Skip to content

Releases: DerKezorm/nexlore

nexlore 1.5.1

Choose a tag to compare

@DerKezorm DerKezorm released this 06 Oct 17:00

Every account now has a mail address of its own, and the mail server has a place of its own in the settings (#13).

New

  • Your mail address: enter it under My account, Profile and press Confirm. nexlore mails you a link, and the address counts once you open it; until then an address confirmed before stays in force. Invitations and notifications by mail go to it.
  • Set by the operator: under Settings, Server, Accounts the operator gives an account an address. It counts at once, and the account sees it under New since your last visit. The list shows every account's address and where it came from.
  • With a sign-in service: an account that signs in only through authentik or another OpenID Connect provider follows the provider's address at every sign-in. A linked account with a password keeps its own address and is offered the provider's when it differs.
  • The mail server as a part of its own: Settings, Server, Mail server (it used to sit under Accounts as Invitation mail). It says what it carries, invitations, notifications and the confirmation links, and tells you when nexlore's public address is still missing.

Changed

  • An address that was entered but never confirmed never links a sign-in through the provider to an account, and no two accounts hold the same address.
  • Without a mail server the address field says why it is locked, and Notifications shows where that is changed.
  • Unlinking an account from the provider removes only an address that came from the provider; one you confirmed yourself stays.

nexlore 1.5.0

Choose a tag to compare

@DerKezorm DerKezorm released this 06 Oct 10:33

nexlore 1.5 reads PDFs itself and puts notes on paper: a PDF opens in nexlore instead of downloading, and any note, or a whole folder, becomes a neatly set PDF.

New

  • Read PDFs in nexlore. A click on a PDF opens it in a reader of its own: the pages with their text to select, copy and find, pictures of the pages and the PDF's own contents on the left, zoom, and a link to the page you are on, such as [[Manual.pdf#page=3]]. On the right you see which notes link the PDF and to which pages, and Note on this PDF makes a note that opens beside it.
  • PDFs in a note. ![[Manual.pdf#page=3]] shows a small reader inside the note, when reading and when editing, as tall as you like with #height=400. [[Manual.pdf#page=3]] opens that page. A PDF also opens beside a note: you read on the right and write on the left, and a page link in the note turns the PDF there.
  • Print and save as PDF. The ⋯ menu of a note has Print … and Save as PDF …, and the folder menu in the sidebar makes one PDF of a whole folder, with a cover and contents with page numbers. A window shows the pages as they come on paper and every choice at once: paper, properties, embedded notes, web addresses as footnotes, header and footer, font. Links between notes in the same PDF can be clicked. Paper is always light.
  • PDFs through the API. GET /api/v1/note/pdf and GET /api/v1/folder/pdf give a note or a folder as PDF, with the token's rights.

Changed

  • Safety. PDFs are drawn by pdf.js in a sandboxed frame without an origin of its own and without any network; the page hands it the file. PDFs made by nexlore are set by Typst on the server, in a process of its own with a time limit, from a folder holding only the note and the pictures the reader may see; every word of a note reaches Typst as text, never as code.
  • Words across the family. Languages are listed by their names, and the program's version is called "Version" in German.
  • The guide explains reading, embedding, printing and saving PDFs.

nexlore 1.4.0

Choose a tag to compare

@DerKezorm DerKezorm released this 05 Oct 22:26

nexlore 1.4 brings Ask Lore: questions about your notes, answered from them with their sources. Writing in Markdown has a view of its own, and the map has a new look that moves.

New

  • Ask Lore. The spider at the bottom right of every page opens a chat window: ask about your notes, such as "When was the last restore test?". Lore looks in the spaces you may read, answers from them as she writes and puts a small number after every statement; a click shows the source, another opens the note at that spot. What your notes do not say, Lore says plainly. On a note the window talks about that note and can leave a change on it as a proposal, which you compare and take over or leave; Lore never changes a note herself. An answer can become a note of its own, and when the model can use tools, Lore keeps looking herself. The page Ask Lore in the header keeps all your conversations, and nobody but you sees them.
  • One AI service for everybody. Under Settings, Server, AI, API and plugins the operator allows Ask Lore (off by default) and chooses whether every account brings its own AI service or one service serves all, such as Ollama at home. With one for all and a model for meaning, Lore also finds notes that say your question in other words, and the tab Links beside a note shows the notes most like it. Everything that goes to the service is listed under "What went out".
  • The Markdown view. While editing, the switch Visual | Markdown in the toolbar shows the text with all its signs. It stands on the page like the visual editor, without a frame, and keeps the whole toolbar: bold, lists, headings and links write the signs for you, and undo takes them back. Under Settings, General, Editor you choose which view your notes open in.
  • Glow on the map can be switched off under Settings, Look, for older computers.

