Repository navigation
Releases: yexca/kikoto
Release list
v0.8.0
Important
Upgrade notes. Back up config/ before upgrading. Keep the existing
data/ mount; the version upgrade does not require copying it.
Existing v0.7.1 databases advance from schema 047 through numbered migrations
048–059; fresh installs use baseline/059_v0.8.0.sql. Do not replace an
existing database with a fresh-install baseline. Databases created by
unreleased development builds after v0.6.1 are no longer accepted; recreate
them or restore a backup from a released version.
The migrations add shared tags, circle identities, language-scoped and
per-user titles, remote metadata provenance, tag name learning state,
purchase bonus links, favorite list icons, and local file versions. They
queue existing works instead of rewriting them, so tag projection, sort
titles, remote title projection, and the search index catch up in the
background after startup; lists and search stay available while they
drain. Migration 048 removes only all-language title overrides that
exactly match a trimmed DLsite title from the same work family. Startup also
moves cached remote covers to the nested cache layout once and removes the
old instance-wide metadata language setting.
The bundled docker-compose.yml now runs the container with a read-only
root filesystem, all Linux capabilities dropped, no-new-privileges, and a
bounded /tmp tmpfs. /config, /cache, and /data stay writable. Copy
these settings into a custom Compose file to get the same isolation.
The web app and Android WebView now require Chrome 111+, Safari 16.4+, or
Firefox 128+. Outbound proxies must support CONNECT to the destination
ports, and the container must be able to resolve source hostnames.
Note
Use docker compose up -d --pull always to upgrade the production stack;
restarting a container reuses its installed image. Update KIKOTO_IMAGE
first if it is pinned to an older release.
Kikoto v0.8.0 rebuilds shared metadata around multilingual tags and titles,
lets each user choose a metadata language, and adds an opt-in remote metadata
fallback, background tag name learning, and purchase bonus links. Work
detail, Favorites, the header, Settings, Workflows, and About are
redesigned, and outbound requests, served media, and the production
container are hardened.
Metadata Languages And Titles
- Preferred metadata language is a personal choice for every signed-in user
in the account panel. It selects that user's titles, introductions, tag
names, and default detail edition, sorts lists by the titles shown, and
leads that user's remote-source requests. Origin, each work's original
language, is the default and is also what anonymous visitors see. - The instance-wide default metadata language is removed. Stored and shared
metadata, background syncs, creator catalogs, and Activity text always use
each work's original language.GETandPATCH /api/settingsno longer
carrydlsiteMetadataLanguage(s). - Titles can be set per language. A language title applies before DLsite
editions, an all-language title replaces only the displayed text, and every
manual title is searchable. Known translation labels such as a leading
language-edition tag are hidden for display only; stored titles keep them. - Remote sources can supply language titles from the edition relationships
and sibling titles already in their work metadata, without extra requests
or extra works. - A work's shared tags always come from its original edition, so every
language shows the same tags under translated names. - Remote sources replace the per-source request language with a Fallback
language. Requests send the viewer's languages first and the fallback
last; viewers on Origin, anonymous visitors, and background jobs ask in the
fallback language only. Cached remote works are kept per language.
Shared Tags, Circles, And Voice Actors
- Tags are shared across works with stable ids. Administrators can name a
tag per language, hide it everywhere, or merge it into another tag and undo
the merge; merged names stay searchable. Work editors can add or remove tags
per work and create custom tags, which reuse an existing tag with the same
name in any language. - Learn tag names fills missing translated DLsite genre names in the
background for every language some user prefers. It asks DLsite once for the
work covering the most unnamed genres, so requests scale with missing
genres rather than works, follows the existing pacing and proxy routes,
resumes after interruption, and reports progress in Activity. - Circles support manual names, confirmed aliases, and reviewed, reversible
merges that move creator relations and personal circle data. - Metadata → Tags lists tags by id, with the DLsite genre id and a column
for each of Japanese, Simplified Chinese, Traditional Chinese, English, and
Korean. Circles are ordered by DLsite maker id, and Voice actors become a
table keyed by Kikoto id. All three share the works table layout, and a
numeric search matches ids. - The Admin role now has
library:writefor work metadata, covers, metadata
links, untracking sources, shared tags, and circle changes.
Metadata Editor And Sources
- The metadata editor on work detail and Metadata → Works has Title, Cover,
Tags, Credits, and Metadata source sections that mark unsaved changes.
Every change, including reverts and metadata link changes, is a draft until
Save; Cancel confirms before discarding drafts, and Ctrl+Enter saves. - Each language title row starts with the title it currently shows. Only
changed text becomes a manual title. Covers are picked from a thumbnail grid
that starts with the original DLsite cover, and circle, series, voice actor,
and tag fields complete from suggestions with keyboard selection. - Edits send only changed fields, and a cover-only edit no longer freezes
titles or creator metadata. - Remote metadata fallback is opt-in under Configure on the Metadata
sync workflow. When DLsite reports a work as not found, the selected
metadata-capable remote sources fill title, release date, circle, tags, and
a missing cover in the configured order. Each value records its source, and
later DLsite data takes over. Retryable DLsite failures never contact
remote sources, and no work is created. - The editor can refresh one work's metadata From a chosen remote source
on demand, without enabling the automatic fallback. Manual and DLsite
values keep their precedence. - Metadata sync links a purchase bonus, such as an early purchase bonus, to
the work it came with when its title or release date names exactly one of
the circle's works. The bonus stays its own work, takes only the tags,
voice actors, and series it lacks, and links to the parent from its detail.
The switch is on by default, and editors can link or unlink a bonus by hand. - Catalog freshness days moves to a new Creator catalogs section in
Settings -> Library.
