semantic-release-bot
006b7c4509
chore(release): 0.16.0 [skip ci]
...
# [0.16.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.15.0...v0.16.0 ) (2026-03-28)
### Features
* add password generator and browser save prompt on change-password page ([7c76c2a ](https://github.com/siddharthksah/Stirling-Image/commit/7c76c2a2a0116de8418b0438a3859fc1add419e3 ))
2026-03-28 06:13:13 +00:00
semantic-release-bot
21675623e7
chore(release): 0.15.0 [skip ci]
...
# [0.15.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.14.2...v0.15.0 ) (2026-03-28)
### Features
* add forced password change page on first login ([01cd1d9 ](https://github.com/siddharthksah/Stirling-Image/commit/01cd1d9f71427319284579b438ad08ede56517a6 ))
2026-03-28 06:02:41 +00:00
semantic-release-bot
1c8a6f10c8
chore(release): 0.14.2 [skip ci]
...
## [0.14.2](https://github.com/siddharthksah/Stirling-Image/compare/v0.14.1...v0.14.2 ) (2026-03-28)
### Bug Fixes
* **tests:** remove temp DB cleanup that races with other test files ([b08e006 ](https://github.com/siddharthksah/Stirling-Image/commit/b08e006512744f13b893e92e9ac20ee6299ab41c ))
2026-03-28 04:49:54 +00:00
semantic-release-bot
a0f68465ac
chore(release): 0.14.1 [skip ci]
...
## [0.14.1](https://github.com/siddharthksah/Stirling-Image/compare/v0.14.0...v0.14.1 ) (2026-03-28)
### Bug Fixes
* handle migration race condition in concurrent test workers ([ce51065 ](https://github.com/siddharthksah/Stirling-Image/commit/ce5106524333b9bc7ee214b699d76e4b52371519 ))
2026-03-28 03:46:26 +00:00
Siddharth Kumar Sah
ce51065243
fix: handle migration race condition in concurrent test workers
...
Drizzle's migrate() throws when multiple vitest workers race to apply
migrations on the same temp database. The DrizzleError wraps a
SqliteError ("table already exists") in its cause chain. Add a
same-process guard and a catch that checks both the outer message and
cause for "already exists" so the second worker continues safely.
2026-03-28 11:45:54 +08:00
semantic-release-bot
fb7077cf16
chore(release): 0.14.0 [skip ci]
...
# [0.14.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.13.1...v0.14.0 ) (2026-03-28)
### Features
* multi-arch Docker support, security hardening, and test improvements ([6cfa3b0 ](https://github.com/siddharthksah/Stirling-Image/commit/6cfa3b0c38d81a19b230e1bdbad750dce2783afb ))
2026-03-28 03:19:36 +00:00
Siddharth Kumar Sah
6cfa3b0c38
feat: multi-arch Docker support, security hardening, and test improvements
...
Remove hardcoded --platform=linux/amd64 from Dockerfile so buildx produces
native arm64 images for Apple Silicon and Raspberry Pi. Add audit logging
for auth events, harden file storage with extension whitelists and
double-extension attack prevention, reject null-byte buffers in validation,
add data-testid attributes to all tool settings components, update
deployment docs with architecture notes and correct CI workflow references,
and fix unit test mock to match throwWithMessage error extraction.
2026-03-28 11:19:09 +08:00
semantic-release-bot
8f09c0678b
chore(release): 0.13.1 [skip ci]
...
## [0.13.1](https://github.com/siddharthksah/Stirling-Image/compare/v0.13.0...v0.13.1 ) (2026-03-27)
### Bug Fixes
* **docs:** remove hero logo from home page ([d3f6bac ](https://github.com/siddharthksah/Stirling-Image/commit/d3f6bac62b7e01e3a39371a1a52d865909412117 ))
2026-03-27 12:55:10 +00:00
semantic-release-bot
55df7dd768
chore(release): 0.13.0 [skip ci]
...
