- POST /api/auth/ayon/exchange: redeem single-use ticket (issued by the
AYON addon) via AYON_EXCHANGE_URL, mint session JWT, get-or-create
internal user row and the <project>/<task> board in the AYON collection
- db: getOrCreateAyonUser / getOrCreateAyonBoard / grantAyonCollectionAccess
- frontend: /b route redeems ticket from URL and forwards to the board
- password login/register paths untouched (legacy instance support)
examples/compose/cloudflared-paired.yml pairs RefBoard with a cloudflared
sidecar reading a TUNNEL_TOKEN env var — no inbound ports needed, suitable
for home / studio servers.
examples/compose/behind-caddy.yml + Caddyfile fronts RefBoard with Caddy
for automatic Let's Encrypt TLS on a public hostname. Caddy 2's
reverse_proxy transparently upgrades Socket.IO WebSockets.
examples/fly.toml deploys to Fly.io using the GHCR image and a persistent
volume mounted at /app/data. STORAGE_BACKEND=fs so the whole stack is one
machine with one disk.
examples/render.yaml is a Render.com Blueprint targeting the same shape
(GHCR image + attached disk + FS storage).
examples/README.md indexes everything and adds notes for Coolify /
Dokploy / CapRover / Railway, which consume the existing compose file
directly without a dedicated template.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
scripts/setup.sh (bash) and scripts/setup.ps1 (PowerShell) wrap the
canonical Docker Compose flow: detect Docker + Compose v2 (with legacy
docker-compose fallback), copy .env.example to .env if missing, pull the
GHCR image, bring the stack up, poll /health until it's ready (90s cap),
print a summary, and open the URL in the default browser. Idempotent —
safe to re-run.
README quick-start now points designers at the one-liner as the primary
path, with the raw docker compose commands kept underneath for reference.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Two changes that drop the friction in self-hosting RefBoard so the install
story becomes "docker compose up, open the URL".
1. JWT_SECRET is now optional. On first boot the backend generates a
64-byte random secret and persists it in the existing settings table.
process.env.JWT_SECRET still wins when set, so ops setups that manage
secrets out-of-band are unaffected. The prod-throws-without-env guard
is gone (auto-generation is a strictly safer default than the previous
hardcoded dev fallback).
2. STORAGE_BACKEND=fs|minio picks between MinIO (default, unchanged) and
a new local-filesystem adapter. The FS adapter exposes a fake minioClient
that mirrors the methods RefBoard calls (statObject, getObject,
getPartialObject, listObjectsV2, putObject, removeObject(s), bucketExists,
makeBucket), so consumers swap require('./minio') for require('./storage')
and nothing else changes. Sidecar .mime files hold Content-Type so the
range-aware media proxy still serves the right response headers.
examples/compose/minimal-fs.yml is the single-container variant that uses
the FS adapter. The default docker-compose.yml still spins up MinIO.
README quick-start collapses to one block (cp .env, docker compose pull,
docker compose up -d). The first user you register on the Login screen is
auto-promoted to admin, same as before.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Build linux/amd64 + linux/arm64 from the existing Dockerfile on every push
to main, on git tags v*.*.*, and on manual workflow_dispatch. Pushes to
ghcr.io/metalfinger/refboard with tags :latest (default branch), :sha-XXX
(every push), and semver tags on releases. Uses GHA cache for speed.
Tightens .dockerignore so multi-arch builds don't ship docs/, examples/,
scripts/, .github/, or .docker-data into the image context.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
crypto.randomUUID is restricted to secure contexts (HTTPS or localhost).
When RefBoard is served over plain HTTP on a LAN IP (e.g.
http://192.168.x.x:8000), the function is undefined and the editor crashes
on first ID generation with:
Uncaught TypeError: crypto.randomUUID is not a function
The frontend calls crypto.randomUUID in ~20 places (uploadManager,
SceneManager, Editor, canvas tools, grouping, scene-format, etc.), so a
single polyfill at the entry point is the smallest fix.
