Skip to content

Releases: orlandoc01/tallyo

v0.3.5

Choose a tag to compare

@github-actions github-actions released this 29 Sep 07:33
27220d6

Fixed

  • A SimpleFIN connection no longer fails as a whole when one account or holding reports a non-USD currency. USD accounts sync as before, including holdings such as ETH whose market value SimpleFIN reports in the account's currency, so those holdings are recorded as assets rather than dropped or recounted as cash. Accounts whose own currency is not USD are skipped, and the connection's health note lists them until a later sync finds none. Thanks to @vivekrathod for the report and initial fix in #4.

v0.3.4

Choose a tag to compare

@github-actions github-actions released this 28 Sep 20:54
f287f7b

Fixed

  • The tab strip in the desktop account detail and asset edit dialogs no longer shows a stray vertical scrollbar in browsers with classic scrollbars. The active tab underline now renders as a solid 2px line over the strip's rule.
  • The snapshot history list in account details highlights the selected date as a single-choice row instead of showing a checkbox per date. The same selected-row highlight applies to the net worth, cash flow, and asset filter pickers.

v0.3.3

Choose a tag to compare

@github-actions github-actions released this 28 Sep 07:52
e1baaaf

Changed

  • Mobile form sheets. Every remaining form popup on phones is now a bottom sheet, completing the mobile sheet work from 0.3.2: the asset editor (Info · Tracking tabs), category groups and categories (Info · Plaid tabs), budgets, tags, new transactions, rules (Filters · Changes tabs), bulk edit and bulk delete, manual accounts, sync settings, crypto wallet, home, and connection linking, new assets, balance review, Plaid credentials, and passkeys. Desktop is unchanged. No API or database changes.
  • Destructive actions inside mobile sheets (delete transaction, account, budget line, rule, tag, category, Plaid credential; remove connection, wallet, or property) use one full-width tinted button at the bottom of the sheet with a two-tap confirm that resets after 4 seconds, replacing the assorted red text rows, header buttons, and native confirm dialogs.

v0.3.2

Choose a tag to compare

@github-actions github-actions released this 26 Sep 08:23
e880317

Changed

  • Mobile detail sheets. On phones, every popup is now a bottom sheet: transaction details (edits staged and saved in one step, Hidden/Recurring toggles, merchant link, delete), account details with Info and Valuation tabs (12-month sparkline, snapshots grouped by month, rows that expand in place), net worth holding details, recurring charge details, budget line details, row action menus, the add-account chooser, the Transactions "+ Create" menu, and the Expenses sort and Settings timezone pickers. Desktop is unchanged. No API or database changes.
  • Mobile sheets dismiss with a swipe down on the handle, in addition to the close button, backdrop tap, and Escape.

v0.3.1

Choose a tag to compare

@github-actions github-actions released this 23 Sep 07:15
7f1ade9

Changed

  • UI revamp. Every page of the web app is redesigned on a new design system: semantic color tokens with matching light and dark palettes (Settings › General › Appearance: Light, Dark, or System), shared primitives (buttons, cards, tabs, chips, grids, charts), and dedicated desktop and mobile layouts for Net Worth, Transactions, Cash Flow, Expenses, Portfolio, Budgets, Review, Recurring, Accounts, Settings, and the setup wizard. No API or database changes.

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 20 Sep 19:04
7d05e51

The server is rewritten in Rust (axum, async-graphql, sqlx, rmcp). The web app, the GraphQL API, the 26 MCP tools, the configuration UI, and the SQLite database are unchanged. You get one static binary and a smaller image.

Upgrading from 0.2.x

Plaintext database (no DB_ENCRYPTION_KEY): pull the new image or binary and start it. Migrations run automatically. Nothing else to do.

Encrypted database: 0.2.x encrypted with the adiantum VFS; 0.3.0 uses SQLCipher and cannot open the old file. Convert once, with the server stopped:

  1. Decrypt with the last 0.2.x binary: DB_PATH=/data/tallyo.db DB_ENCRYPTION_KEY=$KEY ./tallyo-0.2.1 --backup-plain-data writes /data/tallyo.plain.db. Without an extracted binary: docker run --rm --user "$(id -u):$(id -g)" -v /data:/data -e DB_PATH=/data/tallyo.db -e DB_ENCRYPTION_KEY="$KEY" ghcr.io/orlandoc01/tallyo:0.2.1 --backup-plain-data.
  2. Move the adiantum file aside and put the plaintext copy at DB_PATH.
  3. Encrypt with the new binary: DB_PATH=/data/tallyo.db DB_ENCRYPTION_KEY=$KEY ./tallyo --encrypt-db. The original is kept as tallyo.db.bak.
  4. Start 0.3.0 with the same DB_PATH and key.