# [0.13.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.12.1...v0.13.0 ) (2026-03-27)
### Features
* **docs:** add gem logo to GitHub Pages nav bar and home hero ([98478e2 ](https://github.com/siddharthksah/Stirling-Image/commit/98478e271934c8b3deb1b3003d88fe1a165e75a0 ))
2026-03-27 12:52:29 +00:00
semantic-release-bot
10b15bf838
chore(release): 0.12.1 [skip ci]
...
## [0.12.1](https://github.com/siddharthksah/Stirling-Image/compare/v0.12.0...v0.12.1 ) (2026-03-27)
### Bug Fixes
* **docs:** clean up footer llms.txt links ([a4d4d36 ](https://github.com/siddharthksah/Stirling-Image/commit/a4d4d368286a80decf73563ca6d7e7cae119099a ))
2026-03-27 09:11:21 +00:00
semantic-release-bot
efc96f98c4
chore(release): 0.12.0 [skip ci]
...
# [0.12.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.11.1...v0.12.0 ) (2026-03-27)
### Bug Fixes
* **api:** resolve team name lookup and show server error messages ([620b8ad ](https://github.com/siddharthksah/Stirling-Image/commit/620b8ad038506a03633ab9baf738c6c316fa4336 ))
### Features
* **docs:** add llms.txt links to GitHub Pages footer ([c59e4a0 ](https://github.com/siddharthksah/Stirling-Image/commit/c59e4a06686db62ad8ec134ec1c97080673fbcb3 ))
2026-03-27 08:42:16 +00:00
Siddharth Kumar Sah
620b8ad038
fix(api): resolve team name lookup and show server error messages
...
- Backend: look up teams by name first (frontend sends name, not ID)
- Frontend: parse response body on API errors instead of showing
generic "API error: 400" — now shows the actual server message
(e.g. "Password must be at least 8 characters...")
2026-03-27 16:41:44 +08:00
semantic-release-bot
b5721d9854
chore(release): 0.11.1 [skip ci]
...
## [0.11.1](https://github.com/siddharthksah/Stirling-Image/compare/v0.11.0...v0.11.1 ) (2026-03-27)
### Bug Fixes
* **docs:** ignore localhost dead links in VitePress build ([5c4b2a5 ](https://github.com/siddharthksah/Stirling-Image/commit/5c4b2a59d3a9f1fa2dd428fd626f2bbbb9e3fea6 ))
2026-03-27 05:54:02 +00:00
semantic-release-bot
355022d374
chore(release): 0.11.0 [skip ci]
...
# [0.11.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.10.0...v0.11.0 ) (2026-03-27)
### Bug Fixes
* **a11y:** add aria-hidden to decorative GemLogo SVG ([d47548a ](https://github.com/siddharthksah/Stirling-Image/commit/d47548a1d7d2de995c881465b79a463de20354df ))
* **api:** allow Scalar docs through auth and CSP ([a46d500 ](https://github.com/siddharthksah/Stirling-Image/commit/a46d500012e1f0724038c695a17e7dafd9be0c40 ))
* **api:** use content instead of spec.content for Scalar v1.49 API ([05854fd ](https://github.com/siddharthksah/Stirling-Image/commit/05854fd61f90a1096e1682ad021d744d178d9b9b ))
* **ui:** clean up settings, automate page, fullscreen logo, and README ([e3a8558 ](https://github.com/siddharthksah/Stirling-Image/commit/e3a85581349b6a992939b08ede932705613d915f ))
### Features
* **api:** add all remaining endpoints to OpenAPI spec ([9ed1090 ](https://github.com/siddharthksah/Stirling-Image/commit/9ed109065189f20545eb24893c2c0b9332e40249 ))
* **api:** add all tool endpoints to OpenAPI spec ([2bf8689 ](https://github.com/siddharthksah/Stirling-Image/commit/2bf86894d0005ff4c273334699c30de1fcb38ee6 ))
* **api:** add llms.txt and llms-full.txt endpoints ([cff1930 ](https://github.com/siddharthksah/Stirling-Image/commit/cff1930920c488fc853eab5aa36128fac19b3bf5 ))
* **api:** add OpenAPI 3.1 spec skeleton with common schemas ([9488201 ](https://github.com/siddharthksah/Stirling-Image/commit/948820180663783d463a07f966dd4336c1a7c503 ))
