Changelog

9e2ef16
2026-09-16T17:58:17Z
  • Logging in from a protected page (a user page opened from the Hall of Fame, say) now returns to that page afterwards instead of the home or profile page, for both passkey and TeamSpeak logins
27370d6
2026-09-16T17:16:33Z
  • Made the Docker image builds on CI reuse cached Gradle dependencies between runs instead of re-downloading them on every push, so deploys reach the server faster
797b653
2026-09-16T16:54:04Z
  • Gave the production database the column defaults the migrations declare, so an insert can no longer pass the tests and fail in production
7c43c8c
2026-09-16T16:51:38Z
  • Fixed the admin TeamSpeak user list crashing because most identities have no recorded client id
e5156b4
2026-09-14T06:57:18Z
  • Replaced a Gradle configuration DSL deprecated in Gradle 9.6 in the build scripts
f19e8dd
2026-09-14T06:54:40Z
  • Moved the frontend build to Rollup 4 (with rollup-plugin-import-css 4) and dropped the unused @rollup/plugin-commonjs
5b3f8ca
2026-09-14T06:44:14Z
  • Updated JTE to 3.2.4, with the Gradle plugin now taking its version from the same jteVersion property as the runtime
4f4cf68
2026-09-14T06:33:03Z
  • Upgraded to Spring Boot 4.1.1 for real (the earlier bump only moved the Gradle plugin) and made the dependency BOM and jOOQ follow the plugin version, so they can't drift apart again; brings Spring Security 7.1 and jOOQ 3.21
fda7df7
2026-09-13T21:01:39Z
  • Fixed a passkey login with a deleted or unknown passkey answering 500 instead of 401, which also kept the browser from forgetting that passkey
5b43d15
2026-09-13T20:04:11Z
  • Upgraded Kotlin from 2.2.21 to 2.4.20, and made the Spring Boot BOM follow the Kotlin plugin's version so the two can't drift apart
c078a49
2026-09-13T18:13:06Z
  • Stopped pinning webauthn4j separately; it now always matches the version Spring Security is built against, so a lone bump can no longer break passkey login
09ad73d
2026-09-13T18:00:36Z
  • Updated frontend build dependencies (rollup 3.30.0, minimatch 5.1.9, picomatch 2.3.2), replacing three stale Dependabot PRs
9cbaa89
2026-09-13T17:47:22Z
  • Eingangsbereich now counts as an AFK channel everywhere (activity chart, user pages, live view markers, widget, records), and the widget no longer lists people in "bei Bedarf anstupsen" as active
  • Removed eleven sessions between 2016 and 2022 that the recorder had left running for up to five days or that were spent parked overnight; they inflated the total time of the users involved
  • Added records to the hall of fame: longest streak, longest session, best week, most users online at once and busiest day, plus the current streaks, and each user page now shows that user's longest session and best week
4c685d9
2026-09-13T09:28:48Z
  • Fixed three regressions from the Tabler 1.5 update: missing gap between channel icons and names in the live view, unreadable chart axis labels in dark mode, and the recent activity chart growing taller every time its time span was changed
2b69493
2026-09-13T09:01:51Z
  • Updated htmx to 2.0 and minified the frontend bundle, which makes it smaller than before despite the new version
e7b19d8
2026-09-13T08:49:19Z
  • CI now also builds the frontend bundle on every pull request, as a separate check next to the Kotlin build, so a broken rollup build or dependency bump is caught before it reaches the Docker image
188a1f2
2026-09-13T07:48:00Z
  • Updated the passkey browser library to SimpleWebAuthn 14 and switched the passkey-manager sync to its sendSignal helper
babd1cd
2026-09-12T22:08:07Z
  • Passkeys now carry the account name as their username in password managers instead of the numeric user id; already registered passkeys are relabelled on the next profile visit in browsers that support the Signal API
87e28e1
2026-09-12T22:03:10Z
  • Removed the legacy Python/Django application together with its scripts, CI workflows and IDE config; the static assets it still provided now live in spybot-web
54aac25
2026-09-12T21:47:41Z
  • Renamed the JTE templates to PascalCase so the generated template classes and their call sites no longer mix snake_case and camelCase (#228)
9659c8a
2026-09-12T21:42:51Z
  • Offered to add a passkey right after a TeamSpeak login, and kept the browser's passkey manager in sync when passkeys are deleted or an account is renamed (WebAuthn Signal API)
53ad9ef
2026-09-12T21:33:12Z
  • Split the single query service into per-domain services (recorder, statistics, passkeys, admin, ...) so each consumer depends only on what it uses
94b2690
2026-09-12T21:16:39Z
  • Pages are rendered by calling the generated JTE templates directly with compile-checked parameters instead of Spring MVC models and view names
fa1171d
2026-09-12T21:13:16Z
