source: Klonkt/CHANGELOG.md@ d8f8f07

main
Last change on this file since d8f8f07 was 0d5bd2c, checked in by Robin <roboburr@…>, 5 weeks ago

chore(release): 1.7.0

Minor omdat de afhankelijkheden onder Klonkt verschoven zijn, niet omdat er
functionaliteit bij kwam: zeven adviezen dicht, waarvan sanitize-html kritiek
was en nodemailer drie hoofdversies opschoof.

Changelog in nl/en/de krijgt daarvoor een rubriek Beveiliging/Security/
Sicherheit -- die bestond nog niet, en dit is precies waar keep-a-changelog
hem voor heeft.

Co-Authored-By: Claude Opus 5 <noreply@…>

  • Property mode set to 100644
File size: 29.2 KB
Line 
1# Changelog — Klonkt
2
3All notable changes to Klonkt. Newest at the top.
4Versions follow [SemVer](https://semver.org/).
5
6## [Unreleased]
7
8## [1.7.0] · 2026-08-07
9
10### Added
11- **Messages is one conversation view.** Messages, Conversations and Sent were
12 three separate filters, so a single exchange fell apart: what you sent sat
13 under Sent, what came back under one of the other two, and you had to switch
14 filters to follow a thread. They are now one Conversations view in which sent
15 and received sit in the same thread, oldest at the top, with your own
16 contributions marked. Four filters remain: All, Conversations, Activity and
17 Moderation.
18- **A conversation says what it is about.** When a thread hangs off one of your
19 posts, its header links to that post. Without it a reply in a list is
20 impossible to place. Threads that are not about a post run per person instead.
21- **Posts in Messages look like posts.** Formatting, images, audio, video, quote
22 cards and link previews now render the same way they do in News, including on
23 the messages you sent yourself — a photo you attached used to arrive as bare
24 text on your own screen while everyone else saw the picture.
25- **The Guardian app shows a ward's posts in full.** The same gap sat in the
26 guardian view: a post from your ward arrived without its media, quote card or
27 emoji, which is exactly the post a guardian needs to be able to judge. A
28 content warning still stays collapsed there, as before.
29- **Reply from inside a conversation.** A thread has its own reply editor, the
30 rich one with formatting, media and a language picker. Waving stays a separate
31 button next to it: a wave is a nudge, not an answer.
32
33### Fixed
34- **People on privacy-strict servers can follow you again.** Some servers only
35 hand out an account's public key to a signed request. Klonkt asked without
36 signing, got turned away, and could therefore not check the follow request that
37 had just arrived — so it was refused, and the other server kept retrying for
38 days. Klonkt now signs that lookup, and those follows go through. This also
39 affected everything else fetched from such a server: profiles, posts and
40 replies.
41- **Replies from other people now arrive in threads.** When someone replied to a
42 post in a conversation you were part of, their server forwarded that reply to
43 you — and it was turned away, because the forwarding server signs with its own
44 key rather than the author's. Threads were quietly incomplete on your side.
45 Such a reply is now checked at the source instead of being refused: the post is
46 fetched from the server that hosts it, and only what comes back from there is
47 stored. A forwarded delete is still refused, because a deleted post cannot be
48 checked.
49- **A like or boost looks the same everywhere.** The same post could show as
50 liked in News and as not liked on the interact page, because both kept their
51 own record. There is one record now, so the buttons agree — including for
52 everything you reacted to before this release, which is carried over
53 automatically when the site updates.
54- **A like from an app now sticks.** Liking a post from Shaer was stored, but
55 the app never got that back, so the heart popped off again on the next reload
56 — and because the app never saw the like, it could only offer "like" again and
57 never undo it. Un-liking from an app now works.
58
59### Security
60
61- **Updated components close seven security advisories.** The heaviest one sat
62 in the library that cleans up posts arriving from elsewhere: a carefully built
63 post could slip a script past it, and a script running on your page can act as
64 if it were you. At the same time mail handling moved three major versions on,
65 closing a cluster of holes around sending — among them one where a prepared
66 name could smuggle commands into the conversation with the mail server, and
67 one where a message could end up at a different domain than the one addressed.
