source: Klonkt/CHANGELOG.md@ feced2c

main
Last change on this file since feced2c was feced2c, checked in by Robin <roboburr@…>, 7 weeks ago

Feature: media in replies — rich replies phase 2 (klonkt-demo-c7f)

Drop, paste or pick images/audio/video in the reply editor; they upload, show
as removable chips, travel as AS2 attachments on the federated Note, and render
in the thread.

  • POST /posts/upload-reply-media (requireSiteManager): image/audio/video by extension AND mimetype, stored as-is under /media/reply-media/ (no transcode; a reply attachment is not a track), 32MB cap, returns {url, mediaType, name}.
  • Editor: paperclip button + hidden file input (the mobile path), paste-files and drag/drop handlers, busy/error chips, image thumbnails, max 4, hidden attachments JSON field. Media-only submit allowed (text no longer required when something is attached).
  • deliverReply({attachments}): re-validates server-side — own /media/ paths only (the upload route is the sole producer, remote URLs rejected), image|audio|video mimetypes, capped at 4; stored as JSON on ap_outbox (additive column). Dedup guard now includes attachments so two media-only replies to the same parent are distinct from each other but double-submits still dedup.
  • buildNote reply branch: attachment array with Image/Audio/Video types and absolute URLs. getInteractions passes media through; fedi-node renders it (img/audio/video) for visitors too, loading the stylesheet when the owner-only editor is not on the page.

3 new tests (foreign-URL and type rejection, typed absolute Note attachments,
media-only allowed, only-invalid rejected); 91 green. Browser-verified end to
end: real upload via the endpoint, paste-event -> chip with thumbnail ->
submit -> ap_outbox row with content+language+attachments -> media rendered in
the thread -> /ap/notes/<id> serves the typed absolute attachment.

Co-Authored-By: Claude Opus 4.8 <noreply@…>

  • Property mode set to 100644
File size: 21.4 KB
RevLine 
[eb5f978]1# Changelog — Klonkt
[90259da]2
[eb5f978]3All notable changes to Klonkt. Newest at the top.
[054b603]4Versions follow [SemVer](https://semver.org/).
[90259da]5
6## [Unreleased]
7
[d49b60b]8### Added
[feced2c]9- **Media in replies (rich replies, phase 2).** Drop, paste or pick images,
10 audio and video straight into the reply editor (the paperclip works on
11 phones). Files upload to your own site, show as removable chips while you
12 write, travel as real attachments on the federated note, and render in your
13 thread. A media-only reply (no text) works too.
[33e1dbd]14- **Rich replies (phase 1).** Replying to fediverse comments (inline in the
15 thread and on the interact page) now uses a shared rich editor: bold, italic,
16 links, lists and quotes, plus a language picker for your reply (sent along as
17 the note's language map). On phones the editor opens as a full-screen compose
18 view, the pattern that actually works on mobile. Without JavaScript the plain
19 text box keeps working. Media in replies is the next phase.
[2d66d66]20- **Revoke connected apps from your account page.** A "Connected apps" section
21 lists every app you authorized over OAuth (name, site, scope, last used) with
22 a Revoke button. Tokens you already granted show up too, since they were
23 always stored (hashed); the bearer itself is never kept, so revocation is keyed
24 on the token hash.
[4407c67]25- **The account owner can read their own followers and following over C2S.** The
26 `followers` and `following` collections stay count-only for the public
27 (privacy), but a request carrying a C2S bearer scoped to that site now returns
28 the real actor URIs, so an app (Shaer) can build a friends list. Anonymous
29 callers are unchanged.
[d49b60b]30- **App access via OAuth 2.0 (ActivityPub Client-to-Server, phase 1).** Klonkt
31 now speaks the standard AP C2S auth handshake so native and web clients (the
32 Shaer apps first) can connect: dynamic client registration (RFC 7591), a
33 PKCE authorization-code flow with a consent screen that picks which of your
34 sites the app may post as, and bearer tokens (stored hashed, single-use
35 codes). The actor document advertises the OAuth and uploadMedia endpoints and
36 `/.well-known/oauth-authorization-server` (RFC 8414) exposes the metadata, so
37 clients discover everything instead of hardcoding paths. Public clients + PKCE
[dd568e7]38 only, no client secrets.