  • Multi-statement writes (session start/close, channel moves, identity creation, weekly awards) are now atomic, and the hall of fame loads with one query instead of 26
cf46479
2026-09-12T21:10:41Z
  • Reads of NOT NULL columns now fail loudly instead of silently defaulting to 0, "" or now(); query results map onto DTOs by constructor, checked at compile time
fd0cb2e
2026-09-12T16:07:35Z
  • Fixed browsers keeping a day-old copy of the site's scripts and styles after a deploy, which broke passkey registration right after the passkey rework
738a72c
2026-09-12T16:05:59Z
  • Polished the passkey list on the profile page: provider icon and synced/device-bound badge, relative timestamps, inline rename, and updates without a page reload
7062cd9
2026-09-12T15:45:16Z
  • Moved passkeys to Spring Security's WebAuthn support: existing passkeys were removed and need to be re-added, and passkeys now survive merging two accounts (#218)
77363b9
2026-09-12T14:03:32Z
  • Made changelog rows link to their commit on GitHub, with a hover highlight and relative timestamps instead of a repeated hash (#217)
41b38df
2026-09-12T13:06:30Z
  • Fixed passkey registration and login failing in production with a generic error because the origin was reconstructed from proxy headers that report http
373c3f1
2026-09-12T12:47:04Z
  • Fixed the weekly awards job crashing on the production database because awards, news events and queued messages were inserted without a date
f3f88ce
2026-09-12T10:00:26Z
  • Added Silicon Valley personalities (Sam Altman, Mark Zuckerberg, Tim Cook, …) and US politicians (Donald Trump, Bernie Sanders, Joe Biden, …) to the name generator (#214)
aafc09c
2026-09-12T09:52:58Z
  • Added "baits" to the name generator's Counter-Strike terms so "Bill Baits" can be generated, and removed "bomb" (#213)
9bcaf46
2026-09-11T22:37:49Z
  • Required a changelog entry on every pull request via a CI check, and grouped the changelog page by the master commit that added each entry (#209)
  • Added a Steam name generator page that puns famous people's names with Counter-Strike terms, matched by pronunciation rather than spelling (#208)
  • Attached the Sentry OpenTelemetry agent for per-operation tracing spans, including individual SQL queries (#207)
  • Enabled Sentry's Logs product so application logs are forwarded to Sentry, not only error events (#206)
  • Fixed Sentry crashing both apps at startup on Spring Boot 4 by switching to the Spring Boot 4 Sentry module (#205)
  • Fixed TeamSpeak channel ordering to follow the server's real sibling order instead of sorting channel_order as a plain number (#204)
  • Fixed Flyway migrations not running at all on Spring Boot 4 (#204)
  • Added Sentry.io error and log reporting to spybot-web and spybot-recorder (#203)
  • Sped up Docker image CI by building natively on an arm64 runner with GitHub Actions layer caching (#202)
  • Polished the user page statistics card, replaced the navbar theme toggle with a Light/Dark/System picker, fixed nav icons hidden at tablet widths, and added a users-this-week/today tile to the home page (#201)
  • Fixed the recorder's clientlist query missing the dash on its -uid flag, which made every recorder restart drop still-connected users from the live view (#200)
  • Fixed racing deploys so a newer commit on master can no longer be overwritten by an older, slower build (#199)
  • Fixed the recorder reconnecting every ~5 minutes by sending a periodic keepalive, and a stale-session cleanup that could drop a still-connected user from the live view (#198)
  • Let browsers cache static assets for a day instead of refetching icons, scripts and styles on every page load (#197)
  • Fixed the recorder using the wrong jOOQ SQL dialect, which broke channel sync on every connection attempt (#196)
  • Fixed the Caddyfile bind mount on deploy and removed orphaned containers left over from the pre-rewrite stack (#195)
  • Published both the spybot-web and spybot-recorder Docker images to GHCR and made deploys pull the exact commit's images instead of building on the server (#193, #194)
v3.0.0-beta.1
2026-08-31T20:43:47Z · 684824b
  • Rewrote Spybot on Spring Boot + Kotlin (spybot-core, spybot-web, spybot-recorder), alongside the existing Django app
  • Added the admin interface (dashboard, merged users, TS users, news events, merge users)
  • Fixed TeamSpeak channel/username display so escaped ServerQuery characters render correctly
  • Fixed the recorder hanging on TS3's "\n\r" line terminator, with exponential backoff on reconnect failures
  • Added Steam ID validation and a linked-account modal to the profile page
  • Last release of the original Python/Django Spybot, before the Spring Boot + Kotlin rewrite began