Releases: beastyrabbit/moddrop
Release list
v0.6.4 — Settings and media reliability
Note
🤖 GPT-6 responding on behalf of beastyrabbit
Moddrop 0.6.4 simplifies room settings and media controls while preserving their behavior. Username and upload-filename normalization also handles long punctuation runs in linear time.
Room validation, byte-range parsing, collaborator search, settings and audio rendering now separate their decisions into smaller functions. Regression coverage checks allowed-user validation and validation errors, OBS URL controls, YouTube consent, keyboard selection and audio playback. Component props and shape metadata that never change are now readonly.
No migration or configuration change is required. The frontend and stream-canvas images deploy together through the existing Flux image automation. The generated Convex exclusion remains unchanged.
Validation: lint, formatting, all typechecks, 95 frontend tests, 48 backend tests with disposable PostgreSQL, both builds, compiled runtime configuration, Convex codegen and eight browser flows pass. Independent candidate and release reviews by Claude Opus 5.5 at high effort, plus the configured Codex code/security reviews, found no issues. A fresh desktop/mobile settings check also passed on the exact release SHA.
The post-merge main SonarQube scan reports 36 open findings, down from 107. Code changes resolved 75 previously open findings, including all five critical complexity findings, and one previously accepted finding. Four newly detected findings remain open. One separately documented false-positive classification was made; five previously accepted risks remain. Complexity findings are maintainability issues, not security vulnerabilities.
Desktop and mobile settings on the reviewed release candidate, using synthetic test data:
View the mobile settings screenshot
Changes: #10
v0.6.3
Note
🤖 Claude Opus 5.5 responding on behalf of beastyrabbit
Moddrop 0.6.3 makes backend handovers safer. When a canvas backend gives up leadership, it now always frees the room for the next one, even if a shutdown step fails.
Reliable leadership handover
The canvas backend holds a PostgreSQL advisory lock while it owns live rooms. Before this release, a shutdown handler that failed synchronously skipped the step that releases that lock and its database connection. A successor could then not admit sessions until the connection died. Every handler failure is now collected and reported together. The lock and connection are released in all cases.
A regression test covers this path against a disposable PostgreSQL database. It fails on 0.6.2.
Hardened frontend image
The frontend container's entrypoint is now owned by root. The unprivileged runtime user can execute it but can no longer modify it.
Code analysis and delivery
SonarQube now analyses main and non-draft pull requests from this repository, replacing the previous OpenGrep workflow. Convex's generated code is excluded from analysis. The backend guide now describes the current delivery path: the release tag publishes both images, Flux image automation rolls them out to the Homelab, and a bad release is fixed forward with a new tag.
Upgrade and verification
No schema migration or configuration change is required. Both 0.6.3 images roll out together; the backend keeps its stop, flush and start handover.
Verification covered lint, formatting, types, 86 frontend tests, 40 backend tests with disposable PostgreSQL and WebSocket scenarios, seven browser flows, both builds, the compiled runtime configuration check, and a container smoke test. SonarQube's quality gate passes with no blocker issues or vulnerabilities on main. An independent release review and the repository's Codex code and security reviews found no issues.
One existing lifecycle test assertion about disposal timing fails intermittently on 0.6.2 as well. This release doesn't change it.
v0.6.2
Note
🤖 GPT-6 responding on behalf of beastyrabbit
Moddrop 0.6.2 keeps live canvas access, OBS policy and media recovery consistent while a stream is running.
Reliable collaboration and OBS
Removing a collaborator or regenerating OBS credentials closes existing sessions. Saved Twitch and YouTube settings reach connected editors and mirrors immediately. YouTube policy now also covers normal pasted links, encoded URLs and older standard embed shapes.
Canvas disposal waits for the latest snapshot, and writes use the database connection that owns leadership. Concurrent first-room creation and interrupted connection attempts recover without stranding rooms.
Media that recovers
Audio, image and video URLs renew when needed. Temporary access-URL failures recover without moving a shape or reloading OBS; playback position survives renewal. Failed YouTube and Twitch script loads can retry. Preview controls remain usable when browser storage is blocked or full, and collaborator selection supports keyboard navigation.
Desktop and mobile captures from the reviewed local fixture show a collaborator selected by keyboard and the retry control after a simulated Twitch outage.
Safer operation and delivery
WebSocket errors are contained throughout connection lifetime. Pending room loads count toward capacity, and S3 deadlines cancel the underlying requests and response streams. Invalid upload capabilities are rejected before database or storage work.
Releases use the existing Homelab ARC runner to verify the application before deploying Convex and publishing both GHCR images. Local development binds PostgreSQL to loopback and leaves the default Compose database alone when an alternate database is configured.
Upgrade and verification
No PostgreSQL schema migration is required. Deploy both 0.6.2 images together using their verified digests. The backend retains its stop/flush/start handover; allow at least 30 seconds for termination. DATABASE_POOL_SIZE must be at least 2.
Local verification passes 86 frontend tests, 40 backend tests with disposable PostgreSQL/WebSocket scenarios, and seven browser flows, plus lint, formatting, types, builds and compiled runtime configuration checks. Independent correctness and scope reviews passed. Browser fixtures use local identities and player substitutes.
