Releases: jsldvr/vscode-journal
Releases · jsldvr/vscode-journal
Release list
Release v1.3.3
Security
- Journal entry operations now fail closed on symbolic links and Windows
junctions anywhere below the workspace root. The configured blog and
entries directories, the generated.vs-journaldirectory, the
index.sqlite3database and its.corrupt/-journal/-wal/-shm
siblings, every entry subdirectory, and every entry file must be a
real, non-symlink path of the expected type; a link is rejected even
when its target stays inside the workspace. Entry scanning no longer
follows linked files or directories and cannot be sent into a
directory-link cycle, activation reconciliation prunes rows for a
previously real subtree that has been replaced by a link, and the file
watcher, "Rescan All Entries", entry opening, and "New Blog Entry" all
revalidate the physical path immediately before they read, write, open,
index, move, or delete. Passive activation still never creates missing
directories; deliberate creation flows validate each parent and
revalidate each component they create. Linked entry trees remain
unsupported rather than resolved.
Contributors
Release v1.3.2
Fixed
- Changing
vsJournal.blogPathwhile the entry index was still opening for
the previous directory could leave the old index active: the in-flight
open published its result without checking that the configuration still
pointed at that directory, so the host served directory A's index under
configuration B, and a subsequent New Entry could be written into the old
directory. Index open/reopen/dispose are now serialized by generation
ownership: only the current configuration's open can become the active
index, every index opened for a superseded configuration is closed, a
failed open can be retried, and deactivation is terminal and idempotent --
it awaits the in-flight open and every owned close and no later call can
reopen. Startup and configuration-change continuations re-check ownership
after their awaits before rebinding watchers or refreshing views. New
Entry now always acquires the current directory's index; passive startup
still never creates an absent blog directory, and New Entry still
escalates to create it on demand.
Contributors
Release v1.3.1
Fixed
- The Match Case / Whole Word / Regex search now runs its
RegExpscan on a
worker thread with an enforced 2-second per-search budget. A pattern with
catastrophic backtracking (for example(a+)+$over a long non-matching
line) previously executed synchronously on the extension host and could
freeze the window; it is now terminated at the budget and reported inline as
"Regex search timed out", the editor stays responsive, and the next search
works without a reload. Overlapping searches settle in submission order, so a
slower earlier search can no longer cancel a newer one into a stuck
"Searching..." state; only one scan worker is ever live at a time, and it is
fully torn down when the index closes or the extension deactivates. Literal/FTS
andtag:searches, the other toggles,
supported regex syntax, result ordering, the result limit, snippets, and the
friendly invalid-pattern error are unchanged.
Contributors
Release v1.3.0
Added
vsJournal.mediaPathsetting (defaultmedia) that resolves the media
directory against the configured blog directory. The value must stay inside
the blog directory; an absolute path or one that escapes it (for example
../shared) is refused and the Media section reports an unavailable state
instead of reading, watching, or writing outside the blog.Journal: Set Media Directorycommand (Command Palette) that opens a folder
picker and stores the selection as a portable, forward-slash, blog-relative
path at Workspace scope. A folder outside the blog directory is rejected and
leaves the setting unchanged.Journal: Reveal Media Directorycommand (Journal view overflow menu and
Command Palette) that opens the current media directory in the OS file
manager. A missing, unsafe, or symlinked directory is reported as an error
and is neither created nor revealed.- A workspace-relative media location on the Media heading (for example
Media: blog/assets), truncated with the full label on hover, that reflects
vsJournal.blogPathandvsJournal.mediaPath, updates when either changes,
and readsMedia: unavailablewhen no safe directory resolves. Showing the
path never creates the directory. - One-click insertion of a media file as Markdown at every cursor in the
active journal entry. An image insertswith
alt textas a pre-selected, editable snippet placeholder; any other file
inserts[file.pdf](media/file.pdf)using the file name as the link label. - Markdown link targets composed from the configured
vsJournal.mediaPath,
always forward-slashed and percent-encoded per path segment (including(
and)), with non-image link labels Markdown-escaped, so filenames or
configured paths containing spaces, parentheses, or brackets still produce
valid links.
Changed
- The primary media-tile action (click, Enter, or Space) now inserts Markdown
into the active entry instead of opening the details tab. Insertion requires
the active editor to be a saved Markdown file inside the blogentries/
directory, and the media root and selected file are re-validated at that
moment; when nothing is eligible or the target is unsafe, the Media status
line reports it and nothing is inserted, created, or opened. - Opening a media file's details moved to a secondary Details button on
each tile. It still reuses a single editor-area tab and is never opened
automatically by sidebar refreshes, uploads, or media insertion. - The media watcher, webview resource roots, and Media view now rebind at
runtime whenvsJournal.blogPathorvsJournal.mediaPathchanges. - Lazy creation (the directory is created only on first upload), blog-directory
containment, path-traversal rejection, symlinked-root and symlinked-ancestor
handling, and webview resource-root protections now cover the configurable
media path.
