 | be reached when the ward calls for help. It builds on ordinary ActivityPub, so
|
|---|
| 159 | guardian and ward can live on different servers.
|
|---|
| 160 | - **A Guardian app you can install.** A separate, installable corner at
|
|---|
| 161 | `/guardian` for guardians: add and manage your wards, a message centre for
|
|---|
| 162 | incoming calls for help, and its own notifications for help requests and
|
|---|
| 163 | guardianship traffic, even with the app closed.
|
|---|
| 164 | - **Guardianship offers land in your Messages.** When someone offers to become
|
|---|
| 165 | your guardian, it shows up in your own Messages as a clear item with Accept
|
|---|
| 166 | and Decline, so you answer where you already read your messages instead of
|
|---|
| 167 | somewhere separate.
|
|---|
| [0cea12b] | 168 | - **The owner can read their inbox over C2S.** A GET on the inbox with the
|
|---|
| 169 | account's own bearer returns recent inbound posts (the accounts you follow)
|
|---|
| 170 | as Create(Note) items, so a connected app (Shaer) can build a unified feed.
|
|---|
| 171 | For everyone else the inbox stays write-only.
|
|---|
| [9209cfa] | 172 | - **"Load more" on the feeds.** Solo (home), Cirkel, News and Messages now page
|
|---|
| 173 | in blocks of 72 with a "Load more" button instead of a hard cap, so older
|
|---|
| 174 | items are reachable. 72 divides by 2, 3 and 4, so the grid views always end on
|
|---|
| 175 | a full row. Appending is instant (htmx), the Messages search and filters keep
|
|---|
| 176 | working across pages, and the button disappears on the last page.
|
|---|
| 177 | - **"Interact via the fediverse" next to Share.** On a post, visitors get a
|
|---|
| 178 | button beside Share to reply, like or boost from their own fediverse server
|
|---|
| 179 | (it asks for your server, then hands off to your instance). Hidden for the
|
|---|
| 180 | site owner and when federation is off.
|
|---|
| [162c7a7] | 181 | - **FEDERATION.md (FEP-67ff).** The repository root now documents what Klonkt
|
|---|
| 182 | speaks on the wire: ActivityPub S2S and C2S, WebFinger, HTTP Signatures,
|
|---|
| 183 | NodeInfo 2.1, OAuth (PKCE), the activities and object types it sends and
|
|---|
| 184 | receives, the Mastodon-compatible extension terms, and the FEPs it supports or
|
|---|
| 185 | tracks. Helps other implementations interoperate.
|
|---|
| [544e9c2] | 186 | - **Messages: your poll finished.** When one of your own polls closes, Messages
|
|---|
| 187 | shows a "poll finished" item with the final result: a bar per option with its
|
|---|
| 188 | percentage, and the number of voters. It lives under the Activity chip and is
|
|---|
| 189 | searchable like the rest.
|
|---|
| [8ed65a6] | 190 | - **Messages: sharper filters and a search box.** The filter chips are now
|
|---|
| 191 | Messages (@mentions and private/DM replies), Conversations (public replies),
|
|---|
| 192 | Activity (likes, boosts, follows), Moderation (reports) and Sent, next to All.
|
|---|
| 193 | A search box filters the list by sender and message text, and combines with
|
|---|
| 194 | the active chip. All client-side, instant.
|
|---|
| [ff3b8ce] | 195 | - **The reply editor got a visual clean-up.** Its toolbar now uses the same
|
|---|
| 196 | icon set and 32px buttons as the post editor, with active formatting shown
|
|---|
| 197 | filled in the accent colour, a framed editor box with a focus ring, and
|
|---|
| 198 | tidier language, mention and attachment chips. One editor family across the
|
|---|
| 199 | site.
|
|---|
| [e9c9ae1] | 200 | - **The reply editor shows who you are addressing (rich replies, phase 3).** A
|
|---|
| 201 | "To:" bar above the editor lists the conversation partners (the author you
|
|---|
| 202 | reply to plus the thread's earlier authors) as removable chips, instead of
|
|---|
| 203 | cluttering your text with @mentions. Remove a chip and that person is no
|
|---|
| 204 | longer mentioned, tagged or pinged; mentions you type yourself stay in the
|
|---|
| 205 | text. Editing a sent reply keeps every co-mention intact.
