Release Date: 2026-10-01
New Features
- Redesigned session form in the Journal – the edit/add session form is now organized into four section tabs (Overview, Equipment & Acquisition, Calibration & Outcome, Logs & Files) under a sticky header with Save, Save Draft and Cancel. The layout is denser and more consistent, with project chips, a filterable exposure table with star ratings, logs and uploads as cards with Replace/Remove, and a restyled Session History sidebar. Saving with an invalid field automatically jumps to the tab containing it.
- Toast notifications – flash messages are now toast cards with an icon, a countdown bar (pauses on hover) and a close button; errors stay until dismissed. A loading toast with a progress bar is shown while config imports run.
- Deleting a user removes all of their data (multi-user) – removing a user via the admin page, the CLI or the deprovision API now purges their objects, projects, journal sessions and files as well, with purges synchronized across Gunicorn workers. A new
purge-orphaned-usersCLI command cleans up leftovers from earlier versions. Admin accounts and self-deletion are protected. - Login and guest mode (multi-user) – unauthenticated visitors are no longer silently treated as a shared guest: page requests are redirected to the login page (remembering where you wanted to go) and API/telemetry requests get a 401. A new
/guestentry point provides guest mode explicitly. Single-user mode is unaffected. @allowed in usernames – with format validation in the admin page and CLI user commands.- Language kept on logged-out pages – the selected UI language is stored in a cookie and also applies to the login and guest pages.
Improvements
- Inspiration tab – the dashboard no longer re-renders the Inspiration candidates on background refreshes, and the candidate list is frozen while you paginate, so switching pages no longer reshuffles the list.
- Custom filters in reports – custom filter values now appear in the session report and the project Exposure Summary, and a session keeps its filter data if the filter definition is later deleted.
- Opportunities and Rig Data – both object tabs now share the same card and table styling.
- Dashboard – an empty Nova ranking is no longer cached, so objects show up as soon as the catalog has results.
- Ask Nova – a reply that cannot be parsed now returns a clear error instead of failing silently, and the button works again after switching sessions with the AJAX session loader.
- Log uploads – the ASIAIR and PHD2 file pickers now offer
.txt, matching what the server accepts; mobile custom filter values accept decimals. - Translations – added de/fr/es/zh/ja translations for the new toast and upload strings.
- Dependency updates: PyJWT 2.14.0, soupsieve 2.9.0.
Bug Fixes
- “Add New Session” opens a blank form – it previously carried over the rig, custom filter values and uploaded files of the session you were viewing; Cancel now returns to the previously viewed session.
- Editing a session no longer overwrites its saved moon values.
- “Create New Project” in the session form works again.
- After switching sessions with the AJAX loader, the form keeps its listeners, a rejected file upload no longer discards your other edits, and the Ask Nova button reinitializes.
- Opening a project URL that no longer exists redirects cleanly instead of showing an error page.
- The Inspiration source link is fixed and its values are properly escaped.
- Multi-user – usernames containing
@are handled correctly when rewriting links in imports, and a guest’s language choice no longer leaks to other logged-out visitors.
Security
- Path traversal – session, project and journal image saves and deletes, the thumbnail self-healing process, and the
/uploadsroute are now guarded against path escape via crafted filenames or usernames. - XSS hardening – server- and log-derived values are escaped everywhere they are inserted into pages (shared config items and notes, error messages, mobile mosaic messages, add-object messages, the Inspiration source link), backed by a new global
escapeHtmlhelper. - Multi-user authentication – admin-only endpoints (telemetry, tools import/export, database repair, update triggers, AI prefilter debug) are restricted to admin accounts; login redirects are validated; the login session is bound to an account fingerprint to prevent session ID reuse.
- Fresh installs no longer default to
admin/admin– the first admin account gets a random generated password, and unused default credentials were removed from the.envtemplate with its file permissions tightened. - Regular expression safety – object names are length-capped before the normalization regexes, and the link-rewrite regex in YAML imports is bounded, removing potential regex denial-of-service vectors.
- Error responses – exception text is no longer reflected in responses (ICS generation, Stellarium proxy).
- Docker – the publish workflow runs with read-only default permissions.
SECURITY.mdwas revised with a clearer support and vulnerability reporting process.
Heads Up
- Multi-user mode now gates the app behind the login page. If you relied on anonymous access, either log in or use the guest link; single-user mode works exactly as before.
- Fresh multi-user installations generate a random admin password (shown once) instead of the
admin/admindefault. - Deleting a user from the admin page, the CLI or the deprovision API now also deletes all of their data, not just the login.