v1.4.0
Released: 2026-09-28
Feature release: managed media Library (#197, PR #198) with review-driven hardening.
Features
- Library workspace (#197): new header action opens a dedicated media Library replacing the editor/preview pane (sidebar stays; selecting a note returns to the editor). Browses the managed
images/andvideos/roots with Images/Videos tabs, per-item usage lookup (which notes reference a file, via IntersectionObserver), preview, copy-path, insert-as-markdown (image or video embed), and guarded deletion (DELETE /library/file/*behind the app's auth/CSRF posture). - Explorer decluttering: root
images//videos/managed folders are hidden from the note Explorer — display-only, disk unchanged. Folders that still contain Markdown anywhere beneath them (pre-existing note folders by those names) remain visible, so nothing vanishes from the file finder or wikilink autocomplete. - Library fully localized in all 7 languages.
Security / hardening (from the two-lane PR audit)
- Media paths go through the app's containment stack (segment gate, per-type extension allowlist,
PathSafetydouble-check, managed-root re-check, per-component symlink-freelstatwalk) — audit verdict: "the most defensively-coded filesystem surface in the codebase". - NUL bytes rejected in media path segments (500 → not-found).
- CSRF regression pin added for the new DELETE endpoint; quote-payload XSS pin tests added for all three Library
innerHTMLsinks. - Boot-time
/libraryfetch removed (loads on open); video preview autoplays muted.
Test Coverage
- 926 Ruby tests (3,256 assertions), 1,901 JavaScript tests; hosted CI green on the release tree including
test_ruby.