v2.2.0
v2.2.0
First-Run Onboarding
- 8-step guided walkthrough appears automatically on first login after setup
- Covers every tab in order — Instances, Scheduler, Search Behavior, Throttling, History & Stats, Advanced & Backlog Nudges
- Progress dots, Prev/Next navigation, dismisses permanently on "Got it"
- Designed to give new users the context they need before their first run
Safe Defaults
- Scheduler off by default — nothing runs until you enable it
- Max Per Run starts at 1 for both Radarr and Sonarr
- Batch Size starts at 1, Sleep at 5 seconds
- Fresh installs do nothing until the user deliberately turns things up
Security
- Passwords now stored using PBKDF2-HMAC-SHA256 with a unique random salt per password — resistant to rainbow table and dictionary attacks
- Existing SHA256 hashes auto-migrate to the new format on next successful login — no action required
- Progressive lockout on failed login attempts: 3 failures → 30s, 6 → 5min, 10 → 30min, 15+ → 1hr
- Live countdown timer on login page — button disables and counts down during lockout, re-enables automatically
- Timing-safe comparison via
hmac.compare_digestthroughout
PUID / PGID
- Container now runs as the UID and GID you specify via
PUIDandPGIDenvironment variables - Uses numeric IDs directly via
su-exec— no conflicts with Alpine built-in users - Defaults to
1000:1000if not set. Unraid users:PUID=99PGID=100
Stats
- Lifetime Movies and Shows totals now persist through Clear Stats
- Clear Stats now actually works — backend endpoint was missing entirely
- Existing confirmed entries automatically seeded into lifetime totals on first run after upgrade
UI
- Advanced tab right column reordered — History Size → Stats → Security
- Onboarding walkthrough matches tab order left to right
Docs
- Reverse proxy guidance added for anyone considering public internet exposure
- PUID/PGID platform reference table — Unraid, Linux, Synology
- Upgrade notes section documents breaking changes across versions
- Security section updated to reflect all new hardening
Upgrade Notes
- v2.2.0 changes default settings for new installs only — existing configs are not affected
- Lifetime stats totals are a one-way migration — downgrading will show zeros on the pills
- Password hashes upgrade automatically on next successful login