* **New Features**
* Customize table columns by showing, hiding, and reordering them, with keyboard or pointer controls.
* Save layouts per account, restore defaults, and resolve conflicts when preferences change elsewhere. On installations without web authentication, settings are shared.
* CSV tables now support saved layouts for recognized table structures.
* **Bug Fixes**
* Improved pagination bounds and page-size validation.
* Settings requests now return clearer errors for oversized or unreadable request bodies, and recheck access after waiting for settings to become available.
* **Documentation**
* Added guidance for table customization and the settings API.
* **New Features**
* Added an EPG group view with channel counts, programme details, and channel search.
* Added timeline zooming and panning, recording controls for eligible upcoming programmes, and a resizable side panel with keyboard and pointer controls.
* **Improvements**
* EPG group and grid results support JSON or CBOR responses and show up to 1,000 channels per group.
* Channel filters support case-insensitive text and regular expressions; invalid patterns are rejected with an error.
feat(dvr)!: unify live and VOD/series recording into one recoverable DVR
Merge fix/merge_live_and_vod_recording into develop.
- One recording queue for scheduled live captures and VOD/series transfers,
with a shared transition graph, provider-slot scheduling, resumable HTTP
transfers (strong ETag / Last-Modified validation) and ffmpeg live capture.
- Crash-recoverable persistence: B+Tree repository with a journal-first
recovery history; one file can be shared by several library entries.
- Admission checks quota and disk on request, at transfer start (real size)
and before an entry attaches to a finished file; idempotent requests.
- REST is command-only; state reaches clients via owner-filtered WebSocket
snapshots.
- Deleting a recording removes the file once no entry holds it; removing an
entry keeps a finished file and cleans up orphaned partials.
- User ids derive from the configured username (web:/api:); the identity
registry is gone.
- Spanish locale added; ru/ar completed; locale parity test.
BREAKING CHANGE: `video.download` is now `video.recording` (nested
`recording` keys move up, `download_priority`/`recording_priority` become
`priority`); old configs fail to load with a migration hint.
BREAKING CHANGE: `/api/v1/file/download*` and `/file/record` are removed in
favour of `/api/v1/recording/*`.
BREAKING CHANGE: `download.*` and `recording.write` permissions are replaced
by `recording.read|create|manage|delete`; tokens from before the change must
re-authenticate.
BREAKING CHANGE: the old recording queue does not migrate; existing
`identity_registry.json` is ignored.
* **New Features**
* Added a setting to limit Flussonic HLS catch-up archive duration. Valid values range from 1 second to 7 days; the default is 4 hours.
* Bounded archive requests are capped at the configured limit, while shorter valid requests retain their requested duration. Changes apply after a playlist refresh.
* Added a dashboard credits card with app and TMDB attribution.
* **Bug Fixes**
* Open filter dialogs now render in the document body when available, helping them display correctly.
* **Documentation**
* Documented the archive-duration setting and bounded-archive behavior.
- add target-wide TMDB Trending discovery for movie/TV and day/week, bounded by an optional `limit` (default 100, range 1–500) of unique remote references before local matching
- compose concrete Trakt and TMDB sources under one target curation policy while retaining legacy `output[].trakt` compatibility
- match only positive TMDB IDs of the same media kind and preserve existing catalog identities, series closure, and Xtream alias behavior
- require every active selector to complete before target IDs, writers, caches, or watches can change
- preserve the YAML-owned block through Source Editor operations and add TMDB setup/failure documentation and application Credits attribution
- validate complete decoded pages under independent request, selector, and shared target-batch budgets, using a configured TMDB-only HTTP profile with certificate/hostname verification and no redirects or replays
New Features
Added target-specific bouquet filtering with whitelist and blacklist modes for Live, VOD, and Series groups.
Added an in-context bouquet editor with search, selection controls, status indicators, reset, and streaming previews.
Targets are managed by name, with saved selections available through the Source Editor.
Improved stream alias resolution and provider failover behavior.
