github cedya77/aiometadata v2.11.0

latest releases: v2.11, v2
2 hours ago

2.11.0 (2026-08-06)

Features

  • allow for per-provider policies in proxy-only environments (9e50b45)
  • allow for per-provider policies in proxy-only environments (e8a85fc)
  • auth: add OpenID Connect sign-in (3af2e06)
  • auth: let an administrator session reach the dashboard (3af2e06)
  • auth: open a configuration saved to an account without its password (3af2e06)
  • auth: sign in with an identity provider and reach your configurations (3af2e06)
  • dashboard: add an accounts panel for identity provider sign-ins (c4f5946)
  • discover: add Today and This Week date presets (2a7d3d1)
  • Hide Stremio-specific catalogs (d13e887)
  • Hide Stremio-specific catalogs (fcef660)
  • mdblist: offer score filters on every list catalog (6f0bf01)
  • mdblist: use quick_search on the search endpoint (2c1a481)
  • sso: apply group mapping changes to live sessions (03e6b37)
  • sso: confirm settings changes that would remove your own access (97c81e6)
  • sso: expose account sessions, configurations and deletion (46328b8)
  • sso: let an admin revoke an account's sessions (a180a7b)

Bug Fixes

  • admin: require authentication on every admin route (3af2e06)
  • catalogs: keep the catalog list responsive when it is long (329c4b9)
  • collections: apply the digital release and unknown-source checks to the right sources (329c4b9)
  • collections: carry catalogs with a shared collection (329c4b9)
  • collections: embed catalog definitions in the exported collections (329c4b9)
  • collections: give rebuilt discover catalogs a form state (329c4b9)
  • collections: hold imported catalogs until the design is applied (329c4b9)
  • collections: make routing Nuvio's own sources through the addon opt-in (329c4b9)
  • collections: rebuild catalogs from a Nuvio collection file (329c4b9)
  • collections: recreate account catalogs from their id (329c4b9)
  • collections: stop a Fusion export silently dropping most of a design (329c4b9)
  • collections: stop an import exceeding the catalog ceiling (329c4b9)
  • config: rate limit profile saves per configuration (62343a3)
  • dashboard: let an SSO instance reach the dashboard without an admin key (133814e)
  • dashboard: reach the accounts panel on mobile and report what its actions did (bdb1e66)
  • dashboard: report heap usage against the limit V8 enforces (ec183ff)
  • dashboard: say how to reach the dashboard when no admin key is set (f43b5b5)
  • docs: run self-hosted Jikan search on Typesense (a5cda44)
  • image cache: stop image provider connections piling up TLS sessions (dbbd875)
  • meta: build deep links from the identifier the client installed (097c676)
  • movielens: fix movielens sign up url (76d3754)
  • settings: register TRUST_PROXY_HOPS in the settings registry (187ff67)
  • sso: bind an OIDC sign-in to the browser that started it (3c531e1)
  • sso: bound how many sign-in failures the log will keep and read (7b781dd)
  • sso: close the window where a sign-in outlives the block that hit it (8d5ca17)
  • sso: delete the account row before sweeping its sessions (255a2f5)
  • sso: delete the payloads a trimmed failure index leaves behind (89afe3f)
  • sso: destroy the minted session when the block re-read throws (648f323)
  • sso: honour AUTH_SIGNIN_FAILURE_LOG_MAX when listing failures (8eeb5e3)
  • sso: keep a rate-limited request refused when recording it fails (ff3b798)
  • sso: keep refusals visible and sign-ins tied to a live account (e0f5e46)
  • sso: make account revocation authoritative again (884430d)
  • sso: make the self-demotion guard model a settings reset correctly (9a22467)
  • sso: point an unreadable mapping at the setting, not at every account (4f3bbce)
  • sso: rate limit sign-in by an address the client cannot forge (00911bf)
  • sso: refuse a post-sign-in redirect that leaves the instance (976f513)
  • sso: refuse the login when the group mapping cannot be read (3540713)
  • sso: report a block whose session sweep failed as saved, not failed (5ebbff3)
  • sso: report the sessions a failed sweep did destroy (ad78e04)
  • sso: say what a settings change does to other admins, per outcome (d668a2b)
  • sso: separate the parts of a multi-outcome warning with semicolons (b50d4c3)
  • sso: stop a full refusal log hiding every provider error (1ef32b4)
  • sso: stop unauthenticated attempts evicting recorded refusals (48a84c7)
  • sso: tell a refused account apart from an unrecorded one (ea4aebf)
  • sso: tell an admin what a settings change would actually do (515227c)
  • sso: warn that an unreadable mapping refuses everyone, not just admins (3fb6d57)

Performance Improvements

  • sso: index sessions per account instead of scanning the keyspace (8c82f1b)

Don't miss a new aiometadata release

NewReleases is sending notifications on new releases.