- Python source archives include the built web interface, so the wheel produced by
uv buildserves/app/; archive contents are limited to public project inputs instead of unrelated workspace files. Release checks inspect the resulting archives. - Document a reproduced Zotero 10.0.1 file-conflict bug: equal displayed modification dates can make Remote select the local bytes. This client bug remains unfixed upstream.
- Two real desktop profiles exercise item and file conflict dialogs, group permission and membership transitions, collection and annotation changes, interrupted-download recovery, concurrent writers and credential relinking. PostgreSQL acceptance runs create isolated databases, and CI runs each scenario separately. See the commands and remaining gaps.
- A write naming a missing item's, collection's or saved search's previous version returns an object-level 404, allowing Zotero to reconcile an edit against a remote deletion. Found by two real desktops; complete stale objects no longer recreate themselves silently.
- Competing attachment uploads carry the attachment version on their 412 response, allowing Zotero to resolve the file conflict. Found by synchronizing two real desktops concurrently.
- Extend desktop compatibility checks to live reads and writes, files, full text, streaming, every schema type, seeded sequences with shrinking, and two real desktop profiles. Record a pinned dataserver cross-check and prove that seven protocol mutations are detected. See the commands.
- Return absolute attachment download locations, required by Zotero's separate download request, found by replaying its original ZFS transfer code.
- Fix group-list pagination and missing Link headers that prevented Zotero's account preferences from reading groups, found by the expanded desktop tests.
- Desktop compatibility checks execute original Zotero functions on altero responses, covering group permissions, cached group versions and sync watermarks. Source discovery reports possible omissions and unmapped consumers, with CI artifacts and an optional automated-review interface.
- Members of a group can edit it from Zotero desktop as the group's policy allows, where until now everybody but the owner synced a read-only library: a group's JSON carries the
adminsandmembersarrays the client looks itself up in, shown to members only. Upgrading moves every group library's version once, so clients already holding a group fetch it again. Found by @alpichlabs in #14. - The documentation points Android users at zotero-self-hosted-sync, a third-party patch bundle by @raphaelbahat that points the app at altero, and records Android sync as working on a device.
- The documentation says how the iOS and Android applications reach altero: through a build of your own, unofficially but supported.
- The Zotero iOS and Android applications can sign in: the login page's address carries a query, as upstream's does, so the
&app=1the Android application appends to it no longer names a page that does not exist. - An attachment with no file yet serves
md5andmtimeas null, as upstream does, and a write naming either empty is skipped. The Android application never uploaded a file for an attachment that carried them as empty strings. Reported by @raphaelbahat in #13. - The Zotero iOS and Android applications can upload files: an authorization asking for
params=1is answered with the form they expect, and the upload takes the multipart body they send. Reported by @raphaelbahat in #13. - An upload that stops part way no longer leaves a file where a whole one should be: the bytes are written under a name of their own and moved onto their digest, so the store holds a file or does not. A restore writes the same way, and a file left half written is swept with the unreferenced ones. Reported by @raphaelbahat in #11.
- Ukrainian joins the interface languages, counting in three forms as Russian and Polish do and taking its words from Zotero's own Ukrainian.
- Registering an upload reads the stored file back and refuses it unless it is the one that was sent, so a store that takes a write and loses it costs a retry rather than an attachment the client will never offer again.