|
|---|
| [5190152] | 206 | - **Editing a sent reply uses the rich editor too.** The edit forms on Messages
|
|---|
| 207 | and the interact page open the same editor as new replies (formatting kept,
|
|---|
| 208 | language adjustable, full-screen on phones). Attachments on the reply survive
|
|---|
| 209 | an edit untouched.
|
|---|
| [feced2c] | 210 | - **Media in replies (rich replies, phase 2).** Drop, paste or pick images,
|
|---|
| 211 | audio and video straight into the reply editor (the paperclip works on
|
|---|
| 212 | phones). Files upload to your own site, show as removable chips while you
|
|---|
| 213 | write, travel as real attachments on the federated note, and render in your
|
|---|
| 214 | thread. A media-only reply (no text) works too.
|
|---|
| [33e1dbd] | 215 | - **Rich replies (phase 1).** Replying to fediverse comments (inline in the
|
|---|
| 216 | thread and on the interact page) now uses a shared rich editor: bold, italic,
|
|---|
| 217 | links, lists and quotes, plus a language picker for your reply (sent along as
|
|---|
| 218 | the note's language map). On phones the editor opens as a full-screen compose
|
|---|
| 219 | view, the pattern that actually works on mobile. Without JavaScript the plain
|
|---|
| 220 | text box keeps working. Media in replies is the next phase.
|
|---|
| [2d66d66] | 221 | - **Revoke connected apps from your account page.** A "Connected apps" section
|
|---|
| 222 | lists every app you authorized over OAuth (name, site, scope, last used) with
|
|---|
| 223 | a Revoke button. Tokens you already granted show up too, since they were
|
|---|
| 224 | always stored (hashed); the bearer itself is never kept, so revocation is keyed
|
|---|
| 225 | on the token hash.
|
|---|
| [4407c67] | 226 | - **The account owner can read their own followers and following over C2S.** The
|
|---|
| 227 | `followers` and `following` collections stay count-only for the public
|
|---|
| 228 | (privacy), but a request carrying a C2S bearer scoped to that site now returns
|
|---|
| 229 | the real actor URIs, so an app (Shaer) can build a friends list. Anonymous
|
|---|
| 230 | callers are unchanged.
|
|---|
| [d49b60b] | 231 | - **App access via OAuth 2.0 (ActivityPub Client-to-Server, phase 1).** Klonkt
|
|---|
| 232 | now speaks the standard AP C2S auth handshake so native and web clients (the
|
|---|
| 233 | Shaer apps first) can connect: dynamic client registration (RFC 7591), a
|
|---|
| 234 | PKCE authorization-code flow with a consent screen that picks which of your
|
|---|
| 235 | sites the app may post as, and bearer tokens (stored hashed, single-use
|
|---|
| 236 | codes). The actor document advertises the OAuth and uploadMedia endpoints and
|
|---|
| 237 | `/.well-known/oauth-authorization-server` (RFC 8414) exposes the metadata, so
|
|---|
| 238 | clients discover everything instead of hardcoding paths. Public clients + PKCE
|
|---|
| [dd568e7] | 239 | only, no client secrets.
|
|---|
| 240 | - **The outbox accepts posts from apps (C2S, phase 1 complete).** A
|
|---|
| 241 | bearer-authenticated `POST` to `/ap/users/:slug/outbox` now drives your account
|
|---|
| 242 | from a client: publish a note, reply, like, boost, follow, and undo any of
|
|---|
| 243 | those. Activities are translated onto the same delivery machinery the web UI
|
|---|
| 244 | uses; a bare Note is wrapped in a Create per the spec; content is sanitized;
|
|---|
| 245 | the token is scoped to one site so it can't post as another. Note: this is
|
|---|
| 246 | ActivityPub C2S, which the Shaer apps speak. Mastodon clients (Ivory etc.) use
|
|---|
| 247 | Mastodon's own API and are not supported by this.
|
|---|
| [d49b60b] | 248 |
|
|---|
| [c867b7b] | 249 | ### Fixed
|
|---|
| [bf72108] | 250 | - **OAuth consent now hands off reliably to native apps.** After Allow/Deny, a
|
|---|
| 251 | redirect to a native custom scheme (e.g. `com.klonkt.shaer:/oauth`) was a plain
|
|---|
| 252 | 302, which mobile browsers silently drop. The consent step now serves a tiny
|
|---|
| 253 | interstitial for non-http redirect URIs that auto-forwards and offers an "Open
|
|---|
| 254 | the app" tap link (a tap reliably launches the app on Android; iOS's web-auth
|
|---|
| 255 | session intercepts either way). Web (http/https) clients still get a 302.