Work Detail
- The detail opens with a cover-tinted hero: title, circle, series, voice
actors, a stat strip of rating, age, sales, release date, and duration, and
the provider and personal tags. Edition and language are two compact chips
beside the work code. - The directory is one folder explorer: a folder column on wide screens or a
Folders sheet on phones, album-style track lists that mark the resume
position and the playing track, an image gallery, documents, and other
files. - Files open in a viewer that steps through sibling files with buttons,
arrow keys, or swipes. Images fit the window or zoom to actual size with
drag panning, and LRC, WebVTT, and SRT files show time-stamped lines. - On wide screens Source info lists the selected source's actions inline.
Manage files is a single tree that selects by location and by format and
shows the selected count and size. - The List menu can create a list in place. Personal tags open a library
tag search like DLsite tags do.
Library And Favorites
- Work cards set the cover inside the card with availability chips on it,
move the product code above the title, and are about a row shorter. - A single Display options control sets columns and items per page.
Desktop columns are now Auto or 3 to 8; a saved choice of 1 or 2 reverts to
Auto. - Favorites opens on shelves: All Favorites, Marked, your lists, and
followed circles and voice actors. Each shelf has a cover mosaic header, a
collapsible Continue listening strip, quick-mark status filters, and a
card or list view. Lists can carry an icon chosen in Edit lists. - Back from a detail returns to the list that opened it with its filters,
page, and scroll position. - Recently played shows only the track name, and opening a remote source
no longer flashes an empty placeholder page.
Playback
- Settings -> Playback adds two per-account switches, both off by
default: Quick source switching turns the Now Playing source label into
the source menu, and Switch sources on failure continues from the
track's next usable location. With the second switch off, a failed location
stops with a Retry action. - A single-track queue in loop mode restarts correctly, and progress saves
stay with the account and server that made them.
Header, Settings, And Workflows
- The header groups Quick actions, notifications, appearance, and the
native server connection into one icon tray. Quick actions is a lightning
button with its Ctrl K or Cmd K shortcut in the tooltip. - Notifications open a notification center with personal updates and, for
workflow operators, runs that need attention and the running job. The
avatar opens one account panel with profile, shortcuts, UI and metadata
languages, Settings, and sign-out. - Settings uses an icon rail, and History and Recommendations are separate
tabs again. ...
v0.7.1
Important
Upgrade notes. Back up config/ before upgrading. Keep the existing
data/ mount; the version upgrade does not require copying it.
Existing v0.7.0 databases advance from schema 044 through numbered migrations
045–047; fresh installs use baseline/047_v0.7.1.sql. Do not replace an
existing database with a fresh-install baseline.
Migration 045 adds per-work metadata links and changes no existing rows.
Migrations 046 and 047 add DLsite variant titles and a genre dictionary to
the search index, backfill the genres from each work's latest DLsite
snapshot, and queue the affected works. The index catches up in the
background after startup; search stays available while it drains.
The bundled docker-compose.yml passes the new optional
KIKOTO_HOST_PROXY_HOST and maps host.docker.internal to the Docker host,
so a Local machine proxy also works on Linux engines. Copy both changes
into a custom Compose file if you plan to use a proxy that runs on the host.
Note
Use docker compose up -d --pull always to upgrade the production stack;
restarting a container reuses its installed image. Update KIKOTO_IMAGE
first if it is pinned to an older release.
Kikoto v0.7.1 adds outbound proxies, cross-language title and tag search,
per-work metadata links, Kikoeru account import, and a ranged listening
report. It also reorganizes Settings, Metadata, and Workflows, and stops
library setup from reappearing after an upgrade from v0.7.0.
Search
- Searching matches a work's original DLsite title even after the metadata
language priority replaced the displayed title. - A tag search in one language finds works whose stored tags use another
language, because DLsite genres are matched by their stable ids. - Exact matches on title text, circle, voice actor, or tag are listed ahead of
partial matches before the selected sort. - The search field's + button opens a floating condition editor, and
selecting an existing condition badge edits it in place without moving the
results. - Clearing a search that was started from a tag shortcut reloads the
unfiltered list immediately instead of after a refresh. - Opening search on mobile from the search button or a tag no longer raises
the keyboard.
Metadata
- A work can take its metadata from another DLsite code, for example when a
bonus edition is no longer sold and the regular edition has a different
code. Metadata sync requests only the linked code and stores the result on
the work under its own code; the linked code does not become a separate work. - Metadata chooses All, the attention categories, or Voice aliases from a
vertical icon rail. Work records appear as a management table of code and
title, circle, status, and actions; users who can edit the library open the
metadata editor from the table. The list no longer refreshes every five
seconds, only on navigation, filter changes, actions, and manual refresh. - The preferred metadata language moves from Metadata settings to the header
Appearance menu, below the interface language, for source administrators.
Proxies
- The new Settings -> Proxy tab manages an ordered list of outbound
proxies (HTTP, HTTPS, SOCKS5, or SOCKS5h) that requests try by priority.
Passwords are write-only. - A Local machine proxy uses the address of the machine that runs Kikoto:
host.docker.internalin a container, or the value of
KIKOTO_HOST_PROXY_HOST. - Proxy scope routes DLsite, remote-source, and other outbound requests, with
an All switch and per-source direct or proxy overrides. Requests fail closed
when every proxy fails, unless the optional direct-connection fallback is
on. The Metadata settings popover keeps a shortcut to the DLsite route. - Requests through a proxy still validate the destination and every redirect.
Personal Data And History
- Your data can import reviews, and playlists where offered, directly from
a Kikoeru account: choose a configured Kikoeru-compatible source or enter an
API address, then sign in with a token or a name and password. An
open-source Kikoeru SQLite database can also be uploaded to read one
account's reviews. Both use the existing preview and import. - Credentials, a manual address, or a database upload require confirming a
risk notice. Credentials are used once and never stored or logged, requests
never follow a redirect, and manual LAN addresses are limited to
administrators unless an administrator allows them for every account. - Kikoeru JSON files that use typed BJ, VJ, or CC numeric ids are now accepted
instead of rejected. - History and Recommendation are merged into History & recommendations,
which opens with a listening report for the last 30 days, the last 12
months, or all time. Totals, the activity chart, and most listened works
follow the chosen range; imported totals have no dates and count only in All
time. - Most listened works appear as ranked cover cards. The full listening history
is collapsed below the report and loads when opened. Recommendation activity
is shown as a report above the recommendation tuning.
