Update for v1.31.0: rTorrent, OPDS covers, import-blocked, dual-format scans, hardlink warning, Hardcover sync
The wiki had not been touched since 2026-06-05 and was missing rTorrent
entirely, along with everything the last six releases changed about imports
and library scans.
0817db9
Add Contributing — onboarding & FAQ page
New contributor on-ramp: dev setup, where to start, which CI checks gate,
migration numbering, changelog fragments, and scope FAQ. Linked from the
sidebar and Home.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
ef1d7eb
wiki: fix wrong auth/OIDC recipes; add download + CWA learnings
Accuracy fixes (current recipes are wrong and harmful):
- Recover-admin: remove the bcrypt password-hash recipe (Bindery is
argon2id-only; a bcrypt hash is silently rejected). Replace with the
admin reset-password endpoint and the delete-users setup-wizard path.
- Fix the user-role endpoint everywhere: PUT /auth/users/{id}/role
(not the bare PUT /auth/users/{id}).
- Rotate-OIDC-secrets: the per-provider-id PUT/POST endpoints do not
exist; the API is a whole-array GET/PUT. Rewrote to read-modify-write
the full array, with a warning that a single-provider PUT deletes all
other providers. Fix session-secret rotate path to
POST /auth/session-secret/rotate.
- Troubleshooting: multi-user 'User A sees User B data' is the documented
default (BINDERY_ENFORCE_TENANCY defaults off), not a bug.
Added learnings:
- SAB/NZBGet now upload NZB content (addfile / base64 append) so the
client never needs to reach the indexer.
- History tab now records scheduler auto-grabs (#938).
- 'connection refused' diagnostics: interface-binding / host-firewall
framing (not Docker-subnet).
- CWA ingest folder (cwa.ingest_path) + External import mode workaround
for duplicate book rows; noted #940/#941 as not-yet-shipped.
0c62c97
Wire Authentik OIDC how-to into Sidebar and Home
19c04b8
Authentik OIDC: tighten troubleshooting after real-setup feedback
8efc82d
Add Authentik OIDC how-to
9b478d0
docs: add {Series}/{SeriesNumber} tokens, series scanner matching, NZBGet/Transmission sections, URL Base reverse-proxy guide
fbe37ea
docs: update version refs to v1.0.0/v1.0.1 (proxy auth, OIDC, multi-user all ship in v1.0)
9397d82
Fix placeholder troubleshooting entry in Howto-Google-OIDC
Replace draft stub (pre-#4 merge) with real entries: issuer URL
scheme requirement and state cookie/proxy stripping diagnosis.
root
committed
Apr 19, 2026
63e52a5
Add Phase 3 multi-user howto set (v1.0)
- Howto-Migrate-to-multi-user.md: backup, dry-run, upgrade, rollback, migration 019 troubleshooting
- Howto-Add-a-second-user.md: local/OIDC/proxy users, roles, promote/demote, delete safely
- Howto-Recover-admin-access.md: API recovery, direct DB update (Docker + K8s), password reset, API key retrieval
- Howto-CSRF-tokens.md: session-cookie preflight, migration from X-Requested-With, API-key exemption
Update Home.md and _Sidebar.md with "Multi-user — v1.0.0" section.
root
committed
Apr 19, 2026
3ac5c73
Document client_secret preservation semantics and add API scripting notes
- PUT with empty/absent client_secret preserves existing secret (write-only)
- POST for new providers requires non-empty client_secret (400 otherwise)
- Step 2 rewritten: minimal targeted rotation curl, no full-object repost needed
- New "API scripting notes" section: contract table, minimal rotation, update-non-secret, create examples
- "When this goes wrong" updated: replaced stale "can't retrieve" entry with the three secret-semantics gotchas
root
committed
Apr 19, 2026
8d066e4
Add Phase 2 OIDC howto set and update navigation
- Howto-Google-OIDC.md: OAuth 2.0 client setup, consent screen, redirect URI, test login
- Howto-GitHub-OIDC.md: GitHub OAuth App + Dex connector config, org/team restriction
- Howto-Authelia-OIDC.md: Authelia native OIDC provider (vs Phase 1 forward-auth), group mapper, comparison table
- Howto-Keycloak-OIDC.md: confidential client creation, group mapper, realm-path issuer note
- Howto-Rotate-OIDC-secrets.md: per-IdP rotation steps, session secret distinction, verification
- Howto-Recover-broken-OIDC.md: API key recovery, password fallback, debug log diagnosis, fix/remove provider
- _Sidebar.md: Phase 2 OIDC section added
- Home.md: Phase 2 OIDC howto table added
root
committed
Apr 19, 2026
6a55d41
Add missing OIDC risk mitigations and cross-link troubleshooting-auth.md
- Two new OIDC entries: (issuer,sub) composite key explanation, plaintext client secret known limitation
- See also section updated to link docs/troubleshooting-auth.md and updated doc paths (multi-user.md, upgrade-v2.md)