|
|---|
| [c867b7b] | 256 | - **Visitors can reply to the site owner's own comments.** The "reply via the
|
|---|
| 257 | fediverse" button only appeared on comments from others; the site's own
|
|---|
| 258 | comments in a thread offered visitors nothing, so you could not respond to
|
|---|
| 259 | the author from your own instance.
|
|---|
| 260 |
|
|---|
| [05cd954] | 261 | ## [1.5.0] · 2026-07-18
|
|---|
| 262 |
|
|---|
| [010e073] | 263 | ### Added
|
|---|
| [f1a23b8] | 264 | - **Messages: your replies and notifications on one page.** A single Messages
|
|---|
| 265 | tab replaces Replies and Notifications. One stream with filter chips (All,
|
|---|
| 266 | Conversations, Activity, Sent): your own sent replies join the conversation
|
|---|
| 267 | (with edit and delete), likes and boosts on the same post group into one line,
|
|---|
| 268 | private replies carry a lock badge, and items new since your last visit get a
|
|---|
| 269 | dot. The interact bookmarklet moved along. Old /fediverse and /notifications
|
|---|
| 270 | links redirect to /messages.
|
|---|
| [010e073] | 271 | - **Connect: your following and followers on one page.** A single Connect tab
|
|---|
| 272 | replaces the separate Following and Followers pages, showing each connection's
|
|---|
| 273 | direction (following →, follower ←, mutual ↔) and, for accounts you deliver to,
|
|---|
| 274 | when they were last reached. Accounts you can no longer reach move to a
|
|---|
| 275 | collapsed "Unreachable" section for cleanup. Old /following and /followers
|
|---|
| 276 | links redirect to /connect.
|
|---|
| [67c1f24] | 277 | - **Moderate incoming replies on your own posts.** As the site owner you can now
|
|---|
| 278 | remove a reply from your thread (it stays removed: re-delivery and
|
|---|
| 279 | thread-filling are blocked by a tombstone) and report it to its author's
|
|---|
| 280 | server, straight from the thread. This also works for private replies, which
|
|---|
| 281 | cannot be handled via the fediverse interact flow.
|
|---|
| [010e073] | 282 |
|
|---|
| [9dbb175] | 283 | ### Fixed
|
|---|
| [7d19465] | 284 | - **A boosted video post keeps its video in the Circle.** Boosting a video-only
|
|---|
| 285 | post (Loops.video) stored it without its media, so the Circle showed a bare
|
|---|
| 286 | text tile instead of a video thumbnail; re-boosting could even wipe the video
|
|---|
| 287 | from an already-cached copy. Boosts now carry the full typed media, and a
|
|---|
| 288 | refresh never erases cached media.
|
|---|
| [92a2c46] | 289 | - **The interact page title follows your language.** "Interacteer via de
|
|---|
| 290 | fediverse" was hardcoded Dutch in the browser tab, even on an English site.
|
|---|
| 291 | - **The Apple Music icon looks like the Apple logo again.** The old icon was a
|
|---|
| 292 | garbled shape.
|
|---|
| 293 | - **Statistics columns no longer jump around in the 30 and 90 day views.**
|
|---|
| 294 | Columns without a date label collapsed slightly; every column now keeps its
|
|---|
| 295 | label line.
|
|---|
| [3778ddb] | 296 | - **Private replies no longer show on the public post page.** A followers-only
|
|---|
| 297 | or direct (DM) reply to your post was rendered in the public thread for
|
|---|
| 298 | everyone. Incoming replies now record their fediverse addressing; the public
|
|---|
| 299 | thread only shows public and unlisted replies. Private ones still reach you in
|
|---|
| 300 | notifications, with the post they belong to.
|
|---|
| [9dbb175] | 301 | - **Bare video/audio embeds no longer overflow their column.** A `.webm` /
|
|---|
| 302 | `.mp4` / `.mp3` player now fits the content width like the iframe embeds do;
|
|---|
| 303 | the width rule previously covered only `iframe`.
|
|---|
| 304 |
|
|---|
| [87d2787] | 305 | ## [1.4.0] · 2026-07-14
|
|---|
| 306 |
|
|---|
| 307 | ### Added
|
|---|
| 308 | - **Followers list with delivery health.** A new Fediverse tab shows who follows
|
|---|
| 309 | you and when each account was last reached, so dead accounts stand out and you
|
|---|
| 310 | can remove them after a check.