* **api:** add Scalar docs route and install dependency ([abb2916 ](https://github.com/siddharthksah/Stirling-Image/commit/abb2916233de85e62675e609b9d497dcc0a01882 ))
* **api:** register docs route in server and test helper ([849878e ](https://github.com/siddharthksah/Stirling-Image/commit/849878e72fc0e5cb3e775afeea802dac933c4e13 ))
* **branding:** add faceted gem SVG logo assets ([0214ac1 ](https://github.com/siddharthksah/Stirling-Image/commit/0214ac11b1ba4142349c09fd2465a425b4e8dd6b ))
* **branding:** add favicon and meta tags to index.html ([0364927 ](https://github.com/siddharthksah/Stirling-Image/commit/036492725eea6cb6b4c0aff307edeee8516ec280 ))
* **branding:** add OG social preview image ([dcd926c ](https://github.com/siddharthksah/Stirling-Image/commit/dcd926c57e9877c2b47e70c494b679f0c00d93d6 ))
* **branding:** add PWA manifest and PNG logo assets ([26cc183 ](https://github.com/siddharthksah/Stirling-Image/commit/26cc18342fb6d4027f2130b198090469e27ef797 ))
* **branding:** show gem icon in app header as default logo ([39dfb93 ](https://github.com/siddharthksah/Stirling-Image/commit/39dfb93679765366253115240adcbc573e83b8e7 ))
* **docs:** add gem favicon to VitePress site ([42ec0f2 ](https://github.com/siddharthksah/Stirling-Image/commit/42ec0f2490267f2e3730764539bdd2920b7b3793 ))
* **docs:** add llms.txt and llms-full.txt to GitHub Pages ([e6dc7b0 ](https://github.com/siddharthksah/Stirling-Image/commit/e6dc7b0a18d3d022de4e2f0b971bf25678042b3a ))
2026-03-27 05:51:30 +00:00
Siddharth Kumar Sah
cff1930920
feat(api): add llms.txt and llms-full.txt endpoints
...
Serve LLM-friendly documentation at /llms.txt (index) and
/llms-full.txt (full API docs as markdown). Generated from the
OpenAPI spec at startup.
2026-03-27 13:50:04 +08:00
Siddharth Kumar Sah
9ed1090651
feat(api): add all remaining endpoints to OpenAPI spec
...
Add batch, pipeline, file, auth, API key, settings, teams, branding, and
system endpoints — bringing the total from 38 to 67 documented paths.
2026-03-27 13:50:03 +08:00
Siddharth Kumar Sah
2bf86894d0
feat(api): add all tool endpoints to OpenAPI spec
2026-03-27 13:50:03 +08:00
Siddharth Kumar Sah
05854fd61f
fix(api): use content instead of spec.content for Scalar v1.49 API
2026-03-27 13:50:03 +08:00
Siddharth Kumar Sah
9488201806
feat(api): add OpenAPI 3.1 spec skeleton with common schemas
2026-03-27 13:50:03 +08:00
Siddharth Kumar Sah
849878e72f
feat(api): register docs route in server and test helper
2026-03-27 13:50:03 +08:00
Siddharth Kumar Sah
a46d500012
fix(api): allow Scalar docs through auth and CSP
2026-03-27 13:50:03 +08:00
Siddharth Kumar Sah
abb2916233
feat(api): add Scalar docs route and install dependency
2026-03-27 13:50:03 +08:00
semantic-release-bot
d4d4321b98
chore(release): 0.10.0 [skip ci]
...
# [0.10.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.9.0...v0.10.0 ) (2026-03-26)
### Bug Fixes
* **ocr:** update PaddleOCR for v3 API and add Tesseract fallback ([f71c3c8 ](https://github.com/siddharthksah/Stirling-Image/commit/f71c3c8c05bc7203d37a46743bebb62b79c8ac51 ))
### Features
* **erase-object:** replace mask upload with in-browser brush painting ([40656a0 ](https://github.com/siddharthksah/Stirling-Image/commit/40656a0452109c1d6ea2441b2735b0ffaf4f3867 ))
2026-03-26 09:34:20 +00:00
semantic-release-bot
563892774d
chore(release): 0.9.0 [skip ci]
...