Settings And Workflows
- The administration toggle is removed. Administrators see every Settings tab
in one row, with Library, Cache & Fetch, Cleanup, and Users grouped last
behind a shield icon. Your data moves to the end of Account; existing
links to the former tabs still open the right section. - Workflows groups the built-in workflows into Basic, Collect, Follow, and
Remote, chosen from an icon rail on wide layouts or an icon row on mobile.
An All entry lists every workflow.
Library Setup
- An instance that already ran v0.7.0 or later no longer reopens Set up
your library on every start when setup was postponed. Upgrades from
v0.6.1 or earlier and new installations still show it. - A new installation that restarts before finishing setup keeps setup pending
instead of switching to the Standard layout.
Maintenance
- The frontend build dependencies include the patched
brace-expansion
release for current npm audit advisories.
v0.7.0
Warning
English: v0.7.0 removes custom workflows. A migration tool preserves
definitions and triggers for review and can convert exact preset matches,
but it cannot guarantee a complete reproduction of your workflows. If you
use custom workflows, back up config/ before upgrading.
**简体中文:**v0.7.0 移除了自定义工作流。迁移工具会保留定义和触发器供检查,
并可转换与内置预设完全匹配的工作流,但不能保证完整复现原有工作流。
如果使用了自定义工作流,请在升级前备份 config/。
**繁體中文:**v0.7.0 移除了自訂工作流程。遷移工具會保留定義與觸發器供檢查,
並可轉換與內建預設完全相符的工作流程,但無法保證完整重現原有工作流程。
如果使用了自訂工作流程,請在升級前備份 config/。
**日本語:**v0.7.0 ではカスタムワークフローを削除しました。移行ツールは定義と
トリガーを確認用に保存し、組み込みプリセットと完全に一致するものは変換できますが、
元のワークフローを完全に再現できる保証はありません。カスタムワークフローを
使用している場合は、アップグレード前に config/ をバックアップしてください。
한국어: v0.7.0에서 사용자 지정 워크플로를 제거했습니다. 마이그레이션 도구는
정의와 트리거를 검토할 수 있도록 보존하고 기본 프리셋과 정확히 일치하는 항목을
변환할 수 있지만, 기존 워크플로의 완전한 재현은 보장하지 않습니다. 사용자 지정
워크플로를 사용 중이라면 업그레이드 전에 config/를 백업하세요.
Important
Upgrade notes. Back up config/ before upgrading. Keep the existing
data/ mount; the version upgrade does not require copying it.
Existing v0.6.1 databases advance from schema 034 through numbered migrations
035–044; fresh installs use baseline/044_v0.7.0.sql. Do not replace an
existing database with a fresh-install baseline.
Migration 035 removes user-authored workflow definitions and triggers. The
upgrade hook preserves them for review before applying that migration, but
instances that already passed 035 need a pre-035 database backup to recover
definitions removed by an earlier build. Run history remains in Activity.
Migration 038 adds a derived card-summary cache for
metadata snapshots and queues every existing snapshot. The server fills it in
small background batches after startup; lists stay correct while it drains.
Migration 039 disables every Follow a circle, Follow a series, and Follow a
voice actor trigger, because their options changed (Track, Fetch, the new
works switch, and the metadata refresh choice were removed). Each disabled
trigger shows that it needs reconfiguring: open it, check its Run options,
save it, and turn it on again. Manual runs are unaffected.
Migration 041 adds the creator lookup expression indexes and the missing
foreign-key child indexes used by cleanup cascades.
By default KIKOTO_ROOT_PASSWORD no longer sets the administrator password on
every start. Existing accounts keep their current passwords, so the root
account still signs in with the last applied value and can now change it in
Settings. Remove KIKOTO_ROOT_PASSWORD from .env; Kikoto logs a warning
while it is set. To keep the previous behavior, set
KIKOTO_ROOT_ACCOUNT_MODE=environment instead. Update docker-compose.yml
either way, because the previous file neither passes the new variables nor
starts without KIKOTO_ROOT_PASSWORD.
Migration 040 signs everyone out once, in browsers and in the Android app,
because sessions are now stored as digests and the existing plaintext
sessions are deleted. Sign in again after upgrading.
Migration 042 keeps only the two latest stored snapshots of each circle,
which may make the database noticeably smaller after the next Compact
database. The first start after upgrading re-derives voice credits and
circles from every work's metadata once in the background; later starts and
metadata syncs only process works whose metadata changed.
Migration 043 adds durable account-owned listening history without inferring
duration for old play events. Migration 044 stores preserved workflow review
data and resumable library-layout migration state.
Kikoto v0.7.0 replaces custom workflow editing with built-in presets and
adds library storage pools, first-run setup, database backups, personal data
transfer, and persistent listening history. It also improves Fetch recovery,
search, playback, and startup performance.
Custom Workflow Migration
- The custom workflow canvas, user-authored definitions and triggers, slash
commands, and definition run dialog are removed. Built-in workflows remain
available for manual runs and automation. - During an upgrade from a pre-035 database, Kikoto saves user-authored
definitions and triggers for review before migration 035 deletes the active
copies. Exact preset matches can be converted into disabled triggers for
reconfiguration; other definitions can be exported. Run history remains
readable in Activity. Conversion does not promise equivalent behavior.
Personal listening and data
- Android pauses when headphones disconnect, including in the background, and
does not automatically resume on reconnection. - Sleep timers can rewind 0–120 minutes within the current track after pausing,
including finish-current-track, and preserve the rewound cursor. - Personal tag management supports rename, merge, delete and unused-tag cleanup for work,
circle and voice tags. New workflow defaults reuse tags without a date;
existing saved templates keep their behavior. - Listening history persists independently of 90-day recommendation cleanup.
