github PanSalut/Koffan v2.16.0

latest release: v2.16.1
3 hours ago

Back up your database file before upgrading. On its first start, 2.16.0 migrates the database (item history becomes per workspace), whether or not you enable the new accounts. There is no downgrade path: older versions cannot save item history on a migrated database. To go back, restore the backup. If you pull :latest automatically (for example with Watchtower), make a backup now.

Accounts and workspaces (optional)

One Koffan instance can now serve several households. Set MULTI_USER=true to replace the shared password with personal logins:

  • Workspaces group lists, templates and autocomplete history for the people in them (a household, the in-laws, a parent). Switch between your workspaces from the header.
  • Roles: anyone can create a workspace and owns it; owners manage its members; administrators create accounts, reset passwords and can manage every workspace. The first administrator is created from ADMIN_USER and APP_PASSWORD.
  • Isolation: lists, real-time updates, export, import and Clear database stay inside a workspace. People removed from a workspace, deleted or given a new password lose access immediately, including open tabs and live updates.
  • REST API: with accounts enabled, the token works on the workspace in API_WORKSPACE_ID (default 1).
  • Your existing lists move into the default workspace "Home", owned by the first administrator.

Nothing changes unless you set MULTI_USER=true. The shared password, the REST API and webhooks behave as in 2.15.

Setup, roles, password recovery and reverse proxy notes: README and the wiki.

Good to know

  • Webhooks are not per workspace. WEBHOOK_URL receives events from every workspace without a workspace id. On a shared instance, only enable them if everyone trusts the receiver.
  • Behind a reverse proxy the login rate limit is shared by all accounts. Consider LOGIN_MAX_ATTEMPTS=0 and limiting logins at the proxy. When serving over plain HTTP, the proxy must pass the original Host header.
  • With Docker Compose, set MULTI_USER, APP_PASSWORD (at least 8 characters, not the default) and optionally ADMIN_USER in a .env file. Compose now also passes API_TOKEN through.

Other changes

  • Italian: the confirmation for deleting a list now shows the list's name instead of {{nome}}.
  • README: new Upgrading section; the Build from source example now uses docker-compose.local.yaml, which publishes the port.

Don't miss a new Koffan release

NewReleases is sending notifications on new releases.