# [0.9.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.8.2...v0.9.0 ) (2026-03-26)
### Bug Fixes
* **blur-faces:** switch from MediaPipe to OpenCV and auto-orient images ([f15102c ](https://github.com/siddharthksah/Stirling-Image/commit/f15102c632d3fcbc5d33b33fd9cfdea5e4689eb6 ))
* **docker:** add build layer caching for faster Docker rebuilds ([14c630f ](https://github.com/siddharthksah/Stirling-Image/commit/14c630ff23d973aa9d512ed87ede049ebd4b600f ))
* **upscale:** auto-orient images before upscaling and improve UI ([8ee4d7b ](https://github.com/siddharthksah/Stirling-Image/commit/8ee4d7b2fb3f88b2869ada8d6a6c5fb0df432e3b ))
### Features
* **adjustments:** add real-time live preview for all color tools ([f357b18 ](https://github.com/siddharthksah/Stirling-Image/commit/f357b18ced8757da0a6c34f18541bb8875c2199a ))
* **image-to-pdf:** add live PDF page preview with margin visualization ([ddde152 ](https://github.com/siddharthksah/Stirling-Image/commit/ddde152545456770ec4a97418968c2ad309a88e0 ))
* **rotate:** add editable angle input and fine-tune +/- buttons ([bf62820 ](https://github.com/siddharthksah/Stirling-Image/commit/bf6282006489a4cadcd849b476e97239e3624673 ))
2026-03-26 08:02:46 +00:00
Siddharth Kumar Sah
f15102c632
fix(blur-faces): switch from MediaPipe to OpenCV and auto-orient images
...
Fix face detection failure caused by MediaPipe 0.10.33 removing the
mp.solutions API. Replace with OpenCV Haar cascade which works reliably
in headless Docker. Add autoOrient() call before detection to handle
EXIF-rotated phone photos. Remove technical jargon from UI.
2026-03-26 16:01:56 +08:00
Siddharth Kumar Sah
8ee4d7b2fb
fix(upscale): auto-orient images before upscaling and improve UI
...
Fix rotated output by calling autoOrient() before passing images to
the Python upscaler, correcting EXIF orientation metadata. Replace
2x/4x buttons with 2x-8x slider plus quick-select buttons (2x, 3x,
4x, 6x, 8x). Remove technical jargon about Real-ESRGAN/Lanczos from
the UI and progress bar.
2026-03-26 16:01:40 +08:00
semantic-release-bot
21e40f5bbf
chore(release): 0.8.2 [skip ci]
...
## [0.8.2](https://github.com/siddharthksah/Stirling-Image/compare/v0.8.1...v0.8.2 ) (2026-03-25)
### Bug Fixes
* **test:** add missing PNG fixture files to repo ([8474b0e ](https://github.com/siddharthksah/Stirling-Image/commit/8474b0ee52fe803c55247a082becc4334e83186f ))
* **test:** exclude e2e tests from vitest and fix CI test suite ([91acab9 ](https://github.com/siddharthksah/Stirling-Image/commit/91acab9967e2b5dd7dbc7a98e667f785f3e7364e ))
2026-03-25 17:33:09 +00:00
semantic-release-bot
bf23e83ef4
chore(release): 0.8.1 [skip ci]
...
## [0.8.1](https://github.com/siddharthksah/Stirling-Image/compare/v0.8.0...v0.8.1 ) (2026-03-25)
### Bug Fixes
* resolve test failures from shared DB race conditions ([b474480 ](https://github.com/siddharthksah/Stirling-Image/commit/b474480698695cda2eaf2c9ae642ac3ffd15d007 ))
2026-03-25 17:21:05 +00:00
Siddharth Kumar Sah
b474480698
fix: resolve test failures from shared DB race conditions
...
