dev
854f2d4650
feat: публикация наружу через Cloudflare Quick Tunnel (cloudflared)
2026-09-12 15:06:56 +03:00
dev
779270fb73
UI: пагинация, вынос пагинатора, быстрые действия
2026-09-12 14:18:15 +03:00
dev
1d706f1356
Dashboard: add Блокировки link to navigation
2026-09-12 12:52:23 +03:00
dev
a8e1aa743d
Build app image on host network to bypass bridge egress/TLS issues
2026-09-12 12:22:59 +03:00
dev
1e38419f07
Dockerfile: cascade apk mirror fallback to HTTP (signature-verified) with diagnostics on total failure
2026-09-12 12:09:15 +03:00
dev
21b00a8e09
Dockerfile: fall back to edge.kernel.org mirror when dl-cdn TLS fetch fails
2026-09-12 11:30:13 +03:00
dev
db684efe9e
Dockerfile: retry apk add on transient Alpine mirror TLS failures
2026-09-12 11:04:40 +03:00
dev
fd753c1318
Add cookie notice with settings, jfif preview support, and share page title from link name
2026-09-12 10:05:02 +03:00
dev
192de5e690
Sidebar: color inactive nav icons by section meaning via data-nav attribute
2026-09-12 01:18:57 +03:00
dev
809b978c4b
Bans: confirm unban via alert; audit labels for ip.ban/ip.unban; worker page lucide icons
2026-09-12 01:14:58 +03:00
dev
c54a5b180c
Settings bans card: unban also requires confirmation
2026-09-12 01:06:24 +03:00
dev
e69426882a
Bans: unban requires inline confirmation row with yes/cancel
2026-09-12 01:01:59 +03:00
dev
5aee2ce3f5
Bans page: users-style table with badges, client-side pagination, manual ban modal (POST /api/bans with ip/reason/hours), unban row buttons
2026-09-12 00:59:32 +03:00
dev
7dd816cfce
Add dedicated Bans page (bans.html) with active IP bans table, unban and refresh; nav item for admins; settings card kept
2026-09-12 00:53:35 +03:00
dev
19b0c855a9
Cache HTML/JS/CSS with no-cache revalidation (ETag 304): browsers always get fresh pages after docker restart; vendor and image caches unchanged
2026-09-12 00:47:18 +03:00
dev
d5359dd31f
Add honeypot field to login form: instant 24h IP ban on autofill
2026-09-12 00:40:29 +03:00
dev
2c7ec17c8b
Add IP autoban system: banned_ips table, global ipGuard middleware, 24h bans on honeypot fill / 10 failed logins / 10 wrong share passwords; trust proxy for real client IPs behind funnel; admin API and settings UI to manage active bans
2026-09-12 00:35:51 +03:00
dev
2bebfc071c
Replace emoji icons with lucide icons on settings page
2026-09-12 00:04:55 +03:00
dev
fd9b470c4c
Add server-side image thumbnails (sharp): /uploads/thumb/<name> route, ?thumb=1 on file endpoints, disk-cached 480px WebP previews; grids now load thumbnails with lazy loading
2026-09-12 00:02:23 +03:00
dev
9798872f20
Add in-memory caching layer with TTL and invalidation for settings, groups, students, entries, share payloads and stats; add static asset caching headers
2026-09-11 23:52:58 +03:00
dev
f9d310c8ea
Add .dockerignore to reduce build context from 542MB to 5kB
2026-09-11 23:29:58 +03:00
dev
f8036fae79
Fix: backup/restore now includes group_photos and entry_photos tables; increase AI request timeout to 120s (configurable via AI_REQUEST_TIMEOUT_MS)
2026-09-11 23:12:16 +03:00
dev
4db02d75bc
Add AI-check details modal on worker page and raise backup upload limit
2026-09-11 16:26:30 +03:00
dev
ee19da7fa0
Add audit details modal and translate remaining action labels
...
- Make Детали cell clickable to open a modal with the full details text\n- Translate missing audit action keys (auth.login, user.*, branch.*, group.photo.*, entry.photo.*)
2026-09-11 14:45:07 +03:00
dev
7044505915
Fix AI status badge sizing on worker page
...
Restore .ai-badge as a text pill and scope the compact icon circle to .ai-badge-ic (used by journal); worker page text badges now render at correct size
2026-09-11 14:38:46 +03:00
dev
ad81adfe71
Migrate UI to Lucide icons, reorder sidebar, and polish journal/groups UX
...
