Repository navigation
v0.3.0
v0.3.0 - 2026-09
Description
Security, research output, and identity. The backend now meets the OWASP ASVS 5.0 baseline:
multi-factor authentication, audit logging, upload scanning, token revocation, and rate limits. A
dataset release pipeline tracks contributor consent and publishes under CC BY 4.0. Every surface
moved onto the Cyanotype design system under the name "Relab". Deployment is reproducible: restic
backups, systemd timers, Cloudflare configuration as code, and telemetry over OTLP.
Breaking Changes
- Registration requires a username; public profiles moved to
/users, account screens to/account - Recovery codes replace the email-based MFA reset
- Product dismantling time fields removed
- Newsletter signup and
/organizationsremoved - Stored videos must be HTTP URLs; media lookups are scoped by parent id and type
frontend-apprenamed toapp,frontend-webtowww
Features
Security and Hardening
- TOTP multi-factor authentication with recovery codes and step-up re-authentication
- Audit events for authentication, authorization denials, rate limits, and sensitive actions
- Token revocation on user deletion and sensitive account updates
- Argon2id passwords, a common-password blocklist, and registration that does not reveal existing emails
__Host-prefixed auth cookies, explicit JWT algorithm and audience checks, auth tokens in URL fragments- Upload allowlists, MIME and filename agreement, a quota ledger, and optional ClamAV scanning
- Rate limits on expensive and write routes; request body size enforced while streaming
- Row-level locks on destructive lookups; objects owned by others answer as not found
- Database and Redis TLS, least-privilege Postgres roles, trusted proxy CIDR validation
- Content Security Policy and HSTS on the API and the static sites
- Admin user erasure that anonymizes or deletes the user's content
- Browser JavaScript policy that blocks remote scripts, CDN assets, and analytics tags
Dataset and Research Outputs
- Dataset release build with Zenodo deposit tooling, consent scoping, and a report of exclusions
- Terms of use, release-credit consent, and recorded terms acceptance
- CC BY 4.0 dataset licence; API specification under Apache-2.0
- Contributor roles with upload quotas per role
- Data-model diagrams and dataset codebook generated into the docs site
Backend API
- Stats endpoints for totals, categories, and time series
- Accent-insensitive full-text and trigram search; fuzzy product-type label matching
- Idempotency keys on product and component creation
- Image derivatives with pixel dimensions and uploader metadata
- Email change verification and password-change notifications
- Indexes on foreign keys and search paths; autovacuum tuning for high-churn tables
Raspberry Pi Camera
- WebSocket relay bounded against unresponsive devices and disconnects mid-command
- Pairing records restored when a claim fails; device assertions expire and are checked for ownership
- Device key stays on the LAN; relay allowlist rejections answer 403
- Livestream and recording lifecycle fixed; healthy cameras no longer flap to offline
- Circuit breaker state kept in Redis with atomic failure recording
Brand and Design System
- Cyanotype design system: Prussian blue and manila with the IBM Plex superfamily
- Titillium-derived wordmark, flask marks, and a theme-adaptive favicon
- Design tokens generated from one source and synced across subrepos
- Shared brand assets with a sync-and-verify script
Frontend App
- Migrated off react-native-paper to Uniwind with vendored primitives
- Lucide icons; feature logic moved into
features/modules - Desktop top navigation, phone bottom navigation, and a responsive page scaffold
- Product detail rebuilt as a spec sheet with an expandable bill of materials
- Capture-first creation flow, offline resilience for field work, and infinite catalogue scroll
- MFA management, session revocation, and OAuth link and unlink with re-authentication
- Motion pass across galleries and overlays; focus traps and Escape to dismiss
- WCAG 2.2 tags enforced, accessibility statement published, accessibility lint on every PR
Frontend Web
- Landing page rebuilt around the 9R ladder, a teardown blueprint hero, and the method section
- Statistics panel fed by the public stats API with a monthly activity chart
- Build-time data layer with a fixture fallback so builds work without the API
- Static security headers aligned with the browser baseline
Documentation
- Public API reference hosted with Scalar and styled from the brand tokens
- Attack-surface baseline, review guidelines, and expanded privacy and session documentation
- Architecture diagrams in the brand palette
Deployment and Operations
- restic backups: hourly snapshots, maintenance, offsite copy, and a restore path
- Scheduled jobs on systemd timers; a watchdog for API health and backup freshness
- Cloudflare edge and zone configuration in OpenTofu with encrypted state and provider-mocked tests
- Host configuration in a single root
.env; secrets export and restore for password managers - Compose network and secret policy checks; Caddy and backup containers run as non-root
- Container logs, host metrics, and API metrics shipped over OTLP
Developer Experience and CI/CD
- One CI workflow with a single required check and a shared runtime setup action
- Each check has one home: git hooks fix staged files,
justrecipes verify, CI runs those recipes - Pull requests run only the checks that gate them; image scans and coverage run after merge
- Markdown linting on rumdl; the browser JavaScript policy is a tested script instead of semgrep
- Every tool version pinned once, in the file its own tooling reads
- OpenAPI and generated API types checked for freshness in CI
Testing
- Backend suite split by execution cost with parallel integration runs
- Accessibility scans on www, docs, and the app web build; cross-browser E2E matrix
- Full-stack E2E against a seeded Docker backend; k6 performance baseline