Skip to content

v4.0.0

Latest

Choose a tag to compare

@kantorge kantorge released this 26 Sep 20:12
ee8ae45

4.0.0 (2026-09-26)

Major release: standalone budgets, a new recurrence engine, exact decimal arithmetic, API tokens with two-factor authentication, and Laravel 13.

Before upgrading, read the 3.x to 4.x upgrade guide. Update to the latest 3.x release first, run php artisan app:check:budget-migration, and back up your database. The data migrations cannot be undone with migrate:rollback.

⚠ BREAKING CHANGES

  • budgets: the transactions.budget flag is removed and replaced by a standalone Budget entity. Budget-only transactions are converted to Budget rows (one per category) and deleted from transactions. The "Budget" checkbox on the transaction form is removed; budgets are managed from Reports → Schedules and Budgets (#525, #528)
  • schedules: schedule and budget recurrence is stored in a single RFC 5545 rrule column, and the frequency/interval/count/end_date columns are dropped. The recurrence fields in the UI and API are unchanged (#548)
  • api: money and quantity fields in /api/v1/* responses are decimal strings instead of JSON numbers. Report endpoints are unaffected (#522)
  • api: GET /api/v1/transactions/scheduled-items no longer accepts type=budget|budget_only|both|any. The budget-vs-actual chart response adds budgetBreakdown and scheduleBreakdown arrays (#525)
  • auth: reCAPTCHA is removed from login, registration and password reset. RECAPTCHA_* variables are no longer read (8530275)
  • platform: requires Laravel 13 and the ext-bcmath PHP extension. Laravel 13 changes the default CACHE_PREFIX, REDIS_PREFIX and SESSION_COOKIE values, so pin them in .env to keep existing cache and sessions (8530275, #522)
  • docker: the Caddy reverse proxy is now the https Compose profile instead of a commented-out block. Re-apply any manual Caddy edits and start it with docker compose --profile https up -d (#531)
  • ai documents: deleting an AI document no longer deletes the transaction created from it (#547)

✨ Features

  • budgets: standalone budgets with a combined Schedules and Budgets report, budget-vs-actual chart drill-down, inflation-adjusted forecasting and dashboard widgets (#525, #528)
  • schedules: ordinal weekday patterns such as "first Wednesday of every month" or "last Friday of November" (#518)
  • schedules: "N days before month end" and "last business day of month" patterns for schedules and budgets (#548)
  • schedules: "skip to nearest future occurrence" when entering a scheduled transaction, step buttons and pattern validation for the next occurrence date, and a new dashboard calendar (#518)
  • security: personal API access tokens with read/write/settings scopes, and optional TOTP two-factor authentication with recovery codes, both managed from user settings (#512)
  • precision: exact decimal arithmetic for money and quantities, which removes rounding drift in split totals, investment values and monthly summaries (#522)
  • reports: Find Transactions adds transaction type and investment filters, a category waterfall chart and item-level breakdown filtering. The dashboard waterfall widget now links into the report (#520)
  • ai documents: opt-in, per-user retention policy that deletes old finalized documents, and sends reminder emails for old documents that are not finalized (#547)
  • accounts: account history uses virtual scrolling for large histories, and tables across the app use a single contextual action menu per row (#543)
  • docker: the container generates and keeps its APP_KEY on first boot, so docker compose up -d works without editing .env (#527)
  • docker: HTTPS through Caddy as a Compose profile, with a configurable APP_PORT (#531)

🐛 Bug Fixes

  • render notification and toast text as plain text to prevent XSS (#552)
  • "first Wednesday" style schedules no longer fall back to a fixed day of the month (#525)
  • over-precise money input is rejected instead of silently rounded, and amounts display with their stored precision (#542, 4753265)
  • forms in modals ask for confirmation before discarding unsaved input, and deleting currencies, tags, categories and groups works without a page reload (#535)
  • investment price web scraping no longer depends on the unmaintained roach-php package (#537)
  • AI documents created from pasted text stored an invalid file path. A migration repairs existing ones (#547)
  • many smaller fixes to schedules, budgets, forms, tables and migrations found during 4.0 testing and review

🚀 Performance Improvements

  • redundant indexes removed, and primary/unique keys added to pivot tables. Duplicate pivot rows are cleaned up during migration (#526)
  • number and date formatters are cached, which speeds up large tables (#543)

🛠️ Chores

  • upgrade to Laravel 13 and PHPUnit 13 (8530275, #538, #539)
  • ESLint cleanup and 2-space JS/Vue formatting (#551)
  • Docker image versioning and deployment improvements (2387ec1, da9a2cc)