68 None of this changes how Klonkt looks or behaves. One advisory is knowingly
69 left open: it concerns a way of generating identifiers that Klonkt does not
70 use.
71
72## [1.6.0] · 2026-07-31
73
74### Added
75- **Guardians (FEP-633c).** An account can now be watched over by one or more
76 guardians, the way a child has parents. A guardian offers to look after
77 someone; the ward accepts in their own Messages, and any existing guardians
78 co-approve, so no one can attach themselves to a child on their own. Once
79 agreed, the guardian appears on the ward's actor (`shaer:guardians`) and can
80 be reached when the ward calls for help. It builds on ordinary ActivityPub, so
81 guardian and ward can live on different servers.
82- **A Guardian app you can install.** A separate, installable corner at
83 `/guardian` for guardians: add and manage your wards, a message centre for
84 incoming calls for help, and its own notifications for help requests and
85 guardianship traffic, even with the app closed.
86- **Guardianship offers land in your Messages.** When someone offers to become
87 your guardian, it shows up in your own Messages as a clear item with Accept
88 and Decline, so you answer where you already read your messages instead of
89 somewhere separate.
90- **The owner can read their inbox over C2S.** A GET on the inbox with the
91 account's own bearer returns recent inbound posts (the accounts you follow)
92 as Create(Note) items, so a connected app (Shaer) can build a unified feed.
93 For everyone else the inbox stays write-only.
94- **"Load more" on the feeds.** Solo (home), Cirkel, News and Messages now page
95 in blocks of 72 with a "Load more" button instead of a hard cap, so older
96 items are reachable. 72 divides by 2, 3 and 4, so the grid views always end on
97 a full row. Appending is instant (htmx), the Messages search and filters keep
98 working across pages, and the button disappears on the last page.
99- **"Interact via the fediverse" next to Share.** On a post, visitors get a
100 button beside Share to reply, like or boost from their own fediverse server
101 (it asks for your server, then hands off to your instance). Hidden for the
102 site owner and when federation is off.
103- **FEDERATION.md (FEP-67ff).** The repository root now documents what Klonkt
104 speaks on the wire: ActivityPub S2S and C2S, WebFinger, HTTP Signatures,
105 NodeInfo 2.1, OAuth (PKCE), the activities and object types it sends and
106 receives, the Mastodon-compatible extension terms, and the FEPs it supports or
107 tracks. Helps other implementations interoperate.
108- **Messages: your poll finished.** When one of your own polls closes, Messages
109 shows a "poll finished" item with the final result: a bar per option with its
110 percentage, and the number of voters. It lives under the Activity chip and is
111 searchable like the rest.
112- **Messages: sharper filters and a search box.** The filter chips are now
113 Messages (@mentions and private/DM replies), Conversations (public replies),
114 Activity (likes, boosts, follows), Moderation (reports) and Sent, next to All.
115 A search box filters the list by sender and message text, and combines with
116 the active chip. All client-side, instant.
117- **The reply editor got a visual clean-up.** Its toolbar now uses the same
118 icon set and 32px buttons as the post editor, with active formatting shown
119 filled in the accent colour, a framed editor box with a focus ring, and
120 tidier language, mention and attachment chips. One editor family across the
121 site.
122- **The reply editor shows who you are addressing (rich replies, phase 3).** A
123 "To:" bar above the editor lists the conversation partners (the author you
124 reply to plus the thread's earlier authors) as removable chips, instead of
125 cluttering your text with @mentions. Remove a chip and that person is no
126 longer mentioned, tagged or pinged; mentions you type yourself stay in the
127 text. Editing a sent reply keeps every co-mention intact.
128- **Editing a sent reply uses the rich editor too.** The edit forms on Messages
129 and the interact page open the same editor as new replies (formatting kept,
130 language adjustable, full-screen on phones). Attachments on the reply survive
131 an edit untouched.