39- **The outbox accepts posts from apps (C2S, phase 1 complete).** A
40 bearer-authenticated `POST` to `/ap/users/:slug/outbox` now drives your account
41 from a client: publish a note, reply, like, boost, follow, and undo any of
42 those. Activities are translated onto the same delivery machinery the web UI
43 uses; a bare Note is wrapped in a Create per the spec; content is sanitized;
44 the token is scoped to one site so it can't post as another. Note: this is
45 ActivityPub C2S, which the Shaer apps speak. Mastodon clients (Ivory etc.) use
46 Mastodon's own API and are not supported by this.
[d49b60b]47
[c867b7b]48### Fixed
[bf72108]49- **OAuth consent now hands off reliably to native apps.** After Allow/Deny, a
50 redirect to a native custom scheme (e.g. `com.klonkt.shaer:/oauth`) was a plain
51 302, which mobile browsers silently drop. The consent step now serves a tiny
52 interstitial for non-http redirect URIs that auto-forwards and offers an "Open
53 the app" tap link (a tap reliably launches the app on Android; iOS's web-auth
54 session intercepts either way). Web (http/https) clients still get a 302.
[c867b7b]55- **Visitors can reply to the site owner's own comments.** The "reply via the
56 fediverse" button only appeared on comments from others; the site's own
57 comments in a thread offered visitors nothing, so you could not respond to
58 the author from your own instance.
59
[05cd954]60## [1.5.0] · 2026-07-18
61
[010e073]62### Added
[f1a23b8]63- **Messages: your replies and notifications on one page.** A single Messages
64 tab replaces Replies and Notifications. One stream with filter chips (All,
65 Conversations, Activity, Sent): your own sent replies join the conversation
66 (with edit and delete), likes and boosts on the same post group into one line,
67 private replies carry a lock badge, and items new since your last visit get a
68 dot. The interact bookmarklet moved along. Old /fediverse and /notifications
69 links redirect to /messages.
[010e073]70- **Connect: your following and followers on one page.** A single Connect tab
71 replaces the separate Following and Followers pages, showing each connection's
72 direction (following →, follower ←, mutual ↔) and, for accounts you deliver to,
73 when they were last reached. Accounts you can no longer reach move to a
74 collapsed "Unreachable" section for cleanup. Old /following and /followers
75 links redirect to /connect.
[67c1f24]76- **Moderate incoming replies on your own posts.** As the site owner you can now
77 remove a reply from your thread (it stays removed: re-delivery and
78 thread-filling are blocked by a tombstone) and report it to its author's
79 server, straight from the thread. This also works for private replies, which
80 cannot be handled via the fediverse interact flow.
[010e073]81
[9dbb175]82### Fixed
[7d19465]83- **A boosted video post keeps its video in the Circle.** Boosting a video-only
84 post (Loops.video) stored it without its media, so the Circle showed a bare
85 text tile instead of a video thumbnail; re-boosting could even wipe the video
86 from an already-cached copy. Boosts now carry the full typed media, and a
87 refresh never erases cached media.
[92a2c46]88- **The interact page title follows your language.** "Interacteer via de
89 fediverse" was hardcoded Dutch in the browser tab, even on an English site.
90- **The Apple Music icon looks like the Apple logo again.** The old icon was a
91 garbled shape.
92- **Statistics columns no longer jump around in the 30 and 90 day views.**
93 Columns without a date label collapsed slightly; every column now keeps its
94 label line.
[3778ddb]95- **Private replies no longer show on the public post page.** A followers-only
96 or direct (DM) reply to your post was rendered in the public thread for
97 everyone. Incoming replies now record their fediverse addressing; the public
98 thread only shows public and unlisted replies. Private ones still reach you in
99 notifications, with the post they belong to.