Two moderate advisories remain in unused Minio transitive paths without a compatible upstream fix. The backend README records the triage. An existing tldraw font-loading rejection can occur during browser teardown. Snapshot writes coalesce for 100 ms; abrupt leadership loss can discard edits that have not persisted.
Changes: #6
v0.6.1
What’s New
Runtime and dependencies
- Upgraded Next.js, Clerk, Hono, Lucide, pnpm, PostCSS, and browser compatibility data to their latest releases.
- Adopted TypeScript 7 for project type-checking while retaining the official TypeScript 6 compatibility API required by Next.js builds.
- Updated transitive build and image-processing dependencies to their latest patched releases; the dependency audit now reports no known vulnerabilities.
Release infrastructure
- Upgraded Forgejo Actions, Infisical CLI, Dockerfile frontend, and container pnpm tooling.
- Fixed redundant pnpm dependency verification and improved frontend/backend image build reliability.
Maintenance
- Enabled Renovate dependency management for ongoing automated update tracking.
- Added accessible titles to the canvas audio and YouTube icons.
v0.5.0
What is New
App workspace
- Redesigned rooms and settings with the Moddrop visual identity.
- Added clearer loading, error, empty, and retry states.
- Improved collaborator search and safer OBS secret regeneration.
Interactive landing canvas
- Added draggable and keyboard-movable stream overlays.
- Added visual-only on-stream animations, live-layer counting, and layout reset.
- Unified logo and header components across the public and authenticated surfaces.
Local development
- Standardized HTTPS Portless URLs and local CORS configuration.
- Added Node runtime and native dependency build configuration.
v0.3.0 - Stream Canvas Security Hardening
Highlights
- Hardened stream-canvas WebSocket access with short-lived signed room tickets instead of raw Clerk session tokens in query strings.
- Added hashed-at-rest OBS secrets with one-time regeneration reveal, legacy backfill, stricter token exchange, and no-referrer OBS headers.
- Locked down uploads with request size caps, magic-byte MIME sniffing, sanitized filenames, signed media access URLs, and refresh-aware canvas media loading.
- Added server-side validation and rate limits for room settings, OBS access, upload flows, WebSocket auth, and repeated auth failures.
- Reduced user/profile data exposure in Convex user queries and added bounded username resolution/search behavior.
Fixes
- Split owner/settings room response data from collaborator/public room data.
- Added DB-level filtering for accessible room lookup and consolidated upload access checks.
- Improved WebM audio/video detection by inspecting EBML track metadata.
- Kept auth-failure limiter state across successful requests and cleaned expired limiter entries from read checks.
- Fixed the OBS missing-secret fallback so it remains readable despite the transparent OBS overlay layout.
Notes
- Existing rooms with legacy plaintext OBS secrets are migrated to hashed secrets at startup. Users who need to copy a secret again should regenerate the OBS URL from settings.
- External media URLs remain allowed; this release focuses on token, upload, room, and referrer hardening.
Verification
pnpm --dir backend/stream-canvas run typecheckpnpm --dir backend/stream-canvas run testpnpm run lintpnpm run typecheckpnpm run testpnpm run build
v0.2.1
What's New
Landing Page
- Updated the platform strip so Works with highlights Twitch only.
- Added a Coming soon logo row for YouTube Live, Kick, TikTok Live, and Rumble.
- Removed outbound platform links and removed Discord from the landing page platform presentation.
Assets
- Added local brand SVG assets for Kick, TikTok, and Rumble.
- Attached a fresh landing page screenshot for the release.
v0.2.0
What's New
Landing Page
- Rebuilt the Moddrop landing page around the new brand direction with a tighter hero, product mockup, feature grid, setup flow, creator CTA, and platform brand row.
- Added the new Moddrop logo and icon asset pack, including favicon, lockups, monochrome variants, app icon, and partner brand marks.
- Swapped the mockup's blue highlight direction into Moddrop's green accent system.
- Tightened the mobile header so the logo and primary CTA stay clean on small screens.
v0.1.1
Fixes
- fix the stream-canvas production image so better-sqlite3 builds correctly in the container
- keep workspace lifecycle scripts disabled during image install while rebuilding the native SQLite binding explicitly
Impact
- restores the production /canvas-api backend so control room requests and room access stop returning 503
v0.1.0
What's New
Auth and Production Readiness
- Switched Moddrop to the new Clerk setup across frontend, Convex, and stream-canvas.
- Updated production secret wiring so the live app, Convex, and canvas backend all point at the same Clerk issuer.
- Improved token handling for stream-canvas requests to better recover from Clerk token refreshes.
Control Room and Sign-In
- Fixed the top-right login flow and removed blocked interactions caused by decorative overlays.
- Improved the Clerk sign-in modal styling for Moddrop's dark theme so the auth flow is readable and consistent with the app.
- Kept the landing and control room experience focused by removing extra CTA clutter under the title.
Dev and Deployment Workflow
pnpm devnow starts frontend, Convex, and stream-canvas together from the repo root.- Fixed the missing tracked landing footer component that was breaking frontend image builds in CI.
- Cleaned up the canvas dev hostname path so local auth no longer collides with other projects using stream-canvas.
Important
This release is intended to be deployed together with the updated kub-homelab Moddrop secrets and image tags so production uses the new Clerk configuration end to end.


