Repository navigation
Releases: DerKezorm/nexcanvas
Release list
nexcanvas 0.3.0
Mails come in the language of whoever receives them, invitations say who invites, and signing in stands up better to strangers.
Update with docker compose pull && docker compose up -d (image ghcr.io/derkezorm/nexcanvas:0.3.0). Nothing needs doing by hand; the database gets what it lacks at the start. One thing changes on its own: team leads no longer change their teams until you allow it (see below). After the update, every account sees what is new in the app itself.
Changed
- Team leads need your permission. Until now the lead of a team took people in and out, and so gave them the team's rights in every space. That now works only when the operator allows it, with the switch "Team leads change their teams" under Settings, Teams. It is off by default, also after this update; switch it on there to keep things as they were.
New
- Mails in your own language. Invitations and test mails go out in the language of whoever receives them: the one of their account, else the one of their browser at the last sign-in. Without an account yet, the language of the person who invites applies, and the date in an invitation follows the language.
- Invitations with a name and a space. The invitation page says who invites and gives the rule for the sign-in name before anyone mistypes it; an expired link says that it expired. The operator can invite new people straight into a space and choose the right that comes with it (Settings, Server, Accounts, "Invite into nexcanvas").
- Signing in stands up better to strangers. A browser you signed in with before gets in despite someone else's failed tries, also behind a proxy nexcanvas was not told about. When an account has to wait after too many wrong passwords, its API tokens keep working. An account the operator blocked learns after its right password that it is blocked, and whom it can ask. An
X-Forwarded-Forthat nexcanvas was not told to believe no longer changes who counts as the sender. - authentik says what went wrong. When a step of "authentik in one step" does not work, it says why beside it (out of reach, token not accepted, an unexpected answer) and what you can check. After a move to a new address the button finds its provider in authentik again, also when it was renamed there or a second nexcanvas uses the same authentik; the accounts keep their sign-in.
Also
- Public boards and every other page of nexcanvas stay out of search engines, and the tab names the board or page you are on.
- A link to a space, a board or a page that does not exist says so and leads to all boards; whoever is in no space yet reads on the start page whom to ask.
- Pictures of more than 50 million pixels are refused before they are decoded.
- Invisible control characters in names and titles are refused, and so is a new password that is the old one.
- A test mail without a mail server says so instead of failing.
- The account list shows every line whole, backups have worded buttons, and moments are written the same way everywhere.
- In light mode, letters in circles, status colours and chosen tabs are easier to read (at least 4.5 to 1).
- A board title or display name that is too long cannot be typed any more, and a refusal names the limit.
- An open page notices within seconds when its session was ended, and says so.
nexcanvas 0.2.2
A fix on top of 0.2.1. Update with docker compose pull && docker compose up -d (image ghcr.io/derkezorm/nexcanvas:0.2.2); nothing needs doing by hand.
Fixed
- Keeping more than 100 backups can be saved. 0.2.1 let the interface offer up to 365 backups to keep, but the setting still took only up to 100, so saving a larger number failed. Both now take 1 to 365.
nexcanvas 0.2.1
Moving to a new server now works in the interface, videos on the board can be played, and a few things say what they really do. Update with docker compose pull && docker compose up -d (image ghcr.io/derkezorm/nexcanvas:0.2.1); nothing needs doing by hand.
New
- Upload a backup. Under Settings, Server, Backup a downloaded backup goes back in, say on a new server: upload it, check it, restore it, and the new server has the old accounts, spaces, boards, photos and files. Uploading asks for the operator's password, an uploaded backup is listed as "uploaded", and the automatic clean-up of old backups leaves it alone.
- Play videos. An MP4 or MOV on a board was a card to download only. It now shows a play button that opens the video in the browser, with the download next to it, on public pages too.
Fixed
- The restore button says what it does. It was called "Restore from file", but it restores the backup it stands next to; it is now "Restore".
- Keeping backups up to 365. The interface stopped at 100 while the server accepts up to 365; both now allow 365.
- The hint for links is true. It promised a page title fetched by the operator's choice, which nexcanvas does not do; the card takes its title from the path of the address.
- No claims that do not hold. The README and
docs/api.mdno longer name nexdeck as a reader of the API, and the server no longer has a branch for a service worker and manifest that nexcanvas does not ship.
nexcanvas 0.2.0
nexcanvas for teams: people who work together get rights as a group, every member sees who is in a space, and the operator keeps every space and account in hand.
