dev
6cfb13310d
chore: checkpoint before date grouping on share page
2026-09-16 15:05:56 +03:00
dev
2c8beedc4b
feat: анти-спам блокировка повторной отправки на главной (cooldown по spam_interval_min)
...
- index.html/index.js: экран подтверждения отправки с обратным отсчётом
- локальный запрет повторной отправки через localStorage (по настройке spam_interval_min)
- server.js: отдаём spam_interval_min в public-settings (default 30)
- Dockerfile: timeout для apk add, чтобы сборка не зависала на недоступном зеркале
- docker-compose.yml: отключаем cloudflared сервис (закомментирован)
2026-09-13 12:27:35 +03:00
dev
0b763e5738
feat(cloudflared): timeout+fallback for WG handshake (WG_HANDSHAKE_TIMEOUT) so tunnel still starts when VPN peer is down
2026-09-13 00:34:43 +03:00
dev
1fc17225b0
fix(cloudflared): chmod 600 wg config in /tmp before wg-quick so WG starts regardless of host perms
2026-09-13 00:29:41 +03:00
dev
a7692b1c35
chore: exclude wg/ from docker build context so WG config stays host-only
2026-09-13 00:20:51 +03:00
dev
fac668567e
feat: редизайн страницы отчёта ученика — портфолио-стиль, галерея с листанием и видео
...
- renderStudentReport: детский учебный дизайн (крупные скругления, sticky-навигация, секции-карточки)
- журнал занятий в две колонки (одна на мобильных)
- единая галерея фото и видео: листание кнопками/стрелками, счётчик
- воспроизведение видео прямо в лайтбоксе
- кнопка закрытия ✕, закрытие по фону и Esc
- модалка экспорта отчёта ученика (период и выбор содержимого)
2026-09-12 23:55:35 +03:00
dev
3c40e94a57
fix: get cloudflared WireGuard tunnel actually serving
...
- Dockerfile.cloudflared: add iptables + ip6tables (wg-quick needs them for ::/0 full tunnel)
- docker-compose: privileged:true for cloudflared so wg-quick can set net.ipv4.conf.all.src_valid_mark
- start-cloudflared.sh: restore resolv.conf after wg-quick (resolvconf wiped docker DNS 127.0.0.11 => app unresolvable => Host Error)
2026-09-12 18:51:19 +03:00
dev
dd4d306a4e
feat: cloudflared container with optional WireGuard egress
...
- Dockerfile.cloudflared builds cloudflared (official static binary) on Alpine with wireguard-tools
2026-09-12 17:40:42 +03:00
dev
9203eee5d2
fix: требовать фотографию при создании записи (POST /api/entries) на уровне API
2026-09-12 17:26:51 +03:00
dev
b263a735ac
fix: обязательная фотография в форме отправки; модалка редактирования шире и в две колонки; поддержка .jfif в прикреплении
2026-09-12 17:19:53 +03:00
dev
854f2d4650
feat: публикация наружу через Cloudflare Quick Tunnel (cloudflared)
2026-09-12 15:06:56 +03:00
dev
779270fb73
UI: пагинация, вынос пагинатора, быстрые действия
2026-09-12 14:18:15 +03:00
dev
1d706f1356
Dashboard: add Блокировки link to navigation
2026-09-12 12:52:23 +03:00
dev
a8e1aa743d
Build app image on host network to bypass bridge egress/TLS issues
2026-09-12 12:22:59 +03:00
dev
1e38419f07
Dockerfile: cascade apk mirror fallback to HTTP (signature-verified) with diagnostics on total failure
2026-09-12 12:09:15 +03:00
dev
21b00a8e09
Dockerfile: fall back to edge.kernel.org mirror when dl-cdn TLS fetch fails
2026-09-12 11:30:13 +03:00
dev
db684efe9e
Dockerfile: retry apk add on transient Alpine mirror TLS failures
2026-09-12 11:04:40 +03:00
dev
fd753c1318
Add cookie notice with settings, jfif preview support, and share page title from link name
2026-09-12 10:05:02 +03:00
dev
192de5e690
Sidebar: color inactive nav icons by section meaning via data-nav attribute
2026-09-12 01:18:57 +03:00
dev
809b978c4b
Bans: confirm unban via alert; audit labels for ip.ban/ip.unban; worker page lucide icons
2026-09-12 01:14:58 +03:00
dev
c54a5b180c
Settings bans card: unban also requires confirmation
2026-09-12 01:06:24 +03:00
dev
e69426882a
Bans: unban requires inline confirmation row with yes/cancel
2026-09-12 01:01:59 +03:00
dev
5aee2ce3f5
Bans page: users-style table with badges, client-side pagination, manual ban modal (POST /api/bans with ip/reason/hours), unban row buttons
2026-09-12 00:59:32 +03:00
dev
7dd816cfce
Add dedicated Bans page (bans.html) with active IP bans table, unban and refresh; nav item for admins; settings card kept