[9dbb175]100- **Bare video/audio embeds no longer overflow their column.** A `.webm` /
101 `.mp4` / `.mp3` player now fits the content width like the iframe embeds do;
102 the width rule previously covered only `iframe`.
103
[87d2787]104## [1.4.0] · 2026-07-14
105
106### Added
107- **Followers list with delivery health.** A new Fediverse tab shows who follows
108 you and when each account was last reached, so dead accounts stand out and you
109 can remove them after a check.
110- **Bare media links play inline.** A plain `.webm`, `.mp4` or `.mp3` link now
111 renders a native player instead of a dead link.
112- **Hashtags, links and mentions are clickable on your site too.** `#tags`, URLs
113 and `@mentions` in a post become links on the site itself, not only on the
114 federated copy. Mentions are resolved once when you save, so pages stay fast.
115
116### Fixed
117- **Replies, comment deletes and reply edits always arrive.** They used to be
118 dropped when a server was briefly unreachable; they now go through the retry
119 queue like posts do.
120- **Video thumbnails for more videos.** Covers from videos with their metadata at
121 the end of the file (Loops.video, phone exports) now get a thumbnail instead of
122 none.
123- **A video-only cover shows a poster on the post page.** It no longer renders
124 blank in the Solo view.
125- **The installed app no longer shows old data on a shaky start.** A cold launch
126 on a poor connection refreshes instead of showing a stale page.
127- **The Updates page follows your branch.** On the stable branch you no longer
128 see main's changes flagged as "latest".
129
[8e7f0ec]130## [1.3.5] — 2026-07-04
131
[0a93c15]132### Fixed
133- **Polls keep their cover art when boosted.** A poll with music or an embed was
134 federating without its cover, so a boosted poll showed a blank tile; the cover
135 now travels with it.
[da71f9d]136- **The Android app's Updates page shows what's actually installable.** It read
137 the newest release branch, which could be ahead of the phone build for a short
138 while — pressing update then reinstalled the same version. It now reads the
139 version of the phone bundle itself.
[0a93c15]140
[6ec0433]141## [1.3.4] — 2026-07-04
142
[236e11b]143### Fixed
144- **Boosts that lost their cover get it back automatically.** Posts you boosted
145 before the cover fix were cached without their artwork; they are refreshed
[14f54a7]146 once on the next restart. If a post's home server is briefly unreachable at
147 that moment, it is retried on the next restarts instead of being skipped for
148 good. Boosting a post again now also refreshes its cached copy (cover,
149 content) — from the feed as well as the interact page.
[236e11b]150
[b7e382f]151## [1.3.3] — 2026-07-03
152
[006a3be]153### Fixed
154- **Boosted music posts keep their cover.** When you boosted a track from
155 someone you don't follow, the cover art went missing; it now shows, just like
156 for people you do follow.
157
[8b5c076]158## [1.3.2] — 2026-07-02
159
[422b20d]160### Fixed
161- **The Updates page now works in the Android app.** It now shows the newest
162 available version, and the update button downloads and installs it right on
163 your phone (your posts and settings are kept).
164
[7d61ab8]165## [1.3.1] — 2026-07-02
166
[421046c]167### Fixed
168- **Music keeps playing in the background on Android.** When a track ended while
169 your phone was locked or the app was in the background, the next track would
170 start and stop again after a second. The player now feeds the whole queue as
171 one continuous stream, so auto-advancing to the next track no longer counts
172 as "new" playback that the browser is allowed to pause.
173
[a369029]174## [1.3.0] — 2026-07-02
175
[1bc0886]176### Added
[3b4095f]177- **Choose a light or dark share card.** The auto-generated share image follows your site theme;
178 under Admin → SEO you can now force it light or dark.
[fe97cc3]179- **A mention is now a notification.** When someone on the fediverse mentions you in a post —
180 even one that isn't a reply to you — it shows up in your fediverse notifications with a link
181 to the original.