Only measured listening contributes duration; remaining legacy play events
are preserved without inferred time. - Data transfer previews and imports versioned personal JSON and Kikoeru review
state, matching existing work codes and offering keep/overwrite choices.
Export contains personal work state, playlists and custom tags.
Accounts
-
Sign-in attempts are throttled, and Argon2id memory use is bounded during
password verification. -
A new production instance no longer needs a password in
.env. The web app
shows Set up Kikoto, and the first administrator is created with a
one-time setup token from the service log orconfig/setup-token, so a
client that can only reach the port cannot claim the instance. -
docker compose exec kikoto /app/kikoto admin reset-passwordresets a
forgotten administrator password from the host while Kikoto runs. It prints
a new password, restores the account as an enabled super administrator, and
signs it out everywhere. -
A reset targets the initial administrator by default. When it no longer
exists, the account must be named with--usernameor
KIKOTO_ROOT_USERNAME; the error lists the super administrators. A named
account must exist, exceptroot, which is created so an instance with no
usable administrator can still be recovered. -
Without shell access,
KIKOTO_ROOT_PASSWORD_RESET=trueapplies
KIKOTO_ROOT_PASSWORDonce at startup. Restarting with the same values does
not undo a password changed later in Settings. -
KIKOTO_ROOT_ACCOUNT_MODE=environmentkeeps the root account defined by
KIKOTO_ROOT_USERNAMEandKIKOTO_ROOT_PASSWORDon every start, as before,
and locks its password, role, enabled state, and deletion in the app. The
password reset switch and the reset command do not apply to that account. -
In the default
setupmode the initial administrator is managed like any
other super administrator: it can change its own password, and another super
administrator can change its role or delete it. -
New passwords must have at least 8 characters and must not be a value that
appeared in the documentation. -
The database and its backups store only a SHA-256 digest of each session
token, so a copied database or backup can no longer be used to sign in. -
The Android app is excluded from Android cloud backup and device-to-device
transfer, so its stored session no longer leaves the device in a backup. A
restored or transferred app asks for the server and sign-in again.
Workflows
- Follow a circle, Follow a series, and Follow a voice actor are organized as
Input, Filter, and Actions. Input is the target and the catalog refresh
(Incremental or Full). Filter holds a release date range and a work limit,
both off by default. Actions are Sync metadata for catalog works that lack it,
the tag, and for circles Check remote sources. - Without a filter, a follow syncs every catalog work that lacks metadata. The
trigger popover warns before saving an automated follow without a filter and
recommends turning one on. - Track and Fetch are no longer follow actions, and a follow no longer refreshes
the metadata of works that already have it. - Metadata sync can refresh all works, one circle's works, or one voice actor's
works, either only missing or outdated metadata or all of it. Scheduled
metadata sync triggers keep their previous behavior until edited. - The release date filter now uses the catalog's release date for works not yet
in the library, so a release range no longer filters out every new circle or
series work. - Circle and voice actor detail refreshes keep their behavior.
- A trigger popover that stays open while you select another workflow tab now
saves to the workflow it was opened for. Before, a new trigger could be
created on the other workflow, or an edited one moved there with options in
the wrong shape. - Recover stale workflow runs no longer disturbs a job that is still running:
it could return that job to the queue so it ran a second time, and it failed
queued jobs that could not resume, such as a database optimization. It now
requeues or fails only jobs with no running executor. - A job whose heartbeat is delayed, for example by a busy database, is no
longer returned to the queue while it is still running. - A job whose executor stopped without recording a result, including after a
transient source error, is now marked failed or retried instead of staying
running and blocking every other job until a restart. - The new Refresh local work files workflow, second after Scan local library,
indexes the media files inside discovered local work folders ahead of time.
Incremental covers folders that were never indexed and Full re-indexes every
local work. It runs manually or from a Startup or interval trigger. - Editing a trigger while its remote ...
v0.6.1
Important
Upgrade notes. Back up config/ and data/ before upgrading. v0.6.1
adds no numbered migrations and keeps schema 034. Existing databases start
without schema changes, and fresh installations continue to use
baseline/034_v0.6.0.sql. Do not replace an existing database with a
fresh-install baseline.
Note
Use docker compose up -d --pull always to upgrade the production stack;
restarting a container reuses its installed image. Update KIKOTO_IMAGE
first if it is pinned to an older release.
Warning
Planned change to custom workflows. The next release may remove custom
workflow editing and provide only built-in preset workflows. Custom
workflows currently have too many issues while offering limited flexibility,
which makes them costly to maintain.
Kikoto v0.6.1 refines the interface across Library, creators, Metadata,
Settings, and Workflows, adds an administrator Cleanup tab, and introduces a
beginner-friendly Windows deployment helper.
Library, Creators, And Player
- Show library source tabs and search on one row. Recently played opens from a
toolbar icon as a popover on desktop and a bottom sheet on mobile, refreshing
each time it opens. - Move detail back navigation into the sticky app header, showing the section
name and, on desktop, the current work, circle, or voice actor name. - Simplify Circles and Voice Actors with denser cards, a shared profile header,
and a work toolbar on detail pages that matches the Library. - Keep the page height stable when switching player modes. The full player
sizes artwork to the available stage, adds a desktop lyrics and queue column,
seekable lyrics, a short-landscape layout, and screen lyrics through Document
Picture-in-Picture, video Picture-in-Picture, or an Android overlay. - Reduce the favorites desktop header to two rows with a list dropdown.