The full runbook with a restore drill is in server-rs/README.md under "Converting an adiantum database to SQLCipher". Every intermediate file is a plaintext copy of your secrets; keep them on the same volume and shred them once the drill passes.

Release artifacts changed. Binaries are published for Linux amd64 and arm64 only; macOS and Windows archives are no longer built. SBOM files are no longer attached; checksums.txt remains.

Added

  • Net Worth as of any date. Click a point on the history chart to focus that day: the rest of the series dims, the URL gains ?focus_date=YYYY-MM-DD, and the breakdown donut and details table re-render as of that day behind a "Breakdown as of …" banner with a "Show current" button. The hero card and account sidebar stay live. API: NetWorthInput.asOfDate.
  • Rules search. A search box on the Rules page (?q=) and RulesInput.search in the API filter rules by merchant name, merchant pattern, and original pattern through an FTS5 index. The MCP list_rules tool takes the same filter.
  • --encrypt-db: one-shot conversion of a plaintext database at DB_PATH into SQLCipher, keeping the original as <DB_PATH>.bak.

Fixed

  • Duplicate Plaid dividends. Chase and Fidelity re-issue a dividend the day after it posts under a new Plaid id, and the old one disappears from Plaid's response. Investment sync now removes stored rows that Plaid no longer returns inside the re-fetched window.
  • LLM categorization with Ollama. Responses wrapped as {"transactions": [...]} failed to parse and every batch reported zero categorized. Any array-valued wrapper key is accepted.
  • Transaction filters. An explicit false on isReviewed, isRecurring, isPending, or isHidden now filters; it used to mean "no filter".
  • Fresh installs seed the USD asset, balance-sync schedules, and retention sweeps that the initial-data migration was meant to create.
  • An empty master password is no longer treated as set by the disable-all-auth check.

Changed

Parity with 0.2.x was verified against a copy of a production database, the full frontend test suite, and MCP flows. Differences you may notice:

  • Free-text validation messages come from the Rust libraries (for example serde's missing field `datetimeRange` instead of datetimeRange is required). Error codes, GraphQL response shapes, and MCP tool schemas are unchanged.
  • A failing non-null root field is omitted from data instead of nulling the whole response.
  • /query accepts GET and POST only; other methods answer 405. /index.html is served directly instead of redirecting to /.
  • CSV export no longer quotes fields with a leading space.
  • Token lifetimes accept the same 15m / 168h strings; the docs no longer call them Go durations.
  • Email is sent with lettre over SMTP with plain authentication and TLS.

Removed

  • The startup Plaid institution logo backfill.

Internal

  • Rust 1.97.1, Node 24, npm 11. Static musl binaries built with cargo-zigbuild; thin LTO release profile.
  • SQL is generated by sqlc with the public sqlc-gen-rust plugin; GraphQL types and resolver traits are generated from schema/*.graphql.
  • CI: cargo audit replaces govulncheck, CodeQL analyses Rust, Dependabot tracks the Cargo lockfiles. Server line coverage is 91.9% under cargo-llvm-cov.

v0.2.1

Choose a tag to compare

@github-actions github-actions released this 29 Aug 02:40

Tallyo v0.2.1

Highlights

  • Live demo. Try the full app in your browser at orlandoc01.github.io/tallyo — no install, no backend. It runs on a fictional household's data (a year of transactions, budgets, recurring charges, net-worth history, and a classified portfolio); edits reset on reload, and anything that needs a real server (bank sync, sign-in) says so instead of failing silently.
  • Small UI polish to modals, destructive buttons, and the Rules page.

Demo

  • The demo is the same SPA served statically with a mock API in a service worker. Plaid Link, passkey registration, and email sign-in report that they need a real Tallyo server; SimpleFIN claim, categorization settings, import/export, and every edit flow work against the in-browser data.
  • It is installable like the real app ("Tallyo Demo" on your home screen or desktop) — same manifest and icons, minus the offline precache.
  • It deploys automatically from GitHub Actions on every release (.github/workflows/pages.yml), and the README links to it.

UI

  • Destructive actions: "Delete"-style buttons are outlined red; the solid red variant is reserved for the final confirm step (categories, accounts, balance reviews, bulk delete, Plaid credentials).
  • Modals: static sub-cards now sit one step above the modal surface in dark mode instead of borrowing the hover tone.
  • Rules: the edit modal's sections and list boxes are rounded consistently, the accounts picker scrolls with an overflow fade and shows a count, and the page header matches the other pages (the "Click to edit" pill is gone).
  • Add Connection: provider choices are card-style options; the property-address form uses regular section headings.

