- Fix media pipeline ([18019948e](https://github.com/pixelfed/pixelfed/commit/18019948e47e11a152d833efa90d0594b24b9515))
- Allow RUNTIME_UID and RUNTIME_GID build customize www-data ([fbd887408](https://github.com/pixelfed/pixelfed/commit/fbd8874081f39bf44086c922929f144963d6fb25))
- Fix fetching by properly retrying certain error responses ([56b96359c](https://github.com/pixelfed/pixelfed/commit/56b96359c3f73ba861311a55081c4ab3ef914829))
- Fix RemoteReplyResolvePipeline, make unique until processing ([226785f08](https://github.com/pixelfed/pixelfed/commit/226785f085c54d96a351fdda6ca25b97fe5c730a))
- Refactor Direct Messages, add Group Chat support and proper context threading with Mastodon ([9c81a75ad](https://github.com/pixelfed/pixelfed/commit/9c81a75ad3153172f3fa2732a36551b4efaad44a))
- Update AP transformers, fix improper arrays ([2c709c9eb](https://github.com/pixelfed/pixelfed/commit/2c709c9ebea31b0a77e0bf6385bf397a94515473))
- Fix FeedInsertRemotePipeline date handling. Fixes [#7406](https://github.com/pixelfed/pixelfed/issues/7406) ([2cf8508ca](https://github.com/pixelfed/pixelfed/commit/2cf8508ca6f51a026264131aba2559d000b9d52a))
- Remove sudo mode from admin dashboard. Closes [#7396](https://github.com/pixelfed/pixelfed/issues/7396) ([713c63757](https://github.com/pixelfed/pixelfed/commit/713c63757a7d95836500ea92fb71b073da2bddd8))
- Update profile view, show website link for verfication purposes ([f6da697e2](https://github.com/pixelfed/pixelfed/commit/f6da697e2a669598e487af604cf7a485e7f5d6c3))
- Fix deletes, again ([a4c176d52](https://github.com/pixelfed/pixelfed/commit/a4c176d52006ce893d227860345bcbf97e84316b))
This release includes `FEP-044f: Consent-respecting quote posts`, `FEP-8fcf followers collection synchronization`, and a bunch of ActivityPub federation improvements.
- Update Login view, fix tab from email to password ([e215fb64f](https://github.com/pixelfed/pixelfed/commit/e215fb64f97effe5558345eb6b614237fb479f9a))
- Update FeedInsertRemotePipeline, prevent statuses older than a week from being distributed ([c7600fb51](https://github.com/pixelfed/pixelfed/commit/c7600fb51a303eeda39b92c5e5481f60dd0fc23b))
- HCaptcha ENV have changed - CAPTCHA_SITEKEY/CAPTCHA_SECRET is now CAPTCHA_H_SITEKEY/CAPTCHA_H_SECRET (We've added support for additional Captchas - Turnstile, and Cap)
- APP_LOCALE needs to be updated from "2 letter codes" to "locale tags". Examples: `es` to `es-ES` or `de` to `de-DE`. (Notice: I have mapped the old names to the new names for this release, but that mapping will be removed in future releases).
- Use now() helper instead of Carbon::now() for current-time access ([277b8aa97](https://github.com/pixelfed/pixelfed/commit/277b8aa97067e4f811e12c231e2535f24df36433))
- Replace Str::of() fluent chains with static Str::/native calls ([a42449342](https://github.com/pixelfed/pixelfed/commit/a4244934203bae935df2119284ebc8a520662b10))
- Use LazilyRefreshDatabase instead of plain RefreshDatabase in tests ([255bdaa2a](https://github.com/pixelfed/pixelfed/commit/255bdaa2a0be9ade8cfe533a0fa6b5b485ae7efa))
- Upgrade to Laravel 13 ([42620e584](https://github.com/pixelfed/pixelfed/commit/42620e584b4b6c3dab1be71458b4723d62284811))
- Fix Redis queue retry_after being shorter than Horizon's timeout ([582083a7f](https://github.com/pixelfed/pixelfed/commit/582083a7faa6f2bf50e11b2dbe4c821ecbb1a914))
- Fix dangling DB transactions in CustomFilterController ([8fa18ff8c](https://github.com/pixelfed/pixelfed/commit/8fa18ff8c60d827239aa11d78aff8dae5b9d267a))
- Stop swallowing overlay ValidationException into a generic 500 ([62d3bc840](https://github.com/pixelfed/pixelfed/commit/62d3bc8406bb8844de4cbe8c9847a61adc55524d))
- Change storage size calculation from floor to ceil ([ad686571b](https://github.com/pixelfed/pixelfed/commit/ad686571bf317b0116e4e2a369ad5fe9f5cb15bd))
- Add redirect for Horizon dashboard ([815b13862](https://github.com/pixelfed/pixelfed/commit/815b13862084f9d9a6e03916128e86cae611f687))
- Fix story video upload probe path ([#7203](https://github.com/pixelfed/pixelfed/pull/7203))
- Add failure logging to admin:MediaMoveStorageLocalToCloud and enable debug by default ([0c68b6a68](https://github.com/pixelfed/pixelfed/commit/0c68b6a680feecc2d973c106a6863817f0f49095))
- Make original_sha256 verify opt-in in MediaMoveStorageLocalToCloud ([441a94e73](https://github.com/pixelfed/pixelfed/commit/441a94e73180c58661e6ff702730ad7a53bb6ff0))
- Revert debug-by-default in MediaMoveStorageLocalToCloud ([438560415](https://github.com/pixelfed/pixelfed/commit/438560415aef8497773a1f4718487dbf55c25896))
- Remove sha256 verification from MediaMoveStorageLocalToCloud ([341351c47](https://github.com/pixelfed/pixelfed/commit/341351c47e9083eb2f86a1807cc9700ab1189de1))
- Fix web notifications not loading ([#7195](https://github.com/pixelfed/pixelfed/pull/7195))
- Add notification epoch inline fallback test ([#7162](https://github.com/pixelfed/pixelfed/pull/7162))
- Normalize cropped story images to the 1080x1920 canvas ([#7215](https://github.com/pixelfed/pixelfed/pull/7215))
- chore(deps-dev): bump laravel/pint from 1.30.5 to 1.31.1 ([1ba0535bb](https://github.com/pixelfed/pixelfed/commit/1ba0535bb0710d917c3db50285526e9b41c7798e))
- chore(deps): bump league/iso3166 from 4.4.0 to 4.5.0 ([d1081f2bc](https://github.com/pixelfed/pixelfed/commit/d1081f2bc7426904c1123c1311da2ac8872d6be7))
- chore(deps-dev): bump laravel/telescope from 5.23.0 to 5.24.0 ([0388d3e4f](https://github.com/pixelfed/pixelfed/commit/0388d3e4fbff31afb7a02c964d0abc2ba3ca20aa))