- Make ensureDefaultAdmin idempotent with onConflictDoNothing (fixes
UNIQUE constraint error when parallel test files share a DB)
- Move duplicate-username check before user-limit check so 409 takes
priority over 403
- Bump MAX_USERS from 5 to 50 (tests create ~15 users across files)
2026-03-26 01:20:29 +08:00
semantic-release-bot
170395ae40
chore(release): 0.8.0 [skip ci]
...
# [0.8.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.7.0...v0.8.0 ) (2026-03-25)
### Bug Fixes
* **docker:** skip husky prepare script in production install ([200e7d1 ](https://github.com/siddharthksah/Stirling-Image/commit/200e7d10c1cbffeeeae95434b4ae8f2d6b69b8a0 ))
* prevent useAuth infinite loop causing rate limit storms ([3b4f522 ](https://github.com/siddharthksah/Stirling-Image/commit/3b4f522bf4d63109254edc22baca568fdfd7dd98 ))
### Features
* **api:** add logo upload/serve/delete routes with tests ([6a13065 ](https://github.com/siddharthksah/Stirling-Image/commit/6a1306570660d4962f89e741dfb684d2ed0e7f6c ))
* **api:** add persistent file management helpers to frontend api module ([8a3a731 ](https://github.com/siddharthksah/Stirling-Image/commit/8a3a731267f4e3cd84a01a78d89975197ce2ebad ))
* **api:** add teams CRUD routes and update auth team references ([ab370a7 ](https://github.com/siddharthksah/Stirling-Image/commit/ab370a74fefebc8735e337f9b42e48ab6625c5b4 ))
* **api:** add tool filtering and DB-backed cleanup settings ([acfff75 ](https://github.com/siddharthksah/Stirling-Image/commit/acfff754b54b5f9be474c6db6eb39b3cbf91fc21 ))
* **api:** add user files CRUD routes at /api/v1/files/* ([4e2aa58 ](https://github.com/siddharthksah/Stirling-Image/commit/4e2aa5876701ef56514957a30fe63c27c615cf05 ))
* **db:** add teams table and migration ([926b52d ](https://github.com/siddharthksah/Stirling-Image/commit/926b52d33045dc1f15192bb65d4f005f6c82ce00 ))
* **db:** add userFiles table and migration ([dda37e9 ](https://github.com/siddharthksah/Stirling-Image/commit/dda37e90cc294140c236332563befae0a3b02852 ))
* **env:** add FILES_STORAGE_PATH config variable ([4927f57 ](https://github.com/siddharthksah/Stirling-Image/commit/4927f574badda883ad72ba05c30a8d9fae973ee6 ))
* **files:** add Files page with nav, list, details, upload, and routing ([788b8c8 ](https://github.com/siddharthksah/Stirling-Image/commit/788b8c8bad8cf6800137f4764f5a50ac80845f2f ))
* **files:** add mobile layout for Files page ([c99f43f ](https://github.com/siddharthksah/Stirling-Image/commit/c99f43fe60aac2a7babeb7cea39e140281936009 ))
* **files:** wire serverFileId for version tracking ([20f153d ](https://github.com/siddharthksah/Stirling-Image/commit/20f153d611c9dec478ab89cd050c6c65b0e41287 ))
* **i18n:** add translation keys for settings phase 1 ([ffb676d ](https://github.com/siddharthksah/Stirling-Image/commit/ffb676d648027804e653b868139f349b5a3c6c96 ))
* implement Files page with persistent storage and version tracking ([62fbb54 ](https://github.com/siddharthksah/Stirling-Image/commit/62fbb5484c669b74132b4ecd23576bf0ba5b50b2 ))
* **storage:** add file storage helpers module ([fbca20d ](https://github.com/siddharthksah/Stirling-Image/commit/fbca20d78c213e0b7f00f6c59eae4af32123a587 ))
* **stores:** add Zustand store for Files page state management ([24644c1 ](https://github.com/siddharthksah/Stirling-Image/commit/24644c1c1052146a2b581ffc3a791a9276fab6a1 ))
* **tool-factory:** auto-save results to persistent file store when fileId provided ([bf6c30c ](https://github.com/siddharthksah/Stirling-Image/commit/bf6c30c3c0d9beeaa24a7b7b998de9354ec7e353 ))
* **ui:** add teams, tools, feature flags, temp files, logo to settings dialog ([4b2621d ](https://github.com/siddharthksah/Stirling-Image/commit/4b2621d9f2c5fcc930baf9ed1a6b555de77f0b93 ))
2026-03-25 17:12:41 +00:00
Siddharth Kumar Sah
627ff8a82c
chore: remove internal docs from repo, update public documentation
...
