Nova DSO Tracker v6.8.0 released

Release Date: 2026-10-01

New Features

  • Redesigned session form in the Journal – the edit/add session form is now organized into four section tabs (Overview, Equipment & Acquisition, Calibration & Outcome, Logs & Files) under a sticky header with Save, Save Draft and Cancel. The layout is denser and more consistent, with project chips, a filterable exposure table with star ratings, logs and uploads as cards with Replace/Remove, and a restyled Session History sidebar. Saving with an invalid field automatically jumps to the tab containing it.
  • Toast notifications – flash messages are now toast cards with an icon, a countdown bar (pauses on hover) and a close button; errors stay until dismissed. A loading toast with a progress bar is shown while config imports run.
  • Deleting a user removes all of their data (multi-user) – removing a user via the admin page, the CLI or the deprovision API now purges their objects, projects, journal sessions and files as well, with purges synchronized across Gunicorn workers. A new purge-orphaned-users CLI command cleans up leftovers from earlier versions. Admin accounts and self-deletion are protected.
  • Login and guest mode (multi-user) – unauthenticated visitors are no longer silently treated as a shared guest: page requests are redirected to the login page (remembering where you wanted to go) and API/telemetry requests get a 401. A new /guest entry point provides guest mode explicitly. Single-user mode is unaffected.
  • @ allowed in usernames – with format validation in the admin page and CLI user commands.
  • Language kept on logged-out pages – the selected UI language is stored in a cookie and also applies to the login and guest pages.

Improvements

  • Inspiration tab – the dashboard no longer re-renders the Inspiration candidates on background refreshes, and the candidate list is frozen while you paginate, so switching pages no longer reshuffles the list.
  • Custom filters in reports – custom filter values now appear in the session report and the project Exposure Summary, and a session keeps its filter data if the filter definition is later deleted.
  • Opportunities and Rig Data – both object tabs now share the same card and table styling.
  • Dashboard – an empty Nova ranking is no longer cached, so objects show up as soon as the catalog has results.
  • Ask Nova – a reply that cannot be parsed now returns a clear error instead of failing silently, and the button works again after switching sessions with the AJAX session loader.
  • Log uploads – the ASIAIR and PHD2 file pickers now offer .txt, matching what the server accepts; mobile custom filter values accept decimals.
  • Translations – added de/fr/es/zh/ja translations for the new toast and upload strings.
  • Dependency updates: PyJWT 2.14.0, soupsieve 2.9.0.

Bug Fixes

  • “Add New Session” opens a blank form – it previously carried over the rig, custom filter values and uploaded files of the session you were viewing; Cancel now returns to the previously viewed session.
  • Editing a session no longer overwrites its saved moon values.
  • “Create New Project” in the session form works again.
  • After switching sessions with the AJAX loader, the form keeps its listeners, a rejected file upload no longer discards your other edits, and the Ask Nova button reinitializes.
  • Opening a project URL that no longer exists redirects cleanly instead of showing an error page.
  • The Inspiration source link is fixed and its values are properly escaped.
  • Multi-user – usernames containing @ are handled correctly when rewriting links in imports, and a guest’s language choice no longer leaks to other logged-out visitors.

Security

  • Path traversal – session, project and journal image saves and deletes, the thumbnail self-healing process, and the /uploads route are now guarded against path escape via crafted filenames or usernames.
  • XSS hardening – server- and log-derived values are escaped everywhere they are inserted into pages (shared config items and notes, error messages, mobile mosaic messages, add-object messages, the Inspiration source link), backed by a new global escapeHtml helper.
  • Multi-user authentication – admin-only endpoints (telemetry, tools import/export, database repair, update triggers, AI prefilter debug) are restricted to admin accounts; login redirects are validated; the login session is bound to an account fingerprint to prevent session ID reuse.
  • Fresh installs no longer default to admin/admin – the first admin account gets a random generated password, and unused default credentials were removed from the .env template with its file permissions tightened.
  • Regular expression safety – object names are length-capped before the normalization regexes, and the link-rewrite regex in YAML imports is bounded, removing potential regex denial-of-service vectors.
  • Error responses – exception text is no longer reflected in responses (ICS generation, Stellarium proxy).
  • Docker – the publish workflow runs with read-only default permissions.
  • SECURITY.md was revised with a clearer support and vulnerability reporting process.

Heads Up

  • Multi-user mode now gates the app behind the login page. If you relied on anonymous access, either log in or use the guest link; single-user mode works exactly as before.
  • Fresh multi-user installations generate a random admin password (shown once) instead of the admin/admin default.
  • Deleting a user from the admin page, the CLI or the deprovision API now also deletes all of their data, not just the login.
Scroll to Top