Changelog ========= You can subscribe to release announcements by: - Following `funkwhale@mastodon.eliotberriot.com `_ on Mastodon - Subscribing to the following Atom feed: https://dev.funkwhale.audio/funkwhale/funkwhale/commits/develop?format=atom&search=Merge+tag This changelog is viewable on the web at https://docs.funkwhale.audio/changelog.html. .. towncrier 0.20.1 (2019-10-28) ------------------- Upgrade instructions are available at https://docs.funkwhale.audio/index.html Denormalized audio permission logic in a separate table to enhance performance ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ With this release, we're introducing a performance enhancement that should reduce the load on the database and API servers (cf https://dev.funkwhale.audio/funkwhale/funkwhale/merge_requests/939). Under the hood, we now maintain a separate table to link users to the tracks they are allowed to see. This change is **disabled** by default, but should be enabled by default starting in Funkwhale 0.21. If you want to try it now, add ``MUSIC_USE_DENORMALIZATION=True`` to your ``.env`` file, restart Funkwhale, and run the following command:: python manage.py rebuild_music_permissions This shouldn't cause any regression, but we'd appreciate if you could test this before the 0.21 release and report any unusual behaviour regarding tracks, albums and artists visibility. Enhancements: - Added a retry option for failed uploads (#942) - Added feedback via loading spinner when searching a remote library - Denormalized audio permission logic in a separate table to enhance performance - Placeholders will now be shown if no content is available across the application (#750) - Reduce the number of simultaneous DB connections under some deployment scenario - Support byYear filtering in Subsonic API (#936) Bugfixes: - Ensure password input doesn't overflow outside of container (#933) - Fix audio serving issues under S3/nginx when signatures are enabled - Fix import crash when importing M4A file with no embedded cover (#946) - Fix tag exclusion in custom radios (#950) - Fixed an issue with embed player CSS being purged during build (#935) - Fixed escaped pod name displayed on home/about page (#945) - Fixed pagination in subsonic getSongsByGenre endpoint (#954) - Fixed style glitches in dropdowns Documentation: - Documented how to create DB extension by hand in case of permission error during migrations (#934) Contributors to this release (translation, development, documentation, reviews, design): - Ciarán Ainsworth - Dag Stenstad - Daniele Lira Mereb - Eliot Berriot - Esteban - Johannes H. - knuxify - Mateus Mattei Garcia - Quentin PAGÈS 0.20 (2019-10-04) ----------------- Upgrade instructions are available at https://docs.funkwhale.audio/index.html Support for genres via tags ^^^^^^^^^^^^^^^^^^^^^^^^^^^ One of our most requested missing features is now available! Starting with Funkwhale 0.20, Funkwhale will automatically extract genre information from uploaded files and associate it with the corresponding tracks in the form of tags (similar to Mastodon or Twitter hashtags). Please refer to `our tagging documentation `_ for more information regarding the tagging process. Tags can also be associated with artists and albums, and updated after upload through the UI using the edit system released in Funkwhale 0.19. Tags are also fetched when retrieving content via federation. Tags are used in various places to enhance user experience: - Tags are listed on tracks, albums and artist profiles - Each tag has a dedicated page were you can browse corresponding content and quickly start a radio - The custom radio builder now supports using tags - Subsonic apps that support genres - such as DSub or Ultrasonic - should display this information as well If you are a pod admin and want to extract tags from already uploaded content, you run `this snippet `_ and `this snippet `_ in a ``python manage.py shell``. Content and account reports ^^^^^^^^^^^^^^^^^^^^^^^^^^^ It is now possible to report content, such as artists, tracks or libraries, as well as user accounts. Such reports are forwarded to the pod moderators, who can review it and delete reported content, block accounts or take any other action they deem necessary. By default, both anonymous and authenticated users can submit these reports. This makes sure moderators can receive and handle takedown requests and other reports for illegal content that may be sent by third-parties without an account on the pod. However, you can disable anonymous reports completely via your pod settings. Federation of the reports will be supported in a future release. For more information about this feature, please check out our documentation: - `User documentation `_ - `Moderator documentation `_ Account deletion ^^^^^^^^^^^^^^^^ Users can now delete their account themselves, without involving an administrator. The deletion process will remove any local data and objects associated with the account, but the username won't be able to new users to avoid impersonation. Deletion is also broadcasted to other known servers on the federation. For more information about this feature, please check out our documentation: - `User documentation `_ Landing and about page redesign [Manual action