Remove docs/superpowers/, .claude/ config, and PRD.md from version
control (kept locally via .gitignore). Update README, CHANGELOG,
VitePress docs, and .env.example to reflect recent features: Files
page, teams, admin settings, persistent storage, and various API
improvements.
2026-03-26 01:11:40 +08:00
Siddharth Kumar Sah
6a13065706
feat(api): add logo upload/serve/delete routes with tests
...
Add branding API at /api/v1/settings/logo supporting:
- POST: admin uploads PNG/SVG/JPEG (max 500KB), auto-converts to 128x128 PNG
- GET: public endpoint serves custom logo (404 if none)
- DELETE: admin removes custom logo
Includes 13 integration tests covering upload, conversion, size/type
validation, auth enforcement, resize, and idempotent deletion.
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
acfff754b5
feat(api): add tool filtering and DB-backed cleanup settings
...
Add feature flag support to skip disabled/experimental tools at startup
by reading disabledTools and enableExperimentalTools from the settings
table. Refactor cleanup.ts to read tempFileMaxAgeHours from DB settings
(with env var fallback) and respect the startupCleanup setting.
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
585d66f0c9
refactor: rename Tool.alpha to Tool.experimental
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
ab370a74fe
feat(api): add teams CRUD routes and update auth team references
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
62fbb5484c
feat: implement Files page with persistent storage and version tracking
...
Three-panel file manager (nav, list, details) modeled after Stirling-PDF.
- Backend: user_files table, /api/v1/files/* CRUD routes, file storage
helpers, thumbnail generation via Sharp, recursive CTE version chains
- Frontend: FilesNav, FileList, FileDetails, FileUploadArea components,
Zustand store, mobile layout with bottom sheet
- Integration: tool-factory auto-saves results as new versions when
fileId is provided, "Open File" loads file into tool processing flow
- Search, bulk select/delete/download, version badges, tool chain tags
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
926b52d330
feat(db): add teams table and migration
2026-03-26 01:10:51 +08:00
Siddharth Kumar Sah
bf6c30c3c0
feat(tool-factory): auto-save results to persistent file store when fileId provided
...
Adds optional fileId multipart field; when present, inserts a new versioned
userFiles record after successful processing and returns savedFileId in the
response. Non-fatal — tool processing succeeds even if the save fails.
2026-03-26 01:10:50 +08:00
Siddharth Kumar Sah
4e2aa58767
feat(api): add user files CRUD routes at /api/v1/files/*
...
Implements all 7 routes for the persistent file library:
list with pagination/search, upload (multi-file), details with recursive
version chain CTE, download stream, on-the-fly Sharp thumbnail, bulk delete
of entire version chains, and save-result for tool output versioning.
Registered in index.ts after fileRoutes.
2026-03-26 01:10:50 +08:00
Siddharth Kumar Sah
fbca20d78c
feat(storage): add file storage helpers module
...
Adds ensureStorageDir, saveFile, deleteStoredFile, and getStoredFilePath
utilities that manage the lifecycle of files on the local filesystem
under FILES_STORAGE_PATH.
2026-03-26 01:10:50 +08:00
Siddharth Kumar Sah
4927f574ba
feat(env): add FILES_STORAGE_PATH config variable
...
Adds a FILES_STORAGE_PATH env variable (defaults to ./data/files) to
control where uploaded user files are persisted on disk.
2026-03-26 01:10:50 +08:00
Siddharth Kumar Sah
dda37e90cc
feat(db): add userFiles table and migration
...
