Schaffa 0.10.0
Note
馃 Codex responding on behalf of beastyrabbit
Schaffa 0.10.0 makes publishing and guide recording more reliable, carries local images into presentations, and makes large publication libraries easier to manage.
Publishing and recording
- Page updates keep allocating new version URLs after deletion or an interrupted migration.
- Mixed file and page queues drain without starving files. Image conversion respects storage limits, and cleanup failures preserve already-published images.
- Browser and desktop recording recover from a concurrent guide edit. Saved manifests can sync without an active recording session.
- Presentations embed local PNG, JPEG, GIF, and WebP assets, including slide backgrounds.
Guides and administration
Guides now have configurable step, revision, and metadata budgets. Metadata accounting is transactional, and draft edits that reduce usage remain available above lowered limits. Published history stays immutable; reaching a cap requires more capacity or an administrator's full takedown.
Public guides and screenshots support conditional requests and five-minute cache revalidation. Enlarged screenshots open in an accessible new tab. Administration filters publications in SQL and displays at most 50 per page; form errors provide a recovery link.
Desktop administration and a mobile guide, captured from synthetic local fixtures:
Upgrade
- Replace
TRUST_PROXY_HOPSwith explicitTRUSTED_PROXIESIP addresses or narrow CIDRs for the proxy peers the application actually sees. The default trusts no forwarding headers. - Server and development require Node 24 or newer. The standalone CLI requires Node 22.12.0 or newer.
- Back up the complete data volume before startup applies the SQLite migrations. Version numbers deleted before the migration cannot be reconstructed.
- Containers now publish to
ghcr.io/beastyrabbit/schaffa. Pin the immutable reference in the attachedcontainer-digest.txt. - Existing downloaded content cannot be recalled. Sensitive material in published guide history requires full guide takedown. The interactive sandbox does not provide complete network isolation.
The CLI release bundles its locked runtime dependencies and is audited after a clean install. Container release tags are promoted only after the candidate digest passes the vulnerability gate.
Verification
104 tests pass, including real-browser presentation, recording, keyboard, and mobile flows. Type, lint, build, secret, and dependency checks pass. Live identity-provider login and actual desktop input capture were not exercised. See PR #1 for the full resolution mapping and review evidence.