|
|---|
| 311 | - **Bare media links play inline.** A plain `.webm`, `.mp4` or `.mp3` link now
|
|---|
| 312 | renders a native player instead of a dead link.
|
|---|
| 313 | - **Hashtags, links and mentions are clickable on your site too.** `#tags`, URLs
|
|---|
| 314 | and `@mentions` in a post become links on the site itself, not only on the
|
|---|
| 315 | federated copy. Mentions are resolved once when you save, so pages stay fast.
|
|---|
| 316 |
|
|---|
| 317 | ### Fixed
|
|---|
| 318 | - **Replies, comment deletes and reply edits always arrive.** They used to be
|
|---|
| 319 | dropped when a server was briefly unreachable; they now go through the retry
|
|---|
| 320 | queue like posts do.
|
|---|
| 321 | - **Video thumbnails for more videos.** Covers from videos with their metadata at
|
|---|
| 322 | the end of the file (Loops.video, phone exports) now get a thumbnail instead of
|
|---|
| 323 | none.
|
|---|
| 324 | - **A video-only cover shows a poster on the post page.** It no longer renders
|
|---|
| 325 | blank in the Solo view.
|
|---|
| 326 | - **The installed app no longer shows old data on a shaky start.** A cold launch
|
|---|
| 327 | on a poor connection refreshes instead of showing a stale page.
|
|---|
| 328 | - **The Updates page follows your branch.** On the stable branch you no longer
|
|---|
| 329 | see main's changes flagged as "latest".
|
|---|
| 330 |
|
|---|
| [8e7f0ec] | 331 | ## [1.3.5] — 2026-07-04
|
|---|
| 332 |
|
|---|
| [0a93c15] | 333 | ### Fixed
|
|---|
| 334 | - **Polls keep their cover art when boosted.** A poll with music or an embed was
|
|---|
| 335 | federating without its cover, so a boosted poll showed a blank tile; the cover
|
|---|
| 336 | now travels with it.
|
|---|
| [da71f9d] | 337 | - **The Android app's Updates page shows what's actually installable.** It read
|
|---|
| 338 | the newest release branch, which could be ahead of the phone build for a short
|
|---|
| 339 | while — pressing update then reinstalled the same version. It now reads the
|
|---|
| 340 | version of the phone bundle itself.
|
|---|
| [0a93c15] | 341 |
|
|---|
| [6ec0433] | 342 | ## [1.3.4] — 2026-07-04
|
|---|
| 343 |
|
|---|
| [236e11b] | 344 | ### Fixed
|
|---|
| 345 | - **Boosts that lost their cover get it back automatically.** Posts you boosted
|
|---|
| 346 | before the cover fix were cached without their artwork; they are refreshed
|
|---|
| [14f54a7] | 347 | once on the next restart. If a post's home server is briefly unreachable at
|
|---|
| 348 | that moment, it is retried on the next restarts instead of being skipped for
|
|---|
| 349 | good. Boosting a post again now also refreshes its cached copy (cover,
|
|---|
| 350 | content) — from the feed as well as the interact page.
|
|---|
| [236e11b] | 351 |
|
|---|
| [b7e382f] | 352 | ## [1.3.3] — 2026-07-03
|
|---|
| 353 |
|
|---|
| [006a3be] | 354 | ### Fixed
|
|---|
| 355 | - **Boosted music posts keep their cover.** When you boosted a track from
|
|---|
| 356 | someone you don't follow, the cover art went missing; it now shows, just like
|
|---|
| 357 | for people you do follow.
|
|---|
| 358 |
|
|---|
| [8b5c076] | 359 | ## [1.3.2] — 2026-07-02
|
|---|
| 360 |
|
|---|
| [422b20d] | 361 | ### Fixed
|
|---|
| 362 | - **The Updates page now works in the Android app.** It now shows the newest
|
|---|
| 363 | available version, and the update button downloads and installs it right on
|
|---|
| 364 | your phone (your posts and settings are kept).