Introduces the user_files table to track uploaded files per user,
including metadata fields for dimensions, versioning, and tool chains.
2026-03-26 01:10:50 +08:00
semantic-release-bot
5d261398b1
chore(release): 0.7.0 [skip ci]
...
# [0.7.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.6.0...v0.7.0 ) (2026-03-24)
### Features
* harden auth, security headers, SVG sanitization, and pipeline ownership ([432cc92 ](https://github.com/siddharthksah/Stirling-Image/commit/432cc92471b73b73ab9d1be4a82a71d3ed3a88ad ))
* **pipeline:** add inline settings configuration for automation steps ([adc7e1c ](https://github.com/siddharthksah/Stirling-Image/commit/adc7e1c0370df1687b0660bdff279c90ac9d0871 ))
2026-03-24 13:38:48 +00:00
Siddharth Kumar Sah
432cc92471
feat: harden auth, security headers, SVG sanitization, and pipeline ownership
...
- Add password strength validation (8+ chars, uppercase, lowercase, number)
- Add username validation rules
- Optimize API key lookup with SHA-256 prefix (O(1) vs O(n) scan)
- Require password change on default admin first login
- Revoke API keys on password change
- Add session cleanup cron (hourly expired session purge)
- Add Permissions-Policy, HSTS, and CSP security headers in production
- Strengthen SVG sanitizer: block XInclude, foreignObject, processing
instructions, javascript/data/file URI schemes
- Add userId ownership to pipelines with authorization checks
- Add keyPrefix column to api_keys table
- Update integration tests for new auth behavior
2026-03-24 21:38:06 +08:00
semantic-release-bot
75f38a9fe2
chore(release): 0.6.0 [skip ci]
...
# [0.6.0](https://github.com/siddharthksah/Stirling-Image/compare/v0.5.2...v0.6.0 ) (2026-03-24)
### Features
* extract auto-orient utility and expand test coverage ([e5086ad ](https://github.com/siddharthksah/Stirling-Image/commit/e5086ada6e2f4402973f203b726578dd42da4a32 ))
2026-03-24 12:37:44 +00:00
Siddharth Kumar Sah
e5086ada6e
feat: extract auto-orient utility and expand test coverage
...
Extract EXIF auto-orientation logic into a shared auto-orient module
used by both single-tool and batch routes. This ensures camera photos
display correctly after processing regardless of entry point.
Also expands e2e and integration tests significantly.
2026-03-24 20:37:14 +08:00
semantic-release-bot
06eabdd045
chore(release): 0.5.2 [skip ci]
...
## [0.5.2](https://github.com/siddharthksah/Stirling-Image/compare/v0.5.1...v0.5.2 ) (2026-03-23)
### Bug Fixes
* restore APP_VERSION import used by health endpoint ([7dfa7a2 ](https://github.com/siddharthksah/Stirling-Image/commit/7dfa7a295de407f45832b68a2ef64acf2f21205f ))
2026-03-23 16:49:00 +00:00
Siddharth Kumar Sah
7dfa7a295d
fix: restore APP_VERSION import used by health endpoint
2026-03-24 00:48:36 +08:00
semantic-release-bot
3735a749d6
chore(release): 0.5.1 [skip ci]
...
## [0.5.1](https://github.com/siddharthksah/Stirling-Image/compare/v0.5.0...v0.5.1 ) (2026-03-23)
### Bug Fixes
* **crop:** use percentCrop from onChange to fix inflated pixel values ([fbdbe09 ](https://github.com/siddharthksah/Stirling-Image/commit/fbdbe0949a64d072e4e86d08c7b39372592eaf04 ))
2026-03-23 16:42:37 +00:00
Siddharth Kumar Sah
0aa2a5e5de
chore: remove swagger deps, parallelize CI jobs
...
- Remove @fastify/swagger and @fastify/swagger-ui (API docs live on GitHub Pages)
- Run typecheck, build, and docker CI jobs in parallel instead of sequentially
2026-03-24 00:41:54 +08:00