[8cf8b5f]182- **Cover art on openly shared audio.** A track shared openly on the fediverse now carries its
183 cover art (or the post cover), so audio players that support artwork show it instead of a blank tile.
[1c2dcba]184- **Report a post to the fediverse.** From a fediverse post you can now report it to the moderators
[737ea05]185 of its own home server, with an optional reason — and if someone reports your site, the report
186 shows up in your fediverse notifications.
[0688b5f]187- **Set a post's language.** Choose the language you wrote a post in — on the fediverse it enables
188 timeline language filtering and the translate button.
[d18c60e]189- **Alt text for images.** Give your cover image a description (and inline images keep their own
190 alt text) — it federates to the fediverse and lets screen readers describe the picture.
[f1956d7]191- **Mention people in a post.** Typing `@user@server` in a post now links to their profile and
192 notifies them on the fediverse — even if they don't follow you — just like a mention in a reply.
[1bc0886]193- **Short videos in the feed autoplay and loop.** An animated cover or a short (≤30s) clip in the
194 News feed now plays automatically and loops muted, like a GIF; longer videos keep their controls.
[55a73f0]195- **Vote on fediverse polls.** A poll from an account you follow now shows in the News feed with its
196 options and current results, and you can cast your vote — it federates back like any Mastodon vote.
[0403187]197- **Create your own polls.** A post can now carry a poll (single or multiple choice, with a set
198 duration). It federates as a real fediverse poll, so your Mastodon followers can vote from their own
199 app; the live results show on the post and the poll closes itself when the time is up.
[1bc0886]200
[c06816e]201### Changed
202- **Sharing audio openly is now one-way.** Once a track is shared openly on the fediverse the file
203 has spread, so "closing" it again would be false security — the editor now locks the choice after
204 opening and warns you before you tick it.
205
[e00c0e9]206### Fixed
[e67828e]207- **Remote videos show a preview frame.** A video in the News feed or a Circle tile (e.g. from
208 Loops or PeerTube) used to appear as a black box until you pressed play; it now shows a real
209 poster frame. (Longer videos keep their player controls by design — only clips under 30 seconds
210 autoplay like a GIF.)
[fc229f5]211- **Mentions, hashtags and links inside brackets now work.** A mention like `(@user@server)`, a
212 `(#hashtag)` or a bracketed URL federated as plain text — and the mentioned person was never
213 notified. They now link (and notify) like their unbracketed forms.
[e00c0e9]214- **Plain web addresses become links on the fediverse.** A bare URL typed in a post or reply now
215 federates as a clickable link instead of plain text.
216
[131e266]217## [1.2.0] — 2026-07-01
218
219### Added
220- **PeerTube videos in the feed.** A PeerTube link in a post now shows an inline player in the News
221 feed, like YouTube, Spotify and SoundCloud already did.
222- **Light share images.** Sites whose default theme is Light now get a matching light Open Graph card
223 when a page is shared, instead of always a dark one.
224- **Leave your own visits out of the stats.** As the admin you can now exclude your own IP address
225 from your site statistics, for a truer picture of real visitors.
226- **Right-click "Save" is turned off on covers, images and videos** — a light bit of friction so the
227 artwork isn't one click from being saved (it's friction, not protection).
228
[1b1cc89]229### Fixed
[131e266]230- **Animated video covers now render correctly everywhere.** In the Circle and the grid they could
231 show up as a broken image or a blank tile; they now display as a proper looping video that fills the
232 square, centred. Right-clicking a cover gives the normal link menu instead of the browser's video controls.
[1b1cc89]233- **Following someone no longer gets stuck.** A follow whose first delivery fails (the other server
234 briefly unreachable) is now retried automatically with backoff, instead of staying on "pending" forever.
235- **Boosted posts show their real text** in the Circle, instead of a "RE: <link>" prefix.
[131e266]236- **Hardened fediverse handling** — stricter signature checks on incoming activity, blocks now also
237 cover a boost of a blocked author, and pinned-post syncing no longer races when you save several times quickly.