suggested] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ In this release, we've completely redesigned the landing and about page, by making it more useful and adapted to your pod configuration. Among other things, the landing page will now include: - your pod and an excerpt from your pod's description - your pod banner image, if any - your contact email, if any - the login form - the signup form (if registrations are open on your pod) - some basic statistics about your pod - a widget including recently uploaded albums, if anonymous access is enabled The landing page will still include some information about Funkwhale, but in a less intrusive and proeminent way than before. Additionally, the about page now includes: - your pod name, description, rules and terms - your pod banner image, if any - your contact email, if any - comprehensive statistics about your pod - some info about your pod configuration, such as registration and federation status or the default upload quota for new users With this redesign, we've added a handful of additional pod settings: - Pod banner image - Contact email - Rules - Terms of service We recommend taking a few moments to fill these accordingly to your needs, by visiting ``/manage/settings``. Allow-list to restrict federation to trusted domains ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ The Allow-Listing feature grants pod moderators and administrators greater control over federation by allowing you to create a pod-wide allow-list. When allow-listing is enabled, your pod's users will only be able to interact with pods included in the allow-list. Any messages, activity, uploads, or modifications to libraries and playlists will only be shared with pods on the allow-list. Pods which are not included in the allow-list will not have access to your pod's content or messages and will not be able to send anything to your pod. If you want to enable this feature on your pod, or learn more, please refer to `our documentation `_! Periodic message to incite people to support their pod and Funkwhale ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Users will now be reminded on a regular basis that they can help Funkwhale by donating or contributing. If specified by the pod admin, a separate and custom message will also be displayed in a similar way to provide instructions and links to support the pod. Both messages will appear for the first time 15 days after signup, in the notifications tab. For each message, users can schedule a reminder for a later time, or disable the messages entirely. Replaced Daphne by Gunicorn/Uvicorn [manual action required, non-docker only] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ To improve the performance, stability and reliability of Funkwhale's web processes, we now recommend using Gunicorn and Uvicorn instead of Daphne. This combination unlock new use cases such as: - zero-downtime upgrades - configurable number of web worker processes Based on our benchmarks, Gunicorn/Unicorn is also faster and more stable under higher workloads compared to Daphne. To benefit from this enhancement on existing instances, you need to add ``FUNKWHALE_WEB_WORKERS=1`` in your ``.env`` file (use a higher number if you want to have more web worker processes). Then, edit your ``/etc/systemd/system/funkwhale-server.service`` and replace the ``ExecStart=`` line with ``ExecStart=/srv/funkwhale/virtualenv/bin/gunicorn config.asgi:application -w ${FUNKWHALE_WEB_WORKERS} -k uvicorn.workers.UvicornWorker -b ${FUNKWHALE_API_IP}:${FUNKWHALE_API_PORT}`` Then reload the configuration change with ``sudo systemctl daemon-reload`` and ``sudo systemctl restart funkwhale-server``. Content-Security-Policy and additional security headers [manual action suggested] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ To improve the security and reduce the attack surface in case of a successfull exploit, we suggest you add the following Content-Security-Policy to your nginx configuration. ..note:: If you are using an S3-compatible store to serve music, you will need to specify the URL of your S3 store in the ``media-src`` and ``img-src`` headers .. code-block:: add_header Content-Security-Policy "...img-src 'self' https:// data:;...media-src https:// 'self' data:"; **On non-docker setups**, in ``/etc/nginx/sites-available/funkwhale.conf``:: server { add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:; object-src 'none'; media-src 'self' data:"; add_header Referrer-Policy "strict-origin-when-cross-origin"; location /front/ { add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:; object-src 'none'; media-src 'self' data:"; add_header Referrer-Policy "strict-origin-when-cross-origin"; add_header X-Frame-Options "SAMEORIGIN"; # … existing content here } # Also create a new location for the embeds to ensure external iframes work # Simply copy-paste the /front/ location, but replace the following lines: location /front/embed.html { add_header X-Frame-Options "ALLOW"; alias ${FUNKWHALE_FRONTEND_PATH}/embed.html; } } Then reload nginx with ``systemctl reload nginx``. **On docker setups**, in ``/srv/funkwhalenginx/funkwhale.template``:: server { add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:; object-src 'none'; media-src 'self' data:"; add_header