- chore(deps): bump laravel/horizon from 5.48.3 to 5.49.0 ([e654143a1](https://github.com/pixelfed/pixelfed/commit/e654143a1a76de34de603098080101d2e2ec6233))
- Update AP Delivery Service, fix signing and delivery ([868e09b64](https://github.com/pixelfed/pixelfed/commit/868e09b64df4b1aa80a5d1fcd5978473b423880e))
- Update PublicApiController, fix getStatus to use database check ([a3160cdd2](https://github.com/pixelfed/pixelfed/commit/a3160cdd2300b23e45fc8325d6a214c652b7af88))
- Update AdminStatsService, fix reports_monthly stat ([6a2208087](https://github.com/pixelfed/pixelfed/commit/6a2208087c636469e7397b6398ad244cd8ab4010))
- Fix AdminApiController profiles endpoint, dont include deleted accounts ([e0550c441](https://github.com/pixelfed/pixelfed/commit/e0550c441c97fba3006b80c0fd17a536c10460bf))
- Use absolute path for /horizon dashboard redirect ([ac872c12e](https://github.com/pixelfed/pixelfed/commit/ac872c12edc7932617c53c73039c67abe0881e9d))
- Invalidate notification cache when deleting a status ([f1e4536d1](https://github.com/pixelfed/pixelfed/commit/f1e4536d1963997bc2b07b99724d4504b1dbfcda))
- Guard home timeline filter against null account ([b13c374f2](https://github.com/pixelfed/pixelfed/commit/b13c374f21331018c2fbeb6120b516ebf67cc086))
- Escape message in curated register details email to fix reflected XSS ([623f03bb6](https://github.com/pixelfed/pixelfed/commit/623f03bb683dbc18f91645ac79eca80b529e60c3))
- Import Purify facade in ApiV1Controller to fix larastan class.notFound ([5ec239404](https://github.com/pixelfed/pixelfed/commit/5ec239404bc0e6996103cc208b82c7011dacd960))
- Extend story author-key TTL instead of overwriting so it survives to the longest-lived story ([fe382bdb8](https://github.com/pixelfed/pixelfed/commit/fe382bdb86750c20e1f10e37e7d91a5b0b2b9418))
- Validate report object_id as a positive integer to fix 500 on array input ([b4bd3c87a](https://github.com/pixelfed/pixelfed/commit/b4bd3c87a0ada5c7837917f4c24c9ea2b42b3a24))
- Send verification email for admin-invite users that require verification ([cfbdabdd6](https://github.com/pixelfed/pixelfed/commit/cfbdabdd61c869c0bd87794f856906df7dae2694))
- Fix remove-all follower purge chunkById key and gate the route behind dangerzone ([7b90bc869](https://github.com/pixelfed/pixelfed/commit/7b90bc869976366a16704910ae1edc8964db6b58))
- Purge status_edits on account and status deletion ([60284a871](https://github.com/pixelfed/pixelfed/commit/60284a871e08f2557274635774aded70b2523913))
- Enforce can-post role check on POST /api/v2/media ([3a2360657](https://github.com/pixelfed/pixelfed/commit/3a2360657354b1aec8475c17ba6f49e9ab49c910))
- Validate remote update attachments before detaching existing media ([9b829ca56](https://github.com/pixelfed/pixelfed/commit/9b829ca56e55e08b18cf6dfd95b8f4d7b24f3b10))
- Mark OIDC login session password-confirmed to fix dangerzone lockout ([fbca487bc](https://github.com/pixelfed/pixelfed/commit/fbca487bcdd8732938b3d440d96dc394599838d2))
- Isolate fanout delivery failures from StatusDelete local cleanup ([8a4567a5c](https://github.com/pixelfed/pixelfed/commit/8a4567a5c28d740275df5ba52181b3c321ba82b7))
- fix(federation): swallow ConnectionException on synchronous AP delivery ([729396302](https://github.com/pixelfed/pixelfed/commit/729396302a8b7bf40042e302c0def8151159d5fd))
- test(federation): run AP delivery tests in production env ([7b11b72e1](https://github.com/pixelfed/pixelfed/commit/7b11b72e1d4b1491c1bd13fa55bbd69bcfdcecc5))
- Make the landing page translatable ([443962c92](https://github.com/pixelfed/pixelfed/commit/443962c92b0a68d050bd0949e46a9d4da898d233))
- Fix last untranslated strings on the login + explore pages ([ac790b1d8](https://github.com/pixelfed/pixelfed/commit/ac790b1d8a3b6db75294da7ca381be958a211979))
- More translatable strings : landing, privacy policy, terms ([6537787c4](https://github.com/pixelfed/pixelfed/commit/6537787c4e6d4024ab53ce71e587c0358da31a4a))
- Automate Crowdin sync via GitHub Action ([9002d6ea2](https://github.com/pixelfed/pixelfed/commit/9002d6ea2458fd0874149d35d05a6b266528dac8))
- Remove dead notification.php and timeline.php lang files ([0f10ec0a4](https://github.com/pixelfed/pixelfed/commit/0f10ec0a470758645d6c55cf52705cd23fa34317))
- Use locale_get_display_name for language labels ([f4dbddd8b](https://github.com/pixelfed/pixelfed/commit/f4dbddd8b52cf50c342449f8dc422d722720e118))
- Revert "Remove dead notification.php and timeline.php lang files" ([2eaf0eaf3](https://github.com/pixelfed/pixelfed/commit/2eaf0eaf34efe2be06b0597ce7f797e1742d90e7))
- Add experimental DB-matrix test workflow (mysql/mariadb/postgres) ([983e51240](https://github.com/pixelfed/pixelfed/commit/983e512409fa37093aa9ab90921ff42b363b26f3))
- Modify workflow triggers for staging and unstable branches ([d574ddf1f](https://github.com/pixelfed/pixelfed/commit/d574ddf1f4b293b243030bec31d20a579d94a501))
- Compile FFmpeg from source in Docker image ([484b92138](https://github.com/pixelfed/pixelfed/commit/484b921382e4edb234dd3c07be3c7b9492f23bce))
- Disable buildx provenance/SBOM attestations for GHCR images ([19e4620de](https://github.com/pixelfed/pixelfed/commit/19e4620deb2123d84cf70ab214831285416aa368))
- Isolate Redis keys per DB matrix entry; use mariadb connection ([fe289c312](https://github.com/pixelfed/pixelfed/commit/fe289c31264bf4db98dd436254d5c73f2e93fb97))
- Bump DB matrix to PHP 8.5 and mysql 8.5 ([5bdc18e47](https://github.com/pixelfed/pixelfed/commit/5bdc18e479c15c1117d1f7bcd539f8fcc6689af8))
- Make DB matrix workflow manual-only (workflow_dispatch) ([8eda1d039](https://github.com/pixelfed/pixelfed/commit/8eda1d039ffeeeeb3555b27783f7ab63dc922d17))