[1b1cc89]238
[b1edba0]239## [1.1.0] — 2026-06-30
240
241### Added
242- **Animated covers play smoothly everywhere.** Upload an animated WebP as a cover and Klonkt also
243 makes a muted, looping video of it. iOS Safari — where animated WebP is janky — gets the smooth
244 video, every other browser keeps the crisp WebP, and on the fediverse the cover federates as a
245 video that plays in Mastodon and its apps. Shown on the post, the grid, the feed and related posts.
246- **Media library (Admin → Media).** See every uploaded image, where each one is used, copy its URL,
247 and clean up unused files in one click — including the leftover video/poster of an animated cover.
248 Images, Audio and Playlists now share one tab bar.
249- **Share button** at the bottom of every post (native share sheet, or copy link).
250- **Replace a track's audio file** without re-creating the track.
251- **Music on the fediverse (first step).** Audio posts now carry schema.org *MusicRecording* /
252 *MusicAlbum* data, and a per-post toggle can share a hosted track as a real fediverse audio
253 attachment that plays in followers' feeds.
254
255### Changed
256- **Cleaner embeds on Mastodon.** A post with a YouTube/Spotify/SoundCloud link now lets Mastodon
257 show its player card; link-only tracks share their streaming links. The cover still shows in other
258 Klonkt feeds. (On your own site nothing changes — the player and cover render as before.)
259- **Circles stay in sync the fediverse way** — edits and missed posts catch up automatically via
260 standard ActivityPub, so a Circle no longer drifts out of date.
261- **Everything Klonkt federates is now valid AS2 / JSON-LD**, guarded by a test, so stricter servers
262 accept it.
263- The track list is sorted **newest-first**.
264
265### Fixed
266- **Animated WebP covers are no longer frozen to a single frame** (the crop editor and the thumbnailer
267 left them static).
268- **Link-only tracks** (Spotify/YouTube, no uploaded file) can be inserted into a post again.
269- **Link previews** (og:image / Twitter card) now use absolute image URLs, so they show on Signal,
270 WhatsApp and other scrapers.
271- Several **fediverse delivery fixes**: covers/links no longer turn into a black tile on Mastodon,
272 raw audio files don't clutter a post that already has a player, and dead links from a renamed
273 remote post heal themselves.
274- The **mobile feed** loads full-resolution covers; long titles wrap instead of overflowing.
275- **Self-hosting updates** are more reliable: re-running the installer keeps your channel, and the
276 updater no longer restarts or claims an update when you're already up to date.
277
[054b603]278## [1.0.0] — 2026-06-30
279
[eb5f978]280### Added
[98fe58a]281- **Klonkt is now on the fediverse (ActivityPub).** Your site is a real fediverse
282 account: people on Mastodon — or another Klonkt — can follow you, and your posts
283 reach their feeds. You can follow accounts and read their posts in a **News** feed,
284 get **notifications**, and **like, boost and reply** to posts. Incoming activity is
285 verified, so fake replies, likes and followers are rejected.
286- **Anyone can reply, like or boost your posts from the fediverse** — visitors interact
287 from their own account (they just enter their server); no account on your site needed.
288- **Circles**: follow other Klonkt sites and show each other's public posts in your
289 Circle — decentralised, with no central platform.
290- **Sensitive (NSFW) posts** with your own content-warning text: blurred with
291 click-to-reveal across the site, and shown as a content warning on the fediverse.
292- **Block** an account or an entire domain you'd rather not hear from.
293- Search now also finds **tracks** (by title, artist and album), playable straight from
294 the results with a link to the post they appear in — and post search matches as you type.
295- **Live theme preview** in Admin → site settings: accent, theme and palette update
296 instantly, before you save.
297- Uploaded images are automatically optimised to **WebP** for faster pages.
298- A roomier **mobile writing experience**: tap to open a distraction-free fullscreen
299 editor, with the formatting toolbar staying in view above the keyboard.
