Releases: ChalidNL/todoless
Releases · ChalidNL/todoless
Release list
todoless v1.0.0
todoless v1.0.0
The stable release — todoless is out of beta. One shared place for your family's tasks, calendar and groceries, self-hosted.
Feature
- Mobile/PWA: secondary screens split out of the startup bundle; committed Playwright mobile E2E suite
- Calendar: subscribable ICS feed
GET /api/calendar.ics(#100) - Auth: complete forgot-password flow inside the app (#68)
- API: paginated entry listing without silent cap; batched users/labels lookups (#102, #28)
- PocketBase: bootstrap settings from environment on first run (#51)
Bug Fixes
- Realtime: broadcast update events and apply them locally instead of refetching (#77)
- Auth: persist device-onboarding marker for every signed-in session
- API: validate
/api/v1input and keep the task note in sync (#224, #225) - Recurrence: keep description/location and the time block; no duplicate tasks on re-complete
- Subtasks: repair server-side linking (
add_subtask, subtasks route,v1/linked_to) - Hooks: canonical task/item record hooks with the PB 0.23+ signature;
respondErrorloaded inside handlers - Logging: request logger uses
e.realIP()so proxied requests log the client (#43) - Security: block credential forging and owner spoofing via the native collection API
- UI: header title-band order, inbox sort modes, calendar chip filters; type-scale calibration; mobile overflow/phantom-scroll fixes; canonical logo + PWA icons
- i18n: route aria-labels through translations (#84); missing
common.savedkey
Other
- CI: single reusable quality gate; SHA-pinned GitHub Actions; secret scan; migration gate (duplicate-prefix + upgrade-from-previous-tag tests)
- Builds pinned to verified images; containers run as non-root
- Website live at todoless.eu with public docs and Swagger API reference
Images: ghcr.io/chalidnl/todoless:latest and :v1.0.0 (FE) / :v1.0.0 (PB).
Upgrade notes: see the README — PocketBase applies new migrations automatically on restart.
todoless v0.3.0-beta
First tagged release of todoless (v0.3.0-beta) — the releases page now has something to show (GH#5).
What changed
Publishing workflow
Build & Publish Docker Imagesnow triggers onv*tags and tags the GHCR images with the semver from the ref (leadingvstripped): push tagv0.3.0-beta→ghcr.io/chalidnl/todoless-frontend:0.3.0-beta/ghcr.io/chalidnl/todoless-pocketbase:0.3.0-beta(stablev0.3.0tags would additionally get:0.3line tags). Branch builds keeplatest/beta/pre/red/dev+ SHA tags.
Notable fixes & features in this line
- Security & auth: rate-limited requests answer 429 JSON + Retry-After (GH#42); agent/token auth consolidated into one shared lib (GH#30); tokenKey rotation (GH#37); 8-char password minimum (GH#67); raw exception text no longer leaks to clients (GH#9)
- Migrations: files made immutable & idempotent so renames never re-run (GH#34); migration numbering normalised (GH#38)
- ICS/calendar: due-date-only and all-day tasks export correctly, no empty DTEND (GH#12, GH#13); RFC 5545 robustness (octet-accurate folding, TZ-safe all-day)
- Members/agents: member delete no longer cascade-deletes family content (GH#27); agents accept owner role (GH#23); agent key expiry enforced on GET dispatch (GH#21)
- Ops: both containers run non-root with dropped capabilities (GH#45); linux/arm64 frontend image (GH#40); daily scheduled backups + docs (GH#52); request/error logs to stdout (GH#56); real /api/version (GH#33); vendored Swagger UI (GH#64); OpenAPI path parity gate (GH#65); migration upgrade + integration smoke suites (GH#34, GH#98)
- UI/i18n: English nav labels, invite copy fallback, delete-confirm copy, realtime local-state updates, calendar multi-day spans, label ownership gating (GH#70/83/86/77/82/84…)
Update
docker compose pull
docker compose up -dPocketBase applies new migrations automatically on restart. For pinning a version instead of :latest:
services:
frontend:
image: ghcr.io/chalidnl/todoless-frontend:0.3.0-beta
pocketbase:
image: ghcr.io/chalidnl/todoless-pocketbase:0.3.0-beta