The polyfill uses crypto.getRandomValues — available on insecure origins —
to build an RFC 4122 v4 UUID with the correct version/variant bits. It is
a no-op when the native function exists, so HTTPS and localhost paths are
unchanged.
No crypto.subtle usage exists in the source, so randomUUID is the only
secure-context API the frontend depends on today.
Captures two install upgrades in dependency order so a future session can
pick them up without re-thinking:
Tier 1 — scripts/setup.sh: one-liner installer for terminal-comfortable
designers. Auto-generates JWT_SECRET, prompts for admin email/password,
brings up docker compose, opens the browser. Floor: Docker Desktop must
be installed (script exits with a friendly install link if not).
Tier 2 — native installer: .dmg / .exe with no Docker, no terminal.
Replaces MinIO with a local-filesystem storage adapter, bundles the
Node backend + frontend dist into a single binary via pkg, wraps in a
Tauri tray app. Designer double-clicks, gets a menu-bar icon, clicks
"Open RefBoard."
Both unchecked in README roadmap and detailed in docs/install-roadmap.md
with file layout, estimated effort, and open questions.
Adds an audit trail per board, visible from a new clock-icon button on the
toolbar. Useful for review-style work where someone wants to see who
contributed which references and when.
Logged events (high-signal only — canvas-edit noise intentionally skipped):
- image / video / pdf added (whether dropped, pasted, or pulled from a URL)
- board created / renamed / deleted
- thread started, resolved, reopened
- comment posted on a thread
Backend:
- new activity_logs table (id, board_id, user_id, denormalised actor name +
email, action, target_type/id/label, metadata JSON, created_at) with an
index on (board_id, created_at DESC).
- logActivity helper resolves the user once at log time and stores their
display name + email so entries survive deactivation/rename.
- recordActivity wraps logActivity + a Socket.IO emit to the board's room
so the panel updates live without polling.
- GET /api/boards/:id/activity?limit=&before= for pagination
(collection-membership gated, viewer+).
Frontend:
- ActivityPanel side-drawer: time-grouped feed (Today / Yesterday / older),
per-action icons + tone colours (add/remove/edit/comment), pagination
via "Load older", live append on Socket.IO 'activity:new'.
- Relative timestamps refresh every 30s.
- Wired into Editor + Toolbar.
README updated; roadmap entry checked off.
Self-registration is now controlled at runtime from the admin panel rather
than at build time via an env var. Default: off.
- New `settings` table (key/value/updated_at) plus getSetting/setSetting
helpers. Idempotent first-boot migration seeds allow_self_registration
from the ALLOW_SELF_REGISTRATION env var; after first boot the env var
is ignored and admins control the toggle from the UI.
- New public GET /api/auth/config (no auth) — returns
{ allowSelfRegistration, hasUsers }. The Login page polls this on mount
to decide whether to show a Register link, and to render
"Create the first admin account" mode when the install is empty.
- New admin GET /api/admin/settings + PUT /api/admin/settings/:key for
the dashboard. Constrained to a known-keys allowlist with type coercion
so unrecognized keys can't be stored.
- POST /api/auth/register now reads the toggle from the database instead
of process.env. The first user is still always allowed and is auto-
promoted to admin.
- Admin.tsx grows a "Settings" card with a labelled toggle switch and
toast feedback. The card sits above the user table.
- VITE_ALLOW_SELF_REGISTRATION dropped — runtime fetch replaces it.
Docs: README + .env.example clarify that ALLOW_SELF_REGISTRATION is now
an initial seed only, the going-public checklist points at the dashboard
toggle, and the features list calls out runtime control.
Adds an /admin route, visible only to users with role=admin, that lets an
operator manage the user base from the UI:
- list / search users (active + inactive)
- create new accounts (with role and optional display name)
- reset a user's password
- promote/demote between admin and member
- deactivate / reactivate (soft-delete via is_active flag)
Backend changes:
- New adminOrApiKeyMiddleware accepts EITHER a Bearer JWT belonging to a
role=admin user (UI path) OR the existing X-API-Key (bot/server-to-server).
- Existing /api/admin/* routes switched to the hybrid middleware, so the same
endpoints serve both the dashboard and any external scripts.