Referrer-Policy "strict-origin-when-cross-origin"; location /front/ { add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self' data:; object-src 'none'; media-src 'self' data:"; add_header Referrer-Policy "strict-origin-when-cross-origin"; add_header X-Frame-Options "SAMEORIGIN"; # … existing content here } # Also create a new location for the embeds to ensure external iframes work # Simply copy-paste the /front/ location, but replace the following lines: location /front/embed.html { add_header X-Frame-Options "ALLOW"; alias /frontent/embed.html; } } Then reload nginx with ``docker-compose restart nginx``. Rate limiting ^^^^^^^^^^^^^ With this release, rate-limiting on the API is enabled by default, with high enough limits to ensure regular users of the app aren't affected. Requests beyond allowed limits are answered with a 429 HTTP error. For anonymous requests, the limit is applied to the IP adress of the client, and for authenticated requests, the limit is applied to the corresponding user account. By default, anonymous requests get a lower limit than authenticated requests. You can disable the rate-limiting feature by adding `THROTTLING_ENABLED=false` to your ``.env`` file and restarting the services. If you are using the Funkwhale API in your project or app and want to know more about the limits, please consult https://docs.funkwhale.audio/swagger/. Broken audio streaming when using S3/Minio and DSub [manual action required] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Some Subsonic clients, such as DSub, are sending an Authorization headers which was forwarded to the S3 storage when streaming, causing some issues. If you are using S3 or a compatible storage such as Minio, please add the following in your nginx ``~ /_protected/media/(.+)`` location:: # Needed to ensure DSub auth isn't forwarded to S3/Minio, see #932 proxy_set_header Authorization ""; And reload your nginx process. Detail ^^^^^^ Features: - Added periodical message to incite people to support their pod and Funkwhale (#839) - Admins can now add custom CSS from their pod settings (#879) - Allow-list to restrict federation to trusted domains (#853) - Content and account reports (#890) - Dark theme (#756) - Enforce a configurable rate limit on the API to mitigate abuse (#261) - Redesign of the landing and about pages (#872) - Support for genres, via tags (#432) - Users can now delete their account without admin intervention (#852) Enhancements: - Added a info message on embed wizard when anonymous access to content is disabled (#878) - Added Catalan translation files - Added Czech translation (#844) - Added field to manage user upload quota in Django backend (#903) - Added the option to replace the queue's current contents with a selected album or track (#761) - Artists with no albums will now show track count on artist card (#895) - Ensure API urls answer with and without a trailing slash (#877) - Hardcoded list of supported browsers to avoid unexpected regressions (#854) - Hardened security thanks to CSP and additional HTTP headers (#880) - Improve display of search results by including artist and album data - Increase the security of JWT token generation by using DJANGO_SECRET_KEY as well as user-specific salt for the signature - Mods can now change a library visibility through the admin UI (#548) - New keyboard shortcuts added for enhanced control over audio player (#866) - Now refetch remote ActivityPub artists, albums and tracks to avoid local stale data - Numbers on the stats page will now be formatted in a human readable way and will update with the locale (#873) - Pickup folder.png and folder.jpg files for cover art when importing from CLI (#898) - Prevent usage of too weak passwords (#883) - Reduced CSS size by 30% using purgecss - Replaced Daphne by Gunicorn/Uvicorn to improve stability, flexibility and performance (#862) - Simplified embedded docker reverse proxy IP configuration (#834) - Support embeds on public playlists - Support for M4A/AAC files (#661) - Switched from Semantic-UI to Fomentic-UI - Add dropdown menu to track table (#531) - Display placeholder on homepage when there are no playlists (#892) - Make album cards height independent (#710) Bugfixes: - Added context strings to en_GB translations so that picking the language changes the interface as expected - Ensure selected locale is not reset to browser default when refreshing app - Fix missing license information on track details page (#913) - Fix regression to quota bar color (#897) - Fixed a responsive display issues on 1024px wide screens (#904) - Fixed album art not being retrieved from Ogg/Opus files - Fixed broken embedded player layout after dependency update (#875) - Fixed broken external HTTPS request under some scenarios, because of missing PyOpenSSL - Fixed broken less listened radio (#912) - Fixed broken URL to artist and album on album and track pages (#871) - Fixed empty contentType causing client crash in some Subsonic payloads (#893) - Fixed import crashing with empty cover file or too long values on some fields - Fixed in-place imported files not playing under nginx when filename contains ? or % (#924) - Fixed remaining transcoding issue with Subsonic API (#867) - Fixed search usability issue when browsing