root
committed
Apr 19, 2026
6a0015d
Add Phase 1 proxy auth howtos and sidebar
- Howto-Authelia-proxy-auth.md: step-by-step for Traefik+Authelia, Caddy, nginx variants
- Howto-Authentik-proxy-auth.md: step-by-step for Authentik embedded outpost with Caddy/Traefik
- Howto-Troubleshoot-proxy-login.md: 7-step diagnostic guide for stuck proxy logins
- _Sidebar.md: new wiki sidebar surfacing all pages
- Home.md: How-to guides section with Phase 1 proxy auth entries
- Troubleshooting.md: proxy SSO, OIDC, multi-user sections (from earlier work)
- Reverse-proxy-and-SSO.md: updated SSO section to reference proxy auth mode
root
committed
Apr 19, 2026
1548aae
docs: add Deluge and {ASIN} token documentation for v0.20.0
b583f77
Calibre integration: note Bindery Generate button for API key
root
committed
Apr 17, 2026
50cb62e
Calibre integration: add plugin mode, remove drop_folder, update decision tree
- Add plugin (HTTP bridge) mode section with architecture diagram,
3 install options (manual GUI, kubectl exec for PVC containers,
k8s init-container), K8s service port config, Bindery settings,
and failure behaviour table
- Remove drop_folder mode (removed in v0.17.0)
- Update decision tree: calibredb vs plugin (was calibredb vs drop_folder)
- Add links to docs/CALIBRE-PLUGIN.md and bindery-plugins repo
root
committed
Apr 17, 2026
6ca2801
docs: add the seven pages Home.md already links to
Home.md links to seven reference pages that did not yet exist — clicking
them rendered GitHub's default "create this page?" stub. Fill them in:
- Delay-profiles.md — CRUD surface today; scoring layer on the roadmap (#93)
- Custom-formats.md — same story (#94); condition schema documented so users can
define formats now and have them take effect when the scoring wire-up lands
- Notifications.md — generic-webhook model (no built-in Slack/Discord/ntfy
adapters); recipes per provider; SSRF policy escape hatch
- Reverse-proxy-and-SSO.md — Traefik/Caddy/nginx snippets; ForwardAuth +
Authelia/Authentik patterns; how OPDS + scripts bypass SSO cleanly
- OPDS.md — endpoint map, auth precedence (api key / session / basic),
KOReader/Moon+/Aldiko setup
- Calibre-integration.md — the three modes (off / calibredb / drop-folder)
with a decision tree and the real per-mode setting keys
- Indexer-and-downloader-recipes.md — Newznab/Torznab pattern, SABnzbd +
qBittorrent setup, path-remapping, category IDs (7020 / 3030)
Every page reflects actual code paths (verified against internal/api,
internal/notifier, internal/calibre) rather than Sonarr-style boilerplate.
Features that have CRUD APIs but no enforcement layer yet are explicitly
flagged as such, with roadmap links.
b284f60
docs(troubleshooting): correct lockout recovery — /config path, drop bogus empty-hash step
Two defects:
1. The sqlite path was /data/bindery.db; the container actually writes to
/config/bindery.db (BINDERY_DB_PATH default). The old path silently fails
because sqlite3 creates an empty file in /data and then "updates" zero
rows.
2. Option 1 ("UPDATE users SET password_hash = '' lets you log in with any
password") was wrong. internal/auth.VerifyPassword returns false
immediately when the PHC hash doesn't start with '$argon2id$' — an empty
hash is rejected, not treated as unset. Following that advice leaves you
still locked out with an additionally-damaged user row.
Keep the "delete the users row → setup wizard re-runs" flow, which is the
only recovery path that actually works, and add the kubectl variant that
was missing.
76240d0
docs: correct password hash algorithm + ROADMAP link
Bindery switched from bcrypt to argon2id (OWASP 2024 params) in v0.12.0;
the wiki still said bcrypt.
The Quality-profiles page linked to ROADMAP.md at the repo root, but the
file actually lives in docs/.
c55427c
docs(troubleshooting): add log-viewer DEBUG-level guide
The in-process log viewer (Settings → Logs, shipped in v0.11.0) lets
users toggle DEBUG without a restart. Document the flow so users reach
for it before asking for help.
0892dcd
docs(prowlarr): add Prowlarr setup page
Document how to wire Prowlarr-managed Newznab/Torznab indexers into
Bindery without a dedicated Prowlarr provider type. Covers URL format,
API-key source, category IDs, and common failure modes.
Linked from Home under Setup guides.
3489282
docs(security): add Security page covering v0.12.0 posture
969fa1b
docs: add Troubleshooting page — covers, downloads, scanner, auth
5a0ba42
docs: add Quality profiles reference page
1492328
docs: flesh out wiki home page with navigation index
49ab38d
Add Quickstart and Migrating-from-Readarr wiki pages
de8d24f