4.3.0
Added
TREK Places API
- Place search runs on TREK's own API, rebuilt monthly from Overture and served from places.liketrek.com: 73.6 million places, no key, no quota. It answers search, autocomplete, place details, the map's category pills and booking geocoding.
- The TREK API is on by default, with no admin toggle.
TREK_PLACES_ENABLED=falsekeeps search on OpenStreetMap plus Google, andTREK_PLACES_URLpoints an instance at a self-run copy. - Opening hours come from a separate layer of 5.7 million objects, read in 5 ms: OpenStreetMap first, then the hours a place publishes itself.
- Restaurants, shops and hotels take their description from their own site, credited by host and linked. 43 percent of places in the TREK API carry a website.
- A trip's surroundings download for offline use, up to 3000 places per request and kept per trip. Rostock costs about a megabyte, and search and autocomplete then work with no network, labelled as cache rather than live.
- Every hit carries a source badge naming TREK, OpenStreetMap or Google.
- Results are yours to keep: CDLA-Permissive-2.0, Apache-2.0 and CC0, where Google's contract forbade storing them.
- An optional Place Search Log records query, pick and rank, tied to no user, and deletes rows after 180 days.
Road trip addon
- Plans a whole trip as one continuous drive, off until an admin enables it under Admin, Addons. A Days and Road trip switch shows trip distance, driving time and stop count.
- Search runs along the driven road, 2, 5 or 10 km either side, for fuel, charging, rest areas, campsites, hotels, food and sights, listed in the order you pass them.
- Clicking the route drops a via point: drag it to move it, right-click it to remove it.
- Other ways offers the roads the router would take instead, and how much slower each is.
- Driving settings avoid toll roads, motorways and ferries where possible and flag what could not be avoided. The public FOSSGIS Valhalla answers these by default. An admin can point it at their own Valhalla instance under Admin, Default user settings, in effect after a restart. An instance that only sets its own OSRM never asks the public Valhalla.
- Three limits are yours to set: longest drive in one go, driving per day, tank or charge range. Legs and days over them are marked, as is the stop you would reach past your range.
- Daily travel times cap a day, and the overflow continues on extra calculated days.
- Pinned times hold, and a stop's End is when the drive leaves it. The schedule recomputes both ways from them.
- Stay length replaces check-out, reaches a full day, and carries past midnight. Booking a night puts its place on the check-in day as a service stop, which moves with the booking when its dates change.
- Add manually puts a charger OpenStreetMap lacks onto a leg you pick. Charger availability and published tariffs load without an API key.
- A day can follow an imported GPX or KML track.
- DWD weather warnings and GDACS disaster alerts can be shown on the map, off until switched on in the driving settings. They never change the route.
- The phone gets a Road trip tab of its own: the open day as a chain, sheets instead of stacked badges, and fuel and charging offers with the detour they cost.
- MCP plans road trips headless, including via points and Google Maps route imports.
Dawarich addon
- Reads the stays and routes a Dawarich instance recorded. It is read-only and off until an admin enables it under Admin, Addons, and nothing is ever written back. Dawarich publishes its side on the same day as 4.3.0, so the integration is listed on both ends from day one: Freika/dawarich.
- Each user connects their own instance. The key is encrypted at rest, never handed back, and cleared when the address changes.
- Recorded stays arrive as suggestions. Nothing is entered on its own: you accept or dismiss each one.
- Syncing again never duplicates or overwrites. Delete an accepted stay and the suggestion comes back.
- The recorded route lies over trip and journal maps, one colour per day, cut along your own timezone. Tracks are fetched for the visible stretch and discarded: no position is stored in TREK.
- Journal days fold their stays into one line with the Dawarich mark that opens on tap. The fold stays hidden until the addon is on.
- Atlas proposes the countries and cities the recordings prove, confirmed one at a time.
- The wish list ticks off at 250 m and 20 minutes, dated to the visit, undoable.
Document sync
- A trip can be bound to a Paperless-ngx tag, a Papra organisation and tag, a Nextcloud folder, an OpenCloud space or a Synology folder, and documents then move both ways: what someone uploads in TREK appears there, and what someone files there appears in TREK. A file one side will not take, by type or size, stays where it is and is listed under Needs a look.
- The trip owner binds it once and TREK works under that one account, so every member sees the same documents while the store never learns who is on the trip.
- TREK keeps its own copy of every document, so download, trash, offline use, PDF export and backups work as before, and a store that is down does not empty a trip.