Contributors
Release v1.2.1
Added
- Support for Astro-style
pubDatefrontmatter. Entries that usepubDate
instead ofdateare now indexed, sorted, grouped, and displayed by that
date. When both keys are present,dateremains authoritative.
Contributors
Release v1.2.0
Changed
- Breaking: raised the minimum supported VS Code version from 1.74.0 to
1.125.0 (engines.vscode). The extension can no longer be installed on
older VS Code releases. - Migrated the ESLint configuration from
.eslintrc.jsonto flat config
(eslint.config.js), upgradingeslintto ^10.8.1 and
@typescript-eslint/eslint-plugin/@typescript-eslint/parserto ^8.67.0. - Upgraded
typescriptto ^6.0.3,@types/nodeto ^25.9.5,@types/vscode
to 1.125.0, andlint-stagedto ^16.4.0.
Removed
- The deprecated
@types/momentstub package;momentships its own type
definitions.
Contributors
Release v1.1.0
Added
- A Media library section built into the single Journal sidebar webview,
below the entry browse list, for browsing, uploading, and managing files
under<blogPath>/media(a sibling ofentries/, created lazily on first
upload). The section has its own pinned toolbar (search, a type filter --
All/Images/Audio/Video/Documents, Upload, and Refresh) and a responsive
thumbnail grid with real image previews and labeled placeholders for other
types. - An editor-area details view (
vsJournal.mediaDetails) that opens when a
media tile is selected, showing a preview, filename, relative path, type,
size, and last-modified time, plus Copy Path, Open, Reveal in File
Explorer/Finder, and Delete actions. Selecting another tile reuses the same
tab; nothing is ever auto-selected on load, refresh, or upload. Journal: Upload MediaandJournal: Refresh Media Librarycommands,
also available as toolbar buttons in the Media section.- A recursive file watcher on
media/that keeps the library in sync with
files added, changed, deleted, or renamed on disk. - Collision-safe uploads: colliding filenames are renamed with a numeric
suffix (image-2.png,image-3.png, ...) instead of overwriting existing
files. - Symlink- and traversal-hardened filesystem handling for the media
directory: a symlinked media root or a symlinked ancestor between the
workspace root and the media root is treated as unsafe and disables the
webview resource root rather than exposing it; individual file resolution
rejects traversal, absolute paths, non-regular files, and symlinked
intermediate directories; delete re-validates its target immediately
before removal to close the TOCTOU window.
Contributors
Release v1.0.0
Added
- A repository-local SQLite/FTS5 index at
<blog>/entries/.vs-journal/index.sqlite3
covering entry metadata, tags, and full-text content (frontmatter excluded),
with versionedPRAGMA user_versionmigrations, WAL mode, transactional
updates, activation-time reconciliation, and automatic rebuild when the
database is missing, corrupt, or written by an incompatible schema version. - An inline sidebar Search view (webview) with a persistent input, ranked
full-text results with highlighted snippets, date/path/tag metadata,
clickable tag chips, keyboard-accessible controls, and idle/loading/
no-results/error states. Search is case-insensitive substring matching via
the FTS5 trigram tokenizer;tag:<value>remains a relational tag query. - A one-time offer to add
**/.vs-journal/to the workspace.gitignore
when the journal's repository does not already ignore the generated index. - Platform-specific packaging scripts (
package:<target>) that stage the
matchingsqlite3N-API prebuilt binary beforevsce package --target,
plus a CI job that packages and verifies every supported target. - Contributor guidance covering repository structure, commands, testing, and agent workflows.
- GitHub Actions checks for compilation, linting, and unit tests on pushes and pull requests.
- A default pull request template and structured bug and feature issue forms.
- Weekly grouped Dependabot updates for npm dependencies.
- Pre-commit type checking and staged TypeScript linting with Husky and lint-staged.
- A comprehensive test system under
test/with unit, VS Code Extension Host
acceptance, property, bounded torture, mutation, and aggregate QA suites. - Automated GitHub releases driven by the
package.jsonSemVer, with
platform-specific VSIX artifacts, changelog release notes, contributor
attribution, duplicate-release protection, and prerelease support.
Changed
- The explorer, welcome state, entry creation, file watchers, and rescans now
read and write the SQLite index instead ofentries/map.json. Existing
map.jsonfiles are left untouched but are no longer required or updated. Journal: Search Blognow reveals and focuses the persistent Search view
input instead of opening a modal input box.- Search results are ranked by full-text relevance with snippets instead of
raw match counts, and no query re-reads Markdown files from disk. - The VS Code development launch now installs dependencies before starting the compiler watcher.
- The npm package identifier is now
vscode-journal, and the extension version
is1.0.0.
Removed
- The map.json-based search TreeDataProvider and the mapStore module.