VERSIONS
Changelog
See what was added and fixed in every application version.
What's new?
No new features in this release.
What's fixed?
- Parent History now paginates the full filtered result with Previous/Next; Any time is no longer a silent short window. The child dashboard still shows only the five latest History entries.
- Surprise-card boards stay opaque until reveal, and in-app copy uses Surprise cards instead of lottery or win wording.
- Child Gift and Feedback sit in one floating action stack so mobile task buttons stay reachable.
- Backup health on Settings loads after the page opens, so opening Settings does not wait on the backup agent.
- Official documentation now matches 26.6.8 Parent History pagination, surprise-card reveal, PIN alarm behaviour, backup status loading, background push, trusted proxies, and the child floating-action stack.
- One-winner money paths claim SQLite rows immediately and with conditional updates, so concurrent approvals cannot both win.
- Same-day catalog credits, active-child money and unlock actions, and sibling-scoped child lookups now match the existing ownership invariants.
- Web Push is delivered after commit on a background thread with a hard per-endpoint timeout, so a slow push cannot block or fail the user action.
- The household-wide child PIN counter is alarm-only; device, profile, and IP limits still hard-block, and changing a PIN uses the same profile lockout as sign-in.
- Initial setup rate-limits failed claims and requires a long setup code; SMTP and Web Push destinations must resolve to public addresses; trusted proxies default to loopback only.
What's new?
No new features in this release.
What's fixed?
- Parent Home child cards now use Add / Assign plus a More menu for adjust, penalty, and credit actions, with clearer credit and lottery-ticket metadata.
- Pending requests are easier to scan, with an in-panel heading and count badge and clearer mobile actions.
- Parent Settings are grouped into Everyday, People and devices, and Server sections with clearer status chips and save guidance.
- Parent History rows and mobile filter chips are tighter to scan, and the filter dialog stays usable as a bottom sheet with sticky apply actions.
- Manage uses a single section navigation for Tasks, Rewards, Penalties, and Goals, with clearer edit flows and empty states.
- Official parent documentation and screenshots now match the 26.6.7 Home, Settings, History, and Manage UI.
- Approve-goal save-mode radio layout and legend spacing.
What's new?
No new features in this release.
What's fixed?
- Release and installation documentation now separates release-candidate images from production image defaults and refreshes screenshot and network-access guidance.
- Parent account deactivation now preserves the last active parent and the last active parent administrator while cleaning up that parent's push subscriptions.
- Child-only network access now leaves parent login and password recovery available from a device with an active child session.
- Django is updated to 5.2.17 for the latest supported security fixes.
What's new?
No new features in this release.
What's fixed?
- Parent account management now distinguishes ordinary parents from parent administrators, while scheduled backups retry temporary failures with bounded same-day backoff.
- The deployment Compose network now gives the application only the outbound access it needs while keeping backup control traffic internal.
- Proposal, reward, and related pending-state transitions now claim rows conditionally so concurrent requests cannot both win on SQLite.
- Failed upgrades now stop with a compatibility warning instead of silently restoring an older image after migrations may have changed the database.
- Web Push subscriptions now validate public HTTPS endpoints and structurally valid keys, enforce per-owner limits, and exclude inactive parent accounts.
- Child-only network restrictions now also cover active child sessions on shared feedback and screenshot routes.
What's new?
No new features in this release.
What's fixed?
- Child dashboards now show a personalized greeting with a safe fallback when a name is unavailable.
- Paired child devices now receive automatic icons, broad non-fingerprinting browser/device identification, a stable short ID, last-seen status, and rolling cookie renewal while actively used.
- Parent account settings now use a clearer account-type selector and dialog-based editing, while pending requests receive stronger visual emphasis.
- Production settings now default DEBUG to False and require an explicit secret key when debug is disabled.
- Application responses now include a nonce-based Content Security Policy, while preserving the existing local scripts, image previews, and styles.
- CI now audits the locked Python dependency set with pip-audit, and Dependabot monitors Python and GitHub Actions dependencies.