116 Commits
Author SHA1 Message Date
dev db684efe9e Dockerfile: retry apk add on transient Alpine mirror TLS failures 2026-09-12 11:04:40 +03:00
dev fd753c1318 Add cookie notice with settings, jfif preview support, and share page title from link name 2026-09-12 10:05:02 +03:00
dev 192de5e690 Sidebar: color inactive nav icons by section meaning via data-nav attribute 2026-09-12 01:18:57 +03:00
dev 809b978c4b Bans: confirm unban via alert; audit labels for ip.ban/ip.unban; worker page lucide icons 2026-09-12 01:14:58 +03:00
dev c54a5b180c Settings bans card: unban also requires confirmation 2026-09-12 01:06:24 +03:00
dev e69426882a Bans: unban requires inline confirmation row with yes/cancel 2026-09-12 01:01:59 +03:00
dev 5aee2ce3f5 Bans page: users-style table with badges, client-side pagination, manual ban modal (POST /api/bans with ip/reason/hours), unban row buttons 2026-09-12 00:59:32 +03:00
dev 7dd816cfce Add dedicated Bans page (bans.html) with active IP bans table, unban and refresh; nav item for admins; settings card kept 2026-09-12 00:53:35 +03:00
dev 19b0c855a9 Cache HTML/JS/CSS with no-cache revalidation (ETag 304): browsers always get fresh pages after docker restart; vendor and image caches unchanged 2026-09-12 00:47:18 +03:00
dev d5359dd31f Add honeypot field to login form: instant 24h IP ban on autofill 2026-09-12 00:40:29 +03:00
dev 2c7ec17c8b Add IP autoban system: banned_ips table, global ipGuard middleware, 24h bans on honeypot fill / 10 failed logins / 10 wrong share passwords; trust proxy for real client IPs behind funnel; admin API and settings UI to manage active bans 2026-09-12 00:35:51 +03:00
dev 2bebfc071c Replace emoji icons with lucide icons on settings page 2026-09-12 00:04:55 +03:00
dev fd9b470c4c Add server-side image thumbnails (sharp): /uploads/thumb/<name> route, ?thumb=1 on file endpoints, disk-cached 480px WebP previews; grids now load thumbnails with lazy loading 2026-09-12 00:02:23 +03:00
dev 9798872f20 Add in-memory caching layer with TTL and invalidation for settings, groups, students, entries, share payloads and stats; add static asset caching headers 2026-09-11 23:52:58 +03:00
dev f9d310c8ea Add .dockerignore to reduce build context from 542MB to 5kB 2026-09-11 23:29:58 +03:00
dev f8036fae79 Fix: backup/restore now includes group_photos and entry_photos tables; increase AI request timeout to 120s (configurable via AI_REQUEST_TIMEOUT_MS) 2026-09-11 23:12:16 +03:00
dev 4db02d75bc Add AI-check details modal on worker page and raise backup upload limit 2026-09-11 16:26:30 +03:00
dev ee19da7fa0 Add audit details modal and translate remaining action labels
- Make Детали cell clickable to open a modal with the full details text\n- Translate missing audit action keys (auth.login, user.*, branch.*, group.photo.*, entry.photo.*)
2026-09-11 14:45:07 +03:00
dev 7044505915 Fix AI status badge sizing on worker page
Restore .ai-badge as a text pill and scope the compact icon circle to .ai-badge-ic (used by journal); worker page text badges now render at correct size
2026-09-11 14:38:46 +03:00
dev ad81adfe71 Migrate UI to Lucide icons, reorder sidebar, and polish journal/groups UX
- Replace emoji icons with Lucide across admin pages; add vendor/lucide.min.js and renderIcons() helper\n- Reorder sidebar logically (Dashboard, Journal, Students, Groups, Files, Links, Trash + admin sections)\n- Groups: open photo chronology only via the Фото button; covers no longer clickable\n- Journal: show group badge over card photo, compact AI-status icon beside description, and date range in empty-state message\n- Update README (AI worker, Lucide, worker.js)
2026-09-11 14:33:41 +03:00
dev 275ed46dfb Add HF model auto-download with configurable AI env, and share link visibility toggles 2026-09-11 13:12:13 +03:00
dev b7e798b867 Add AI auto-check worker, share link message/link fields, and update journal/settings UI 2026-09-11 10:29:49 +03:00