- Replace blocked crowdin/github-action with Crowdin CLI ([a3931bb07](https://github.com/pixelfed/pixelfed/commit/a3931bb0711d3091a38a8ef466868354309aa8bd))
- chore(deps): bump intervention/image-driver-vips from 4.1.4 to 4.1.5 ([b8ce1b0e5](https://github.com/pixelfed/pixelfed/commit/b8ce1b0e5a57bbd8e801692907066c6990a786d9))
- chore(deps-dev): bump larastan/larastan from 3.11.0 to 3.12.0 ([a372ff6f8](https://github.com/pixelfed/pixelfed/commit/a372ff6f8e2a4d1cb610653177c341c20c5d22cf))
- chore(deps-dev): bump laravel/pint from 1.31.1 to 1.32.1 ([31022eb79](https://github.com/pixelfed/pixelfed/commit/31022eb7981c70f1db9dead7f89a4b5aaebd2776))
- Add HasMany return type to CustomFilter::statuses() for Larastan ([11d547415](https://github.com/pixelfed/pixelfed/commit/11d547415e7f42eaef57f4ca57e0e6d58e20d8a4))
- Change section title to 'Host your own instance with' ([a005aa485](https://github.com/pixelfed/pixelfed/commit/a005aa485eee0930fb1170080e900fb1d6f24aa4))
- Enable auto approval for imported translations ([7a59b80cf](https://github.com/pixelfed/pixelfed/commit/7a59b80cf18ca232bb1250eb01d8120adc262c19))
- Default image driver to vips ([99c3f2f6b](https://github.com/pixelfed/pixelfed/commit/99c3f2f6bab41b2197c493a0bfae1103d60dccc6))
- Install libvips on CI runners and test on the vips driver ([ddc617a8d](https://github.com/pixelfed/pixelfed/commit/ddc617a8d2e36954c1d37ec8f5db0789dec6f8c6))
- Fix videos never reaching cloud storage by downscaling in Blurhash ([ef56880a7](https://github.com/pixelfed/pixelfed/commit/ef56880a74a87cc5717f74971bfb52b6e010723b))
- Blurhash::generate() allocates one PHP array per pixel of the source. At
- roughly 255 bytes per pixel (measured: 224 MB peak for a 720x1280 frame) a
- 1920x1080 frame approaches half a gigabyte.
- Image thumbnails survive this because they are capped at 640x640 in
- Image::\_\_construct() _and_ run under that constructor's
- ini_set('memory_limit', '1024M'). Video thumbnails get neither: FFmpeg saves
- them at the source video's resolution, and VideoThumbnail never raises the
- limit. So a video whose frame is 1080p or larger exhausts memory_limit.
- That is a PHP fatal, not an \\Exception, which has three consequences:
- the catch block in VideoThumbnail::handle() does not catch it
- the job never lands in failed_jobs, so nothing reports a problem
- MediaStoragePipeline::dispatch() on the last line of handle() never runs
- The video therefore stays on local disk permanently while images beside it
- replicate normally. Reported in #2652 (2021-02-13) and diagnosed correctly in
- that thread on 2021-11-04.
- Two changes:
- 1. Blurhash::generate() downscales to 128px on the long edge before sampling.
- The result is a 4x4-component DCT, so full-resolution sampling adds
- essentially nothing: measured against the full-resolution hash, mean
- per-channel deviation of the decoded 24x24 preview is ~7.5/255 at a 32px
- sample, ~4.5/255 at 64px, ~2.5/255 at 128px, and no better at 256px. Peak
- memory for the frame above drops from 224 MB to 6 MB.
- This removes the ceiling for every caller rather than moving it, which is
- all that raising memory_limit would have done. Existing stored hashes are
- not recomputed, so nothing already published changes appearance.
- 2. VideoThumbnail wraps the blurhash in its own try/catch, so a decorative
- step can no longer skip the replication dispatch. Change 1 covers the
- fatal; this covers any ordinary exception.
- Verified on a live instance with S3 cloud storage: a 1920x1080 video that
- previously stranded now generates a blurhash, uploads original and thumbnail
- to the bucket, sets cdn_url/thumbnail_url/replicated_at, and removes the local
- copies. Existing images re-hash to visually identical previews.
- Replace jenssegers/agent with matomo/device-detector ([651f0de74](https://github.com/pixelfed/pixelfed/commit/651f0de74faf414f56c6d3297e10636e82479cd0))
- Remove unmaintained jenssegers/agent package (no releases since 2021)
- Add matomo/device-detector v6.5 as actively maintained replacement
- Create App\\Services\\UserAgentService wrapper for drop-in compatibility
- Update UserDevice model and ApiV1Dot1Controller to use new service
- Fix PSR-4 autoload: rename Webfinger.php to WebFinger.php ([47e280b90](https://github.com/pixelfed/pixelfed/commit/47e280b90dd2b02846aa88d209b5e5cb6b65d29b))
- The class is App\\Rules\\WebFinger but the file was named Webfinger.php,
- causing a PSR-4 compliance warning during autoload generation.
- Apply Pint formatting to tests/ ([de3375a9f](https://github.com/pixelfed/pixelfed/commit/de3375a9f9f7c334c7c81bba20522733d5c6566c))
- Apply Pint formatting to resources/ ([e8d6a48cd](https://github.com/pixelfed/pixelfed/commit/e8d6a48cddea439c8c664d4308d3c4843552f46d))
- Apply Pint formatting to bootstrap/ ([3b0fd708c](https://github.com/pixelfed/pixelfed/commit/3b0fd708c8814dc848abafd17f46d12800c001c5))
- Apply Pint formatting to public/ ([de965d410](https://github.com/pixelfed/pixelfed/commit/de965d41065faf1774974b72b8c5dd83e29f2823))
- Adopt short array syntax ([4c7780944](https://github.com/pixelfed/pixelfed/commit/4c77809444db6e6330db07e664aa49510b9ea250))
- Since PHP 5.4 the short array syntax `\[\]` may be used instead of `array()`.
- Convert string references to `::class` ([19880c2ff](https://github.com/pixelfed/pixelfed/commit/19880c2ffb54899f90d000a91a85b393ebb23da7))
- PHP 5.5.9 adds the new static `class` property which provides the fully qualified class name. This is preferred over using strings for class names since the `class` property references are checked by PHP.
