Files
Capsule/CHANGELOG.md

4.3 KiB
Raw Blame History

Changelog

All notable changes to Capsule are documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.

[Unreleased]

Added

  • Capsule Local 0.1.2 packages the custom Windows icon and shows the installed version in the dashboard update notice.

  • Opt-in Capsule Local automatic-update testing, with a 0.1.0 bootstrap, isolated unsigned test feed, and 0.1.1 update target. Public signing requirements remain enforced.

  • Capsule Local 0.1.1 displays “you have updated to 0.1.1” on the dashboard for manual installer upgrade testing.

  • TTP Capsule plugin publishing integration with bounded chunk uploads, JSON-compatible YAML metadata, public artifact verification, and single-range update downloads.

  • Windows x64 NSIS packaging with separate unsigned Capsule Local builds and signed public release builds. Release builds require an HTTPS feed and publisher identity; sessions remain outside the installation directory.

  • Main-process automatic update checks at startup and every four hours, background downloads, progress, manual checks, and explicit restart-to-install controls before and after sign-in. Duplicate checks are suppressed; failures remain retryable. Connected sites cannot choose an update feed or installer.

  • Release artifact checksums, metadata-last HTTPS publishing, a Windows automation entry point, updater/IPC tests, and packaging/signing/upgrade instructions in docs/releases.md.

  • Electron + electron-vite desktop shell with a login view and a connected workspace.

  • Password sign-in through POST /api/login and optional connect-with-token from Admin ? Tokens. MFA accounts continue in-app (api/login/mfa/{loginCode}) until a token is issued. loginCode stays in the main process; a pasted Admin token skips MFA. POSTs send session CSRF (X-CSRF-Token); HTTP uses Electron net.fetch so the PHP session cookie persists.

  • Session stored in userData, encrypted with safeStorage when the OS allows it. The renderer never receives the token.

  • Logged-in chrome matches TTP: navy header, Font Awesome 6.7.1 / Bootstrap 5.3, centered full-width search, notifications and messages dropdowns, avatar account menu. Profile settings (avatar, gender, newsletter, timezone, date/time, page size, dark mode) live in-app and save through POST /api/profile/update. Email, password, and phone open the connected site.

  • After sign-in, Capsule loads GET /api/profile plus notifications, the messages inbox, and GET /api/messages/recent for the header dropdown (avatars + unread count). Inbox rows can mark read/unread or hide. Compose and reply follow canSend. Search uses the matching user-token endpoint. Contact and bug reports live on footer pages (#/contact, #/bugreport) and post through POST /api/contact and POST /api/bugreport. Those footer items appear only when profile features (or GET /api/contact / GET /api/bugreport) say the plugin is available, accepting submissions, and allowed for this user. A hash to a disabled page shows the same “not accepting … right now” notice as the site. Disabled plugins show an unavailable note instead of demo data.

  • Footer chrome matches TTP copy and socials. The upper band keeps a dark-mode toggle, Privacy Policy, and Terms of Service. Contact and Report a Bug join that band only when the site is accepting them. There is no subscribe box.

Changed

  • Footer upper band is Contact Us on the left, dark mode in the middle, and More Info on the right, in three equal columns. Contact and Report a Bug stay off the menu until the connected site says those plugins are accepting submissions.
  • Footer copyright no longer lists the connected hostname. It is year plus “Powered by The Tempus Project.”
  • Profile page: space the white panel below the main nav, and cap the avatar at 200×200.

Fixed

  • Settings no longer posts a display-name field. User CP has no such option; users.name is leftover, and Check::name() rejected typical values (Invalid name. / malformed input).
  • Avatar file previews are allowed (blob: on img-src). Choosing a photo no longer shows the missing-image icon. A { "error": "not found" } from the site is reported as a missing Capsule API action (the live TTP install still needs POST /api/profile/update).