Bug Fixes
Existing playlists are preserved when refreshes produce no usable items.
Empty playlists are no longer published.
Configuration changes now recover more safely from persistence failures.
Documentation
Updated feature and configuration documentation and added translations.
* Fix M3U alias credential rewriting on provider fallback
Rewrite opaque authentication query parameters when stream allocation
switches from the primary M3U provider to an alias.
Support unambiguous cross-key mappings such as token to api_key while
preserving unrelated query parameters and rejecting ambiguous mappings.
Add regression coverage for URL rewriting and provider allocation.
New Features
Added translated labels for notification events in English, Arabic, and Russian.
Added plan summaries, inheritance and override indicators, filter notices, and unlimited-value labels to proxy user forms.
Radio button groups can now wrap responsively on smaller screens.
Bug Fixes
Creating a new user list no longer retains the previously selected user.
Improved plan defaults, trial status handling, and form stability when switching plans or refreshing server lists.
UI Improvements
Improved responsive sizing and overflow behavior across tables, panels, lists, and user-management views.
New Features
Added recording availability checks before opening recording forms, with clear service-status errors.
Added configurable recording settings for retention, disk limits, quotas, notifications, priority, and filename templates.
Recording configuration is now available in video settings.
Added validation for recording quotas, ranges, and unsigned values.
Bug Fixes
Improved recording progress updates and configuration preservation.
Recording navigation visibility now follows recording permissions.
Style
Improved muted and debug log-console contrast across themes.
Translations
Updated English, Arabic, and Russian recording-related messages.
New Features
Log consoles now support consistent theming across all available visual themes, including severity and target colors.
Filtering and actions use shared controls with improved accessibility hints and visual states.
Logs are expanded by default, with playlist updates displayed under a dedicated “Playlist Update” section.
Bug Fixes
Improved radio-button group borders and selected-state layering.
Refined stats panel sizing and styling for more consistent layouts.
New Features
Disk-space alerts can now be enabled and saved from the Web UI.
Selected radio buttons now have clearer background, text, border, and focus styling.
Messaging settings preserve configured disk-alert thresholds, including default values.
Bug Fixes
Disabled disk-space alerts are correctly removed when deselected.
Messaging notification types now accept standard and case-insensitive variant names.
Improved reliability when saving messaging configuration changes.
feat: complete DVR and improve streaming, security, configuration, and UI
Complete the Digital Video Recorder subsystem and add a broad set of
reliability, security, streaming, configuration, processing, and Web UI
improvements across Tuliprox.
DVR:
* complete live recording and provider-aware VOD download support
* add recording queue, workers, scheduling, and recurring recording rules
* add conflict detection and capacity-aware scheduling
* add pause, resume, retry, edit, cancel, and delete workflows
* add recording quotas and configurable retention policies
* add crash recovery and startup reconciliation
* add durable lifecycle notifications with per-channel retries
* add DVR health monitoring and diagnostic tooling
* add secure access to recordings, thumbnails, and subtitles
* add WebSocket notifications for recording and rule changes
* add Web UI management for recordings, rules, progress, and task state
* add RBAC, configuration, documentation, and i18n support
Streaming and HLS:
* fix shared-stream idle handling and release dead provider streams correctly
* stop tee streams when both client and cache consumers are gone
* cancel provisioning probes when client streams terminate
* fix transient HLS origin work accounting and intermittent 503 responses
* make stream buffer byte limits configurable
* make shared subscriber idle timeout configurable
* make initial HLS manifest wait timeout configurable
* add configurable TS chunk packet count
* add configurable HLS refresh failure backoff
* centralize redirect limits and retry jitter handling
* improve provider DNS refresh behavior and failover tuning