132- **Media in replies (rich replies, phase 2).** Drop, paste or pick images,
133 audio and video straight into the reply editor (the paperclip works on
134 phones). Files upload to your own site, show as removable chips while you
135 write, travel as real attachments on the federated note, and render in your
136 thread. A media-only reply (no text) works too.
137- **Rich replies (phase 1).** Replying to fediverse comments (inline in the
138 thread and on the interact page) now uses a shared rich editor: bold, italic,
139 links, lists and quotes, plus a language picker for your reply (sent along as
140 the note's language map). On phones the editor opens as a full-screen compose
141 view, the pattern that actually works on mobile. Without JavaScript the plain
142 text box keeps working. Media in replies is the next phase.
143- **Revoke connected apps from your account page.** A "Connected apps" section
144 lists every app you authorized over OAuth (name, site, scope, last used) with
145 a Revoke button. Tokens you already granted show up too, since they were
146 always stored (hashed); the bearer itself is never kept, so revocation is keyed
147 on the token hash.
148- **The account owner can read their own followers and following over C2S.** The
149 `followers` and `following` collections stay count-only for the public
150 (privacy), but a request carrying a C2S bearer scoped to that site now returns
151 the real actor URIs, so an app (Shaer) can build a friends list. Anonymous
152 callers are unchanged.
153- **App access via OAuth 2.0 (ActivityPub Client-to-Server, phase 1).** Klonkt
154 now speaks the standard AP C2S auth handshake so native and web clients (the
155 Shaer apps first) can connect: dynamic client registration (RFC 7591), a
156 PKCE authorization-code flow with a consent screen that picks which of your
157 sites the app may post as, and bearer tokens (stored hashed, single-use
158 codes). The actor document advertises the OAuth and uploadMedia endpoints and
159 `/.well-known/oauth-authorization-server` (RFC 8414) exposes the metadata, so
160 clients discover everything instead of hardcoding paths. Public clients + PKCE
161 only, no client secrets.
162- **The outbox accepts posts from apps (C2S, phase 1 complete).** A
163 bearer-authenticated `POST` to `/ap/users/:slug/outbox` now drives your account
164 from a client: publish a note, reply, like, boost, follow, and undo any of
165 those. Activities are translated onto the same delivery machinery the web UI
166 uses; a bare Note is wrapped in a Create per the spec; content is sanitized;
167 the token is scoped to one site so it can't post as another. Note: this is
168 ActivityPub C2S, which the Shaer apps speak. Mastodon clients (Ivory etc.) use
169 Mastodon's own API and are not supported by this.
170
171### Fixed
172- **OAuth consent now hands off reliably to native apps.** After Allow/Deny, a
173 redirect to a native custom scheme (e.g. `com.klonkt.shaer:/oauth`) was a plain
174 302, which mobile browsers silently drop. The consent step now serves a tiny
175 interstitial for non-http redirect URIs that auto-forwards and offers an "Open
176 the app" tap link (a tap reliably launches the app on Android; iOS's web-auth
177 session intercepts either way). Web (http/https) clients still get a 302.
178- **Visitors can reply to the site owner's own comments.** The "reply via the
179 fediverse" button only appeared on comments from others; the site's own
180 comments in a thread offered visitors nothing, so you could not respond to
181 the author from your own instance.
182
183## [1.5.0] · 2026-07-18
184
185### Added
186- **Messages: your replies and notifications on one page.** A single Messages
187 tab replaces Replies and Notifications. One stream with filter chips (All,
188 Conversations, Activity, Sent): your own sent replies join the conversation
189 (with edit and delete), likes and boosts on the same post group into one line,
190 private replies carry a lock badge, and items new since your last visit get a
191 dot. The interact bookmarklet moved along. Old /fediverse and /notifications
192 links redirect to /messages.
193- **Connect: your following and followers on one page.** A single Connect tab
194 replaces the separate Following and Followers pages, showing each connection's
195 direction (following →, follower ←, mutual ↔) and, for accounts you deliver to,
196 when they were last reached. Accounts you can no longer reach move to a
197 collapsed "Unreachable" section for cleanup. Old /following and /followers
198 links redirect to /connect.