- Add linting scripts to composer.json ([64eb52596](https://github.com/pixelfed/pixelfed/commit/64eb52596bb80396556ced54ee60bc7e3b550ecf))
- Fix first follower/following record excluded from API responses ([396cf2d86](https://github.com/pixelfed/pixelfed/commit/396cf2d86164406059372840c6bc14ad306b35dd))
- Fixes #6695
- When no pagination params are provided, the default min_id was set to 1
- and the query used 'id > 1', which excluded the very first follower row
- (id=1) on fresh instances.
- Changed default min_id from 1 to 0 and switched the direction check from
- truthy evaluation to !== null, so the query becomes 'id > 0' which
- correctly includes all records.
- Show detailed upload error messages instead of generic error ([5eda13081](https://github.com/pixelfed/pixelfed/commit/5eda1308171368e3ef642e78c9e6e2fd6c6e0c4c))
- Fixes #6657
- When media uploads fail with a 422 validation error (e.g. file too large),
- the error dialog now shows the actual validation message including the
- filename, instead of the generic 'An unexpected error occurred.'
- Example: 'DSCF0273.JPG: The file may not be greater than 15000 kilobytes'
- Also improved the default error case to surface server-provided messages
- when available. Applied to both ComposeModal and ComposeClassic components.
- Fix OAuth scope bypass on remove_from_followers endpoint ([822e9c98c](https://github.com/pixelfed/pixelfed/commit/822e9c98cb67be107ade2cfa4fd214ab2bf298a3))
- Fixes #6643
- The POST /api/v1/accounts/{id}/remove_from_followers endpoint was missing
- the token existence check (! $request->user()->token()). While the
- tokenCan('follow') scope check was already present, the missing token
- guard meant unauthenticated token-less requests could potentially bypass
- the scope enforcement.
- Added the standard guard pattern consistent with accountFollowById and
- Fix OAuth client secret not displayed after creation ([655d71ba5](https://github.com/pixelfed/pixelfed/commit/655d71ba5ce1dcc5a94bd03f345515eef1f68040))
- Fixes #6630 (partial — client secret issue)
- In Passport v13, client secrets are hashed at the model level and only
- available as plain_secret on the response from the creation endpoint.
- The previous code immediately re-fetched the client list after creation,
- losing the plain secret since it's not stored or returned on GET.
- Changes:
- Capture plain_secret from the POST response
- Show a dedicated modal with the client ID and secret after creation
- Warn users to copy the secret immediately (it won't be shown again)
- Add a Copy button for convenience
- Show 'Hidden (only shown at creation)' in the table for existing clients
- Handle PAT creation gracefully when not configured ([1ab677a52](https://github.com/pixelfed/pixelfed/commit/1ab677a526eafb65c4569e5d9a27245f27780293))
- Fixes #6630 (partial — PAT 500 error)
- Previously, POST /oauth/personal-access-tokens would throw an unhandled
- RuntimeException (HTTP 500) when:
- OAUTH_PAT_ENABLED is false (the default), or
- No personal access client exists in the database
- Now the endpoint:
- 1. Returns 403 with a clear message if PAT is disabled in config
- 2. Catches RuntimeException from the token factory and returns 500
- with an actionable error message instead of a stack trace
- Prevent deletion of personal access OAuth client ([53759e3ad](https://github.com/pixelfed/pixelfed/commit/53759e3ad64d2492893e503ae604b8d44592dd92))
- Add GitHub Actions workflow for PHP Pint linting ([e8b18f669](https://github.com/pixelfed/pixelfed/commit/e8b18f66901b1762f2018b980b7ec7dc716262ef))
- Add 'unstable' branch to workflow and update PHP version ([699b8af2d](https://github.com/pixelfed/pixelfed/commit/699b8af2d5d534f7665bcdec4fae13f8fecaa3d8))
- Fix ApiV1Controller, ensure follow notifications have an account ([e1235dfd7](https://github.com/pixelfed/pixelfed/commit/e1235dfd75f1eb4e853fa751fe178d7c3330c5e3))
- Update Docker workflow to include unstable branch ([e53917f04](https://github.com/pixelfed/pixelfed/commit/e53917f047b8fe1de72180d87e977b64b934aa56))
- Enhance Docker workflow with concurrency and platforms ([8e3a37553](https://github.com/pixelfed/pixelfed/commit/8e3a375534cc15cf1f227cdbacd8058fef51fbd4))
- Apply pint formatting to resources/ ([78b2bc323](https://github.com/pixelfed/pixelfed/commit/78b2bc3235a62d4f1f0ea2062d20c168e75b8b08))
- Update and rename laravel.yml to php-laravel-tests.yml ([580042f36](https://github.com/pixelfed/pixelfed/commit/580042f36d57415c827a610ad3f8d7c2d4d56afe))
- Update ApiV1Controller, add show_atom support to update_credentials endpoint ([4e2e49f84](https://github.com/pixelfed/pixelfed/commit/4e2e49f8435c143e79566a1185775a76f29bcada))
- refactor: convert string-based routes to ::class array syntax ([28927f6f6](https://github.com/pixelfed/pixelfed/commit/28927f6f661f17040d08b741ad4fec5a3ad0f43f))
- Replace all 'Controller@method' string references with
- \[Controller::class, 'method'\] array syntax across all route files.
- Remove the $namespace property and ->namespace() calls from
- RouteServiceProvider.
- This is required for Laravel 13 compatibility where string-based
- controller routing and automatic namespace prefixing will be removed.
- 742 route references converted across 5 route files.
- refactor: replace deprecated laravel/helpers with native alternatives ([edb4368b0](https://github.com/pixelfed/pixelfed/commit/edb4368b08008c977ea618c1dff96c0e61a61ceb))
- Replace all deprecated helper function calls:
- str_slug() → Str::slug()
- starts_with() → str_starts_with()
- ends_with() → str_ends_with()
- array_first() → Arr::first()
- array_last() → Arr::last()
- array_flatten() → Arr::flatten()
- Remove laravel/helpers package from composer.json as it is no longer
- needed and will not be maintained for Laravel 13.
- refactor: use ::class syntax in EventServiceProvider ([741bc995c](https://github.com/pixelfed/pixelfed/commit/741bc995ca1133bfdf287b15a62fda56c9b36a5c))
- Replace string-based event class references with proper ::class imports
- for better IDE support and static analysis compatibility.
