What's New
Unified subscription sorting (#140, closes #141)
Every sortable column now cycles Default → Ascending → Descending → Default. Active sort rules keep their priority when you change another column, and clearing the last rule restores the default ordering. Sort fields and directions are validated against an allowlist in a new sortorder package before they ever reach an ORDER BY clause.
Thanks to @Explorer-Dong.
Chinese (zh) locale (#135)
Simplified Chinese translation for the web UI — all 346 strings across navigation, dashboard, subscriptions, forms, settings, calendar, analytics, auth, schedules and themes. Select 中文 under Settings → Appearance.
Thanks to @sunriseydy.
Bug Fixes
Currency selection no longer falls back to the default (#129)
When your instance default was not USD, adding a USD subscription silently stored it in the default currency, and the cost field's symbol prefix did not follow the dropdown. Both now track the selected currency.
Thanks to @zbrox.
Added UAH to the supported currencies (#128)
Ukrainian hryvnia (₴) is now selectable and supported for Fixer.io conversion.
Thanks to @zbrox.
Technical Changes
- Added table tests for the
sortorderallowlist, including explicit cases asserting that malicious field and direction values are discarded whether they arrive as a spec string or asRulevalues constructed in Go. - Fixed a stale Playwright assertion in
tests/search-autopay.spec.jsthat still waited on the pre-#140?sort=namequery string. - CI now pins Go 1.24 to match
go.mod, instead of pinning 1.21 and silently downloading a 1.24 toolchain on every run. docker-publish.ymlnow checks out full history so the version stamp resolves viagit describe; the:mainand:sha-*images were previously stampeddev.- Documented two release-process traps:
--delete-branchcannot work on fork PRs, and pinning the release SHA before the final merge leaves Docker build verification watching a cancelled run.
Known Issues
Follow-ups filed during review of this release: #142 (currency falls back to hardcoded USD in the API, MCP and Wallos import paths), #143 (OIDC login UI has no i18n keys), #144 (i18n housekeeping for zh coverage and <html lang>).