v0.2.5
Post-release update (2026-09-18): the self-hosting installer/updater in this release's assets had a bug — on hosts using nodenv for Node version management, in-app updates and CSS-provider installs could fail with
command not foundeven when a valid Node version was installed, and the core updater never removed files a later release renamed or deleted (harmless on a fresh install, but left stale files behind on an in-place update). Both are fixed as of this update; thejustflows.zip/SBOM/checksum below and thev0.2.5tag now point at the patched commit. No functional/feature changes — same v0.2.5.
Added
- Configurable public-site PWA. Settings → PWA lets a site owner turn
their public site into an installable, offline-friendly Progressive Web
App: app identity and generated icons, theme/background colors, display
mode, a validated start URL, up to four app shortcuts, an install prompt,
a branded offline fallback, and bounded static-asset caching. Disabled by
default; enabling requires no build step, plugin, or file edit. Disabling
retires the service worker cleanly at its existing URL so installed apps
recover without manual cleanup. (#127) - Customizable 404 and error pages. Theme customize → Error pages lets
an admin choose, per class (404, 403, 410, 429), what renders: the theme's
own template resolution, Justflows' built-in page, or a specific published
page — offered once per translation group, so the matching locale renders
automatically. The template hierarchy gains403,410,429, and a
sharederrorfallback slot alongside the existing404; themes can ship
templates/403.json/410.json/429.json/error.jsonthrough the
same per-site override mechanism (draft/publish/reset) 404 already had. The
chosen source never changes the HTTP status — a selected page still answers
403/404/410/429, it cannot 200 a blocked or missing resource — and every
error response is sentCache-Control: private, no-store. 500 and a new,
separate maintenance mode (Settings → Site visibility, distinct from
"Site is live") always render a static, dependency-free page with an
admin-editable heading/message and no database, cache, or plugin-runtime
access, so they still work during a database outage; the pre-bootserver.js
layer's boot-failure response no longer leaks the underlying error message
and now renders the same branded page. Both the static fallback and the
built-in 404/403/410/429 pages are localized from the request (URL prefix,
thenAccept-Language) across the site's bundled languages. A real 410 now
fires for a URL whose page was trashed (soft-deleted) rather than never
existing, until trash retention expires it into a normal 404; the public
site's global and search rate limiters now answer 429 with the themed page
instead of plain JSON/text. Admin-provided heading/message text is
sanitized before storage and HTML-escaped at render; built-in copy never
reflects the request path, query, or headers.
(#92)