dev 3850fe35e4 Update project files 2026-09-10 11:26:51 +03:00
dev 7ccc9199e0 Add cover_path column to groups table for group cover photo feature 2026-09-10 01:16:32 +03:00
dev 0d6d059f5b Add JFIF to JPG conversion for student photo uploads 2026-09-10 00:41:16 +03:00
dev 63494f322b Add pagination to audit page 2026-09-10 00:18:56 +03:00
dev 89152295ea Add AI text correction button to journal edit modal 2026-09-10 00:06:38 +03:00
dev 5ae476551d Fix trash: add missing deleted_at IS NOT NULL filter to main query 2026-09-09 23:44:37 +03:00
dev 0681831aaf Add debug logging to trash and restore endpoints 2026-09-09 23:39:30 +03:00
dev 6197f57c43 Fix trash: restore/perm delete buttons not working when clicking card content 2026-09-09 23:32:06 +03:00
dev 0f267ca6a9 Fix trash: improve error handling and add logging for restore/perm delete denials 2026-09-09 23:28:02 +03:00
dev bc3487639d Fix user edit modal: pass full user object instead of just ID 2026-09-09 12:25:49 +03:00
dev 018c65adc5 refactor: move frontend JS to external files and enable strict CSP 2026-09-09 10:06:49 +03:00
dev d6e589d2f5 feat: add branches feature, security audit, and multi-branch support 2026-09-09 09:41:07 +03:00
dev 7a003e5df6 Add system info dashboard to settings
- New /api/system-info endpoint returning DB size, table sizes, photo/file counts, uploads stats, disk usage
- System info cards in settings page (responsive grid)
- Replaced inline onclick handlers with data attributes + event delegation in groups.html
2026-09-09 01:08:48 +03:00
dev 616dabb595 remove name autocomplete/datalist from index form 2026-09-08 12:16:38 +03:00
dev e0cec0f943 add admin audit log (11), hide stacktraces via NODE_ENV=production (13), validate spam_interval_min>=1 (16) 2026-09-08 12:12:29 +03:00
dev 441bdfe0fe group photo upload: respond 500 on DB error instead of hanging (async throw in express4) 2026-09-08 12:00:25 +03:00
dev eef33e457f support HEIC/HEIF uploads: convert to JPEG via heic-convert; graceful multer errors for group photos 2026-09-08 11:54:38 +03:00
dev ea14fd654f fix backup restore: stream-peek gzip content instead of zlib.gunzipFile (node20 API) 2026-09-08 11:38:38 +03:00
dev 8a50b46b7b harden anti-spam and file serving; backup restore to disk; json body limit
- Add honeypot field to public submission form + server-side check
- Serve shared files only in context of a valid share link (/api/share/:shareToken/files/:fileToken)
- Switch backup restore upload to diskStorage (50MB) with temp-dir cleanup
- Limit JSON body to 1mb
- Document fixed audit items
2026-09-08 11:36:34 +03:00
dev 57f2ea4f41 add share-link password/expiry, journal touch-ups, ddns helper and audit docs 2026-09-08 10:54:24 +03:00
dev dd5a2ea288 drop caddy and cloudflared; publish via tailscale funnel; rewrite README 2026-09-08 10:40:20 +03:00
dev 6844d659fc harden security and add public TLS scaffold
- require ADMIN_PASSWORD (no default), remove CORS
- close public DB port, move DB credentials to .env (DB_PASSWORD)
- fix HTML escaping, add helmet + sec headers (no CSP due to inline scripts)
- rate limit public routes by IP (express-rate-limit)
- validate restore data and confine file unlinking to uploads/
- block dangerous upload extensions, 30MB per-entry limit, SVG not served inline
- return 400 on unknown group_id in POST /api/entries
- add commented Caddy/Let's Encrypt reverse-proxy scaffold + Caddyfile.example
- update README
2026-09-07 11:27:04 +03:00
dev b15abc34aa stop tracking .env and backup archives; add comprehensive .gitignore 2026-09-07 09:50:02 +03:00
dev f3885dc0fc write full project README 2026-09-07 09:48:39 +03:00
dev 7c58cd0d4c Merge remote-tracking branch 'origin/main' 2026-09-07 09:46:33 +03:00
dev f13031e9b3 add detach files feature, utf8 filename fix, and error pages 2026-09-07 09:42:28 +03:00
admin 3b0761530e Initial commit 2026-09-07 06:41:48 +00:00
dev 71803d4dcf expose uploads volume to host via bind mount 2026-09-07 09:41:23 +03:00