Releases: pardel/slink
Releases · pardel/slink
Release list
Slink 1.0.2
A security and reliability release. Upgrading is recommended: it closes a cross-site request forgery hole in the admin API.
Security
- Cross-site requests are refused. Cloudflare Access signs you in with a cookie the browser also sends when another site triggers the request, so a malicious page could archive, edit or create links on your behalf. Every
POST,PATCHandDELETEon/api/*must now carry anOriginheader matching the admin host, or it gets a 403. The dashboard is unaffected; a script calling the API must now setOriginitself.
Fixed
- Deleting a link can no longer lose its analytics. The clicks and the link are removed in one transaction; before, a failure between the two statements left the link with its clicks gone.
HEADrequests no longer count as clicks. Link checkers and crawlers get the redirect without inflating the numbers.- A
nullor non-object JSON body gets a 400 instead of a 500. - Account-wide analytics no longer scan every click. A new index on click timestamps (migration
0004) serves them and the daily retention prune, saving D1 reads on the free tier. - The dashboard can't show stale or wrong data after a save. Late list responses are dropped instead of reverting a change, a renamed link resolves at its new URL straight away, and a failed refresh shows a Retry banner.
- Short links and QR codes always use the public host. The dashboard waits for its settings (with Retry on failure) instead of falling back to the admin address.
- The actions menu works everywhere. It no longer hides behind the next card, flips above its button near the bottom of the screen, closes on outside clicks, and is keyboard navigable (focus moves into it; arrows, Home/End, Escape and Tab behave as expected).
- Malformed URLs such as
/links/%show "No link found" instead of a blank dashboard. - README: the Develop steps create
wrangler.jsoncbefore migrating, and the Deploy step usesnpm run deploy, which builds the dashboard first.
Upgrading
Use Node 22, then:
npm ci
npm run db:migrate:remote # adds the clicks timestamp index
npm run deploySlink 1.0.1
A maintenance release: dashboard fixes and a corrected Node requirement.
Fixed
- Node 22 is now required. Wrangler 4 refuses to run on older Node, so the
.nvmrcpin,engines, the README and CI move from 20 to 22. On Node 20, development, migrations and deploys failed. - QR codes always point at the public host. A code generated before the dashboard learned the short-link base could keep pointing at the admin host, and a renamed slug kept its old code.
- Analytics match the selected period. Switching periods while a request was in flight could show 30-day totals under "7 days"; late responses are now discarded.
- A failed load no longer looks like an empty account. The link list and detail pages show an error with a Retry button instead of "No links here yet" or an endless "Loading…"; the analytics views gained a Retry button too.
- Navigation on small screens. Below the tablet breakpoint the sidebar was hidden with nothing in its place; a top bar now carries the brand, Links and Analytics.
Upgrading
Switch to Node 22 (nvm use), then npm ci and npm run deploy. No database migrations.
Slink 1.0.0
The first tagged release of Slink, a self-hosted link shortener with click analytics that runs on Cloudflare Workers and D1 at zero recurring cost.
What's in it
- Short links on your own domain:
example.com/<slug>redirects (302) and passes UTM parameters through to the target. - A public page at
/listing your newest links (10 by default, pinned first), with an optional "Links by ..." owner line. Hide a link from it without breaking the redirect. - Link preview: add
+to any short link (example.com/<slug>+) to see where it goes before following it. No click is logged. - A dashboard on a separate admin host behind Cloudflare Access: create, edit, archive, pin and hide links, and download a QR code for each.
- Analytics per link and across all links: clicks, unique visitors, countries, devices, browsers, referrers and a daily series, for 7 days, 30 days, all time or a custom range.
- Privacy by default: only the referrer's origin is stored, visitor hashes use a daily salt, and clicks older than 180 days are pruned automatically.
- A strict security policy: nothing is loaded from third parties, and fonts and QR codes are generated on your own domain.
Getting started
Clone, copy wrangler.jsonc.template to wrangler.jsonc, and follow the README's Deploy and Cloudflare Access sections.
MIT licensed.