Changed

  • The map, new. Move over a note: it and its neighbours stay bright, the rest steps back, its links light up. The more links a note has, the bigger its dot. Linked notes draw together inside their folder, folders lie as a faint circle behind their notes, small folders open from further away, and the wheel glides. Drag a note with the mouse and its neighbours swim along; it stays where you let go until you reload the page.
  • Lines no longer disappear when you zoom into a space with many links.
  • The guide explains Ask Lore, the Markdown view and the new map.

nexlore 1.3.0

Choose a tag to compare

@DerKezorm DerKezorm released this 05 Oct 07:47

nexlore 1.3 is about backups. A downloaded backup goes back in, so you move to a new server in the interface, and the backups card is tidied up.

New

  • Upload a backup, move to a new server. Under Settings, Server, Backups, "Upload a backup" brings a downloaded backup back in. Download one on the old server, set up nexlore on the new one, upload the ZIP there, check it and restore it: after the restart you sign in with your old account, and every space, note, attachment and account is there. Uploading asks for the operator's password like downloading, an uploaded backup is listed as "uploaded", and the automatic clean-up of old backups leaves it alone.

Changed

  • The backups card, tidied up. The schedule, how many backups stay, uploading and "Back up now" share one row; every backup has small buttons to check, download, restore and delete it, and a window of its own asks for the password. Up to 365 backups can be kept now, in the interface and in the settings. A note for a new backup is gone; the notes of older backups still show in the list.
  • The guide explains in its chapter on backups and moving in how to move a whole server.

nexlore 1.2.0

Choose a tag to compare

@DerKezorm DerKezorm released this 04 Oct 20:47

nexlore 1.2 is about the map. Choose which spaces it shows, and a space you fill one note at a time now grows on the map as it fills.

New

  • Only the spaces you want on the map. The list of spaces at the top right of the map (on a phone behind the button at the top right) has a box for each space: untick it and the map leaves the space out. Only this one, next to a name, shows that space alone; Show all brings every space back. The choice is kept with your account, so it is the same on every device, and each space keeps its colour. Pick a note of a space left out in the sidebar or a search, and its space comes back onto the map.

Changed

  • A space filled bit by bit keeps its shape. A space that was nearly empty when the map first laid it out, and then got its notes one at a time (by hand or by an AI helper through MCP), stayed a tiny bubble: its folders piled up at the edge and its notes lay in a spiral in the middle until the night put them in order. Now the map lays such a space out anew as soon as a new folder or note finds no room in it, and after many notes added one by one.
  • A second nexlore at the same authentik. The authentik button looked for its provider and application by fixed names. A second nexlore set up with it on the same authentik took over the first one's provider and broke its sign-in. Now it takes names of its own, nexlore (address), when another nexlore holds the plain ones. Moving nexlore to a new address and pressing the button again still updates its own provider.

Fixed

  • On a phone with many spaces, the sheet with clouds and spaces grew taller than the screen and its top could not be reached. It scrolls in itself now.
  • The preview of a comment closed whenever the page scrolled, also when the sidebar moved by itself. It closes only when its words scroll away.

nexlore 1.1.0

Choose a tag to compare

@DerKezorm DerKezorm released this 03 Oct 13:17

nexlore 1.1 brings the canvas: a surface without edges for notes, thoughts, pictures and links, joined by arrows. A canvas is a .canvas file beside your notes in the open format JSON Canvas, so Obsidian and other programs that know the format open it unchanged.