Metadata And Settings
- Simplify the Metadata page with compact rows, segmented attention categories,
and a metadata settings dialog with a pinned save footer. - Add a Voice aliases view to Metadata for searching voice actors, adding and
removing aliases, merging duplicates, and undoing merges. Voice actor detail
links to this view instead of editing aliases in place. - Integrate the former Maintenance page into Settings with grouped sections and
save actions that enable only after a change. Remote sources appear as a
compact list with health and an enable switch that saves immediately. - Start a new remote source from one address; the server probes for a
Kikoeru-compatible works API and falls back to manual connection details. - Rework user management into a searchable, paginated list with inline enable
switches, a details dialog, and confirmed deletion. The environment-managed
root account cannot be edited, disabled, or deleted through the user API. - Scope recommendation telemetry to the signed-in user.
- Add an administrator Cleanup tab for transcode and managed media cache
cleanup, stale local paths confirmed missing on disk, orphaned snapshots,
unused tags, expired sessions, dismissed notifications, old workflow runs and
recommendation data, and database compaction. Path checks pause when the data
root appears unmounted.
Workflows And Activity
- Run workflow jobs one at a time and show Activity across all workflows, so a
job started from one workflow stays visible while another is open. - Simplify workflow pages with compact trigger and recent-run lists. Activity
rows show status, trigger, relative time, duration, and live job or Fetch
progress, including transfer rate and remaining time. - Run details list start, finish, duration, trigger, and steps, with a
collapsed diagnostic log that can be copied. Timestamps display in the
viewer's locale. - Require a configured remote source before running the remote popular
workflow.
Interface
- Share Dialog, Input, select, textarea, and segmented-control primitives for
consistent focus, labelling, Escape handling, and dark-mode native controls. - Polish sidebar grouping, mobile navigation, pagination, work cards, and
toasts, and use themed glass tokens in the player. - About now credits development assistance from AI agents and lists the models
used in each release range.
Windows Helper
- Add
kikoto-helper.cmdfor beginner Windows deployments. It selects English
or Simplified Chinese, checks Docker Desktop, downloads versioned Compose
files, creates runtime directories, and configures the administrator
password. - Manage additional media-folder mappings and provide start, stop, upgrade,
status, logs, recreation, and configuration-backup actions. Existing.env
and Compose files are kept on re-runs.
v0.6.0
Important
Upgrade notes. Back up config/ and data/ before upgrading. Releases
v0.5.0 through v0.5.5 use schema 032; v0.6.0 applies numbered migrations
033_metadata_sync_issues.sql and 034_user_preferences.sql on startup.
Existing databases retain their works, user state, and workflow history.
Fresh installations use baseline/034_v0.6.0.sql. The original snapshot was
mislabeled 034_v0.5.5.sql; its filename and checksum remain accepted for
existing databases after the naming correction. Do not replace an existing
database with a fresh-install baseline.
Note
Use docker compose up -d --pull always to upgrade the production stack;
restarting a container reuses its installed image. Update KIKOTO_IMAGE
first if it is pinned to an older release. When upgrading from before
v0.5.0, run the complete Sync work metadata workflow after startup to
refresh the multilingual metadata projection. Optional first-run source
configuration belongs in config/remote-sources.yml; the removed
KIKOTO_REMOTE_SOURCES_FILE setting is no longer read.
This corrected v0.6.0 publication replaces the original images and APK with
the mobile connection layout and baseline naming fixes. Existing v0.6.0 users
should pull the image again or download and reinstall the updated APK; the
application version remains unchanged.
Kikoto v0.6.0 brings account-backed playback and recommendation preferences,
dedicated Metadata management, workflow-scoped Activity, and more reliable
browser and Android playback. This summary covers changes since v0.5.0,
including the improvements previously shipped in v0.5.1 through v0.5.5.
Library And Work Detail
- Keep browse results visible during refreshes, restore scroll position before
the first frame, and retain recent mobile browse workspaces. Switching from
Local back to a remote source now reloads its works reliably. - Improve responsive work-detail layouts, show voice details before the works
list finishes loading, and keep metadata and playback state visible while
local media indexing runs. Unchanged folders retain their completed index. - Present Origin metadata first while retaining the selected language, favor
local editions in local contexts, and distinguish metadata-only editions
from playable files. Translated works appear under their origin circle
without creating duplicate work identities. - Open the playing track's folder when entering the actively playing work;
later manual navigation remains under the listener's control. Re-selecting
a default folder reliably opens it again. - Reduce large-library read work by paging before expanding summaries,
batching voice credits, and aggregating recommendation evidence before
scoring. Recommendation snapshots retain stable ordering per client session. - Decode common legacy text encodings for local and remote previews without
rewriting the original file.
Settings And Interface
- Organize Settings into Account, Playback, and Recommendation. Folder
preference rules, recommendation tuning, and badge thresholds are stored
per account and shared across devices. Accounts without overrides and
anonymous browsing retain the existing instance defaults. - Saving recommendation settings refreshes the current tab's recommendation
session while other tabs retain their snapshots. Restoring defaults now
resets both scoring weights and the badge threshold before saving. - Simplify Maintenance to Library, Cache & Fetch, and Users, with storage paths
under Library and instance access controls under Users. Legacy settings and
maintenance links redirect to their new destinations. - Expand English, Simplified Chinese, Traditional Chinese, Japanese, and
Korean interface coverage. Load locale surfaces and secondary controls on
demand to reduce initial frontend work. - Align UI language, Mode, Style, and Color in the Appearance menu. About uses
an update icon when a newer release is available. Refresh the README showcase
with the current Metadata sidebar entry and official application icon.
Metadata And Scans
- Add a dedicated Metadata page for saved work families, with All, Needs
attention, Metadata issues, and No available source views. Search, paging,
selection, and edition/provider details share one family-level list. - Retry selected metadata issues, recheck missing sources, and review eligible
no-source deletions with server-side availability checks. Metadata settings
open in a dialog that preserves the current list; the sync shortcut opens
the existing workflow. - Track metadata and cover failures separately, preserve known metadata and
manual overrides on failure, and clear only resolved issues after success.
