Repository navigation
3.2.6-sr94.59: Start and end date/time pickers
Start and end date/time pickers
The homepage creation form now uses optional calendar/time pickers instead of
the free-text "Expire in" field. Selected values display exactly as
yyyy-MM-dd HH:mm:ss, including seconds, with explicitly labeled UTC times.
English, French and Spanish are supported.
- Blank start: available immediately. Blank end: no scheduled expiration.
- Apply, Cancel, Escape and Clear preserve predictable draft behavior.
- Validation focuses the visible field and preserves the submitted dates.
- Pending requests lock picker changes without dropping submitted timestamps.
- Responsive keyboard-accessible controls fit desktop and narrow mobile views.
Existing links, users and secrets are preserved. The legacy expire_in API and
existing edit-expiry flows remain compatible. There is no schema migration;
the previous .58 image already enforces the stored start/end fields.
See the lifecycle guide
and deployment/recovery guide.
Verification
- Exact release CI,
main CI and
curated upstream contribution CI passed. - Full isolated source and hardened-image regression, authorization boundaries,
legacy expiry, migration compatibility and writable recovery passed. - All 18 EN/FR/ES, light/dark, desktop/mobile creation-picker combinations passed
locally under enforced CSP. Live picker checks passed EN/1440, FR/390 and
ES/320, with exact UTC seconds and active/scheduled/expired public redirects. - The deployed public community matrix passed 18 layouts and 1,602 browser
requests, including QR decoding, contrast and downloads, with no recorded
JavaScript, CSP or network failures. Disposable fixtures were removed. - Full public API and real Authentik-signed logout/replay passed. WAF, SSO,
CSP, TLS and public short-link behavior were not weakened. - Pre/post local and NAS backups were byte-verified and write-restored. Original
records, database integrity, monitored routes and repeated health checks passed. - Fresh scan: zero Critical/High findings; three Medium BusyBox-package matches
for CVE-2025-60876 have no fixed version listed. Findings are not suppressed.
Source: 7f136a23ef4b4010566863d240d20345b9aee04c.
Published image: ghcr.io/robinmjd/kutt:v3.2.6-sr94.59 at
sha256:34481aeca5f7a26074f65fabcec77b34440d0bc331e2aa8ce019e9884dd149a2.
Chromium mobile-width tests are not physical Safari/iOS acceptance. These are
bounded test and scan results, not an exhaustive security certification.