- fix: resolve PDO::MYSQL_ATTR_SSL_CA deprecation on PHP 8.5 ([5041e1805](https://github.com/pixelfed/pixelfed/commit/5041e180500c8566da4ea86fb5c6a30a7e6c3555))
- Use Pdo\\Mysql::ATTR_SSL_CA when available (PHP 8.5+), falling back to
- the legacy PDO::MYSQL_ATTR_SSL_CA constant for older PHP versions.
- This eliminates the deprecation warning during Docker builds and runtime.
- fix: replace str_random/str_limit/str_slug in Blade templates and tests ([30db57448](https://github.com/pixelfed/pixelfed/commit/30db57448f96c764d1a0cacb776b4ce003ee62d8))
- These deprecated helpers will throw 'undefined function' errors at
- runtime since laravel/helpers was removed. Replace with Str::random(),
- Str::limit(), and Str::slug() respectively.
- fix: remove bootstrap/cache bind mount from docker-compose ([f5d166a93](https://github.com/pixelfed/pixelfed/commit/f5d166a933731a728060d02dd3e3bc8277dc75ca))
- The bootstrap/cache volume mount causes stale service provider references
- to persist across rebuilds. When a package is removed, the host's cached
- packages.php/services.php still reference the old provider, causing
- 'Class not found' errors at container startup.
- The AUTORUN*LARAVEL*\*\_CACHE env vars already handle cache regeneration
- on each container start, making the bind mount unnecessary.
- refactor: migrate to modern bootstrap/app.php architecture ([8e41f6fdf](https://github.com/pixelfed/pixelfed/commit/8e41f6fdf8538f805a1c54c29783cbf0bc3b7adb))
- Consolidate the legacy Laravel 5-era kernel/handler architecture into
- the modern Application::configure() pattern introduced in Laravel 11:
- CSRF exceptions (/api/v1/\*, oauth/token) are now configured via
- $middleware->validateCsrfTokens(except: \[...\]) in bootstrap/app.php.
- All 107 tests pass.
- Add view_oidc_callback_ensure_valid_username unit test ([22ff6810b](https://github.com/pixelfed/pixelfed/commit/22ff6810b9d33507c53451f28b95135b9a50eb0e))
- refactor: replace short facade aliases with fully-qualified imports ([c807a8524](https://github.com/pixelfed/pixelfed/commit/c807a8524c22f53731d0c45ebcfde88041663c4e))
- Convert all 273 short facade alias imports (e.g. 'use Cache;') to their
- fully-qualified class names (e.g. 'use Illuminate\\Support\\Facades\\Cache;')
- across 193 files.
- This resolves 643 PHPStan 'class.notFound' errors caused by the static
- analyzer being unable to resolve global aliases, and aligns with modern
- Laravel conventions. It also unblocks removing the aliases array from
- refactor: update phpstan.neon with Larastan 3.x best practices ([890dc5534](https://github.com/pixelfed/pixelfed/commit/890dc55342785206d077aaeaaf7bdc4c87c8dd90))
- Add databaseMigrationsPath for model property type inference
- Add configDirectories for config key validation
- Add parseModelCastsMethod to read casts() methods
- Add enableMigrationCache for faster repeated analysis
- Ignore intentional 'new static()' pattern (Autolink has subclass)
- Remove stale baseline reference and outdated comments
- fix: resolve undefined $status variable in GroupsPostController::deletePost ([e7ef58969](https://github.com/pixelfed/pixelfed/commit/e7ef58969cd138346843b390d1010d7843086089))
- Replace all references to non-existent $status with $gp (the GroupPost
- instance already in scope). This was a bug where the closure variable
- name was changed but references inside the method body were not updated.
- fix: add return type declarations to Eloquent relation methods ([f2159197e](https://github.com/pixelfed/pixelfed/commit/f2159197e8313d4575f4a82607d170c64677eeb2))
- Larastan 3.x requires explicit return types on relation methods to
- verify relation existence when using with(), has(), etc. This adds
- the appropriate return type declarations to all relation methods
- flagged by the larastan.relationExistence rule.
- Models fixed:
- Profile (avatar, statuses)
- User (profile)
- Status (profile, media, hashtags)
- DirectMessage (status, author, recipient)
- Report (reporter, status, reportedUser)
- Like (actor, status)
- Media (status)
- Notification (item)
- HashtagFollow (hashtag)
- OauthClient (user)
- Story (profile)
- StatusHashtag (status, hashtag, profile, media)
- AccountInterstitial (user)
- Hashtag (posts)
- CustomFilter (keywords)
- CustomFilterKeyword (customFilter)
- AdminShadowFilter (profile)
- ImportPost (status)
- fix: replace Auth facade with $request->user() in request-scoped classes ([0939f495b](https://github.com/pixelfed/pixelfed/commit/0939f495bb0dee5122c16205b49a277da22cdd2a))
- Replace Auth::user() with $request->user() and Auth::check() with
- $request->user() !== null (or ! $request->user()) across all
- controllers and middleware that have access to the request object.
- This resolves 99 larastan.noAuthFacadeInRequestScope errors and
- improves Octane compatibility.
- For protected helper methods without $request in scope, uses the
- request() helper instead.
- Methods that previously lacked a Request parameter but used Auth
- facade now accept Request $request via Laravel's auto-injection.
- Revert "Merge pull request #6851 from pixelfed/fix/phpstan-auth-request-scope-2" ([161773490](https://github.com/pixelfed/pixelfed/commit/1617734907c38dd5db60f8526bc3d8a341ee4e62))
- This reverts commit ce4baf69958cc36d6b6ee3f710849b6e06223661, reversing
- changes made to 9235cb979affb6e9fd7ddbb74ace945da1ea2589.
- fix: replace Auth facade with $request->user() in request-scoped classes ([458150e06](https://github.com/pixelfed/pixelfed/commit/458150e06b024a78ca322fd21e43c0e5cca45a90))
- Replace Auth::user() with $request->user() and Auth::check() with
- $request->user() !== null (or ! $request->user()) across all
- controllers and middleware that have access to the request object.
- This resolves 99 larastan.noAuthFacadeInRequestScope errors and
- improves Octane compatibility.
- For protected helper methods without $request in scope, uses the
- request() helper instead.
- Methods that previously lacked a Request parameter but used Auth
- facade now accept Request $request via Laravel's auto-injection.
- fix: use request() helper for methods without Request parameter ([88e0d92ac](https://github.com/pixelfed/pixelfed/commit/88e0d92ac2b8fef2290775133d169cf52301b61f))
- Methods that are registered as route actions without a Request type-hint
- (settings views, export actions) cannot accept Request $request without
- breaking Laravel's route signature reflection. Use the request() helper
- instead to avoid ReflectionFunction TypeError.