Overlapping family syncs are coordinated within one server instance, and
stale results cannot overwrite newer successful metadata. - Link Activity runs to their outstanding metadata issues without rewriting
execution history or another user's review state. Existing structured
unavailable-product observations enter the recovery list during migration;
historical free-text errors remain in Activity. - Offer an initial metadata-sync prompt after a local scan discovers works
without metadata. Bulk sync now also populates voice actor records. Local
duration probes share a bounded worker and resume pending work on startup.
Workflows
- Use horizontal workflow tabs and filters, with an Activity panel scoped to
the selected workflow. Active runs, Needs attention, History, and run details
remain in the same panel; mobile uses a sheet. - Open the same Activity surface from account actions, notifications, and
legacy Activity links. Run links resolve the relevant workflow before
loading history, and workflow links override an older saved selection. - Stabilize canvas connections and connector geometry. Wheel zoom now
requires a modifier, allowing ordinary scrolling through the page.
Playback And Android
- Prefer direct range playback for compatible local and cached audio. Offer
compatibility playback for a track, queue, or future playback when direct
decoding fails, while missing files continue through source fallback. - Prepare incompatible local or cached audio as complete MP3 files with
duration and HTTP Range support, restoring seekable compatibility playback.
Incompatible video uses a complete HLS VOD timeline with segments generated
on demand. Both use the bounded, rebuildable transcode cache; original media
remains unchanged, and remote proxy playback stays separate. - Configure backward and forward seek intervals from 1 to 300 seconds, with
defaults of 10 and 30 seconds, across player buttons, keyboard shortcuts,
browser Media Session, and Android controls. - Authenticate Android same-server media and protected assets, improve byte
range validation, avoid duplicate seeks, and stabilize HLS playback and
native queue/position updates. Use the project icon in the native splash. - Update Capacitor to 8.5.2, incorporating the Android 10 keyboard-insets fix.
Improve server connection setup and retain default HTTP/HTTPS ports when
editing a saved connection. Health checks omit credentials, and switching
server identity clears the previous session before connecting. - Keep the connection form within narrow mobile screens, with a full-width
address field and protocol and port controls below, retaining 44px touch
targets without horizontal overflow.
Sources, Cache, And Fetch
- Coordinate cache and Fetch writes to the same path, protect active Fetch
inputs from cleanup, re-download stale cache hits, and enforce cache limits
after publication. Explicit replacements are honored even when sizes match
or are unknown; staged content is reused only with a verified manifest. - Improve cancellation of queued source requests, isolate playback capacity,
and reuse bounded transports while retaining origin, redirect, credential,
and DNS-pinning checks. Validate remote cover file signatures and serve
cached covers with explicit raster content types and restrictive headers. - Give Demo its own read-only startup orchestration, bounded language-edition
admission, and remote-only playback without creating a local work solely
for catalog discovery.
Operations, Development, And Docs
- Keep Docker image pulls explicit and support Compose path overrides through
.env. Clarify remote API base URLs and reorganize deployment and user docs. - Tighten production mobile CORS origin validation and update vulnerable
frontend dependencies. Production playback requires FFmpeg and FFprobe;
both are included in the official container image. - Add multilingual READMEs and user guides, documentation link/locale checks,
and UI copy validation. Remove the resolved Android 10 warning from README. - Expand behavioral regression coverage for playback, metadata recovery,
settings, browsing, migrations, and Android. Reuse isolated test schemas and
split CI checks by workload, with path-based planning for pull requests. - Exercise built production images through authentication, local scan, and
range playback. Release publication continues to require successful CI for
the exact tagged commit; local validation uses the corresponding Make targets.
v0.5.5
Important
Upgrade notes. v0.5.5 adds no numbered database migration. Existing
databases remain on schema 032, and fresh installations continue using
baseline/032_v0.5.0.sql. An upgrade from v0.5.4 can start normally. When
upgrading directly from a release older than v0.5.0, run the complete
Sync work metadata workflow after startup so existing works receive the
current multilingual metadata projection.
Kikoto v0.5.5 expands multilingual interface and documentation coverage, fixes
workflow canvas and navigation behavior, tightens production mobile CORS
validation, and improves release validation.
Interface And Languages
- Expanded English, Simplified Chinese, Traditional Chinese, Japanese, and
Korean translations across Library, Favorites, creator pages, work details,
Sources, Workflows, Maintenance, user management, and playback controls. - Localized more permission messages, notifications, remote Fetch review
surfaces, and the offline page. API error toasts use stable error codes to
select translated messages while keeping diagnostic details out of UI copy. - About now records the development model history: GPT-5.5 for v0.1.0,
GPT-5.6-sol from v0.1.1 through v0.5.4, and GPT-6-Astra starting with v0.5.5.
Workflows
- Fixed missing or unstable canvas connections by synchronizing nodes and
ports before rendering edges, refreshing connector geometry, and fitting
the viewport after layout is ready. Editor and run canvases use the
supported default edge renderer. - Workflow links now take precedence over a previously saved selection, so
opening a linked workflow reliably selects the intended definition.
Operations And Reliability
- Tightened the built-in production mobile CORS exception to reject origins
containing ports, credentials, paths, queries, or fragments. Standard native
localhost origins remain supported; development-port origins no longer
qualify for that exception. - Updated Vitest, its coverage package, and affected transitive dependencies
to resolve dependency audit findings.
Development And Docs
- Added multilingual READMEs and user guides, with a language index and
dedicated English, Simplified Chinese, Traditional Chinese, Japanese, and
Korean documentation trees. Legacy product and getting-started entry points
direct readers to the reorganized guides. - Reorganized user, contributor, and security documentation, clarified
migration baseline reuse, and corrected case-sensitive translated links. - Added documentation locale checks and a UI copy check to help catch missing
guide pages and newly introduced untranslated interface text. - Hardened browser tests around accessible controls, navigation state, canvas
geometry, mobile layout, and real failure recovery. Dedicated desktop and
mobile Chromium projects cover the appropriate layouts, and source-text
checks no longer substitute for the affected user interactions. - Added Android JVM tests to local and CI validation, removed generated sample
tests, and synchronized Capacitor before JVM tests so clean checkouts have
the required native project configuration.
