Skip to content

3.2.6-sr94.59: Start and end date/time pickers

Choose a tag to compare

@RobinMJD RobinMJD released this 23 Sep 10:27
· 17 commits to main since this release

Start and end date/time pickers

The homepage creation form now uses optional calendar/time pickers instead of
the free-text "Expire in" field. Selected values display exactly as
yyyy-MM-dd HH:mm:ss, including seconds, with explicitly labeled UTC times.
English, French and Spanish are supported.

  • Blank start: available immediately. Blank end: no scheduled expiration.
  • Apply, Cancel, Escape and Clear preserve predictable draft behavior.
  • Validation focuses the visible field and preserves the submitted dates.
  • Pending requests lock picker changes without dropping submitted timestamps.
  • Responsive keyboard-accessible controls fit desktop and narrow mobile views.

Existing links, users and secrets are preserved. The legacy expire_in API and
existing edit-expiry flows remain compatible. There is no schema migration;
the previous .58 image already enforces the stored start/end fields.
See the lifecycle guide
and deployment/recovery guide.

Verification

  • Exact release CI,
    main CI and
    curated upstream contribution CI passed.
  • Full isolated source and hardened-image regression, authorization boundaries,
    legacy expiry, migration compatibility and writable recovery passed.
  • All 18 EN/FR/ES, light/dark, desktop/mobile creation-picker combinations passed
    locally under enforced CSP. Live picker checks passed EN/1440, FR/390 and
    ES/320, with exact UTC seconds and active/scheduled/expired public redirects.
  • The deployed public community matrix passed 18 layouts and 1,602 browser
    requests, including QR decoding, contrast and downloads, with no recorded
    JavaScript, CSP or network failures. Disposable fixtures were removed.
  • Full public API and real Authentik-signed logout/replay passed. WAF, SSO,
    CSP, TLS and public short-link behavior were not weakened.
  • Pre/post local and NAS backups were byte-verified and write-restored. Original
    records, database integrity, monitored routes and repeated health checks passed.
  • Fresh scan: zero Critical/High findings; three Medium BusyBox-package matches
    for CVE-2025-60876 have no fixed version listed. Findings are not suppressed.

Source: 7f136a23ef4b4010566863d240d20345b9aee04c.
Published image: ghcr.io/robinmjd/kutt:v3.2.6-sr94.59 at
sha256:34481aeca5f7a26074f65fabcec77b34440d0bc331e2aa8ce019e9884dd149a2.
Chromium mobile-width tests are not physical Safari/iOS acceptance. These are
bounded test and scan results, not an exhaustive security certification.