|
|---|
| 365 |
|
|---|
| [7d61ab8] | 366 | ## [1.3.1] — 2026-07-02
|
|---|
| 367 |
|
|---|
| [421046c] | 368 | ### Fixed
|
|---|
| 369 | - **Music keeps playing in the background on Android.** When a track ended while
|
|---|
| 370 | your phone was locked or the app was in the background, the next track would
|
|---|
| 371 | start and stop again after a second. The player now feeds the whole queue as
|
|---|
| 372 | one continuous stream, so auto-advancing to the next track no longer counts
|
|---|
| 373 | as "new" playback that the browser is allowed to pause.
|
|---|
| 374 |
|
|---|
| [a369029] | 375 | ## [1.3.0] — 2026-07-02
|
|---|
| 376 |
|
|---|
| [1bc0886] | 377 | ### Added
|
|---|
| [3b4095f] | 378 | - **Choose a light or dark share card.** The auto-generated share image follows your site theme;
|
|---|
| 379 | under Admin → SEO you can now force it light or dark.
|
|---|
| [fe97cc3] | 380 | - **A mention is now a notification.** When someone on the fediverse mentions you in a post —
|
|---|
| 381 | even one that isn't a reply to you — it shows up in your fediverse notifications with a link
|
|---|
| 382 | to the original.
|
|---|
| [8cf8b5f] | 383 | - **Cover art on openly shared audio.** A track shared openly on the fediverse now carries its
|
|---|
| 384 | cover art (or the post cover), so audio players that support artwork show it instead of a blank tile.
|
|---|
| [1c2dcba] | 385 | - **Report a post to the fediverse.** From a fediverse post you can now report it to the moderators
|
|---|
| [737ea05] | 386 | of its own home server, with an optional reason — and if someone reports your site, the report
|
|---|
| 387 | shows up in your fediverse notifications.
|
|---|
| [0688b5f] | 388 | - **Set a post's language.** Choose the language you wrote a post in — on the fediverse it enables
|
|---|
| 389 | timeline language filtering and the translate button.
|
|---|
| [d18c60e] | 390 | - **Alt text for images.** Give your cover image a description (and inline images keep their own
|
|---|
| 391 | alt text) — it federates to the fediverse and lets screen readers describe the picture.
|
|---|
| [f1956d7] | 392 | - **Mention people in a post.** Typing `@user@server` in a post now links to their profile and
|
|---|
| 393 | notifies them on the fediverse — even if they don't follow you — just like a mention in a reply.
|
|---|
| [1bc0886] | 394 | - **Short videos in the feed autoplay and loop.** An animated cover or a short (≤30s) clip in the
|
|---|
| 395 | News feed now plays automatically and loops muted, like a GIF; longer videos keep their controls.
|
|---|
| [55a73f0] | 396 | - **Vote on fediverse polls.** A poll from an account you follow now shows in the News feed with its
|
|---|
| 397 | options and current results, and you can cast your vote — it federates back like any Mastodon vote.
|
|---|
| [0403187] | 398 | - **Create your own polls.** A post can now carry a poll (single or multiple choice, with a set
|
|---|
| 399 | duration). It federates as a real fediverse poll, so your Mastodon followers can vote from their own
|
|---|
| 400 | app; the live results show on the post and the poll closes itself when the time is up.
|
|---|
| [1bc0886] | 401 |
|
|---|
| [c06816e] | 402 | ### Changed
|
|---|
| 403 | - **Sharing audio openly is now one-way.** Once a track is shared openly on the fediverse the file
|
|---|
| 404 | has spread, so "closing" it again would be false security — the editor now locks the choice after
|
|---|
| 405 | opening and warns you before you tick it.
|
|---|
| 406 |
|
|---|
| [e00c0e9] | 407 | ### Fixed
|
|---|
| [e67828e] | 408 | - **Remote videos show a preview frame.** A video in the News feed or a Circle tile (e.g. from
|
|---|
| 409 | Loops or PeerTube) used to appear as a black box until you pressed play; it now shows a real
|
|---|
| 410 | poster frame. (Longer videos keep their player controls by design — only clips under 30 seconds
|
|---|
| 411 | autoplay like a GIF.)
|
|---|
| [fc229f5] | 412 | - **Mentions, hashtags and links inside brackets now work.** A mention like `(@user@server)`, a
|
|---|
| 413 | `(#hashtag)` or a bracketed URL federated as plain text — and the mentioned person was never
|
|---|
| 414 | notified. They now link (and notify) like their unbracketed forms.
|
|---|
| [e00c0e9] | 415 | - **Plain web addresses become links on the fediverse.** A bare URL typed in a post or reply now
|
|---|
| 416 | federates as a clickable link instead of plain text.