Update with docker compose pull && docker compose up -d (image ghcr.io/derkezorm/nexcanvas:0.2.0). Nothing needs doing by hand; the database gets what it lacks at the start. After the update, every account sees what is new in the app itself.
New
- Teams. The operator makes teams with a name, a colour and a lead, and the lead looks after the members (Settings, Teams). When a space gives a team a right, every member has it; a higher right of one's own stays (Settings, Spaces, "Teams"). So that colleagues can find each other, everybody on the server now sees the names and pictures of the others, also without a space in common.
- Who is in a space. Every member sees who has access, with the teams and how many people that comes to. Invitations by name are in the list and can be withdrawn, and a second invitation link to the same address replaces the first (Settings, Spaces, "Manage members").
- The operator sees every space. The operator manages every space, also one without a right of their own, and the members are told when the operator changes rights in theirs. Every deleted space is in "Spaces in the bin" for the operator to bring back.
- Blocking accounts. A blocked account no longer gets in: open sessions and boards close at once, its API tokens stop answering, and it is no longer offered for teams and invitations. Unblocking works at any time (Settings, Server, Accounts).
Also
- An invitation can also be accepted through the sign-in provider, and with password sign-in off it is no longer a dead end.
- When the session ends or a right goes, an open board closes at once and says why.
- A space in the bin takes its public pages along; only those who manage it can delete it for good.
- When a second factor is required, sign-in leads straight to the account page.
- Copy buttons work without HTTPS on a home network too.
- On the phone the spaces sit in a row, and readers no longer see undo.
- Dialogs taller than the screen scroll inside.
- Texts, plurals, colour names and keyboard shortcuts in the reader's language, and better contrast for dangerous buttons.
- The About page links the new project site, www.nexcanvas.de.
nexcanvas 0.1.0
The first release of nexcanvas: a self-hosted whiteboard in the browser, in the spirit of Apple Freeform, where several people draw, write and arrange on the same board at the same time.
Start it with the docker-compose.yml in this repository or the image ghcr.io/derkezorm/nexcanvas:0.1.0. The first account needs the setup code from docker logs nexcanvas (or the one you set as NEXCANVAS_SETUP_TOKEN). Before you open it to the internet, read "nexcanvas on the internet" in the README.
New
- Live together on one board. Changes reach everyone at once, the others' pointers move across the board with their names, and two people can type in the same note.
- Drawing tools. Notes, text, nine basic shapes, lines and arrows that dock to the edge of a shape, pen, highlighter and eraser. Rotate, group, align, lock and layers; the "+" on a shape adds the next one, Tab a child, Shift+Tab a sibling.
- About 350 shapes in nine packages, plus the Lucide icons. Basic shapes, flowchart, project management, floor plan in centimetres, network, UML and software, BPMN, house and electrics, signs and arrows, in a panel on the left with search, favourites and recent ones. A board carries every shape it uses, so it stays drawn where the package is missing.
- Your own shape packages. Per space or for the whole server, from SVG files or with "Save as shape" from the board; a package is a file that travels to another server.
- Frames, scenes and presenting. Frames hold parts of the board together; every frame is a scene to step through in full screen, on a public page as well.
- Photos, files and PDF. Photos fill empty fields for a mood board, location data is removed on upload, and a PDF pages through on the board with pen notes kept per page.
- 33 templates, and your own. In groups from flow and project to room and network; save any board as a template, or just its frame, for one space or the server.
- A background for each board. Blank, dots, squares, lines, millimetres or isometric, on several paper colours or your own; snapping follows the grid.
- Sharing and passing on. Spaces with the rights read, write and manage, invitations by name or link, public read-only pages with expiry and password. Export as PNG or PDF (board, selection, one page per scene), and JSON Canvas for nexlore, Obsidian or another nexcanvas.
- Phones. All tools in a bar at the bottom, one finger pans, two zoom, photos straight from the camera.
- For the operator. Second factor, OIDC with a button that sets up authentik, backup and restore as one archive, a log in four levels, your own languages as JSON files, and read-only API tokens for dashboards (closed by default). After an update, every account sees what is new in the app itself.