Known Issue
- Android 10 APK builds remain affected by the upstream Capacitor keyboard
insets issue. Browser use on Android 10 is not affected.
v0.5.4
Important
Upgrade notes. v0.5.4 adds no numbered database migration. Existing
databases remain on schema 032, and fresh installations continue using
baseline/032_v0.5.0.sql. An upgrade from v0.5.3 can start normally. When
upgrading directly from a release older than v0.5.0, run the complete
Sync work metadata workflow after startup so existing works receive the
current multilingual metadata projection.
Kikoto v0.5.4 improves audio startup and compatibility recovery, configurable
seeking, playback-aware work detail navigation, responsive detail layouts,
Demo remote playback, and recommendation generation performance.
Library And Work Detail
- Work detail now places work identity in a full-width desktop heading. Medium
layouts use two balanced columns, while wide layouts separate the cover,
identity metadata, and source metadata into three columns so notices,
version controls, and actions are no longer pushed below a tall cover. - Opening the detail page for an actively playing work selects its current
source and opens the playing track's folder. Paused or unrelated playback,
playback started after the page opens, and later manual source or edition
choices leave directory navigation under the user's control. - Recommendation snapshots now aggregate tag, voice, and circle evidence
before scoring the library. This removes repeated history scans during
generation while preserving the existing scores and immutable per-tab
recommendation behavior.
Playback
- Local and cached audio with a browser-oriented extension now starts through
direct range playback without waiting for FFprobe. Unsupported extensions
still enter compatibility conversion automatically. - When direct decoding fails for an existing local or cached file, the player
offers compatibility playback for the current track, current queue, or all
future playback. Confirmed missing files continue through normal source
fallback, and remote media remains outside the conversion path. - Backward and forward seek intervals are configurable in Settings from 1 to
300 seconds, defaulting to 10 and 30 seconds. The selected values apply to
player buttons, keyboard shortcuts, browser Media Session actions, and
Android media controls, scoped to the current server and user. - Playback speed and compatibility scope now share the player's More menu,
leaving the sleep timer directly available beside it. - Demo mode can now play an admitted remote-only work using the remote source's
filtered catalog decision, without requiring a localworkrow. - Android range playback now accepts valid partial responses whose proxy
Content-Lengthis inconsistent or whose total length is omitted, while
still validating the requested offset and bounding the returned stream.
Operations And Reliability
- Android launch now uses the platform splash-screen handoff with the Kikoto
icon, background, and post-launch theme, producing one consistent startup
surface across supported Android versions. - Vulnerable frontend transitive dependencies were updated, together with the
associated browser compatibility data.
Development And Docs
- Recommendation equivalence coverage verifies that aggregated snapshot
scoring matches the prior live calculation. Playback routing, seek
preferences, compatibility recovery, Android ranges, Demo remote playback,
and responsive work detail behavior also gained focused regression coverage. - Product documentation now records direct and compatibility audio behavior,
per-user seek settings, playback-aware directory routing, responsive detail
composition, and the measured criteria for a future large-library candidate
retrieval stage.
Known Issue
- Android 10 APK builds remain affected by the upstream Capacitor keyboard
insets issue. Browser use on Android 10 is not affected.
v0.5.3
Important
Upgrade notes. v0.5.3 adds no numbered database migration. Existing
databases remain on schema 032, and fresh installations continue using
baseline/032_v0.5.0.sql. An upgrade from v0.5.2 can start normally. When
upgrading directly from a release older than v0.5.0, run the complete
Sync work metadata workflow after startup so existing works receive the
current multilingual metadata projection.
Kikoto v0.5.3 improves seekable video playback, Android range handling, local
library responsiveness, and Android release validation.
Library And Work Detail
- Re-selecting the current default folder now reliably requests the folder
again, including when the route path itself has not changed. - Library browse state restores its saved scroll position before the first
frame after returning, reducing visible layout jumps on mobile and desktop. - Mobile retains the two most recently used browse workspaces while desktop can
retain all four, bounding hidden DOM and unfinished request work without
losing recent navigation state. - Lazy local-folder indexing preserves a completed file-tree index when the
folder is unchanged, reconciles missing locations more carefully, and keeps
work-detail playback state stable while indexing is in progress. - Voice detail metadata is displayed as soon as it is available instead of
waiting for the associated works list to finish loading.
Playback
- Incompatible local and cached video now uses a complete seekable HLS VOD
timeline. Six-second H.264/AAC segments are generated on demand under the
rebuildable transcode cache, allowing a later seek without transcoding every
preceding segment. - HLS generation is bounded by segment size, duration, concurrency, and an
independent LRU quota that can be inspected, limited, or cleared from
Maintenance. Audio conversion remains a direct MP3 response stream. - Android media requests now validate requested and returned byte ranges,
disable transparent compression for ranged responses, and avoid duplicate
seeks. Native playback also handles HLS segments with an appropriate timeout
and more stable queue and position updates.
Operations And Reliability
- The CI and release workflows use the complete Temurin LTS build identifier,
so Android jobs can resolve Java correctly on runners without a warm tool
cache. - Playback and transcode cache cleanup now reports its usage and protects
active generated data while bounded maintenance work runs.
Development And Docs
- Playback, cache, architecture, and settings documentation now describe the
seekable HLS path and its independent cache policy. The README also includes
an updated project showcase image.
Known Issue
- Android 10 APK builds remain affected by the upstream Capacitor keyboard
insets issue. Browser use on Android 10 is not affected.
v0.5.2
Important
Upgrade notes. v0.5.2 adds no numbered database migration. Existing
databases remain on schema 032, and fresh installations continue using
baseline/032_v0.5.0.sql. An upgrade from v0.5.1 can start normally. When
upgrading directly from a release older than v0.5.0, run the complete
Sync work metadata workflow after startup so existing works receive the
current multilingual metadata projection.