artists, albums, radios and playlists (#902) - Improved performance of /artists, /albums and /tracks API endpoints by a factor 2 (#865) - Updated docs to ensure streaming works when using Minio/S3 and DSub (#932) Contributors to this release (translation, development, documentation, reviews, design): - Amaranthe - ButterflyOfFire - Ciarán Ainsworth - Eliot Berriot - Esteban - Francesc Galí - Freyja Wildes - hellekin - IISergII - jiri-novacek - Johannes H. - Keunes - Koen - Manuel Cortez - Mehdi - Mélanie Chauvel - nouts - Quentí - Reg - Rodrigo Leite - Romain Failliot - SpcCw - Sylke Vicious - Tobias Reisinger - Xaloc - Xosé M 0.19.1 (2019-06-28) ------------------- Upgrade instructions are available at https://docs.funkwhale.audio/index.html Enhancements: - The currently playing track is now highlighted with an orange play icon (#832) - Support for importing files with no album tag (#122) - Redirect from / to /library when user is logged in (#864) - Added a SUBSONIC_DEFAULT_TRANSCODING_FORMAT env var to support clients that don't provide the format parameter (#867) - Added button to search for objects on Discogs (#368) - Added copy-to-clipboard button with Subsonic password input (#814) - Added opus to the list of supported mimetypes and extensions (#868) - Aligned search headers with search results in the sidebar (#708) - Clicking on the currently selected playlist in the Playlist popup will now close the popup (#807) - Favorites radio will not be visible if the user does not have any favorites (#419) Bugfixes: - Ensure empty but optional fields in file metadata don't error during import (#850) - Fix broken upload for specific files when using S3 storage (#857) - Fixed broken translation on home and track detail page (#833) - Fixed broken user admin for users with non-digit or letters in their username (#869) - Fixed invalid file extension for transcoded tracks (#848) - Fixed issue with French translation for "Start radio" (#849) - Fixed issue with player changing height when hovering over the volume slider (#838) - Fixed secondary menus truncated on narrow screens (#855) - Fixed wrong og:image url when using S3 storage (#851) - Hide pod statistics on about page if those are disabled (#835) - Use ASCII filename before upload to S3 to avoid playback issues (#847) Contributors to this release (commiters and reviewers): - Ciarán Ainsworth - Creak - ealgase - Eliot Berriot - Esteban - Freyja Wildes - hellekin - Johannes H. - Mehdi - Reg 0.19.0 (2019-05-16) ------------------- Upgrade instructions are available at https://docs.funkwhale.audio/admin/upgrading.html Edits on tracks, albums and artists ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Funkwhale was a bit annoying when it camed to metadata. Tracks, albums and artists profiles were created from audio file tags, but basically immutable after that (unless you had admin access to Django's UI, which wasn't ideal to do this kind of changes). With this release, everyone can suggest changes on track, album and artist pages. Users with the "library" permission can review suggested edits in a dedicated interface and apply/reject them. Approved edits are broadcasted via federation, to ensure other instances get the information too. Not all fields are currently modifiable using this feature. Especially, it's not possible to suggest a new album cover, or reassign a track to a different album or artist. Those will be implemented in a future release. Admin UI for tracks, albums, artists, libraries and uploads ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ As part of our ongoing effort to make Funkwhale easier to manage for instance owners, this release includes a brand new administration interface to deal with: - tracks - albums - artists - libraries - uploads You can use this UI to quickly search for any object, delete objects in batch, understand where they are coming from etc. This new UI should remove the need to go through Django's admin in the vast majority of cases (but also includes a link to Django's admin when needed). Artist hiding in the interface ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ It's now possible for users to hide artists they don't want to see. Content linked to hidden artists will not show up in the interface anymore. Especially: - Hidden artists tracks are removed from the current queue - Starting a playlist will skip tracks from hidden artists - Recently favorited, recently listened and recently added widgets on the homepage won't include content from hidden artists - Radio suggestions will exclude tracks from hidden artists - Hidden artists won't appear in Subsonic apps Results linked to hidden artists will continue to show up in search results and their profile page remains accessible. OAuth2 authorization for better integration with third-party apps ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Funkwhale now support the OAuth2 authorization and authentication protocol which will allow third-party apps to interact with Funkwhale on behalf of users. This feature makes it possible to build third-party apps that have the same capabilities as Funkwhale's Web UI. The only exception at the moment is for actions that requires special permissions, such as modifying instance settings or moderation (but this will be enabled in a future release). If you want to start building an app on top of Funkwhale's API, please check-out `https://docs.funkwhale.audio/api.html`_ and `https://docs.funkwhale.audio/developers/authentication.html`_. Better error handling and display during import ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Funkwhale should now be more resilient to missing tags in imported files, and give you more insights when something goes wrong, including the specific tags that were missing or invalid, and additional debug information to share in your support requests. This information is available in all pages that list uploads, when clicking on the button next to the upload status. Support for S3-compatible storages to store media files ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Storing all media files on the Funkwhale server itself may not be possible or desirable in all scenarios. You can now configure Funkwhale to store those files in a S3 bucket instead. Check-out `https://docs.funkwhale.audio/admin/external-storages.html`_ if you want to use this feature. Prune library command ^^^^^^^^^^^^^^^^^^^^^ Users are often surprised by Funkwhale's tendency to keep track, album and artist metadata even if no associated files exist. To help with that, we now offer a ``prune_library`` management command you can run to purge your database from obsolete entries. `Please refer to our documentation for usage instructions `_. Check in-place files command ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ When using in-place import with a living audio library, you'll quite often rename or remove files from the file system. Unfortunately, Funkwhale keeps a reference to those files in the database, which results in unplayable tracks. To help with that, we now offer a ``check_inplace_files`` management command you can run to purge your database from obsolete files. `Please refer to our documentation for usage instructions `_. Features: - Added albums view. Similar to artists view, it's viewable by clicking on the "Albums" link on the top bar. (#356) - Allow artists hiding (#701) - Change the document title to display current track information. (#359) - Display a confirmation dialog when adding duplicate songs to a playlist (#784) - Improved error handling and display during import (#252, #718, #583, #501, #544) - Support embedding full artist discographies (#747) - Support metadata update on tracks, albums and artists and broadcast those on the federation (#689) - Support OAuth2 authorization for better integration with third-party apps (#752) - Support S3-compatible storages for media files (#565) Enhancements: - [Experimental] Added a new "Similar" radio based on users history (suggested by @gordon) - Added a "load more" button on artist pages to load more tracks/albums (#719) - Added a `check_inplace_files` management command to remove purge the database from references to in-place imported files that don't exist on disk anymore (#781) - Added a prune_library management command to remove obsolete metadata from the database (#777) - Added admin options to disable login for users, ensure related content is deleted when deleting a user account (#809) - Added standardized translation context for all strings in the frontend to give accurate hints to translators. - Added twitter:* meta tags to detect tracks and albums players automatically on more sites (#578) Improved responsiveness of embedded player - Advertise the list of supported upload extensions in the Nodeinfo endpoint (#808) - Better handling of follow/accept messages to avoid and recover from desync between instances (#830) - Better workflow for connecting to another instance (#715) Changing the instance used is now better integrated in the App, and it is checked that the chosen instance and the suggested instances are valid and running Funkwhale servers. - Bumped dependencies to latest versions (#815) - Descriptions will now be shown underneath user libraries (#768) - Don't store unhandled ActivityPub messages in database (#776) - Enhanced the design of the embed wizard. (!619) - Ensure the footer always stays at the bottom of the page - Expose an instance-level actor (service@domain) in nodeinfo endpoint (#689) - Improved readability of logo (#385) - Keep persistent connections to the database instead of recreating a new one for each request - Labels for privacy levels are now consistently grabbed from a common source instead of being hardcoded everytime they are needed. - Merged artist/album buttons with title text on artist and album pages (#725) - Now honor maxBitrate parameter in Subsonic API (#802) - Preload next track in queue (#572) - Reduced app size for regular users by moving admin-related code in a dedicated chunk (#805) - Removed broken/instable lyrics feature (#799) - Show remaining storage space during import and prevent file upload if not enough space is remaining (#550) - The buttons displaying an icon now always show a little divider between the icon and the text. (!620) - Use attributedTo instead of actor in library ActivityPub payload (#619) - Use network/depends_on instead of links in docker-compose.yml (!716) Bugfixes: - Add missing command from contributing file (#754) - Add required