- Nothing is deleted on the other side on its own. A document removed at the store is flagged in TREK and waits for a person, and one deleted in TREK is removed at the store only when the binding is set to move it to the recycle bin. On Synology that bin is a
.trek-trashfolder inside the bound folder, and a Nextcloud without its Deleted files app deletes for good. - Once a binding knows five or more documents, a run that sees more than 40 percent of them vanish at once is discarded, because an unmounted share looks exactly like that. The binding then waits until they are back or it is bound again.
- A rename at the store comes through. On Paperless-ngx and Papra a document that came from the store arrives again as a fresh copy after a rename (on Paperless after any edit), and the old copy goes to TREK's trash without its links to bookings, places or expenses. A document taken back out of TREK's trash syncs again.
- Paperless-ngx is supported from version 3 on. Synology works through File Station, two-factor accounts included.
- Stores are off until an admin switches them on under Admin, Addons, Documents, on the desktop or the phone. Switching one off pauses its bindings without touching them. Switching the Documents addon off switches every store off, and each has to be switched on again.
- A store at a private address needs
ALLOW_INTERNAL_NETWORK=true, including one in another container on the same Docker network, a Tailscale address or a.localname. Loopback addresses are never reached. - A binding whose owner leaves the trip stops on every path, the scheduler, webhooks, Sync now and MCP alike, and only picks up again once that person is back on the trip.
- MCP can read a trip's binding, list what needs attention and start a sync.
Journey
- A journey can be searched across entry titles, stories, places and tags, ignoring case and accents.
- Mood, weather and the pros and cons list can be switched off per journey. Written values stay, and a shared journey hides what the owner switched off.
- Desktop entries fill in their own weather from forecast or climate archive by entry date.
- Trip suggestions dismiss one at a time and come back from journey settings.
Trip planner and maps
- Show whole trip draws every travel day in its own colour on one map, with the total summed leg by leg from routed roads rather than straight lines.
- A car booking can carry stops between pick-up and return, on the desktop and the phone.
- Amap answers place search and draws the map, with China's coordinate offset corrected at the projection.
- Satellite view works on the vector basemap, not only on Leaflet.
- Import list takes a shared Google Maps route, up to 30 stops, no key.
Collections
-
A list exports and imports as GPX, the format map apps keep places in, with an OsmAnd flavour that carries the categories. A file can go into a list that already exists; places already on it are recognised and skipped. (#2401)
-
A list exports as a
.trekcollection.jsonfile and imports into another TREK instance as a new list, with its places, addresses, notes, contact details, labels and categories. Ids, star ratings, members and images stored on the sender's disk stay behind. Desktop only. -
A list also exports as GPX, which the map apps people keep places in can read. Name, description with the address, notes, website and category go into the standard fields, everything else into a TREK extension, so a GPX made by TREK imports back as the same list. Places without coordinates are left out and counted.
-
Import takes a
.gpxnext to the list file and tells them apart by content. Waypoints and named route points become places, tracks are counted and left out, a nameless point is named after its position, and Garmin'ssymand OsmAnd's address are read. -
An imported file can go into a list you already keep instead of a new one. Places the list already holds are left exactly as they are and counted as already there, the list keeps its own name, colour and icon, and new places are appended. An import never overwrites what a list already holds.
PDF export
- After the cover comes one map of the whole trip, every planned day in its own colour, stops marked.
- Each day is named underneath with its distance, a scale bar sits in the corner, and the total stands beside the map and on the cover, in your own unit.
- The basemap is drawn once during export and baked in as a picture. Without WebGL or a connection, the map falls back to bundled country outlines that need no key.
- Legs the router answers in time draw as roads, slower ones stay straight, and a trip that cannot be routed still prints with distances left off.
Costs and sharing
- A Final budget card names what the trip cost each traveller. Tap a name for the expenses and transfers behind the figure. The breakdown reads in all 23 languages.
- Receipts and invoices attach to an expense, images or PDFs, by drag and drop.
- Settle-up payments can be edited and undone on the phone, in the currency they were recorded in.
- A Links tab collects the addresses a trip runs on, synced live between members. It is on by default, switchable under Admin like Notes and Polls.
- Chat messages take up to four images, JPEG, PNG, GIF or WebP.
Vacay
- School holidays can be maintained by hand, with no external calendar API: admins add countries, regions and named periods under Personalization. Automatic holiday calendars stay, and school holidays never reduce leave balances.
Admin, API and backends
- Public API keys can be limited to single areas: trips, days, places, day notes, bookings, accommodation, travellers, wish list and statistics. A key without the days scope does not receive day titles and free-text notes. Existing keys keep full read access, so narrow each one by hand in settings.
- Admins can point routing at their own OSRM instance under Admin, Default user settings, in effect after a restart. The public OSRM stays capped at one request per second.