199- **Moderate incoming replies on your own posts.** As the site owner you can now
200 remove a reply from your thread (it stays removed: re-delivery and
201 thread-filling are blocked by a tombstone) and report it to its author's
202 server, straight from the thread. This also works for private replies, which
203 cannot be handled via the fediverse interact flow.
204
205### Fixed
206- **A boosted video post keeps its video in the Circle.** Boosting a video-only
207 post (Loops.video) stored it without its media, so the Circle showed a bare
208 text tile instead of a video thumbnail; re-boosting could even wipe the video
209 from an already-cached copy. Boosts now carry the full typed media, and a
210 refresh never erases cached media.
211- **The interact page title follows your language.** "Interacteer via de
212 fediverse" was hardcoded Dutch in the browser tab, even on an English site.
213- **The Apple Music icon looks like the Apple logo again.** The old icon was a
214 garbled shape.
215- **Statistics columns no longer jump around in the 30 and 90 day views.**
216 Columns without a date label collapsed slightly; every column now keeps its
217 label line.
218- **Private replies no longer show on the public post page.** A followers-only
219 or direct (DM) reply to your post was rendered in the public thread for
220 everyone. Incoming replies now record their fediverse addressing; the public
221 thread only shows public and unlisted replies. Private ones still reach you in
222 notifications, with the post they belong to.
223- **Bare video/audio embeds no longer overflow their column.** A `.webm` /
224 `.mp4` / `.mp3` player now fits the content width like the iframe embeds do;
225 the width rule previously covered only `iframe`.
226
227## [1.4.0] · 2026-07-14
228
229### Added
230- **Followers list with delivery health.** A new Fediverse tab shows who follows
231 you and when each account was last reached, so dead accounts stand out and you
232 can remove them after a check.
233- **Bare media links play inline.** A plain `.webm`, `.mp4` or `.mp3` link now
234 renders a native player instead of a dead link.
235- **Hashtags, links and mentions are clickable on your site too.** `#tags`, URLs
236 and `@mentions` in a post become links on the site itself, not only on the
237 federated copy. Mentions are resolved once when you save, so pages stay fast.
238
239### Fixed
240- **Replies, comment deletes and reply edits always arrive.** They used to be
241 dropped when a server was briefly unreachable; they now go through the retry
242 queue like posts do.
243- **Video thumbnails for more videos.** Covers from videos with their metadata at
244 the end of the file (Loops.video, phone exports) now get a thumbnail instead of
245 none.
246- **A video-only cover shows a poster on the post page.** It no longer renders
247 blank in the Solo view.
248- **The installed app no longer shows old data on a shaky start.** A cold launch
249 on a poor connection refreshes instead of showing a stale page.
250- **The Updates page follows your branch.** On the stable branch you no longer
251 see main's changes flagged as "latest".
252
253## [1.3.5] — 2026-07-04
254
255### Fixed
256- **Polls keep their cover art when boosted.** A poll with music or an embed was
257 federating without its cover, so a boosted poll showed a blank tile; the cover
258 now travels with it.
259- **The Android app's Updates page shows what's actually installable.** It read
260 the newest release branch, which could be ahead of the phone build for a short
261 while — pressing update then reinstalled the same version. It now reads the
262 version of the phone bundle itself.
263
264## [1.3.4] — 2026-07-04
265
266### Fixed
267- **Boosts that lost their cover get it back automatically.** Posts you boosted
268 before the cover fix were cached without their artwork; they are refreshed
269 once on the next restart. If a post's home server is briefly unreachable at
270 that moment, it is retried on the next restarts instead of being skipped for
271 good. Boosting a post again now also refreshes its cached copy (cover,
272 content) — from the feed as well as the interact page.
273
274## [1.3.3] — 2026-07-03
275
276### Fixed
277- **Boosted music posts keep their cover.** When you boosted a track from
278 someone you don't follow, the cover art went missing; it now shows, just like
279 for people you do follow.