New

  • Canvases. Right-click a folder or a space in the sidebar, then New canvas. The guide has a new chapter 14 with an example canvas to try things on.
  • Notes as cards. Drag a note in from the sidebar or pick one with Note at the bottom. A card shows the note or one of its sections; a double click opens it beside the canvas in the editor you know, and what you write there shows on the card right after. Renaming or moving the note, or renaming its space, follows into the canvas.
  • Writing right on the card. Double-click an empty spot for a text card and write in it with the same editor as in notes. The bar over chosen words and the slash menu keep their size however far you zoom.
  • Arrows find their way. Draw an arrow from a point on the edge of one card to another. It runs around the cards in its way at right angles and turns halfway between two cards; its label stays readable however far you zoom out. The file keeps only the two sides, so other programs draw the same arrow their own way.
  • Cards from other spaces, with rights. A card may come from any space you may read; its space stands in the head of the card, and Show in the sidebar takes you to it. Whoever may not read that space sees the card locked with "No access to this space" and never gets anything of what it holds.
  • Arranging. Cards snap to the edges and middles of other cards with guides (not with Alt held; the magnet at the top right turns it off). Groups take along what lies in them. Pictures, files and links are cards too. A card being dragged is see-through, so you see what lies under it.
  • The sidebar's width is dragged at its right edge (arrow keys there, a double click goes back), kept in each browser, and every row shows its whole name under the pointer.

Changed

  • Before deleting, the dialogs on the note page and in the sidebar name the canvases the note, file or folder lies on (only canvases you may read). The card stays and shows it again as soon as it comes back from the trash. The note page's dialog now also warns about public pages, as the sidebar's did.
  • Backlinks of a note name the canvases it lies on, and a canvas has versions like a note.
  • Favourites show canvases and views with their name and their own symbol.
  • Import a ZIP as a space (Files). The import took any ZIP all along but spoke only of Obsidian vaults. A space downloaded as a ZIP from one nexlore (right-click it in the sidebar, Download as ZIP) comes in on another as a new space, every file byte for byte. Versions, comments, members, public pages and the space's settings are not in the ZIP. The guide's chapter 12 has a section on moving a space.

Fixed

  • AI in notes said "The server cannot reach the service" with a valid key since 1.0.0. Some services pack longer answers (the list of models, for one), and nexlore unpacked them twice. It reads them once now.
  • A space at the start of a line (written by the editor as  ) showed as a tag "#x20" when reading.

nexlore 1.0.0

Choose a tag to compare

@DerKezorm DerKezorm released this 02 Oct 17:30

nexlore 1.0. Before this version it went through a large security review with one question in mind: what happens when you open nexlore to the internet? This release is what came out of it. The README now has a section "nexlore on the internet" with a checklist.

New

  • The first start asks for a setup code. Whoever reached a fresh nexlore first used to become its operator. The setup page now asks for a code that nexlore writes to its log when it starts (docker logs nexlore), or the one you set as NEXLORE_SETUP_TOKEN. Servers already set up notice nothing.
  • AI services in your own network, by name. Members may use any public AI service. A service in your own network (Ollama at home, for example) works once the operator lists its host under Settings, Server, AI, API and plugins, "Services in your own network". Every other private address is refused, loopback and link-local always, and redirects are not followed. If your members already use a service at home, add it there after updating.
  • NEXLORE_OPERATOR_NETWORKS. Optional: the operator's settings can only be changed from these networks (for example 192.168.0.0/16). Empty by default, as before.
  • Pictures and files in the sidebar. Pictures, PDFs and other attachments stand in the tree beside the notes, and folders count them. A click opens the file; the right click renames (the ending stays), moves, copies an embedding link or trashes it.