- fix: convert OAuth routes from legacy array syntax to modern fluent syntax ([76d187edd](https://github.com/pixelfed/pixelfed/commit/76d187edd886469d2b176241d00c3777e654fbc2))
- The old 'uses' => \[Controller::class, 'method'\] array format causes a
- ReflectionFunction TypeError in Laravel 12 when Livewire's
- SupportPageComponents tries to resolve route bindings. The framework's
- RouteSignatureParameters::fromAction() expects a Closure or string,
- not an array.
- Convert all OAuth/Passport routes to the modern fluent syntax:
- feat: add critical path test suite and fix auth/config issues ([8a2649b3f](https://github.com/pixelfed/pixelfed/commit/8a2649b3ff89c8ee44053425727c82140c60c069))
- Fix StatusFactory: remove non-existent 'place' column, add 'rendered' field
- Add Api/AccountTest for account endpoint coverage (254 total tests)
- chore: add TODO to replace custom FrameGuard with Laravel built-in security headers ([18c288f88](https://github.com/pixelfed/pixelfed/commit/18c288f88f57be858d8c5adb001bdf0b1c2e5caa))
- ci: refactor GitHub Actions with Redis service and best practices ([c7473cd1a](https://github.com/pixelfed/pixelfed/commit/c7473cd1a838a98b545f549d105dc6316dd92886))
- fix: replace removed Passport scope middleware with current classes ([7a96cd2e9](https://github.com/pixelfed/pixelfed/commit/7a96cd2e915290226de9bdbaee874c85bec32c71))
- Laravel Passport 13 renamed:
- CheckScopes → CheckToken (verifies ALL listed scopes)
- CheckForAnyScope → CheckTokenForAnyScope (verifies ANY listed scope)
- The old class names no longer exist, causing BindingResolutionException
- on all /api/v1/admin/\* routes that use the 'scope' or 'scopes' middleware
- aliases.
- fix: replace removed Passport scope middleware with current classes ([0eae871e4](https://github.com/pixelfed/pixelfed/commit/0eae871e40a0d1a15fad83c2850752a2cbe174a8))
- Laravel Passport 13 renamed:
- CheckScopes → CheckToken (verifies ALL listed scopes)
- CheckForAnyScope → CheckTokenForAnyScope (verifies ANY listed scope)
- The old class names no longer exist, causing BindingResolutionException
- on all /api/v1/admin/\* routes that use the 'scope' or 'scopes' middleware
- aliases.
- test: un-skip Passport scope tests now that middleware is fixed ([9f81a5b42](https://github.com/pixelfed/pixelfed/commit/9f81a5b4259497b49ad54d64beea890229f49d9c))
- All v1 admin route security tests now pass with proper assertions
- after the CheckForAnyScope → CheckTokenForAnyScope fix.
- Neither job is dispatched anywhere in the codebase
- Remote follow is handled by ActivityPub Inbox and FollowPipeline
- fix: remove dead publicApi/homeApi methods from TimelineController ([8cf532156](https://github.com/pixelfed/pixelfed/commit/8cf5321566cabc40e7ead05f354c6a02ce926f06))
- publicApi referenced non-existent StatusTimelineTransformer class
- Revert "fix: remove dead publicApi/homeApi methods from TimelineController" ([ea2d054a4](https://github.com/pixelfed/pixelfed/commit/ea2d054a405d6d6f09c383394e940a5c48c85973))
- This reverts commit 8cf5321566cabc40e7ead05f354c6a02ce926f06.
- comment dead code ([f54e6280b](https://github.com/pixelfed/pixelfed/commit/f54e6280bcae0a20c921148fb96ca4553be18d23))
- refactor: replace $fillable with $guarded = \[\] across all models ([570a30d03](https://github.com/pixelfed/pixelfed/commit/570a30d037a74346ec672e2b0bcf07de5dac58fa))
- Aligns all models with the project convention (see .ai/rules/models.md).
- Model::shouldBeStrict() in non-production will catch any issues early.
- fix: replace deprecated starts_with() with str_starts_with() ([26b8a0a6b](https://github.com/pixelfed/pixelfed/commit/26b8a0a6b0d0f230e406424b29e161db1ebe50ae))
- The starts_with() helper was removed in Laravel 6. Use PHP 8's native
- str_starts_with() instead.
- feat: add throttle:api middleware to the api route group ([ed90e619f](https://github.com/pixelfed/pixelfed/commit/ed90e619fbe68d93977612273d0ecb8f0b5099b4))
- Adds a global rate limiter (240 req/min per user or IP) to all API
- routes. Previously rate limiting was only applied ad-hoc on individual
- fix: unpin symfony/http-foundation to allow patch updates ([0c849ca4e](https://github.com/pixelfed/pixelfed/commit/0c849ca4e7e88528a2b13f70841b914a71e3ff61))
- Changes constraint from exact '7.4.13' to '^7.4.13'. The pin was
- introduced for CVE-2026-48736 but is overly restrictive — any 7.4.x
- release >= 7.4.13 includes the fix. This allows future security
- patches to install via composer update.
- Note: Symfony 8.x is blocked by laravel/framework ^12 which requires
- symfony/http-foundation ^7.2.0. Symfony 8 support arrives with Laravel 13.
- chore: remove unused direct dependencies ([1696dfaca](https://github.com/pixelfed/pixelfed/commit/1696dfacaa86c4b98b5ff629b75c9936db6ec621))
- Remove endroid/qr-code: never imported in app code; only
- bacon/bacon-qr-code is used directly (for 2FA QR generation).
- Remove nesbot/carbon: already pulled in transitively by
- laravel/framework, laravel/horizon, and laravel/pulse.
- fix: enable MySQL strict mode and remove defaultStringLength(191) ([1b64c59be](https://github.com/pixelfed/pixelfed/commit/1b64c59bebc440af8b78546f7ce3173404aaedf5))
- Enable strict mode for MySQL connection to prevent silent data
- truncation, zero-date insertion, and division-by-zero errors.
- Remove Schema::defaultStringLength(191) which was a MySQL 5.7
- workaround no longer needed on MySQL 8.0+ / MariaDB 10.3+.
- fix: replace deprecated $request->get() with $request->input() ([4320231c1](https://github.com/pixelfed/pixelfed/commit/4320231c1f621ba2d40e270afa0719d4d7599515))
- Symfony 8.0 removes Request::get(). Laravel 13 will support Symfony 8,
- so these 11 usages would break on upgrade. Using $request->input()
- which checks both query string and request body (same behavior as the
- old get() method).