NOMINATIM_URLpoints every geocoding call at your own instance, with no fallback.- Transit search can run on Google instead of Transitous, chosen by an admin, and an empty result names the backend that answered.
- Daily route usage counters are on by default: an admin reads them at
/api/route-usage/summary, and theroute_usage_enabledsetting turns them off. They hold no query, coordinate, user or trip, and never leave the instance. ALLOW_LINK_LOCAL_IPSlets TREK reach single link-local addresses, such as169.254.1.2, the host gateway of a rootless Podman container, so an identity provider behind it can sign people in. OIDC, AI parsing and your own routing engines reach a listed address directly; integrations a user sets up also needALLOW_INTERNAL_NETWORK=true. Cloud metadata addresses cannot be listed.- Helm liveness and readiness probes are configurable under
probesinvalues.yaml. - Plugin frames can go fullscreen.
Changed
Place search
- The TREK API and OpenStreetMap are asked together and their results interleaved, TREK API first. Google answers only where both come back empty, and still holds ratings and photos.
- Top five hits over 128 places of a real trip: 50.0 percent on Nominatim alone, 51.6 percent on the TREK API alone, 72.7 percent on both. That is 77.5 percent of what a Google key reaches, where a keyless install used to reach 53.3 percent. Rank one is 5.5 points worse, because the TREK API always opens the list.
- Median search 26 ms, p95 94 ms. The word "bar" took 75.9 s on the shared Nominatim and takes 85 ms now.
- Category pills leave Overpass: 58 ms instead of about 7 s.
Journey
- The phone timeline is photo cards, one segment per day, tap or slide to jump.
- A running journey opens on today, a finished one at its first entry.
- Quick capture asks for the name first, then fills in place, coordinates and weather.
- Both maps show the same marker card: name, place, date, up to three photos.
- The photo picker's calendar jumps by year, not only one month per click.
- A Studio book opens onto a single page 1 instead of a spread.
Costs and sharing
- Settle-up payments carry the day they happened, not the day they were typed.
- A shared stop shows address, description, notes, planned stay time and its links.
App
- On a phone the default bottom bar holds Journey beside Vacay, and Atlas moves into More. A bar you arranged yourself stays as it is.
- The release notes window comes back once after every update, on the desktop, however often it was closed before. It replaces the 4.0.0 notice.
Admin
- With password login switched off, an SSO session lasts
SESSION_DURATION_REMEMBER, 30 days by default, because there is no remember me switch to ask. Set that variable shorter for shorter sessions. - AI parsing recommends Qwen3.5 4B instead of Qwen3 8B, a third smaller. A local model only sees extracted text, so scanned PDFs still need Anthropic.
- Admin settings split into two columns on wide screens, and the API Keys card leads with the TREK API.
Fixed
-
A container edited in a management UI such as Portainer or Unraid boots again: start-up moved into a script, so the command survives being re-tokenised.
COOKIE_SECURE=falsewas never the cause. (#2374) -
An SSO login no longer takes a role away over a claim the provider did not send. With
OIDC_ADMIN_CLAIMset, only a claim that is present and false demotes. (#2364) -
A booking that points at a day or place that does not exist answers 404 instead of a foreign key crash, over REST, MCP and the plugin RPC alike. (#2355)
-
A booking the AI import recognised but could not read now says so; a model answering with almost-JSON used to leave an empty preview. (#2375)
-
Stops that share a spot on the map can be clicked again: clustering no longer switches off at a zoom where the spiderfy never got a chance. (#2344)
-
The journal photo picker searches the provider by the local day, so morning photos no longer go missing from "This day". (#2336)
-
The mobile per-leg route menu offers public transit, as the desktop does. (#2398)
-
OIDC login and every other guarded integration reach dual-stack hosts again. The outbound guard resolved a name to one address and pinned the socket to it; with the AAAA first and IPv6 unreachable on 443, discovery sat until the timeout. Every address is checked and the socket gets the whole list, IPv4 first. (#2406)
-
A drop in the day plan lands where it was dropped when a booked hotel sits above the target; a hotel stop placed mid-day re-pins the day's via points; the Public API and the iCal feed list a booked hotel once. (#2406)
-
Turning a booked night into a pause in the road trip popup asks first and says that the booking and its expense go with it; deleting a place with a booked night says the same. (#2406)
-
The route overview paces its requests to the public routers, retries a rate limit and says which legs it could not route instead of quietly reporting a shorter trip. A click on a via handle on the vector map no longer drops a second via. (#2406)
-
Google transit keeps conventional trains when the train filter is on.