2026-09-12 00:53:35 +03:00
dev
19b0c855a9
Cache HTML/JS/CSS with no-cache revalidation (ETag 304): browsers always get fresh pages after docker restart; vendor and image caches unchanged
2026-09-12 00:47:18 +03:00
dev
d5359dd31f
Add honeypot field to login form: instant 24h IP ban on autofill
2026-09-12 00:40:29 +03:00
dev
2c7ec17c8b
Add IP autoban system: banned_ips table, global ipGuard middleware, 24h bans on honeypot fill / 10 failed logins / 10 wrong share passwords; trust proxy for real client IPs behind funnel; admin API and settings UI to manage active bans
2026-09-12 00:35:51 +03:00
dev
2bebfc071c
Replace emoji icons with lucide icons on settings page
2026-09-12 00:04:55 +03:00
dev
fd9b470c4c
Add server-side image thumbnails (sharp): /uploads/thumb/<name> route, ?thumb=1 on file endpoints, disk-cached 480px WebP previews; grids now load thumbnails with lazy loading
2026-09-12 00:02:23 +03:00
dev
9798872f20
Add in-memory caching layer with TTL and invalidation for settings, groups, students, entries, share payloads and stats; add static asset caching headers
2026-09-11 23:52:58 +03:00
dev
f9d310c8ea
Add .dockerignore to reduce build context from 542MB to 5kB
2026-09-11 23:29:58 +03:00
dev
f8036fae79
Fix: backup/restore now includes group_photos and entry_photos tables; increase AI request timeout to 120s (configurable via AI_REQUEST_TIMEOUT_MS)
2026-09-11 23:12:16 +03:00
dev
4db02d75bc
Add AI-check details modal on worker page and raise backup upload limit
2026-09-11 16:26:30 +03:00
dev
ee19da7fa0
Add audit details modal and translate remaining action labels
...
- Make Детали cell clickable to open a modal with the full details text\n- Translate missing audit action keys (auth.login, user.*, branch.*, group.photo.*, entry.photo.*)
2026-09-11 14:45:07 +03:00
dev
7044505915
Fix AI status badge sizing on worker page
...
Restore .ai-badge as a text pill and scope the compact icon circle to .ai-badge-ic (used by journal); worker page text badges now render at correct size
2026-09-11 14:38:46 +03:00
dev
ad81adfe71
Migrate UI to Lucide icons, reorder sidebar, and polish journal/groups UX
...
- Replace emoji icons with Lucide across admin pages; add vendor/lucide.min.js and renderIcons() helper\n- Reorder sidebar logically (Dashboard, Journal, Students, Groups, Files, Links, Trash + admin sections)\n- Groups: open photo chronology only via the Фото button; covers no longer clickable\n- Journal: show group badge over card photo, compact AI-status icon beside description, and date range in empty-state message\n- Update README (AI worker, Lucide, worker.js)
2026-09-11 14:33:41 +03:00
dev
275ed46dfb
Add HF model auto-download with configurable AI env, and share link visibility toggles
2026-09-11 13:12:13 +03:00
dev
b7e798b867
Add AI auto-check worker, share link message/link fields, and update journal/settings UI
2026-09-11 10:29:49 +03:00
dev
3850fe35e4
Update project files
2026-09-10 11:26:51 +03:00
dev
7ccc9199e0
Add cover_path column to groups table for group cover photo feature
2026-09-10 01:16:32 +03:00
dev
0d6d059f5b
Add JFIF to JPG conversion for student photo uploads
2026-09-10 00:41:16 +03:00
dev
63494f322b
Add pagination to audit page
2026-09-10 00:18:56 +03:00
dev
89152295ea
Add AI text correction button to journal edit modal
2026-09-10 00:06:38 +03:00
dev
5ae476551d
Fix trash: add missing deleted_at IS NOT NULL filter to main query
2026-09-09 23:44:37 +03:00
dev
0681831aaf
Add debug logging to trash and restore endpoints
2026-09-09 23:39:30 +03:00
dev
6197f57c43
Fix trash: restore/perm delete buttons not working when clicking card content
2026-09-09 23:32:06 +03:00
dev
0f267ca6a9
Fix trash: improve error handling and add logging for restore/perm delete denials
2026-09-09 23:28:02 +03:00
dev
bc3487639d
Fix user edit modal: pass full user object instead of just ID
2026-09-09 12:25:49 +03:00
dev
018c65adc5
refactor: move frontend JS to external files and enable strict CSP
2026-09-09 10:06:49 +03:00
dev
d6e589d2f5
feat: add branches feature, security audit, and multi-branch support
2026-09-09 09:41:07 +03:00
dev
7a003e5df6
Add system info dashboard to settings
...