|
|---|
| 417 |
|
|---|
| [131e266] | 418 | ## [1.2.0] — 2026-07-01
|
|---|
| 419 |
|
|---|
| 420 | ### Added
|
|---|
| 421 | - **PeerTube videos in the feed.** A PeerTube link in a post now shows an inline player in the News
|
|---|
| 422 | feed, like YouTube, Spotify and SoundCloud already did.
|
|---|
| 423 | - **Light share images.** Sites whose default theme is Light now get a matching light Open Graph card
|
|---|
| 424 | when a page is shared, instead of always a dark one.
|
|---|
| 425 | - **Leave your own visits out of the stats.** As the admin you can now exclude your own IP address
|
|---|
| 426 | from your site statistics, for a truer picture of real visitors.
|
|---|
| 427 | - **Right-click "Save" is turned off on covers, images and videos** — a light bit of friction so the
|
|---|
| 428 | artwork isn't one click from being saved (it's friction, not protection).
|
|---|
| 429 |
|
|---|
| [1b1cc89] | 430 | ### Fixed
|
|---|
| [131e266] | 431 | - **Animated video covers now render correctly everywhere.** In the Circle and the grid they could
|
|---|
| 432 | show up as a broken image or a blank tile; they now display as a proper looping video that fills the
|
|---|
| 433 | square, centred. Right-clicking a cover gives the normal link menu instead of the browser's video controls.
|
|---|
| [1b1cc89] | 434 | - **Following someone no longer gets stuck.** A follow whose first delivery fails (the other server
|
|---|
| 435 | briefly unreachable) is now retried automatically with backoff, instead of staying on "pending" forever.
|
|---|
| 436 | - **Boosted posts show their real text** in the Circle, instead of a "RE: <link>" prefix.
|
|---|
| [131e266] | 437 | - **Hardened fediverse handling** — stricter signature checks on incoming activity, blocks now also
|
|---|
| 438 | cover a boost of a blocked author, and pinned-post syncing no longer races when you save several times quickly.
|
|---|
| [1b1cc89] | 439 |
|
|---|
| [b1edba0] | 440 | ## [1.1.0] — 2026-06-30
|
|---|
| 441 |
|
|---|
| 442 | ### Added
|
|---|
| 443 | - **Animated covers play smoothly everywhere.** Upload an animated WebP as a cover and Klonkt also
|
|---|
| 444 | makes a muted, looping video of it. iOS Safari — where animated WebP is janky — gets the smooth
|
|---|
| 445 | video, every other browser keeps the crisp WebP, and on the fediverse the cover federates as a
|
|---|
| 446 | video that plays in Mastodon and its apps. Shown on the post, the grid, the feed and related posts.
|
|---|
| 447 | - **Media library (Admin → Media).** See every uploaded image, where each one is used, copy its URL,
|
|---|
| 448 | and clean up unused files in one click — including the leftover video/poster of an animated cover.
|
|---|
| 449 | Images, Audio and Playlists now share one tab bar.
|
|---|
| 450 | - **Share button** at the bottom of every post (native share sheet, or copy link).
|
|---|
| 451 | - **Replace a track's audio file** without re-creating the track.
|
|---|
| 452 | - **Music on the fediverse (first step).** Audio posts now carry schema.org *MusicRecording* /
|
|---|
| 453 | *MusicAlbum* data, and a per-post toggle can share a hosted track as a real fediverse audio
|
|---|
| 454 | attachment that plays in followers' feeds.
|
|---|
| 455 |
|
|---|
| 456 | ### Changed
|
|---|
| 457 | - **Cleaner embeds on Mastodon.** A post with a YouTube/Spotify/SoundCloud link now lets Mastodon
|
|---|
| 458 | show its player card; link-only tracks share their streaming links. The cover still shows in other
|
|---|
| 459 | Klonkt feeds. (On your own site nothing changes — the player and cover render as before.)
|
|---|
| 460 | - **Circles stay in sync the fediverse way** — edits and missed posts catch up automatically via
|
|---|
| 461 | standard ActivityPub, so a Circle no longer drifts out of date.
|
|---|
| 462 | - **Everything Klonkt federates is now valid AS2 / JSON-LD**, guarded by a test, so stricter servers
|
|---|
| 463 | accept it.
|
|---|
| 464 | - The track list is sorted **newest-first**.
