v1.12.1 — Lock out deactivated users, backend tests & CI
Fixed
- Deactivated users were not locked out: they could still log in and keep using existing sessions. Login now refuses deactivated accounts ("This account has been deactivated") and their tokens stop working immediately.
Added
- Backend test suite (
backend/tests/, pytest against a real PostgreSQL — starts a throwaway server automatically): auth and users, projects/categories, tasks, comments, settings, export/import, backup endpoints, migrations, and the backup/restore scripts including rollback. - GitHub Actions CI: backend tests on Python 3.10 and 3.12 with PostgreSQL 16, frontend tests and production build, shellcheck — on every push to
main/devand on pull requests. PM_ENV_FILEforscripts/backup-db.sh/restore-db.shto read connection settings from a file other thanbackend/.env.
Changed
- The two long-standing ESLint warnings in the frontend build are resolved.
Upgrade
- Recommended for everyone with more than one user (security fix).
- Existing install: Settings → Updates → Update now on
main(a database backup is taken first; no schema changes).
Full history: CHANGELOG.md