TREK_PLACES_ENABLED=falsestops the details and enrichment calls too and accepts0,noandoff. Import into an existing list is no longer capped at 100 kB. Chat images past the limit say so. (#2406) -
Document sync: a webhook address pasted into a store by hand works on its own, deleting a connection unregisters its subscriptions, Nextcloud under a sub-path connects, Synology answers a name collision before uploading, Paperless titles are capped at the 128 characters it holds, a refused credential gets a Reconnect button, conflict buttons show only to the owner, and the folder picker no longer spins forever on an error. (#2406)
-
The release notice after an update reaches every user once and only from a bundle built for the version the server runs; the previous shell served from the service worker cache no longer shows it as bare keys or uses it up. (#2406)
-
A trip longer than a year no longer stops at day 365. A trip can span up to 999 days, a longer range is refused with a message instead of being saved with missing days, and a trip that was cut short gets its missing days back on the next start.
-
A place standing on three days makes three journal entries, one per day. Older journals keep every entry, and missing days appear when that trip's plan is next touched.
-
Journey entries take videos, and the editor previews the clip instead of a broken image.
-
Saving a start time on a stop no longer moves it to the top of the day. Untimed stops keep their place, and everyone on the trip gets the new order at once.
-
On the phone, the menu on the leg between two stops offers Public transit, as on the desktop, and opens the search with the leg's two ends and the departure of the stop it leaves.
-
Place search is hinted by the open day instead of the whole trip, and text search gets the hint too: top five hits rise to 70.6 percent, from 54.8 without a hint and 57.1 with the whole trip.
-
The places list and its count follow the open day, like the map. A day drawing five pins no longer counts 55.
-
A stop on a dead end, such as a cave car park, no longer turns a whole day's route into straight lines without driving times. The router may now turn round at a stop, and a routing server that does not know that option is asked again without it.
-
The Costs ledger shows a foreign-currency expense or payment at the rate it was booked at instead of today's, on the desktop and the phone, so it matches the balances.
-
Work offline switches off on logout, and a sync started while working offline no longer downloads over the live connection.
-
Map markers stop lagging behind and snapping back while you drag the map, on every map.
-
An uploaded place image fills its round map marker instead of leaving only the category colour, and a changed or removed image shows without a reload.
-
The upload button on a saved place's cover in Collections no longer covers its category label.
-
A browser with WebGL off draws raster OpenStreetMap tiles instead of an error screen.
-
A short routed car booking leg no longer vanishes until you zoom in.
-
Shared trip maps cluster their pins the way the planner does, and the share page no longer scrolls sideways on a phone.
-
A place's description shows its formatting on the phone instead of raw markdown, in the places list, the day timeline, the Up next card and the place sheet.
-
The Wikimedia photo fallback reaches 60 metres, not 300, and skips shops and restaurants.
-
The photo picker no longer uploads twice and lists Immich and Synology photos newest first.
-
Atlas labels Guangdong, not Guangzhou, and a country's last visit uses the trip's end date.
-
Notification settings name collection invites, a cleared Synology session, plugin notifications and a failed replica instead of showing their internal ids, in all 23 languages.
-
Place searches no longer give up on an Overpass mirror under load:
OVERPASS_TIMEOUT_MSnow defaults to 25000 ms instead of 12000. Drop any lower value you set by hand. -
Switching AirTrail or Collections off ends every open MCP session.
-
The MCP
create_todoandupdate_todotools say 1 is high priority, matching the app.
Security
-
A document sync connection edited to a new address no longer carries the stored token along: a blank form under another origin is refused, the same rule the connection test already applied. Dawarich and AirTrail send a stored key only to the host it was stored for. (#2406)
-
The key rotation script now covers
document_connections.secretsandtrip_document_links.webhook_secret; a rotation used to leave every document binding unauthorized and drop the webhook signature check. (#2406) -
A plugin can no longer write a stay against another trip's day through the reservations RPC. (#2406)
-
An OpenStreetMap place id is checked for shape before it reaches Overpass. (#2406)
-
SSO one-time login codes are bound to the browser that requested them. A code lifted from history, a referrer or a proxy log used to sign the reader in, and it cut both ways: an attacker's code signed a victim into the attacker's account. Redeeming now takes the code plus a one-minute httpOnly cookie, and a code is spent by the first attempt whether it succeeds or not. Login is unchanged. (#2360)
-
A shared link hands out chosen columns, not whole rows. Confirmation numbers, record locators, import metadata, owner notes and Google place ids no longer reach link holders. (#2320)
-
The container image takes Debian's patched SQLite, and the MCP SDK's Hono moves to 4.13.7 for upstream security fixes. (#2314)
-
The MapLibre attribution sanitizer fix is backported, and WebGL1 installs stay supported. (#2300)