- Added PUT /api/admin/users/:id/role and PUT /api/admin/users/:id/reactivate.
- Self-deactivation and self-demotion are explicitly blocked so an admin can't
lock themselves out.
Frontend changes:
- New Admin.tsx page (table view, modals for create + reset, toast feedback).
- Admin button in CollectionList header, only rendered for admin role.
- Wired into App.tsx routing.
Also: friendly error when poppler-utils is missing on the host (PDF uploads
return 501 POPPLER_MISSING with a one-line install hint instead of crashing
the request); README clarifies poppler is required for the manual install.
Cover Cloudflare Tunnel (the path I run myself), Caddy + Let's Encrypt,
nginx with WebSocket headers, Tailscale for tailnet-private access, and
a 'going public' checklist (JWT_SECRET, CORS, registration, MinIO scope,
backups).
- Remove Mattermost integration (OAuth, channel bridge, file sync watcher,
frontend import modal). RefBoard now ships as a self-contained app.
- Replace SSO Login screen with email/password form (+ optional register link
gated by ALLOW_SELF_REGISTRATION).
- Add SEED_ADMIN_EMAIL / SEED_ADMIN_PASSWORD env-var bootstrap so a fresh
install ships with an admin account on first boot (idempotent).
- ALLOW_SELF_REGISTRATION flag (default false) gates POST /api/auth/register.
First user can always register (auto-promoted to admin).
- Drop mattermost_id and mm_file_id columns + board_channel_links table
from the schema; remove related db helpers and exports.
- Add MIT LICENSE, comprehensive README, .env.example, docker-compose.yml
(bundles MinIO so one command boots a working stack).
- Expand .gitignore for typical Node + Docker dev artefacts.
The asset progress overlay (e.g. "Loading assets 6/22") was incompatible
with the viewport culling system — culling only loads nearby textures and
unloads distant ones, so loaded count could never reach total. Simplified
to a brief spinner during scene data parsing only.
- Set texture to Texture.EMPTY before destroying sprites in
AnimatedGifSprite and PdfPageSprite (matches VideoSprite pattern)
- Add full-screen loading overlay that blocks interaction until
scene and assets finish loading
- Move PDF page count check before MinIO upload and DB record creation
to prevent orphaned objects when >500 page PDFs are rejected
- Use job type label (PDF page / Video) in media-worker error messages
instead of hardcoded "Video processing failed"
- Replace LIKE-based idempotency check with exact JSON match to prevent
page 1 matching page 11/12/etc substring collisions
- TransformBox rotates with single-item selection (Figma-style), with
handles and resize math projected into rotated coordinate space
- Fix VideoSprite alphaMode crash by swapping texture to EMPTY before
destroying, preventing PixiJS render loop from reading null source
- Fix Ctrl+V double-paste: internal clipboard now always takes priority
over system clipboard PNG, with wasRecentInternalPaste() guard
- Add asset loading progress bar and suppress "Drop images here" flash
during initial scene load
Replace the split snapshot/native renderer paths with a single
composition pipeline (compositionRenderer.ts) that:
- Loads actual source images and uses naturalWidth/Height for
correct full-resolution sampling (fixes top-left-corner-only bug
caused by data.w/h being capped to 600px display dimensions)
- Routes image-only selections through native Canvas 2D composition
- Falls back to viewport snapshot for mixed/unsupported selections
with explicit warnings instead of silent degradation
- Resolves group children via itemResolver for proper group export
- Rejects group children from native composition (local coords
incompatible with world-space drawing)
- Adds canvas size safety limits with auto-downscale
- Guards VideoSprite._drawFrame against null texture source race
condition during zoom-triggered culling
New files:
- compositionRenderer.ts — unified composition module
- compositionRenderer.test.ts — 16 tests for entry flattening,
bounds, dimensions, group handling
Modified:
- clipboard.ts — uses composeSelection() instead of direct renderers
- export.ts — uses composeSelection() + getCompositionDimensions()
- Editor.tsx, useShortcutHandler.ts — pass scene for group resolution
- VideoSprite.ts — null guard on texture source in frame loop