- Replace emoji icons with Lucide across admin pages; add vendor/lucide.min.js and renderIcons() helper\n- Reorder sidebar logically (Dashboard, Journal, Students, Groups, Files, Links, Trash + admin sections)\n- Groups: open photo chronology only via the Фото button; covers no longer clickable\n- Journal: show group badge over card photo, compact AI-status icon beside description, and date range in empty-state message\n- Update README (AI worker, Lucide, worker.js)
2026-09-11 14:33:41 +03:00
dev
275ed46dfb
Add HF model auto-download with configurable AI env, and share link visibility toggles
2026-09-11 13:12:13 +03:00
dev
b7e798b867
Add AI auto-check worker, share link message/link fields, and update journal/settings UI
2026-09-11 10:29:49 +03:00
dev
3850fe35e4
Update project files
2026-09-10 11:26:51 +03:00
dev
7ccc9199e0
Add cover_path column to groups table for group cover photo feature
2026-09-10 01:16:32 +03:00
dev
0d6d059f5b
Add JFIF to JPG conversion for student photo uploads
2026-09-10 00:41:16 +03:00
dev
63494f322b
Add pagination to audit page
2026-09-10 00:18:56 +03:00
dev
89152295ea
Add AI text correction button to journal edit modal
2026-09-10 00:06:38 +03:00
dev
5ae476551d
Fix trash: add missing deleted_at IS NOT NULL filter to main query
2026-09-09 23:44:37 +03:00
dev
0681831aaf
Add debug logging to trash and restore endpoints
2026-09-09 23:39:30 +03:00
dev
6197f57c43
Fix trash: restore/perm delete buttons not working when clicking card content
2026-09-09 23:32:06 +03:00
dev
0f267ca6a9
Fix trash: improve error handling and add logging for restore/perm delete denials
2026-09-09 23:28:02 +03:00
dev
bc3487639d
Fix user edit modal: pass full user object instead of just ID
2026-09-09 12:25:49 +03:00
dev
018c65adc5
refactor: move frontend JS to external files and enable strict CSP
2026-09-09 10:06:49 +03:00
dev
d6e589d2f5
feat: add branches feature, security audit, and multi-branch support
2026-09-09 09:41:07 +03:00
dev
7a003e5df6
Add system info dashboard to settings
...
- New /api/system-info endpoint returning DB size, table sizes, photo/file counts, uploads stats, disk usage
- System info cards in settings page (responsive grid)
- Replaced inline onclick handlers with data attributes + event delegation in groups.html
2026-09-09 01:08:48 +03:00
dev
616dabb595
remove name autocomplete/datalist from index form
2026-09-08 12:16:38 +03:00
dev
e0cec0f943
add admin audit log (11), hide stacktraces via NODE_ENV=production (13), validate spam_interval_min>=1 (16)
2026-09-08 12:12:29 +03:00
dev
441bdfe0fe
group photo upload: respond 500 on DB error instead of hanging (async throw in express4)
2026-09-08 12:00:25 +03:00
dev
eef33e457f
support HEIC/HEIF uploads: convert to JPEG via heic-convert; graceful multer errors for group photos
2026-09-08 11:54:38 +03:00
dev
ea14fd654f
fix backup restore: stream-peek gzip content instead of zlib.gunzipFile (node20 API)
2026-09-08 11:38:38 +03:00
dev
8a50b46b7b
harden anti-spam and file serving; backup restore to disk; json body limit
...
- Add honeypot field to public submission form + server-side check
- Serve shared files only in context of a valid share link (/api/share/:shareToken/files/:fileToken)
- Switch backup restore upload to diskStorage (50MB) with temp-dir cleanup
- Limit JSON body to 1mb
- Document fixed audit items
2026-09-08 11:36:34 +03:00
dev
57f2ea4f41
add share-link password/expiry, journal touch-ups, ddns helper and audit docs
2026-09-08 10:54:24 +03:00
dev
dd5a2ea288
drop caddy and cloudflared; publish via tailscale funnel; rewrite README
2026-09-08 10:40:20 +03:00
dev
6844d659fc
harden security and add public TLS scaffold
...
- require ADMIN_PASSWORD (no default), remove CORS
- close public DB port, move DB credentials to .env (DB_PASSWORD)
- fix HTML escaping, add helmet + sec headers (no CSP due to inline scripts)
- rate limit public routes by IP (express-rate-limit)
- validate restore data and confine file unlinking to uploads/
- block dangerous upload extensions, 30MB per-entry limit, SVG not served inline
- return 400 on unknown group_id in POST /api/entries
- add commented Caddy/Let's Encrypt reverse-proxy scaffold + Caddyfile.example
- update README
2026-09-07 11:27:04 +03:00