envvar for dev environment (!668) - Added env variable to set AWS region and signature version to serve media without proxy (#826) - Allow users with dots in their usernames to request a subsonic password (#798) - Better handling of featuring/multi-artist tracks tagged with MusicBrainz (#782) - Do not consider tracks as duplicates during import if they have different positions (#740) - Ensure all our ActivityPub fetches are authenticated (#758) - Ensure correct track duration and playable status when browsing radios (#812) - Fixed alignement/size issue with some buttons (#702) - Fixed an encoding issue with instance name on about page (#828) - Fixed cover not showing in queue/player when playing tracks from "albums" tab (#795) - Fixed crashing upload processing on invalid date format (#718) - Fixed dev command for fake data creation (!664) - Fixed invalid OEmbed URL when using a local FUNKWHALE_SPA_HTML_ROOT (#824) - Fixed invalid required fields in Upload django's admin (#819) - Fixed issue with querying the albums api endpoint (#356) - Fixed non-transparent background for volume range on Firefox (#722) - Fixed overflowing input on account detail page (#791) - Fixed unplayable radios for anonymous users (#563) - Prevent skipping on file import if album_mbid is different (#772) - Use proper site name/domain in emails (#806) - Width of filter menus for radios has been set to stop text from overlapping the borders Documentation: - Document how to use Redis over unix sockets (#770) Contributors to this release (commiters and translators): - Ale London - Alexander - Ben Finney - ButterflyOfFire - Ciarán Ainsworth - Damien Nicolas - Daniele Lira Mereb - Eliot Berriot - Elza Gelez - gerry_the_hat - gordon - interfect - jake - Jee - jovuit - Mélanie Chauvel - nouts - Pierrick - Qasim Ali - Quentí - Renon - Rodrigo Leite - Sylke Vicious - Thomas Brockmöller - Tixie - Vierkantor - Von - Zach Halasz 0.18.3 (2019-03-21) ------------------- Upgrade instructions are available at https://docs.funkwhale.audio/admin/upgrading.html Avoid mixed content when deploying mono-container behind proxy [Manual action required] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ *You are only concerned if you use the mono-container docker deployment behind a reverse proxy* Because of `an issue in our mono-container configuration `_, users deploying Funkwhale via docker using our `funkwhale/all-in-one` image could face some mixed content warnings (and possibly other troubles) when browsing the Web UI. This is fixed in this release, but on existing deployments, you'll need to add ``NESTED_PROXY=1`` in your container environment (either in your ``.env`` file, or via your container management tool), then recreate your funkwhale container. Enhancements: - Added title on hover for truncated content (#766) - Ask for confirmation before leaving upload page if there is a an upload in process (#630) - Exclude in-place imported files from quota computation (#570) - Truncate filename in library file table to ensure correct display of the table. (#735) Bugfixes: - Avoid mixed content when deploying mono-container behind HTTPS proxy (thetarkus/docker-funkwhale#19) - Display new notifications immediatly on notifications page (#729) - Ensure cover art from uploaded files is picked up properly on existing albums (#757) - Fixed a crash when federating a track with unspecified position - Fixed broken Activity and Actor modules in django admin (#767) - Fixed broken sample apache configuration (#764) - Fixed constant and unpredictable reordering during file upload (#716) - Fixed delivering of local activities causing unintended side effects, such as rollbacking changes (#737) - Fixed escaping issues in translated strings (#652) - Fixed saving moderation policy when clicking on "Cancel" (#751) - i18n: Update page title when changing the App's language. (#511) - Include disc number in Subsonic responses (#765) - Do not send notification when rejecting a follow on a local library (#743) Documentation: - Added documentation on mono-container docker upgrade (#713) - Added documentation to set up let's encrypt certificate (#745) 0.18.2 (2019-02-13) ------------------- Upgrade instructions are available at https://docs.funkwhale.audio/admin/upgrading.html Enhancements: - Added a 'fix_federation_ids' management command to deal with protocol/domain issues in federation IDs after deployments (#706) - Can now use a local file with FUNKWHALE_SPA_HTML_ROOT to avoid sending an HTTP request (#705) Bugfixes: - Downgraded channels dependency to 2.1.6 to fix denied uploads (#697) - Fixed cards display issues on medium/small screens (#707) - Fixed Embed component name that could lead to issue when developping on OSX (#696) - Fixed resizing issues for album cards on artist pages (#694) 0.18.1 (2019-01-29) ------------------- Upgrade instructions are available at https://docs.funkwhale.audio/admin/upgrading.html Fix Gzip compression to avoid BREACH exploit [security] [manual action required] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ In the 0.18 release, we've enabled Gzip compression by default for various content types, including HTML and JSON. Unfortunately, enabling Gzip compression on such content types could make BREACH-type exploits