Repository navigation
v1.4.0-dev05
Pre-release
Pre-release
Fifth dev pre-release of the 1.4.0 minor
Russian, Android sync rebuilt so accounts, offline edits and deletes stay right, SSO fixes, the weekly summary email, and security updates.
Added
- Russian. NutriTrace can be used in Russian: pick it in Settings → Regional & Units. Translated almost in full by Михаил Малов on Weblate; only the new account-switch prompts are still in English. Thank you!
Changed
- Trace's attach button offers Camera or Gallery on phones and in the Android app (#254), like the other Trace apps. On a computer it opens the file picker. Thanks @librarian.
Fixed
- The weekly summary email is sent. It failed every time, so no one received it. With Weekly Summary on, it now arrives with the notification, and its weight change counts weights logged in the diary.
- SSO with an email that already has an account no longer creates a second account. When the provider doesn't mark the email verified (Authentik's default since 2025.10), sign-in is refused with a pointer to link the provider from your profile.
- SSO works with Authelia 4.39 and later out of the box. Email, username and groups are read from userinfo when the ID token leaves them out.
- The SSO callback works without the provider number, and at
/api/oidc/callback, the address older docs gave. Both ended on a blank page. OIDC_ENABLE_EMAIL_PASSWORD_LOGINworks for providers added in Settings.- Signing in on a plain-HTTP address explains what's wrong instead of looping, links to the fix (
INSECURE_COOKIES=1), and says so in the server log. - The app no longer loads behind the sign-in screen. It waits to learn who is signed in.
- The installed app keeps working when NutriTrace is served from a subpath (#250). Thanks @kgenerozov.
- Recipe servings set in the Android app survive syncing (#255). Thanks @librarian.
- Editing a food or recipe in the Android app no longer clears its photo (#256). Thanks @librarian.
- The diagnostics note about GitHub issues translates as a whole sentence (#253), and the German translation is complete. Thanks @KAiSER086.
- Trace works with OpenAI-compatible endpoints that stream unless told not to (#258, reported by @jsapede). Chat and Smart Log failed with "Unexpected non-whitespace character after JSON".
- Trace's tools work with OpenAI-compatible endpoints that check every field (#259, reported by @jsapede).
- Opening a recipe or food from CookTrace, Mealie, Open Food Facts or USDA no longer shows the one you opened before (#260). Unsaved typing still comes back when you reopen the same item. Thanks @herver1971.
- The Diary's Mark Day Complete bar sits below the date bar instead of running into it, at every screen size, in the browser and the Android app.
- Syncing the Android app no longer wipes the day's note or a food's CookTrace origin. The newer note wins, a cleared note included. Older servers and older apps keep working.
- Foods and meals edited offline in the Android app reach the server after the app restarts.
- Editing or deleting a food or meal in the Android app before it syncs no longer changes a different one. Diary items logged from it link to it once it syncs.
- Clear all data reaches the Android app, wellness, workouts and fasts included, and clears fasts on the server too.
- A phone whose clock is off no longer decides which edit wins. The newer edit wins by the server's clock, and a phone whose edit lost gets the winning copy.
- Marking a day or meal complete in the Android app while offline sticks, and an older change no longer undoes a newer one made elsewhere.
- A setting changed in the Android app before it reached the server is no longer set back when the app loads your settings. It goes up with the next sync.
- Connecting the Android app to a server with Upload or Merge also sends recipes, activities, fasts and Health Connect data, without duplicates, even when the upload runs again. Anything that doesn't go up goes with the next sync.
Security
- Sync can no longer change another account's data. Any account could overwrite or delete another account's foods, meals, activities or fasts through sync by naming their ids.
- Diary items no longer show another account's food details. Only your own foods, foods shared with you, and ingredients of meals shared with you fill an item in.
- The image proxy passes images only, and images can't act as a page. It passed through whatever came back from the app's own address, before sign-in.
- A password reset link can no longer be pointed at someone else's site. Reset, invite and sharing emails link to
PUBLIC_URLwhen set, or to an address an admin uses, and keep theBASE_URLsubpath. - Names in emails can no longer carry markup. Everything an email shows is escaped.
- The CookTrace and Mealie connections forward only the requests the app makes. Any account could send any request through them, including to other services on your network.
- A photo given as a link is only kept when it is an image. Downloads never reach cloud-metadata addresses and check every redirect; only an admin can download from your network, other accounts only with
ALLOW_PRIVATE_IMAGE_URLS=1. - Push notifications never reach cloud-metadata addresses and follow redirects only on the same server. The open
/api/proxychecks every redirect too. - The Android app's SSO sign-in no longer passes the session token through the
nutritrace://link. It carries a single-use code only the app that started the sign-in can redeem. - Uploaded files get unguessable names.
- Signing in to another account on the same phone no longer shows or sends the previous account's data, its settings and unsaved drafts included. If that account left changes that never synced, the app asks before discarding them. The same user id on another server counts as another account.
- The server answers as the account whose token a request carries, never as the one a leftover sign-in cookie names. After an account switch on Android, Health Connect data could go to the previous account. The app also forgets NutriTrace's sign-in cookie on every switch, connect, disconnect and sign-out, and keeps other sites' cookies, such as a sign-in gate in front of your server.
- Capacitor bumped 8.3.4 to 8.5.3 in the Android app, closes GHSA-rvm3-566m-v7fv (critical: remote content could be loaded as part of the app through Capacitor's internal HTTP proxy path).
- proxy-addr bumped 2.0.7 to 2.0.8 on the server, closes GHSA-jqcg-44mw-7w3h (critical: an IPv4-mapped IPv6 address could pass as a trusted proxy). NutriTrace trusts no proxy addresses, so it wasn't exposed.
- @modelcontextprotocol/sdk bumped 1.30.0 to 1.32.1, closes GHSA-6qxp-vccf-f47h (high: its OAuth client could send credentials to a server an MCP server picked). NutriTrace only uses its MCP server side.
- brace-expansion and source-map-js bumped, closing GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p and GHSA-68fv-2mgg-jv7q (high: denial of service). Both are only used to build the app.
npm auditreports 0 vulnerabilities for the app and the server.
NutriTrace is free and always will be. Support on Ko-fi goes toward a Mac and an iPhone so my apps can come to Apple devices, and GitHub Sponsors helps with the monthly costs.