Changed

  • Guessing passwords cannot lock you out. After ten wrong passwords an account still waits a quarter of an hour, but a browser that signed in before gets in anyway. The brake counts per sender and name, so one guesser behind your proxy no longer slows everybody else.
  • Backups ask for your password before one is deleted or restored. Backups, the database, the secret key and the log are readable only by nexlore's own user (0600/0700).
  • Programs and keys. A new password or "Sign out everywhere" also ends every program that signed in over OAuth; a refresh token used twice ends its program; programs sign in again after 90 days, or 30 days unused. An approval runs once however often it is clicked, and a program never has the operator's powers.
  • Notifications and invitations hold under abuse. At most 60 notifications an hour per account, webhooks do not read answers or follow redirects, invitation mails need the public address and are limited per hour.
  • The container refuses PUID or PGID 0, keeps its code owned by root, and logs no request addresses (invitation and share links stay out of the log). docker-compose.yml shows a hardened setup as comments.
  • Workflows pin every action to a commit and run with read rights only. latest is not moved by pre-release tags.

Fixed

  • Notes written to slow nexlore down (thousands of open brackets, deep quotes, YAML aliases, endless headings; web pages with an endless title tag when a link's title is fetched) are read quickly now, on the server and in the browser, and the reading view never goes blank.
  • Display names cannot pass for another account any more.
  • The language picked in the account menu holds the first time. On a slow server it switched back and only held on the second try.
  • Odd input (broken percent signs in addresses, invalid dates, lone surrogates, oversized notes) gets a clear error instead of a server error.

nexlore 0.4.1

Choose a tag to compare

@DerKezorm DerKezorm released this 02 Oct 10:24

New

  • Links jump to the heading. A click on a link like [[Note#Heading]] opens the note right at that heading instead of at the top, while reading, from the editor and on the title of an embedded part. Upper or lower case does not matter. [[#Heading]] without a note's name jumps within the same note.

Fixed

  • [[#Heading]] is a real link. It showed pale as a note that does not exist, and cleaning up listed it among the links to nothing.
  • The log detail goes up for an hour again. “Detailed (1 hour)” and “Everything (1 hour)” were refused by the server, and the choice quietly fell back to normal.
  • Question callouts are yellow in the editor (question, help, faq), as when reading; they were violet.
  • Texts and docs: a few texts still sent people to “My account, AI” (now Connections); docs/api.md and the MCP tool search_notes named search operators that do not exist and missed space:, changed: and OR; docs/mcp.md said a space cannot be renamed.

nexlore 0.4.0

Choose a tag to compare

@DerKezorm DerKezorm released this 02 Oct 05:47

New

  • API tokens for programs. Connect nexlore with n8n, nexdeck or a script of your own under My account, Connections. Each token reads, or also writes, sees all your spaces or only some, and runs out after 30 days, 90 days, a year or never. It is shown once, with the header line for n8n and a command to try it. The API reads spaces, folders, notes, links, search with operators, recent notes, tasks and the numbers for a dashboard, and makes notes (also from a template), changes them, appends, writes the daily note and the inbox and ticks tasks off. It never deletes, moves or shares. See docs/api.md.
  • The operator holds the latch. API tokens are off by default. The operator switches them on under Settings, Server, AI, API and plugins, sees every token with its account, level and last use, never the token itself, and can block one for good.
  • A week before a token runs out it stands out in the list, and nexlore tells you (My account, Notifications, can be switched off).

Changed

  • Every change by a program says so. What an API token writes becomes a version with the source "Program (API)". Changes an AI makes over MCP now say "AI (MCP)" for every tool; setting a property, quick capture, a note from a template, merging and linking a mention said "saved" before.
  • The part of the server settings is now called "AI, API and plugins".

nexlore 0.3.0

Choose a tag to compare

@DerKezorm DerKezorm released this 02 Oct 03:20

New

  • Notifications. Give a webhook address, a notification inbox for example, and switch on mail if the operator set up a mail server. Then choose per account what you hear about: somebody names you with @ or answers in your thread, an invitation or an approval for an AI program waits, and once a day at a time of your choosing, what is due today or overdue. "Send a test" shows at once whether it arrives. A notification names the note and who did something, never what a note or a comment says.
  • Server troubles reach the operator. Operators hear when a scheduled backup failed, when a newer version of nexlore is out and when the disk where nexlore keeps its data runs full. Each of these comes once, not every minute.

Fixed

  • Approvals show when a request runs out as a date and time; before, a time later today read as "today".
  • No id twice on a page: the code symbol in the editor's toolbar and slash menu no longer repeats an SVG id.