280
281## [1.3.2] — 2026-07-02
282
283### Fixed
284- **The Updates page now works in the Android app.** It now shows the newest
285 available version, and the update button downloads and installs it right on
286 your phone (your posts and settings are kept).
287
288## [1.3.1] — 2026-07-02
289
290### Fixed
291- **Music keeps playing in the background on Android.** When a track ended while
292 your phone was locked or the app was in the background, the next track would
293 start and stop again after a second. The player now feeds the whole queue as
294 one continuous stream, so auto-advancing to the next track no longer counts
295 as "new" playback that the browser is allowed to pause.
296
297## [1.3.0] — 2026-07-02
298
299### Added
300- **Choose a light or dark share card.** The auto-generated share image follows your site theme;
301 under Admin → SEO you can now force it light or dark.
302- **A mention is now a notification.** When someone on the fediverse mentions you in a post —
303 even one that isn't a reply to you — it shows up in your fediverse notifications with a link
304 to the original.
305- **Cover art on openly shared audio.** A track shared openly on the fediverse now carries its
306 cover art (or the post cover), so audio players that support artwork show it instead of a blank tile.
307- **Report a post to the fediverse.** From a fediverse post you can now report it to the moderators
308 of its own home server, with an optional reason — and if someone reports your site, the report
309 shows up in your fediverse notifications.
310- **Set a post's language.** Choose the language you wrote a post in — on the fediverse it enables
311 timeline language filtering and the translate button.
312- **Alt text for images.** Give your cover image a description (and inline images keep their own
313 alt text) — it federates to the fediverse and lets screen readers describe the picture.
314- **Mention people in a post.** Typing `@user@server` in a post now links to their profile and
315 notifies them on the fediverse — even if they don't follow you — just like a mention in a reply.
316- **Short videos in the feed autoplay and loop.** An animated cover or a short (≤30s) clip in the
317 News feed now plays automatically and loops muted, like a GIF; longer videos keep their controls.
318- **Vote on fediverse polls.** A poll from an account you follow now shows in the News feed with its
319 options and current results, and you can cast your vote — it federates back like any Mastodon vote.
320- **Create your own polls.** A post can now carry a poll (single or multiple choice, with a set
321 duration). It federates as a real fediverse poll, so your Mastodon followers can vote from their own
322 app; the live results show on the post and the poll closes itself when the time is up.
323
324### Changed
325- **Sharing audio openly is now one-way.** Once a track is shared openly on the fediverse the file
326 has spread, so "closing" it again would be false security — the editor now locks the choice after
327 opening and warns you before you tick it.
328
329### Fixed
330- **Remote videos show a preview frame.** A video in the News feed or a Circle tile (e.g. from
331 Loops or PeerTube) used to appear as a black box until you pressed play; it now shows a real
332 poster frame. (Longer videos keep their player controls by design — only clips under 30 seconds
333 autoplay like a GIF.)
334- **Mentions, hashtags and links inside brackets now work.** A mention like `(@user@server)`, a
335 `(#hashtag)` or a bracketed URL federated as plain text — and the mentioned person was never
336 notified. They now link (and notify) like their unbracketed forms.
337- **Plain web addresses become links on the fediverse.** A bare URL typed in a post or reply now
338 federates as a clickable link instead of plain text.
339
340## [1.2.0] — 2026-07-01
341
342### Added
343- **PeerTube videos in the feed.** A PeerTube link in a post now shows an inline player in the News
344 feed, like YouTube, Spotify and SoundCloud already did.
345- **Light share images.** Sites whose default theme is Light now get a matching light Open Graph card
346 when a page is shared, instead of always a dark one.
347- **Leave your own visits out of the stats.** As the admin you can now exclude your own IP address
348 from your site statistics, for a truer picture of real visitors.
349- **Right-click "Save" is turned off on covers, images and videos** — a light bit of friction so the
350 artwork isn't one click from being saved (it's friction, not protection).
