Skip to content

Schaffa 0.10.0

Choose a tag to compare

@beastyrabbit beastyrabbit released this 06 Sep 11:09
53916d9

Note

馃 Codex responding on behalf of beastyrabbit

Schaffa 0.10.0 makes publishing and guide recording more reliable, carries local images into presentations, and makes large publication libraries easier to manage.

Publishing and recording

  • Page updates keep allocating new version URLs after deletion or an interrupted migration.
  • Mixed file and page queues drain without starving files. Image conversion respects storage limits, and cleanup failures preserve already-published images.
  • Browser and desktop recording recover from a concurrent guide edit. Saved manifests can sync without an active recording session.
  • Presentations embed local PNG, JPEG, GIF, and WebP assets, including slide backgrounds.

Guides and administration

Guides now have configurable step, revision, and metadata budgets. Metadata accounting is transactional, and draft edits that reduce usage remain available above lowered limits. Published history stays immutable; reaching a cap requires more capacity or an administrator's full takedown.

Public guides and screenshots support conditional requests and five-minute cache revalidation. Enlarged screenshots open in an accessible new tab. Administration filters publications in SQL and displays at most 50 per page; form errors provide a recovery link.

Desktop administration and a mobile guide, captured from synthetic local fixtures:

Filtered desktop publication list

Mobile guide with keyboard focus on its screenshot

Upgrade

  • Replace TRUST_PROXY_HOPS with explicit TRUSTED_PROXIES IP addresses or narrow CIDRs for the proxy peers the application actually sees. The default trusts no forwarding headers.
  • Server and development require Node 24 or newer. The standalone CLI requires Node 22.12.0 or newer.
  • Back up the complete data volume before startup applies the SQLite migrations. Version numbers deleted before the migration cannot be reconstructed.
  • Containers now publish to ghcr.io/beastyrabbit/schaffa. Pin the immutable reference in the attached container-digest.txt.
  • Existing downloaded content cannot be recalled. Sensitive material in published guide history requires full guide takedown. The interactive sandbox does not provide complete network isolation.

The CLI release bundles its locked runtime dependencies and is audited after a clean install. Container release tags are promoted only after the candidate digest passes the vulnerability gate.

Verification

104 tests pass, including real-browser presentation, recording, keyboard, and mobile flows. Type, lint, build, secret, and dependency checks pass. Live identity-provider login and actual desktop input capture were not exercised. See PR #1 for the full resolution mapping and review evidence.