Skip to content

v2.0.0-beta

Latest

Choose a tag to compare

@bthavanish bthavanish released this 19 Mar 07:24
· 1 commit to main since this release
e6bb212

What's new in 2.0.0-rc1

New features

User server creation — Users can now create their own servers directly from the panel when the admin enables it in settings. A dedicated /create-server page guides them through image, node, and resource selection. Previously only admins could create servers.

Server folder system — Users can organize their servers into folders from the dashboard. Folders are per-user and support drag-and-drop reordering.

Credits page — A /credits page accessible from the account page lists the project leads, fetches contributors live from the GitHub API (cached in localStorage for 6 hours), and links to the website, Discord, and docs. Includes a scrolling -_- easter egg background — a nod to the Discord community tradition.

Dedicated security admin module — Security settings (rate limiting, IP banning, login lockout, reverse proxy, daemon HTTPS, API key hashing) are now a fully wired backend module with their own routes, previously scattered or missing entirely.

Egg catalogue service — A new eggCatalogueService handler fetches and caches game image definitions from the Airlink egg repository on startup, with an automatic 2-day refresh cycle.

Daemon request interceptor — A new daemonRequest utility centralises all panel → daemon HTTP calls. It respects the enforceDaemonHttps setting and applies HMAC signing to every outbound request. Previously each module made raw axios calls independently.

Image store — A store page for browsing and importing images directly from the catalogue, available on both desktop and mobile.

Settings restructure

The old settings page had two tabs: Appearance and Configuration. The new layout has three focused tabs:

Old New
Configuration → General (upload limit, VirusTotal key, allow registration) Appearance → Registration toggle
Configuration → General (upload limit) Servers → File uploads
Configuration → General (VirusTotal key) Security → VirusTotal
(did not exist) Servers → Default limits (RAM, CPU, disk, server count per user)
(did not exist) Servers → User permissions (allow create/delete)
(did not exist) Security → Login protection (lockout attempts, lockout duration)
(did not exist) Security → Network (reverse proxy, daemon HTTPS, hash API keys)

New settings fields added to the database schema:

  • allowUserCreateServer / allowUserDeleteServer
  • defaultServerLimit / defaultMaxMemory / defaultMaxCpu / defaultMaxStorage
  • loginMaxAttempts / loginLockoutMinutes
  • enforceDaemonHttps / behindReverseProxy / hashApiKeys
  • loginWallpaper / registerWallpaper

Analytics rebuilt

The old analytics page had three separate endpoints (/performance, /usage, and a player stats endpoint) that returned partially broken or empty data. The new page consolidates everything into a single /api/admin/analytics/summary endpoint that:

  • Pulls servers, users, nodes, images, and login history in one Prisma query
  • Checks daemon health live for each node (online/offline, version, server count)
  • Returns node capacity vs. allocation for RAM, CPU, and disk
  • Provides 30-day login activity for charting
  • Surfaces top servers by allocated RAM

The UI has three tabs — Servers, Nodes, Activity — matching the style of the admin overview page. The refresh button shows a spinner and fires a toast on completion.

UI improvements

Frosted glass navigation — The desktop sidebar, desktop topbar, mobile topbar, and mobile bottom nav now use backdrop-filter: blur with 8% opacity backgrounds instead of solid fills. Auth pages (login, register) use the same treatment on the form panel.

Loading overlay — The page loader uses a frosted glass background (backdrop-filter: blur(28px) saturate(180%)) instead of a solid white/dark fill. The text, progress bar, and logo adapt to light and dark mode without a background block.

Mobile auth wallpaper — The configured login and register wallpapers now display on mobile. Previously the wallpaper was hidden with display: none below 768px. On mobile the wallpaper fills the screen and the form sits on top as a frosted glass panel.

Card shadows — Admin panel cards have shadow-sm in light mode so they protrude from the background instead of reading flat.

Admin link hidden from non-admin users on mobile — The per-server navigation tab strip on mobile previously showed the Admin edit link to all users. It now applies the same isAdminItem filter that the desktop already had.

Delete server on mobile — The delete button in the per-server settings page on mobile was gated on user.isAdmin only. It now also shows when settings.allowUserDeleteServer is enabled, matching the desktop behaviour.

npm start runs migrations — The start script now runs prisma db push before launching the app so a fresh database is initialised automatically without manual migration steps.