351
352### Fixed
353- **Animated video covers now render correctly everywhere.** In the Circle and the grid they could
354 show up as a broken image or a blank tile; they now display as a proper looping video that fills the
355 square, centred. Right-clicking a cover gives the normal link menu instead of the browser's video controls.
356- **Following someone no longer gets stuck.** A follow whose first delivery fails (the other server
357 briefly unreachable) is now retried automatically with backoff, instead of staying on "pending" forever.
358- **Boosted posts show their real text** in the Circle, instead of a "RE: <link>" prefix.
359- **Hardened fediverse handling** — stricter signature checks on incoming activity, blocks now also
360 cover a boost of a blocked author, and pinned-post syncing no longer races when you save several times quickly.
361
362## [1.1.0] — 2026-06-30
363
364### Added
365- **Animated covers play smoothly everywhere.** Upload an animated WebP as a cover and Klonkt also
366 makes a muted, looping video of it. iOS Safari — where animated WebP is janky — gets the smooth
367 video, every other browser keeps the crisp WebP, and on the fediverse the cover federates as a
368 video that plays in Mastodon and its apps. Shown on the post, the grid, the feed and related posts.
369- **Media library (Admin → Media).** See every uploaded image, where each one is used, copy its URL,
370 and clean up unused files in one click — including the leftover video/poster of an animated cover.
371 Images, Audio and Playlists now share one tab bar.
372- **Share button** at the bottom of every post (native share sheet, or copy link).
373- **Replace a track's audio file** without re-creating the track.
374- **Music on the fediverse (first step).** Audio posts now carry schema.org *MusicRecording* /
375 *MusicAlbum* data, and a per-post toggle can share a hosted track as a real fediverse audio
376 attachment that plays in followers' feeds.
377
378### Changed
379- **Cleaner embeds on Mastodon.** A post with a YouTube/Spotify/SoundCloud link now lets Mastodon
380 show its player card; link-only tracks share their streaming links. The cover still shows in other
381 Klonkt feeds. (On your own site nothing changes — the player and cover render as before.)
382- **Circles stay in sync the fediverse way** — edits and missed posts catch up automatically via
383 standard ActivityPub, so a Circle no longer drifts out of date.
384- **Everything Klonkt federates is now valid AS2 / JSON-LD**, guarded by a test, so stricter servers
385 accept it.
386- The track list is sorted **newest-first**.
387
388### Fixed
389- **Animated WebP covers are no longer frozen to a single frame** (the crop editor and the thumbnailer
390 left them static).
391- **Link-only tracks** (Spotify/YouTube, no uploaded file) can be inserted into a post again.
392- **Link previews** (og:image / Twitter card) now use absolute image URLs, so they show on Signal,
393 WhatsApp and other scrapers.
394- Several **fediverse delivery fixes**: covers/links no longer turn into a black tile on Mastodon,
395 raw audio files don't clutter a post that already has a player, and dead links from a renamed
396 remote post heal themselves.
397- The **mobile feed** loads full-resolution covers; long titles wrap instead of overflowing.
398- **Self-hosting updates** are more reliable: re-running the installer keeps your channel, and the
399 updater no longer restarts or claims an update when you're already up to date.
400
401## [1.0.0] — 2026-06-30
402
403### Added
404- **Klonkt is now on the fediverse (ActivityPub).** Your site is a real fediverse
405 account: people on Mastodon — or another Klonkt — can follow you, and your posts
406 reach their feeds. You can follow accounts and read their posts in a **News** feed,
407 get **notifications**, and **like, boost and reply** to posts. Incoming activity is
408 verified, so fake replies, likes and followers are rejected.
409- **Anyone can reply, like or boost your posts from the fediverse** — visitors interact
410 from their own account (they just enter their server); no account on your site needed.
411- **Circles**: follow other Klonkt sites and show each other's public posts in your
412 Circle — decentralised, with no central platform.
413- **Sensitive (NSFW) posts** with your own content-warning text: blurred with
414 click-to-reveal across the site, and shown as a content warning on the fediverse.