|
|---|
| 465 |
|
|---|
| 466 | ### Fixed
|
|---|
| 467 | - **Animated WebP covers are no longer frozen to a single frame** (the crop editor and the thumbnailer
|
|---|
| 468 | left them static).
|
|---|
| 469 | - **Link-only tracks** (Spotify/YouTube, no uploaded file) can be inserted into a post again.
|
|---|
| 470 | - **Link previews** (og:image / Twitter card) now use absolute image URLs, so they show on Signal,
|
|---|
| 471 | WhatsApp and other scrapers.
|
|---|
| 472 | - Several **fediverse delivery fixes**: covers/links no longer turn into a black tile on Mastodon,
|
|---|
| 473 | raw audio files don't clutter a post that already has a player, and dead links from a renamed
|
|---|
| 474 | remote post heal themselves.
|
|---|
| 475 | - The **mobile feed** loads full-resolution covers; long titles wrap instead of overflowing.
|
|---|
| 476 | - **Self-hosting updates** are more reliable: re-running the installer keeps your channel, and the
|
|---|
| 477 | updater no longer restarts or claims an update when you're already up to date.
|
|---|
| 478 |
|
|---|
| [054b603] | 479 | ## [1.0.0] — 2026-06-30
|
|---|
| 480 |
|
|---|
| [eb5f978] | 481 | ### Added
|
|---|
| [98fe58a] | 482 | - **Klonkt is now on the fediverse (ActivityPub).** Your site is a real fediverse
|
|---|
| 483 | account: people on Mastodon — or another Klonkt — can follow you, and your posts
|
|---|
| 484 | reach their feeds. You can follow accounts and read their posts in a **News** feed,
|
|---|
| 485 | get **notifications**, and **like, boost and reply** to posts. Incoming activity is
|
|---|
| 486 | verified, so fake replies, likes and followers are rejected.
|
|---|
| 487 | - **Anyone can reply, like or boost your posts from the fediverse** — visitors interact
|
|---|
| 488 | from their own account (they just enter their server); no account on your site needed.
|
|---|
| 489 | - **Circles**: follow other Klonkt sites and show each other's public posts in your
|
|---|
| 490 | Circle — decentralised, with no central platform.
|
|---|
| 491 | - **Sensitive (NSFW) posts** with your own content-warning text: blurred with
|
|---|
| 492 | click-to-reveal across the site, and shown as a content warning on the fediverse.
|
|---|
| 493 | - **Block** an account or an entire domain you'd rather not hear from.
|
|---|
| 494 | - Search now also finds **tracks** (by title, artist and album), playable straight from
|
|---|
| 495 | the results with a link to the post they appear in — and post search matches as you type.
|
|---|
| 496 | - **Live theme preview** in Admin → site settings: accent, theme and palette update
|
|---|
| 497 | instantly, before you save.
|
|---|
| 498 | - Uploaded images are automatically optimised to **WebP** for faster pages.
|
|---|
| 499 | - A roomier **mobile writing experience**: tap to open a distraction-free fullscreen
|
|---|
| 500 | editor, with the formatting toolbar staying in view above the keyboard.
|
|---|
| [127f87e] | 501 | - **Long posts collapse in the News feed** with a *read more* toggle, so a long post no
|
|---|
| 502 | longer fills the whole screen — tap to expand or collapse it.
|
|---|
| [054b603] | 503 | - **See everyone in a Circle**: when a Circle has more than five sites, the member count
|
|---|
| 504 | opens a popup that lists them all, so a big Circle no longer hides its members.
|
|---|
| [0850535] | 505 |
|
|---|
| [eb5f978] | 506 | ### Changed
|
|---|
| [98fe58a] | 507 | - **Palettes revised to 8**: the neutral **Klonkt** (gold accent) is the new default,
|
|---|
| 508 | plus seven full-colour themes — Forest, Ocean, Teal, Lilac, Sunset, Candy and Amber.
|
|---|
| [054b603] | 509 | - **Your profile federates more completely**: the links on your profile, the date you
|
|---|
| 510 | joined and the accounts you follow now travel along to other servers, so your profile
|
|---|
| 511 | looks complete when someone views it from Mastodon or elsewhere.
|
|---|
| 512 | - **Cover images and avatars are sharper** — resized on the server instead of being
|
|---|
| 513 | squeezed by the browser.
