-
1.0.7
Pre-releasereleased this
2026-08-18 18:40:43 +01:00 | 49 commits to main since this releaseAdded
- Per-post ACL in PostIt: a new “Manage ACL” page, opened from the ACL
button on a selected post, lets the post author grant or revoke
grants for individuals or circles. The server scopes each grant
operation tocaller == post.AuthorIdand returns404(not403)
for posts the caller does not own, so the existence of another
user's post is not leaked. - Circle membership API + UI: three new REST endpoints under
/api/circle/{id}/members(GETlist,POSTadd,DELETE
remove) and a new “Members” column on the My Circles page with an
“Add a member” button that opens a search modal. The search modal
reusesIUserDirectory(introduced by theIContactServicesplit
in this same release) — exactly the use case the abstraction was
carved out for. - Publish toggle for blog posts: a new
PUT /api/BlogApi/{id}/publish
endpoint, and aPublishedcheckbox in the post toolbar that
toggles aBlogSpotPublicationrow for the post. The publish
signal flows through the pre-existingPermissionHandler.IsPublic
path, so no new column was needed and the server-side authorisation
logic is unchanged. UserSearchApiControllerinYavsc.Blogs:
GET /api/user-search?q=...&e=...&take=.... Any-authenticated-
caller endpoint that exposes the user's email under a closed-
community assumption (documented in the controller's XML doc).
Wired to the PostIt Desktop address book so the user search modal
picks it up.IYavscApiClientabstraction inYavsc.Api.Client. The transport
for the blog/circle/blog-acl/user-search clients is now accessed
through this interface, soPostIt.Testscan stub the HTTP layer
without spinning up a real WebAPI host.- Forgejo Actions release workflow: a
.forgejo/workflows/release.yml
pipeline that builds and publishes a release with the PostIt APK
on tag push. Written in pure bash (the runner image has no Node),
usesjqfor JSON body construction and response parsing, uses the
runner-providedGITHUB_TOKEN(no repo-level secret needed),
validates the CHANGELOG section heading before allowing the tag
to ship. make release V=<version>target: creates arelease/<V>branch
frommain, bumps the<Version>property in every.csprojvia
dotnet-gitversion /updateprojectfiles, commits the bump on the
release branch, and pushes toorigin. Fails fast if the working
tree is dirty or ifHEADis not onmain.- Forgejo status badges in the README.
Changed
- The new Publish toggle replaces the “Visibility enum” approach
originally drafted in this branch: the existingBlogSpotPublication
table already carried enough information to expose a publish
switch, so no schema change was needed. The originalfeat(blog): add Visibility { Private, Public }commit and its EF migration
were reverted in favour of the endpoint-only toggle. BlogPostDTO andIBlogPostmoved fromPostIt.Modelsto
Yavsc.Abstract.Blogspot, the shared assembly where the server-side
entity and the wire DTO both live. RenamedYavsc.Blogspot.BlogPost
toBlogPostDtoto make the wire/entity distinction explicit.BlogAclApiControllerandCircleApiControllermoved from
Yavsc.Api(not yet enabled in production) toYavsc.Blogs, where
they belong next to theBlogSpotServicethey depend on.IContactServicesplit fromIUserDirectory: the two interfaces
previously conflated the local address-book access (mobile-only,
viaContacts.Default) and the Yavsc user-search access
(Desktop-only, via/api/user-search) behind a single facade. The
split restores theContactDto.Emailsmulti-value shape that was
being silently flattened to a single string before.- CI: the Forgejo Actions build now compiles
.csprojprojects
directly inside the runner container (which ships the .NET SDK +
Android workload), instead of relying on a separate Docker build
step. Node-based third-party actions were replaced with bash + curljq. The validate-release job parses the CHANGELOG section
heading to derive the channel (stable/preview/unstable)
rather than the patch-version parity alone.
Fixed
CircleApiControllerused to read the caller's user id via
FindFirstValue(ClaimTypes.NameIdentifier), which does not match
when JWT Bearer middleware hasMapInboundClaims = false. Switched
toUser.GetUserId()(triessubfirst, then
ClaimTypes.NameIdentifier, thennameid). This was a latent
bug visible in tests but easy to ship to production if a host
ever disabled the remap.CircleApiControllerandBlogAclApiControllerreads and writes
were not always scoped to the caller's own data. Tightened the
authorisation checks: cross-user reads now return404, not the
raw record.validate-releaseCHANGELOG channel check used to parse the
patch-version parity only, which disagreed with the channel
suffix in the section heading (e.g.## [1.0.7] - preview
would be flagged asstablefrom the parity alone). The job now
inspects the heading line and trusts the suffix when present..forgejo/workflows/release.yml: the asset-upload URL now carries
the asset name as a query-string parameter instead of acurl
positional argument. The previous shape triggered Forgejo's
“Missingnameparameter” 400 in some cases.
Removed
- The
## [Unreleased]block has been moved into this section. - The abandoned
Visibility { Private, Public }enum and its EF
migration, reverted in this release. The publish toggle covers
the same user-visible switch without a schema change.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Per-post ACL in PostIt: a new “Manage ACL” page, opened from the ACL