Skip to content

v0.2.5

Choose a tag to compare

@NOOBBase NOOBBase released this 18 Sep 13:35
· 65 commits to main since this release
52ad837

Post-release update (2026-09-18): the self-hosting installer/updater in this release's assets had a bug — on hosts using nodenv for Node version management, in-app updates and CSS-provider installs could fail with command not found even when a valid Node version was installed, and the core updater never removed files a later release renamed or deleted (harmless on a fresh install, but left stale files behind on an in-place update). Both are fixed as of this update; the justflows.zip/SBOM/checksum below and the v0.2.5 tag now point at the patched commit. No functional/feature changes — same v0.2.5.

Added

  • Configurable public-site PWA. Settings → PWA lets a site owner turn
    their public site into an installable, offline-friendly Progressive Web
    App: app identity and generated icons, theme/background colors, display
    mode, a validated start URL, up to four app shortcuts, an install prompt,
    a branded offline fallback, and bounded static-asset caching. Disabled by
    default; enabling requires no build step, plugin, or file edit. Disabling
    retires the service worker cleanly at its existing URL so installed apps
    recover without manual cleanup. (#127)
  • Customizable 404 and error pages. Theme customize → Error pages lets
    an admin choose, per class (404, 403, 410, 429), what renders: the theme's
    own template resolution, Justflows' built-in page, or a specific published
    page — offered once per translation group, so the matching locale renders
    automatically. The template hierarchy gains 403, 410, 429, and a
    shared error fallback slot alongside the existing 404; themes can ship
    templates/403.json / 410.json / 429.json / error.json through the
    same per-site override mechanism (draft/publish/reset) 404 already had. The
    chosen source never changes the HTTP status — a selected page still answers
    403/404/410/429, it cannot 200 a blocked or missing resource — and every
    error response is sent Cache-Control: private, no-store. 500 and a new,
    separate maintenance mode (Settings → Site visibility, distinct from
    "Site is live") always render a static, dependency-free page with an
    admin-editable heading/message and no database, cache, or plugin-runtime
    access, so they still work during a database outage; the pre-boot server.js
    layer's boot-failure response no longer leaks the underlying error message
    and now renders the same branded page. Both the static fallback and the
    built-in 404/403/410/429 pages are localized from the request (URL prefix,
    then Accept-Language) across the site's bundled languages. A real 410 now
    fires for a URL whose page was trashed (soft-deleted) rather than never
    existing, until trash retention expires it into a normal 404; the public
    site's global and search rate limiters now answer 429 with the themed page
    instead of plain JSON/text. Admin-provided heading/message text is
    sanitized before storage and HTML-escaped at render; built-in copy never
    reflects the request path, query, or headers.
    (#92)