- refactor: rename VerifyCsrfToken to PreventRequestForgery ([9958b095d](https://github.com/pixelfed/pixelfed/commit/9958b095dd9c8d3ddbdee3f1262f81a70892ed55))
- Prepares for Laravel 13 where VerifyCsrfToken is deprecated in favor
- of PreventRequestForgery. The old class remains as an alias in v13 but
- will be removed in a future version.
- feat: add serializable_classes to cache config for Laravel 13 prep ([ba90d1bd2](https://github.com/pixelfed/pixelfed/commit/ba90d1bd20bd714e021405cdc8d80f0209967957))
- Laravel 13 defaults serializable_classes to false, blocking arbitrary
- PHP object unserialization from cache. This project caches CustomFilter
- model instances (in getCachedFiltersForAccount), so it must be
- explicitly allowlisted.
- All other cache usage in this project stores scalars, arrays, or
- Fractal-transformed array output — no other classes need allowlisting.
- Change DB_STRICT environment variable to true ([35cb9a9dc](https://github.com/pixelfed/pixelfed/commit/35cb9a9dcb1495cc3c5d38225549fc7bad290cf9))
- Set strict mode to true in database configuration ([542434785](https://github.com/pixelfed/pixelfed/commit/542434785c72a6746018306dac75bea085203454))
- Update model loading behavior in AppServiceProvider ([c04fec21f](https://github.com/pixelfed/pixelfed/commit/c04fec21fcfa94e7b4e160561d5c1b46fd4376d6))
- Move ValidateCsrfToken middleware to a new position ([46393bd9f](https://github.com/pixelfed/pixelfed/commit/46393bd9fc2b8cdba87647ea7206f205cb6e9316))
- refactor: add return type declarations to controller methods ([54cfdf3c2](https://github.com/pixelfed/pixelfed/commit/54cfdf3c2b5f37013c40bc8567a96da1f42627d1))
- Adds explicit return type declarations to 498 controller methods
- across 88 files. Types inferred from return statements:
- JsonResponse for response()->json() returns
- RedirectResponse for redirect()/back() returns
- View (contract) for view() returns
- Response for response() returns
- void for methods with no return value
- array for array returns
- string/int/bool for scalar returns
- Also fixes 3 methods with incorrect bare returns:
- AvatarController::deleteAvatar - bare return → json response
- ImportPostController::checkPermissions - bare return → true
- RemoteAuthController::accountToId - bare return → empty array
- refactor: replace Guzzle pool with Laravel HTTP client in StatusDelete ([00dd5b3d9](https://github.com/pixelfed/pixelfed/commit/00dd5b3d922fbd016a777a457950971165278ca7))
- Replace direct GuzzleHttp\\Client and Pool usage in fanoutDelete()
- with Laravel's Http::pool() facade. This provides:
- Testability via Http::fake() in tests
- Consistent timeout/retry configuration
- No direct Guzzle dependency in application code
- Proper integration with Laravel's HTTP client features
- Merge duplicate story reaction/reply handlers into single handleStoryInteraction method
- Break handleDirectMessage into focused sub-methods
- Reduce Inbox.php to thin verb router (~167 lines)
- No behavioral changes; public API preserved
- refactor: extract shared ActivityPub pool delivery into ActivityPubDeliveryService ([9c9e2a5a2](https://github.com/pixelfed/pixelfed/commit/9c9e2a5a22a9589aab893d4614b868888384f42b))
- Add ActivityPubDeliveryService::pool() using Laravel's Http::pool() to
- consolidate the duplicated delivery pattern found across 10 jobs.
- Updated jobs:
- StatusActivityPubDeliver
- StatusDelete
- StatusLocalUpdateActivityPubDeliverPipeline
- FanoutDeletePipeline
- SharePipeline
- UndoSharePipeline
- StoryFanout
- StoryExpire
- StoryDelete
- ProfileMigrationDeliverMoveActivityPipeline
- The shared method accepts a Profile (sender), audience (inbox URLs),
- and activity (payload array), handling signing, user-agent, timeout,
- and concurrency in one place. No direct Guzzle usage remains in
- app/Jobs/.
- refactor: extract duplicate patterns into shared methods ([e7b70c608](https://github.com/pixelfed/pixelfed/commit/e7b70c6084bc171404af1320283c2aff037a2865))
- 1. Add FractalService with static item() and collection() helpers
- replacing 22 call sites that repeated the 4-line Fractal Manager
- Update HttpClientMigrationTest to use App\\Models\\\* namespace
- refactor: migrate LikePipeline to use NotificationService::firstOrCreateNotification ([8b53f23e7](https://github.com/pixelfed/pixelfed/commit/8b53f23e77f8abc5e9aca03039df9fda8e134f7c))
- Refactor boilerplate examples for deduplication ([6cce21032](https://github.com/pixelfed/pixelfed/commit/6cce2103215450498428194097d812ebb384026a))
- Updated boilerplate examples for ActivityPub Delivery, Username validation, and Notification services to replace repeated code snippets with concise method calls.
- Update DeduplicationChanges.md with service reference ([78a48f0ef](https://github.com/pixelfed/pixelfed/commit/78a48f0ef06d2ca0928252c56ec9b32e9f18a95d))
- chore: remove unused import and fix spacing in cache config ([3be6dbf54](https://github.com/pixelfed/pixelfed/commit/3be6dbf5477673d7613d5403cc1b000f62c9da53))
- Fix ProfileMigrationStorageRequest, use signed requests for gts and other compat ([81245ec46](https://github.com/pixelfed/pixelfed/commit/81245ec4675b95f30606089949b9fcbdcca00ca0))
- Add user:checkpassword read-only command to diagnose rejected logins ([2c7227a9c](https://github.com/pixelfed/pixelfed/commit/2c7227a9c11d164425b14ae71ebe9dd05c853ab6))
- Fix CSRF token not found error on guest pages (login/register) ([54f99334b](https://github.com/pixelfed/pixelfed/commit/54f99334bb7c424d6ecd43bcdeae8a9a29f9db19))
- The app layout renders separate head blocks for auth vs guest users.
- The guest block was missing the <metaname="csrf-token"> tag that
- app.js reads to set the axios X-CSRF-TOKEN header, causing a console
- error on the login and register pages. Add the meta tag to the guest
- head to match the authenticated head block.
- Fix CSRF token not found error on guest pages (login/register) ([32e391d26](https://github.com/pixelfed/pixelfed/commit/32e391d2678fcbd56f3764211efa430d3eb2aa44))
- The app layout renders separate head blocks for auth vs guest users.
- The guest block was missing the <metaname="csrf-token"> tag that
- app.js reads to set the axios X-CSRF-TOKEN header, causing a console
- error on the login and register pages. Add the meta tag to the guest
- head to match the authenticated head block.