* preserve UTF-8 characters in catchup templates
* improve stream history validation and persistence error handling
Security:
* use constant-time credential comparisons
* harden library and media path handling against traversal and symlink escapes
* only trust forwarded client IP headers from configured trusted proxies
* redact credentials and sensitive URL data from logs
* reject invalid authentication status-code configuration
* deny users with unresolved plans or invalid content filters
* improve authentication error handling across proxy and HLS endpoints
Configuration and reliability:
* prevent invalid api-proxy.yml reloads from terminating the running server
* fully validate API proxy configuration before persisting changes
* log configuration and EPG cleanup failures instead of silently discarding them
* keep the last valid configuration active after failed hot reloads
* align backend and shared media-server validation
* remove duplicated path and normalization logic
* improve DNS-store recovery and Windows rename fallback handling
* reject invalid duration, timestamp, and numeric conversions safely
* fix playlist bouquet save error handling
* fix provider record update detection
* fix cache boundary handling
* improve startup and persistence failure diagnostics
Filtering, search, sorting, and processing:
* add field-scoped playlist explorer search
* centralize shared stream-history search field definitions
* extend the filter DSL with string, set, and numeric operators
* add EPG ID, channel number, and detected quality as filterable fields
* add filter dry-run preview API with match statistics and samples
* report filter syntax errors with line and column information
* add natural numeric-aware sorting
* add quality-aware channel deduplication
* add accent-independent deduplication
* move natural sorting and quality detection helpers into shared code
* persist explorer search-field selection across reloads
User plans and content access:
* add reusable API user plans for capability tiers
* support inherited cluster and connection limits with per-user overrides
* add plan-level and user-level content filters
* enforce content filters across Xtream, M3U, direct playback, resource access,
stream info, short EPG, categories, and XMLTV
* add trial plans with automatic expiry and Trial status
* add plan selection and content filtering to the user editor
* add full plan management to the API configuration Web UI
* migrate the API user database to schema V7 with plan and filter persistence
Web UI and accessibility:
* add live logging console to the stats page
* improve login error handling and prevent duplicate authentication requests
* add keyboard navigation to tabs, menus, tables, and search
* add ARIA roles, labels, validation state, and live-region feedback
* add confirmation dialogs for destructive actions
* add unsaved-change warnings and Ctrl/Cmd+S shortcuts
* add loading, progress, empty, and in-flight states across views
* improve dropdown and single-selection behavior
* add clipboard and credential-copy helpers
* persist table pagination and explorer search preferences
* improve error recovery when UI context providers are unavailable
* remove multiple panic-prone unwrap and browser API paths
* replace remaining hardcoded UI strings with translation keys
Maintenance:
* resolve backend and frontend compiler and Clippy warnings
* update packages and test fixtures
* consolidate duplicated helpers and validation logic
* improve documentation for configuration, filters, plans, DVR, and REST APIs
* add and update tests for migrations, filters, deduplication, sorting,
configuration, streaming, and accessibility behavior
New Features
- Added first-class Stalker/Ministra portal support, including live, VOD, series, playback-link refresh, and bulk EPG ingestion.
- Added Stalker configuration and batch/CSV support in the Web UI.
- Added playlist preview and playback handling for Stalker inputs, with support for partial refreshes.
Shared HLS cache session feature and aligns the runtime, cache, provisioning, recovery, custom-response, and documentation paths with the new shared-session model.
* catchup fixes
* feat(frontend): bookmarkable views via URL hash deep linking
Persist the active view to the URL hash so views are bookmarkable and
survive a page refresh. Restore the view from the hash on load, sync the
hash on navigation, and handle browser back/forward via a hashchange listener.
