Repository navigation
3.2.6-sr94.58: community features and English/French/Spanish localization
Community Features And Translations
This release completes the approved 21-item community implementation:
- English (default), French and Spanish with 1,519 messages per validated catalog, request-local translation, safe interpolation and an extensible language registry.
- System/light/dark appearance, stable table sorting, Safari analytics and hostname/proxy/custom-domain routing corrections.
- Verified database/Redis TLS, asymmetric OIDC support, transactional moderation and safe dotted aliases.
- Staged/enforced CSP with fresh nonces and proxy-safe rendered HTML, including HTMX fragments, without expanding script permissions.
- Branded QR PNG/SVG exports with bounded PNG validation, sanitized ephemeral logos and independently decoded output.
- Optional signed OIDC administrator mapping, protected recovery and transactional checks against stale authority.
- Optional separate management origin and explicit shared-domain grants, creator-isolated analytics and permanent scoped-token revocation.
- Optional destination-host policy with consistent enforcement and authorized unchanged-target metadata repair.
- Private authenticated metrics, accessible local country analytics and profile-led SQLite visit indexing.
Native analytics filters show long selected values fully at compact widths. CSV/JSON export controls now use the existing theme-button style and current-color icons. The regression reproduces the old dark contrast failure and checks normal, hover and focus contrast plus actual keyboard downloads in all three languages, both themes and three widths. French/Spanish copy clarifies geography percentages and uses consistent management wording.
These are independently adapted implementations, not blind merges of older proposals. The community guide credits upstream proposals and records each feature's boundaries and tests.
Compatibility And Recovery
Existing links, users and secrets are preserved. Public redirects remain public; management remains authenticated and WAF-protected. Optional role mapping, destination restrictions and management-host splitting are disabled by default. No domain is automatically shared or exposed.
Back up the database and original signing/encryption secrets together and verify a writable restore with the candidate image. Prefer fix-forward after authorization features are used: older images may ignore new state. Never downgrade populated authorization history or revive revoked credentials.
Candidates .50, .53 and .55 were rejected by live acceptance and rolled back; .51, .52 and .54 were superseded before deployment. Their immutable tags and evidence remain. .56 and .57 provide preceding functional evidence, not separate accepted releases. This release includes WAF-compatible QR transport, proxy HTML transformation protection, fresh mapped-administrator write authority, readable analytics filters, reviewed copy and accessible exports. No WAF/SSO/CSP exception was added.
Verification
- Immutable release CI 35740453869, main CI 35740453470, and curated contribution CI 35741346684 passed, including real databases, Redis restart, OIDC, TLS and translated/themed browser suites.
- Exact hardened-image full regression and fresh image scan passed: zero Critical/High findings. Three Medium BusyBox-package findings remain, with no fixed version listed in the scan database.
- The deployed
.58public enforced-CSP matrix passed all 18 layouts, 108 export-contrast states, 36 verified keyboard downloads and independent QR decoding. Compact French/Spanish screenshots were reviewed. No network, JavaScript or CSP failures were recorded; the synthetic fixture was removed. - Original records, integrity and foreign keys remain unchanged. Two post-change samples 65 seconds apart passed with three required probes and zero restarts, scoped alerts, failed units or unhealthy containers; lab configuration validation passed.
- Fresh pre/post backups were copied off-host to the NAS. Both 75-file byte checks and exact-image writable restores passed. This is Kutt recovery evidence, not USB SSD or whole-lab restore certification.
- Source commit:
9360e913bbc2e9ace4f39688569dc5dab7a799e1. Published image:ghcr.io/robinmjd/kutt@sha256:5a3c2efa558b2d915e41210060612971ead7463d65428869102e7656974d356b.
The final .58 public matrix covers 18 translated/theme/width layouts with QR decoding, destination-policy views, geography, measured export contrast and actual CSV/JSON downloads. Full public shared-domain matrices belong to .56; .57 supplies the three-layout follow-up and full public API/real Authentik-signed logout/replay. The only subsequent runtime change is export HTML/CSS; those earlier results are not relabeled as .58 reruns.
SQLite receives the full regression suite; PostgreSQL 17 and MySQL 8.4 receive focused real-engine checks. MariaDB remains configuration-only. Chromium desktop/mobile-width testing is not physical Safari/Firefox/device certification. Physical printing, operator-specific IdP claims/custom templates and SMTP delivery remain separate deployment-specific checks. Scans and passing tests are bounded evidence, not certification that the software is vulnerability-free.