415- **Block** an account or an entire domain you'd rather not hear from.
416- Search now also finds **tracks** (by title, artist and album), playable straight from
417 the results with a link to the post they appear in — and post search matches as you type.
418- **Live theme preview** in Admin → site settings: accent, theme and palette update
419 instantly, before you save.
420- Uploaded images are automatically optimised to **WebP** for faster pages.
421- A roomier **mobile writing experience**: tap to open a distraction-free fullscreen
422 editor, with the formatting toolbar staying in view above the keyboard.
423- **Long posts collapse in the News feed** with a *read more* toggle, so a long post no
424 longer fills the whole screen — tap to expand or collapse it.
425- **See everyone in a Circle**: when a Circle has more than five sites, the member count
426 opens a popup that lists them all, so a big Circle no longer hides its members.
427
428### Changed
429- **Palettes revised to 8**: the neutral **Klonkt** (gold accent) is the new default,
430 plus seven full-colour themes — Forest, Ocean, Teal, Lilac, Sunset, Candy and Amber.
431- **Your profile federates more completely**: the links on your profile, the date you
432 joined and the accounts you follow now travel along to other servers, so your profile
433 looks complete when someone views it from Mastodon or elsewhere.
434- **Cover images and avatars are sharper** — resized on the server instead of being
435 squeezed by the browser.
436
437### Removed
438- **Hub mode** — Klonkt is now **solo or Circles**; you build a collective or label
439 through **Circles** (federated, standalone sites).
440- **Native comments and Google login** — replies, likes and boosts now run entirely
441 through the fediverse.
442- **Local favourites (♥)** — replaced by the ⭐ fediverse like.
443
444### Fixed
445- **Hashtags and mentions now work in every language and script** (e.g. Japanese, Cyrillic,
446 Arabic), both on your site and when federating — not just the Latin alphabet.
447- **Switching a site to solo (federation off) works again.** Turning the fediverse off could
448 make the whole site return “page not found” instead of just disabling federation; it now
449 cleanly switches federation off while the rest of the site keeps working. (Self-hosters:
450 update to pick up the fix.)
451- The Fediverse and Notifications items now disappear from the menu when federation is off,
452 instead of lingering.
453- The mini-player jumps and scrolls to the track that's playing — also from an album or
454 playlist — and keeps it highlighted.
455- Empty album/playlist covers now fall back to the first track's cover.
456- A profile photo that broke in the header after the WebP switch now repairs itself.
457- Many **mobile post-editor** fixes: reliable scrolling, a formatting toolbar that stays
458 put, no page jumps when you tap a button, and a Save bar that sits just above the keyboard.
459- **Boosts now reach the original poster** — their server registers the boost and notifies
460 them, just like a boost from Mastodon — and a boost is retried if a server is briefly
461 unreachable instead of being sent once and forgotten.
462- **Unfollowing an account now takes effect on the other server** (it could previously fail
463 to register, leaving you still following on their side).
464
465## [1.0.0-beta.2] — 2026-06-19
466
467First release where we actively track the version (shown in the footer — click it for
468this page).
469
470### Added
471- Release tracking: the version number in the footer links to this changelog page.
472- Eight premium features (Patreon-gated): newsletter/mailing list, download-for-email,
473 release scheduling + fan-only previews, EPK/press kit, pro statistics, link-in-bio +
474 click stats, embeddable player, and show agenda + notify-me.
475- Newsletter signup field in the footer (on/off in Admin → Settings).
476- SMTP settings configurable in Admin → Settings (no more config-file edit needed), with
477 a test-mail button.
478
479### Changed
480- Tidier settings forms (stacked labels, full-width inputs).
481- EPK/press kit shows the top 10 most-listened tracks.
482- Nicer 404 page (mobile-friendly) and clearer login error messages.
483
484### Fixed
485- The site-wide audio player wasn't loading any tracks.
486- Button text became unreadable on hover.
487- Date pickers now follow the theme.
488- Back/forward navigation no longer shows a doubled header.
Note: See TracBrowser for help on using the repository browser.