[127f87e]300- **Long posts collapse in the News feed** with a *read more* toggle, so a long post no
301 longer fills the whole screen — tap to expand or collapse it.
[054b603]302- **See everyone in a Circle**: when a Circle has more than five sites, the member count
303 opens a popup that lists them all, so a big Circle no longer hides its members.
[0850535]304
[eb5f978]305### Changed
[98fe58a]306- **Palettes revised to 8**: the neutral **Klonkt** (gold accent) is the new default,
307 plus seven full-colour themes — Forest, Ocean, Teal, Lilac, Sunset, Candy and Amber.
[054b603]308- **Your profile federates more completely**: the links on your profile, the date you
309 joined and the accounts you follow now travel along to other servers, so your profile
310 looks complete when someone views it from Mastodon or elsewhere.
311- **Cover images and avatars are sharper** — resized on the server instead of being
312 squeezed by the browser.
[0850535]313
[eb5f978]314### Removed
[98fe58a]315- **Hub mode** — Klonkt is now **solo or Circles**; you build a collective or label
316 through **Circles** (federated, standalone sites).
317- **Native comments and Google login** — replies, likes and boosts now run entirely
318 through the fediverse.
319- **Local favourites (♥)** — replaced by the ⭐ fediverse like.
[1720482]320
[eb5f978]321### Fixed
[127f87e]322- **Hashtags and mentions now work in every language and script** (e.g. Japanese, Cyrillic,
323 Arabic), both on your site and when federating — not just the Latin alphabet.
[0a58300]324- **Switching a site to solo (federation off) works again.** Turning the fediverse off could
325 make the whole site return “page not found” instead of just disabling federation; it now
326 cleanly switches federation off while the rest of the site keeps working. (Self-hosters:
327 update to pick up the fix.)
328- The Fediverse and Notifications items now disappear from the menu when federation is off,
329 instead of lingering.
[98fe58a]330- The mini-player jumps and scrolls to the track that's playing — also from an album or
331 playlist — and keeps it highlighted.
332- Empty album/playlist covers now fall back to the first track's cover.
333- A profile photo that broke in the header after the WebP switch now repairs itself.
334- Many **mobile post-editor** fixes: reliable scrolling, a formatting toolbar that stays
335 put, no page jumps when you tap a button, and a Save bar that sits just above the keyboard.
[054b603]336- **Boosts now reach the original poster** — their server registers the boost and notifies
337 them, just like a boost from Mastodon — and a boost is retried if a server is briefly
338 unreachable instead of being sent once and forgotten.
339- **Unfollowing an account now takes effect on the other server** (it could previously fail
340 to register, leaving you still following on their side).
[90259da]341
342## [1.0.0-beta.2] — 2026-06-19
343
[98fe58a]344First release where we actively track the version (shown in the footer — click it for
345this page).
[90259da]346
[eb5f978]347### Added
348- Release tracking: the version number in the footer links to this changelog page.
349- Eight premium features (Patreon-gated): newsletter/mailing list, download-for-email,
350 release scheduling + fan-only previews, EPK/press kit, pro statistics, link-in-bio +
351 click stats, embeddable player, and show agenda + notify-me.
352- Newsletter signup field in the footer (on/off in Admin → Settings).
[98fe58a]353- SMTP settings configurable in Admin → Settings (no more config-file edit needed), with
354 a test-mail button.
[90259da]355
[eb5f978]356### Changed
[98fe58a]357- Tidier settings forms (stacked labels, full-width inputs).
[eb5f978]358- EPK/press kit shows the top 10 most-listened tracks.
359- Nicer 404 page (mobile-friendly) and clearer login error messages.
[90259da]360
[eb5f978]361### Fixed
[98fe58a]362- The site-wide audio player wasn't loading any tracks.
363- Button text became unreadable on hover.
[eb5f978]364- Date pickers now follow the theme.
[98fe58a]365- Back/forward navigation no longer shows a doubled header.
Note: See TracBrowser for help on using the repository browser.