possible. We've removed the risky content-types from our nginx template files, to ensure new instances are safe, however, if you already have an instance, you need to double check that your host nginx virtualhost do not include the following values for the ``gzip_types`` settings:: application/atom+xml application/json application/ld+json application/activity+json application/manifest+json application/rss+xml application/xhtml+xml application/xml For convenience, you can also replace the whole setting with the following snippet:: gzip_types application/javascript application/vnd.geo+json application/vnd.ms-fontobject application/x-font-ttf application/x-web-app-manifest+json font/opentype image/bmp image/svg+xml image/x-icon text/cache-manifest text/css text/plain text/vcard text/vnd.rim.location.xloc text/vtt text/x-component text/x-cross-domain-policy; Many thanks to @jibec for the report! Fix Apache configuration file for 0.18 [manual action required] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ The way front is served has changed since 0.18. The Apache configuration can't serve 0.18 properly, leading to blank screens. If you are on an Apache setup, you will have to replace the `` block with the following:: # similar to nginx 'client_max_body_size 100M;' LimitRequestBody 104857600 ProxyPass ${funkwhale-api}/ ProxyPassReverse ${funkwhale-api}/ And add some more `ProxyPass` directives so that the `Alias` part of your configuration file looks this way:: ProxyPass "/front" "!" Alias /front /srv/funkwhale/front/dist ProxyPass "/media" "!" Alias /media /srv/funkwhale/data/media ProxyPass "/staticfiles" "!" Alias /staticfiles /srv/funkwhale/data/static In case you are using custom css and theming, you also need to match this block:: ProxyPass "/settings.json" "!" Alias /settings.json /srv/funkwhale/custom/settings.json ProxyPass "/custom" "!" Alias /custom /srv/funkwhale/custom Enhancements: - Added name attributes on all inputs to improve UX, especially with password managers (#686) - Disable makemigrations in production and misleading message when running migrate (#685) - Display progress during file upload - Hide pagination when there is only one page of results (#681) - Include shared/public playlists in Subsonic API responses (#684) - Use proper locale for date-related/duration strings (#670) Bugfixes: - Fix transcoding of in-place imported tracks (#688) - Fixed celery worker defaulting to development settings instead of production - Fixed crashing Django admin when loading track detail page (#666) - Fixed list icon alignement on landing page (#668) - Fixed overescaping issue in notifications and album page (#676) - Fixed wrong number of affected elements in bulk action modal (#683) - Fixed wrong URL in documentation for funkwhale_proxy.conf file when deploying using Docker - Make Apache configuration file work with 0.18 changes (#667) - Removed potential BREACH exploit because of Gzip compression (#678) - Upgraded kombu to fix an incompatibility with redis>=3 Documentation: - Added user upload documentation at https://docs.funkwhale.audio/users/upload.html 0.18 "Naomi" (2019-01-22) ------------------------- This release is dedicated to Naomi, an early contributor and beta tester of Funkwhale. Her positivity, love and support have been incredibly helpful and helped shape the project as you can enjoy it today. Thank you so much Naomi <3 Many thanks to the dozens of people that contributed to this release: translators, developers, bug hunters, admins and backers. You made it possible! Upgrade instructions are available at https://docs.funkwhale.audio/admin/upgrading.html, ensure you also execute the intructions marked with ``[manual action required]`` and ``[manual action suggested]``. See ``Full changelog`` below for an exhaustive list of changes! Audio transcoding is back! ^^^^^^^^^^^^^^^^^^^^^^^^^^ After removal of our first, buggy transcoding implementation, we're proud to announce that this feature is back. It is enabled by default, and can be configured/disabled in your instance settings! This feature works in the browser, with federated/non-federated tracks and using Subsonic clients. Transcoded tracks are generated on the fly, and cached for a configurable amount of time, to reduce the load on the server. Licensing and copyright information ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Funkwhale is now able to parse copyright and license data from file and store this information. Apart from displaying it on each track detail page, no additional behaviour is currently implemented to use this new data, but this will change in future releases. License and copyright data is also broadcasted over federation. License matching is done on the content of the ``License`` tag in the files, with a fallback on the ``Copyright`` tag. Funkwhale will successfully extract licensing data for the following licenses: - Creative Commons 0 (Public Domain) - Creative Commons 1.0 (All declinations) - Creative Commons 2.0 (All declinations) - Creative Commons 2.5 (All declinations and countries) - Creative Commons 3.0 (All declinations and countries) - Creative Commons 4.0 (All declinations) Support for other licenses such as Art Libre or WTFPL will be added in future releases. Instance-level