* feat(dev): add dev container for reproducible development
* feat(frontend): interactive multi-series metric sparklines on stats cards
* feat(frontend): aggregate status health banner with capacity breakdown
* feat(frontend): add guided empty states with hints
* chore(devcontainer): add gh CLI, dev tooling, cache volumes, and tasks
- Install GitHub CLI, git, build-essential, clang, lld, mold, jq
- Add cargo-watch, cargo-llvm-cov, cargo-deny, cargo-machete
- Persist cargo registry, target, and gh config via named volumes
- Fix volume ownership for the dev user in post-create
* chore(vscode): add tasks and launch configs for dev workflow
- tasks.json: backend/frontend dev servers, test, lint, fmt, coverage, deps checks, docs
- launch.json: CodeLLDB configs for backend and workspace tests
* a11y: add accessible labels to inputs and collapsed sidebar buttons
- Input: add aria_label prop, falling back to placeholder when no visible label
- Sidebar: pass translated hint + aria_label to collapsed-mode icon buttons
* feat(frontend): warn on unsaved config changes before page unload
* feat(frontend): handle session expiry with client-side logout
Schedule a client-side logout when the JWT expires, showing a
notification and returning the user to the login screen instead of
silently failing with 401s.
* chore(vscode): update tasks.json
* New Features
Session expiration detection with proactive logout warning
Real-time health status banner showing connectivity and provider status
Live metric sparklines for CPU, memory, and network usage
Deep-linkable views via URL hash with back/forward browser support
Enhanced empty states with guided messages across app sections
Improvements
Faster system metrics sampling (2-second intervals)
Archive and catchup-aware EPG handling for accurate program guides
* New Features
Session expiration detection with proactive logout warning
Real-time health status banner showing connectivity and provider status
Live metric sparklines for CPU, memory, and network usage
Deep-linkable views via URL hash with back/forward browser support
Enhanced empty states with guided messages across app sections
Improvements
Faster system metrics sampling (2-second intervals)
Archive and catchup-aware EPG handling for accurate program guides
* feat(ui): toast progress bar, pause-on-hover, and copy-details for errors
Add a countdown progress bar to auto-dismiss toasts, pause both the timer and bar on hover (resuming with remaining time), and a 'copy details' action on error toasts. Respects prefers-reduced-motion.
* feat(ui): confirm destructive download/recording cancel and remove
Route the download/recording cancel and remove actions through the shared ConfirmDialog (which focuses the safe Cancel button by default), matching the existing confirmation flow for user/target/RBAC deletes.
* feat(ui): runtime-discovered languages with manifest and RTL support
Load available UI languages at runtime from assets/i18n/index.json, add a toolbar language picker (shown when >1 language), persist the choice, and set document dir/lang for RTL languages such as Arabic.
* feat(ui): recoverable error boundary with per-view retry fallback
Add an ErrorBoundary component (context handle + use_error_boundary hook) that shows a recoverable fallback with a retry button instead of blanking a section. Wrap each main view and the API-user playlist individually so a failure in one view stays contained and the rest of the UI keeps working.
* fix(api): use async canonicalize in local file stream handler
Replace the blocking std path.canonicalize() in local_stream_response with tokio::fs::canonicalize().await so the async runtime is not blocked while resolving the local media file path.
* Add Escape-to-close keyboard support for popup menus
Popup menus now close on Escape in addition to outside mouse-down, improving keyboard accessibility.
* Use descriptive alt text for logo and channel logo images
Login and sidebar logo images now use the configured app title, and playlist channel logos use the channel title, improving screen-reader accessibility.
* Add explicit type=button to shared button primitives
IconButton and TextButton now render with type=button to prevent accidental form submission when used inside forms.
* Persist sidebar collapsed state and table page size
The sidebar collapsed/expanded state and the stream-history table page size are now saved to localStorage and restored on reload, matching the already-persisted theme preference.
* Debounce filter editor input parsing
The filter editor textarea no longer re-parses, previews, and emits the filter on every keystroke. The textarea stays responsive via an immediate value while parsing and change notifications are debounced (300ms).
* Show localized message in table empty state
Data/paged tables now render the No content label in their empty state instead of an icon with no text. Sticky headers were already present.
* feat(frontend): improve screen-reader support for sidebar and toasts
* fix(frontend): handle missing window gracefully in sidebar
* feat(frontend): cross-dissolve colors on theme switch
* feat(frontend): add card hover lift, button press feedback, animated chevrons
* Removed code duplicates