Docs

  • Docker image tags carry no v prefix (0.2.1, 0.2, latest); the install docs and README pin a release tag instead of latest for persistent deployments.

Internal

  • npm run build:demo (web) produces the base-path-aware static demo; the normal embedded build is unchanged.

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 28 Aug 06:34

Tallyo v0.2.0

Highlights

  • Authorization settings apply live. Saving the Authorization card no longer exits the server process. Restart policies and supervisors are no longer part of the configuration flow.
  • SimpleFIN SSRF guard. Setup-token and access URLs are validated before the server will talk to them.
  • UI consistency pass: shared page headers, buttons, and segmented controls, unified dark-mode palette, cleaner sign-in and Net Worth screens.
  • Built with Go 1.27.

Authentication & configuration

  • The Authorization section (issuer, master password, token lifetimes, frontend redirects, development CORS origins, disable-all-auth) now takes effect immediately on save, like every other settings section.
  • Enabling the first OAuth provider on a master-password-only instance no longer requires a restart — OAuth routes are always mounted and gated per request (404 until a provider is enabled).
  • Setup wizard: the "waiting for server restart" step is gone. Sign-in settings apply when you finish.
  • MASTER_PASSWORD and DISABLE_ALL_AUTH environment variables continue to override database settings.
  • Behavior note: access tokens issued under a previous issuer URL stop validating after an issuer change. Users sign in again, as before.
  • Documentation updated throughout (auth.md, configuration.md, install.md, troubleshooting.md, faq.md, reverse-proxy.md) to remove the exit-on-save behavior.

Security

  • SimpleFIN: the URL decoded from a setup token, and the access URL it returns, must be HTTPS and may not point at localhost, loopback, or link-local addresses. RFC 1918 private ranges stay allowed for self-hosted bridges.
  • WebAuthn: login rejects a second finish on an already-authenticated session (replay protection) and logs authenticator clone warnings.
  • Rate limiting now also covers /consent, /auth/google, and /auth/google/callback (previously only /register and /authorize).
  • Fixed a data race between WebAuthn configuration commits and request handling on the issuer URL.

UI

  • Unified page headers, button styles, and segmented controls across Transactions, Reports, Cash Flow, Budget, Portfolio, Net Worth, Recurring, and Settings.
  • Dark mode now draws backgrounds, surfaces, borders, and hover states from one warm-stone neutral palette instead of per-element overrides.
  • Sign-in: Google, email, and passkey buttons share one outlined style with a common keyboard focus ring. The Google button no longer auto-focuses on load (which exposed the browser's default blue outline).
  • Net Worth: last-sync time shows as a short relative timestamp ("3m ago", "10h ago", "3d ago") stacked under the balance, so it no longer truncates against long institution names. Tighter sidebar spacing and page gutters.
  • Transactions: pending transaction amounts render in italics.

Performance

  • SQLite now runs with synchronous=NORMAL under WAL (was the default FULL), removing an fsync per commit on the writer connection.
  • Historical net-worth series use binary search for snapshot forward-fill instead of rescanning each account's snapshots per sample date.

Internal

  • Go 1.27.
  • Server row mapping consolidated onto sqlc-generated table/view models (−112 handwritten lines).
  • Coverage is now measured cross-package (-coverpkg=./internal/...): reported total 78.6% → 83.9%. New tests include a real WebAuthn register→login round trip, MCP tool smoke tests, and SimpleFIN URL validation.
  • Auth session cleanup now runs once at startup as well as on its periodic schedule.

v0.1.1

Choose a tag to compare

@github-actions github-actions released this 22 Aug 08:48

Maintenance release — dependency refresh across the stack. No functional changes to the app.

Dependencies

  • Go: mcp-go 0.58.0, ncruces/go-sqlite3 0.35.3, goose 3.27.3
  • Web: Vitest 4.1, Recharts 3.10 (chart internals migrated), typescript-eslint 8.67, @types/node 26, Playwright 1.62
  • CI: actions/checkout v7, setup-go v7, setup-node v7, docker login-action v4, setup-buildx-action v4
  • Docker: busybox 1.38 for the /data bootstrap stage

CI

  • CodeQL Go analysis fixed (autobuild build mode)
  • gitleaks: synthetic test fixtures allowlisted

Full changelog: v0.1.0...v0.1.1

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 22 Aug 07:19

Changelog

Other Changes