Documents 1.0.0, 1.0.1 and the upcoming 1.1.0 in Keep a Changelog format. The tech stack table still claimed Laravel 12 and listed maennchen/zipstream-php, which was dropped in 1.0.1 when ZIP downloads moved to native ZipArchive. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
3.8 KiB
3.8 KiB
Changelog
All notable changes to this project are documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
Unreleased
1.1.0 - 2026-07-23
Changed
- Upgraded to Laravel 13 (
laravel/framework^13.0,laravel/tinker^3.0). PHP 8.5 is now the minimum. - Set
serializable_classestofalseinconfig/cache.php, so a leakedAPP_KEYcannot drive an object gadget chain through the cache. - Upgraded the frontend toolchain to match the Laravel 13 skeleton: Vite 8,
laravel-vite-plugin3, Tailwind CSS 4.3.3, DaisyUI 5.7, Alpine.js 3.15.12 and concurrently 10.
Fixed
- Adding a second batch of files to a share left the uploader stuck on "Processing files…" forever, with the drop zone and the "Create Share Link" button permanently disabled. The uploading state is now cleared by a
files-processedevent dispatched on every batch, instead of a one-offx-initthat only ran the first time the file list appeared. - Dropping files on the drop zone showed no upload progress at all, because
uploadMultiple()was called without progress callbacks. - Dropping a second folder onto an existing selection replaced the collected relative paths instead of appending them, which shifted every earlier file's path onto the wrong file.
Removed
- Dropped the unused
axiosdependency and the stale@rollup/rollup-linux-x64-gnuoptional pin (Vite 8 builds with rolldown).
Security
- Forced
shell-quoteto a patched release via an npm override, clearing GHSA-395f-4hp3-45gv (quadratic complexity DoS).npm auditreports 0 vulnerabilities, down from 3.
1.0.1 - 2026-02-25
Fixed
- ZIP downloads returned 0-byte archives under FrankenPHP. ZipStream writes through
fwrite(php://output), which FrankenPHP silently drops; downloads are now built with nativeZipArchiveand served as a file response. - Docker image was missing the PHP
zipextension required byZipArchive. - Stale
bootstrap/cache/*.phpfrom the build context could load dev-only service providers in the production image. DB_DATABASEnow defaults to/app/database/database.sqliteindocker-compose.yml, so theenv()fallback resolves correctly.- The unlock button on the password-protected share page rendered outside the form and did nothing. Share page action buttons are now consistently full width.
Removed
maennchen/zipstream-phpdependency.
1.0.0 - 2026-02-13
Added
- Initial release.
- File uploading via drag & drop or browse, supporting multiple files and folders with real-time progress.
- Shareable links, one unique link per upload.
- AES-256-GCM encryption at rest, chunked and streaming, with PBKDF2-SHA256 key derivation.
- Optional password protection per share.
- Configurable expiration from 1 hour to 30 days, and per-share download limits.
- ZIP download of all files in a share.
- Hourly auto-cleanup of expired shares and their files.
- Admin dashboard and settings for upload limits, storage quotas and branding.
- Site branding: custom logo, title and description.
- Optional system password gate restricting upload access.
- User authentication (login, registration, password reset, email verification) and TOTP two-factor authentication via Laravel Fortify.
- First-run setup wizard for creating the initial admin account.
- Dark themed UI built with Livewire, Alpine.js, Tailwind CSS and DaisyUI.
- Docker images published to
ghcr.io/surtic86/sealshare, served by FrankenPHP via Laravel Octane.