moderation tools ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ This release includes a first set of moderation tools that will give more control to admins about the way their instance federates with other instance and accounts on the network. Using these tools, it's now possible to: - Browse known accounts and domains, and associated data (storage size, software version, etc.) - Purge data belonging to given accounts and domains - Block or partially restrict interactions with any account or domain All those features are usable using a brand new "moderation" permission, meaning you can appoint one or multiple moderators to help with this task. I'd like to thank all Mastodon contributors, because some of the these tools are heavily inspired from what's being done in Mastodon. Thank you so much! Iframe widget to embed public tracks and albums [manual action required] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Funkwhale now supports embedding a lightweight audio player on external websites for album and tracks that are available in public libraries. Important pages, such as artist, album and track pages also include OpenGraph tags that will enable previews on compatible apps (like sharing a Funkwhale track link on Mastodon or Twitter). To achieve that, we had to tweak the way Funkwhale front-end is served. You'll have to modify your nginx configuration when upgrading to keep your instance working. **On docker setups**, edit your ``/srv/funkwhale/nginx/funkwhale.template`` and replace the ``location /api/`` and `location /` blocks by the following snippets:: location / { include /etc/nginx/funkwhale_proxy.conf; # this is needed if you have file import via upload enabled client_max_body_size ${NGINX_MAX_BODY_SIZE}; proxy_pass http://funkwhale-api/; } location /front/ { alias /frontend/; } The change of configuration will be picked when restarting your nginx container. **On non-docker setups**, edit your ``/etc/nginx/sites-available/funkwhale.conf`` file, and replace the ``location /api/`` and `location /` blocks by the following snippets:: location / { include /etc/nginx/funkwhale_proxy.conf; # this is needed if you have file import via upload enabled client_max_body_size ${NGINX_MAX_BODY_SIZE}; proxy_pass http://funkwhale-api/; } location /front/ { alias ${FUNKWHALE_FRONTEND_PATH}/; } Replace ``${FUNKWHALE_FRONTEND_PATH}`` by the corresponding variable from your .env file, which should be ``/srv/funkwhale/front/dist`` by default, then reload your nginx process with ``sudo systemctl reload nginx``. Alternative docker deployment method ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Thanks to the awesome work done by @thetarkus at https://github.com/thetarkus/docker-funkwhale, we're now able to provide an alternative and easier Docker deployment method! In contrast with our current, multi-container offer, this method integrates all Funkwhale processes and services (database, redis, etc.) into a single, easier to deploy container. Both methods will coexist in parallel, as each one has pros and cons. You can learn more about this exciting new deployment option by visiting https://docs.funkwhale.audio/installation/docker.html! Automatically load .env file ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ On non-docker deployments, earlier versions required you to source the config/.env file before launching any Funkwhale command, with ``export $(cat config/.env | grep -v ^# | xargs)`` This led to more complex and error prone deployment / setup. This is not the case anymore, and Funkwhale will automatically load this file if it's available. Delete pre 0.17 federated tracks [manual action suggested] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ If you were using Funkwhale before the 0.17 release and federated with other instances, it's possible that you still have some unplayable federated files in the database. To purge the database of those entries, you can run the following command: On docker setups:: docker-compose run --rm api python manage.py script delete_pre_017_federated_uploads --no-input On non-docker setups:: python manage.py script delete_pre_017_federated_uploads --no-input Enable gzip compression [manual action suggested] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Gzip compression will be enabled on new instances by default and will reduce the amount of bandwidth consumed by your instance. If you want to benefit from gzip compression on your instance, edit your reverse proxy virtualhost file (located at ``/etc/nginx/sites-available/funkwhale.conf``) and add the following snippet in the server block, then reload your nginx server:: server { # ... exiting configuration # compression settings gzip on; gzip_comp_level 5; gzip_min_length 256; gzip_proxied any; gzip_vary on; gzip_types application/javascript application/vnd.geo+json application/vnd.ms-fontobject application/x-font-ttf application/x-web-app-manifest+json font/opentype image/bmp image/svg+xml image/x-icon text/cache-manifest text/css text/plain text/vcard text/vnd.rim.location.xloc text/vtt text/x-component text/x-cross-domain-policy; # end of compression settings } Full changelog ^^^^^^^^^^^^^^ Features: - Allow embedding of albums and tracks available in public libraries via an