|
|---|
| [0850535] | 514 |
|
|---|
| [eb5f978] | 515 | ### Removed
|
|---|
| [98fe58a] | 516 | - **Hub mode** — Klonkt is now **solo or Circles**; you build a collective or label
|
|---|
| 517 | through **Circles** (federated, standalone sites).
|
|---|
| 518 | - **Native comments and Google login** — replies, likes and boosts now run entirely
|
|---|
| 519 | through the fediverse.
|
|---|
| 520 | - **Local favourites (♥)** — replaced by the ⭐ fediverse like.
|
|---|
| [1720482] | 521 |
|
|---|
| [eb5f978] | 522 | ### Fixed
|
|---|
| [127f87e] | 523 | - **Hashtags and mentions now work in every language and script** (e.g. Japanese, Cyrillic,
|
|---|
| 524 | Arabic), both on your site and when federating — not just the Latin alphabet.
|
|---|
| [0a58300] | 525 | - **Switching a site to solo (federation off) works again.** Turning the fediverse off could
|
|---|
| 526 | make the whole site return “page not found” instead of just disabling federation; it now
|
|---|
| 527 | cleanly switches federation off while the rest of the site keeps working. (Self-hosters:
|
|---|
| 528 | update to pick up the fix.)
|
|---|
| 529 | - The Fediverse and Notifications items now disappear from the menu when federation is off,
|
|---|
| 530 | instead of lingering.
|
|---|
| [98fe58a] | 531 | - The mini-player jumps and scrolls to the track that's playing — also from an album or
|
|---|
| 532 | playlist — and keeps it highlighted.
|
|---|
| 533 | - Empty album/playlist covers now fall back to the first track's cover.
|
|---|
| 534 | - A profile photo that broke in the header after the WebP switch now repairs itself.
|
|---|
| 535 | - Many **mobile post-editor** fixes: reliable scrolling, a formatting toolbar that stays
|
|---|
| 536 | put, no page jumps when you tap a button, and a Save bar that sits just above the keyboard.
|
|---|
| [054b603] | 537 | - **Boosts now reach the original poster** — their server registers the boost and notifies
|
|---|
| 538 | them, just like a boost from Mastodon — and a boost is retried if a server is briefly
|
|---|
| 539 | unreachable instead of being sent once and forgotten.
|
|---|
| 540 | - **Unfollowing an account now takes effect on the other server** (it could previously fail
|
|---|
| 541 | to register, leaving you still following on their side).
|
|---|
| [90259da] | 542 |
|
|---|
| 543 | ## [1.0.0-beta.2] — 2026-06-19
|
|---|
| 544 |
|
|---|
| [98fe58a] | 545 | First release where we actively track the version (shown in the footer — click it for
|
|---|
| 546 | this page).
|
|---|
| [90259da] | 547 |
|
|---|
| [eb5f978] | 548 | ### Added
|
|---|
| 549 | - Release tracking: the version number in the footer links to this changelog page.
|
|---|
| 550 | - Eight premium features (Patreon-gated): newsletter/mailing list, download-for-email,
|
|---|
| 551 | release scheduling + fan-only previews, EPK/press kit, pro statistics, link-in-bio +
|
|---|
| 552 | click stats, embeddable player, and show agenda + notify-me.
|
|---|
| 553 | - Newsletter signup field in the footer (on/off in Admin → Settings).
|
|---|
| [98fe58a] | 554 | - SMTP settings configurable in Admin → Settings (no more config-file edit needed), with
|
|---|
| 555 | a test-mail button.
|
|---|
| [90259da] | 556 |
|
|---|
| [eb5f978] | 557 | ### Changed
|
|---|
| [98fe58a] | 558 | - Tidier settings forms (stacked labels, full-width inputs).
|
|---|
| [eb5f978] | 559 | - EPK/press kit shows the top 10 most-listened tracks.
|
|---|
| 560 | - Nicer 404 page (mobile-friendly) and clearer login error messages.
|
|---|
| [90259da] | 561 |
|
|---|
| [eb5f978] | 562 | ### Fixed
|
|---|
| [98fe58a] | 563 | - The site-wide audio player wasn't loading any tracks.
|
|---|
| 564 | - Button text became unreadable on hover.
|
|---|
| [eb5f978] | 565 | - Date pickers now follow the theme.
|
|---|
| [98fe58a] | 566 | - Back/forward navigation no longer shows a doubled header.
|
|---|