Kikoto v0.5.2 improves media compatibility, translated-work circle
projections, responsive browsing, initial load performance, and release
validation.
Library And Work Detail
- Library, Favorites, Circles, and Voice Actors keep their existing results
visible during refreshes and show a non-blocking status indicator instead of
shifting the browse layout. - Mobile library search can be hidden and reopened without losing its query or
browse scope. Selection controls remain anchored inside the usable viewport,
support keyboard navigation, and do not resize or scroll-lock fixed mobile
surfaces. - Catalog-only work cards now receive a stable empty source-tag collection,
keeping source badges predictable when no media location is available.
Sources And Remote Fetch
- Circle catalog discovery now projects translated editions to the circle that
owns the canonical origin work while retaining the source party and provider
provenance. Translation-only parties are filtered from ordinary catalog
actions, and custom circle workflows use the same visibility boundary.
Metadata And Scans
- Translation classification uses persisted edition metadata and origin maker
relationships rather than a hard-coded provider party. Origin circles can
therefore receive translated catalog works without creating a second work
identity.
Playback
- Local and cached media is inspected with FFprobe. Browser-compatible formats
stream directly with range support; other supported audio and video files are
converted by FFmpeg in real time to an MP3 or fragmented H.264/AAC stream,
without creating a playback derivative under/cache. - The player reports browser audio and video capabilities when selecting a
stream and retries local or cached playback through realtime conversion when
native playback cannot open the source. Converted streams are bounded and do
not provide random range seeking. - Tracked remote and remote-preview media is proxied through the configured
source policy without exposing the upstream URL. Range and conditional
request headers are forwarded, while remote playback remains separate from
both FFmpeg conversion and the optional remote-source cache workflow. - The production image includes
ffmpegandffprobe; other deployments must
provide both binaries on the backend processPATH.
Operations And Reliability
- The application icon is now consistent across the web app, PWA assets,
Android resources, and project documentation. - Canonical validation now includes cross-platform Go formatting and pinned
Go lint checks. Android dependency verification also covers IDE-resolved
source and sample artifacts, while CI formatting and player E2E checks are
robust to Windows line endings and stream query parameters. - Locale resources, the command palette, and workflow launch dialog are loaded
on demand so the initial frontend bundle contains less inactive code. - Frontend class-name helpers now apply Tailwind conflict merging only at
component override boundaries, reducing unnecessary styling work while
preserving caller overrides.
Known Issue
- Android 10 APK builds remain affected by the upstream Capacitor keyboard
insets issue. Browser use on Android 10 is not affected.
v0.5.1
Important
Upgrade notes. v0.5.1 adds no numbered database migration. Existing and
new databases remain on schema 032, and fresh installations continue using
baseline/032_v0.5.0.sql. When upgrading with the default Docker Compose
file, run docker compose up -d --pull always; an ordinary restart reuses the
installed image. The removed KIKOTO_REMOTE_SOURCES_FILE setting is no
longer read: place an optional first-run seed at
config/remote-sources.yml instead.
Note
When upgrading directly from a release older than v0.5.0, the v0.5.0
existing-library metadata refresh is still required. After startup, run the
complete Sync work metadata workflow from Workflows so existing works
receive the multilingual metadata projection.
Kikoto v0.5.1 improves work-detail metadata accuracy, authenticated Android
playback, cache and Fetch reliability, Demo startup, and release operations.
Library And Work Detail
- Work detail now places the provider-declared Origin metadata variant first
while retaining the configured language as the active selection. Local
contexts prioritize editions with local folders or media, and the expanded
selector distinguishes local, remote, metadata-only, and unavailable
editions without implying playback availability. - A persisted work now reports whether metadata has never been synchronized or
the provider has no record. Authorized users can start metadata sync from the
detail page, which refreshes metadata and media state when the workflow
completes. - Favorites no longer reloads its work list when file-source discovery leaves
the active source filters unchanged. - Local and remote text previews decode byte-order marks, declared charsets,
and common legacy encodings to UTF-8 on demand without rewriting the source
file.
Playback, Cache, And Fetch
- The Android client now authenticates same-server media streams, covers,
manual assets, text previews, and downloads through a bounded native
transport. Redirects remain confined to the configured server, and native
playback can fall back to another available local, cache, or remote location
when one location fails. - Remote playback cache controls are now instance-wide. Enabling the cache
explains its tracked-sync behavior separately from Fetch, while active Fetch
inputs are protected from cleanup and stale cache hits are downloaded again. - Cache and Fetch writes to the same path are coordinated, and cache limits are
enforced after Fetch publication so an earlier item cannot evict a later
input. Workflow progress now uses a reconnectable durable event stream with
polling fallback.
Demo And Metadata
- Demo startup initializes the current system workflow definitions for
read-only inspection while running only the dedicated Demo admission scan;
production startup triggers and background jobs remain disabled. - Demo metadata sync now follows provider-declared language editions within a
bounded family, applies the all-ages and permanently-free policy to every
edition independently, and treats an unavailable optional edition as absent
metadata rather than a failed scan.
Operations And Reliability
- Production Compose now makes image updates explicit: ordinary restarts keep
the installed image, while install and upgrade commands use
--pull always. CORS allowed origins are also passed through the production
and development Compose stacks. - First-run remote-source seeding uses the standard mounted configuration path
instead of a redundant environment-variable path setting. - Built-in public endpoints and official project links now have centralized,
tested ownership, and the About page presents clearer credits and references. - Repository validation is available through canonical Make targets with
sensitive-data scanning. Release builds reuse the successful ordinary CI run
for the exact tagged commit before publishing Docker or Android artifacts.
Known Issue
- Android 10 APK builds remain affected by the upstream Capacitor keyboard
insets issue described in the README. Browser use on Android 10 is not
affected.