- New /api/system-info endpoint returning DB size, table sizes, photo/file counts, uploads stats, disk usage
- System info cards in settings page (responsive grid)
- Replaced inline onclick handlers with data attributes + event delegation in groups.html
2026-09-09 01:08:48 +03:00
dev
616dabb595
remove name autocomplete/datalist from index form
2026-09-08 12:16:38 +03:00
dev
e0cec0f943
add admin audit log (11), hide stacktraces via NODE_ENV=production (13), validate spam_interval_min>=1 (16)
2026-09-08 12:12:29 +03:00
dev
441bdfe0fe
group photo upload: respond 500 on DB error instead of hanging (async throw in express4)
2026-09-08 12:00:25 +03:00
dev
eef33e457f
support HEIC/HEIF uploads: convert to JPEG via heic-convert; graceful multer errors for group photos
2026-09-08 11:54:38 +03:00
dev
ea14fd654f
fix backup restore: stream-peek gzip content instead of zlib.gunzipFile (node20 API)
2026-09-08 11:38:38 +03:00
dev
8a50b46b7b
harden anti-spam and file serving; backup restore to disk; json body limit
...
- Add honeypot field to public submission form + server-side check
- Serve shared files only in context of a valid share link (/api/share/:shareToken/files/:fileToken)
- Switch backup restore upload to diskStorage (50MB) with temp-dir cleanup
- Limit JSON body to 1mb
- Document fixed audit items
2026-09-08 11:36:34 +03:00
dev
57f2ea4f41
add share-link password/expiry, journal touch-ups, ddns helper and audit docs
2026-09-08 10:54:24 +03:00
dev
dd5a2ea288
drop caddy and cloudflared; publish via tailscale funnel; rewrite README
2026-09-08 10:40:20 +03:00
dev
6844d659fc
harden security and add public TLS scaffold
...
- require ADMIN_PASSWORD (no default), remove CORS
- close public DB port, move DB credentials to .env (DB_PASSWORD)
- fix HTML escaping, add helmet + sec headers (no CSP due to inline scripts)
- rate limit public routes by IP (express-rate-limit)
- validate restore data and confine file unlinking to uploads/
- block dangerous upload extensions, 30MB per-entry limit, SVG not served inline
- return 400 on unknown group_id in POST /api/entries
- add commented Caddy/Let's Encrypt reverse-proxy scaffold + Caddyfile.example
- update README
2026-09-07 11:27:04 +03:00
dev
b15abc34aa
stop tracking .env and backup archives; add comprehensive .gitignore
2026-09-07 09:50:02 +03:00
dev
f3885dc0fc
write full project README
2026-09-07 09:48:39 +03:00
dev
7c58cd0d4c
Merge remote-tracking branch 'origin/main'
2026-09-07 09:46:33 +03:00
dev
f13031e9b3
add detach files feature, utf8 filename fix, and error pages
2026-09-07 09:42:28 +03:00
dev
71803d4dcf
expose uploads volume to host via bind mount
2026-09-07 09:41:23 +03:00
dev
84fed96097
add full dashboard: activity chart, recent entries, group photos, quick actions, active groups, top students
2026-09-06 15:08:39 +03:00
dev
65e5651be2
redesign settings page UX/UI: structured cards, consistent fields, sticky save bar, backup stats and loading states
2026-09-06 14:56:06 +03:00
dev
621c3c3b5c
add soft delete with trash page and group photo chronology with styling
2026-09-06 13:51:47 +03:00
dev
3c22d72a27
show attached files as type icons labeled as resident's works on share page
2026-09-06 12:37:42 +03:00
dev
d8802b508d
add Files admin section: list with filters, search, student/group/date, pagination
2026-09-06 12:25:39 +03:00
dev
9fbd88983c
open attachment images in the same-page lightbox like photos
2026-09-06 12:05:32 +03:00
dev
3d3856bf35
show project files in share page cards with image preview and file download
2026-09-06 11:50:02 +03:00
dev
a117184a2a
make project file tokens public; keep name links with image preview and file download
2026-09-06 11:35:40 +03:00
dev
ac8621c5aa
serve project files by token hash, preview images inline and download other files
2026-09-06 11:33:33 +03:00
dev
c5fdf006f5
add project file upload to student form, project_files table with backup/restore, download in journal, and crash-proof entries endpoint
2026-09-06 11:29:34 +03:00
dev
c2c5f2ed42
add photo placeholder, mirrored camera capture, configurable footer, and student .url zip export
2026-09-06 11:22:00 +03:00
dev
1d25275fd1
redesign index.html: 2-column layout (photo left, fields right), responsive
2026-09-06 00:44:35 +03:00
dev
5f4dfda799
mirror camera preview by default (scaleX(-1))
2026-09-06 00:42:59 +03:00
dev
94ea5606ff
style student filter inputs (#studentFilter, #linkStudent) to match admin design
2026-09-05 20:30:36 +03:00
dev
3b1341a0c2
add autocomplete input for student selection in journal filters, link creation, and links admin
2026-09-05 20:26:21 +03:00
dev
6dc54e49b8
batch add students: add optional group selection in batch modal
2026-09-05 18:31:28 +03:00