- Add csrf-token meta to anon and app-guest layouts ([ea1a629b1](https://github.com/pixelfed/pixelfed/commit/ea1a629b1a275e28ddfadbaa66e2550b9ebe4383))
- These guest layouts also load app.js, which reads the csrf-token meta
- tag to set the axios X-CSRF-TOKEN header. Without it, they logged the
- same 'CSRF token not found' console error and had no CSRF header for
- AJAX requests. Adds the meta tag to match the other layouts.
- Expand user:status profile section with full column dump and derived metadata ([93f813848](https://github.com/pixelfed/pixelfed/commit/93f81384826f7d90ab7537407b2fdfdd0c598ecc))
- Dump every profiles column dynamically (keys redacted, long text trimmed),
- add derived metadata (local/remote type, urls, live vs cached follower/
- following/status counts, avatar, federation fields), and profile health
- checks (soft-delete, id mismatches, missing crypto keys, count desync).
- Add profile:status command for local and remote profile diagnostics ([92d09ffaa](https://github.com/pixelfed/pixelfed/commit/92d09ffaaf4d4c44c81e557f3b80d4a75878ab1d))
- Unlike user:status (local users only, keyed on the users table),
- profile:status keys on the profiles table so it works for remote/
- following counts, drift/no-drift/no-write, metric restriction, missing
- profile) plus fix:profilecounts command behavior (silent-when-synced,
- dry-run makes no changes).
- Rename to admin:fixProfileCounts, make --active its own mode, add --type ([96f26405f](https://github.com/pixelfed/pixelfed/commit/96f26405f1eef5b0e403d00da3311a91cbb2f650))
- --active is now its own bulk mode (recently-active local accounts),
- mutually exclusive with --all and a single id.
- Add --type=followers|following|statuses to restrict reconciliation to a
- single metric (validated).
- Update/extend tests for the new name, --type restriction and invalid-type
- rejection.
- Update stale command-name reference in comment to admin:fixProfileCounts ([55e9201b1](https://github.com/pixelfed/pixelfed/commit/55e9201b1a0330c236cbcd3f1ccf2a232e36da6b))
- Fix VueIntersect single-element warning in notifications section ([b3be61c47](https://github.com/pixelfed/pixelfed/commit/b3be61c47c0e267ba151258ee800acd61bbfcac7))
- The <intersect> in sections/Notifications.vue wrapped four <placeholder>
- elements directly. vue-intersect requires exactly one child (it checks
- $slots.default.length and observes $slots.default\[0\]), so it logged
- '\[VueIntersect\] You may only wrap one element in a <intersect> component.'
- and only observed the first placeholder. Wrap the placeholders in a single
-<div> so the slot has one root element.
- Require --scope (local/remote/both) for admin:fixProfileCounts --all ([bcd5a5bd7](https://github.com/pixelfed/pixelfed/commit/bcd5a5bd7b6d8aae5ac6015aa654349937765a41))
- Bulk --all reconciliation previously scanned both local and remote profiles
- implicitly. Now --all requires an explicit --scope of local, remote, or
- both. --active stays local-only and rejects a non-local --scope. Adds the
- BelongsTo return type to Profile::user() so the whereHas('user') scope
- filter passes Larastan, and adds tests for scope requirement/validation and
- local/remote filtering.
- Add post:status command for post/media diagnostics ([4aa7b5728](https://github.com/pixelfed/pixelfed/commit/4aa7b572807cc00c41252f97223d1e59671fa1cd))
- Dumps a Status and its media for debugging. Accepts a post id or URL
- (/p/username/ID). Shows status columns, author, every media row's storage
- Rename to admin:MigrateLocalS3MediaURL and drop --avatars ([da9e73dd2](https://github.com/pixelfed/pixelfed/commit/da9e73dd2207b7eea7ee1e0b0a78db91415f6f50))
- Rename the command (and test) to admin:MigrateLocalS3MediaURL to reflect its
- scope: rewriting stale S3/cloud media URLs only. Remove avatar handling and
- the --avatars option; the command now focuses solely on status media
- (cdn_url, thumbnail_url, optimized_url).
- Fix MigrateLocalS3MediaUrl tests failing in CI ([34d6fb31f](https://github.com/pixelfed/pixelfed/commit/34d6fb31f945eb733455110ab1c4397988d5065c))
- config_cache() falls through to config() when instance.enable_cc is off
- (ENABLE_CONFIG_CACHE=false, as in CI/.env.testing), so ConfigCacheService::put()
- alone did not toggle pixelfed.cloud_storage and the command's cloud-enabled
- guard aborted with exit 1. Set the underlying config value too (both in
- Fix duplicate-key violation when importing remote media attachments ([0d01d5a96](https://github.com/pixelfed/pixelfed/commit/0d01d5a96338b72c5265e80672dc579a4553545b))
- Helpers::importNoteAttachment unconditionally inserted a new Media row per
- attachment, so re-importing a remote status (an Announce racing another
- inbox job, a re-fetch, or a duplicate url within one activity) hit the
- media_status_id_media_path_unique constraint and crashed the queue job with
- a 1062 UniqueConstraintViolationException, dropping the boost/import.
- Make createMediaAttachment idempotent on (status_id, media_path): skip when
- a row already exists, and catch the unique-constraint violation as a
- lost-race no-op, returning null so the caller skips re-dispatching storage.
- Adds regression tests (re-import no-op, distinct urls still stored,
- concurrent-insert returns null).
- refactor: rename status debug commands to status: prefix ([16c7c5d2e](https://github.com/pixelfed/pixelfed/commit/16c7c5d2e36752425418ac698402f4a51a01e44c))
- Rename user:status, profile:status, and post:status console commands
- to status:user, status:profile, and status:post. Rename the command
- files and classes to match (StatusUser, StatusProfile, StatusPost) and
- update the cross-reference tip in StatusProfile.
- refactor: organize Artisan commands into subfolders ([1eae4bbd4](https://github.com/pixelfed/pixelfed/commit/1eae4bbd4304d3a59f1bfeadaff4daa2b8754e77))
- Group console commands into Admin, Dev, FixBugs, Install, Internal, and
- User subfolders (matching the earlier reorganization), and add a new
- Status subfolder for the status:user, status:profile, and status:post
- debug commands. Namespaces updated to match; command signatures and the
- total command count are unchanged.
- docs: add README for Artisan commands with listing and audit ([c99b8068a](https://github.com/pixelfed/pixelfed/commit/c99b8068a24726fcee101927870ea5f8ac32f905))
- feat: add admin:fixPostCounts to resync post like/boost/comment counts ([744e45360](https://github.com/pixelfed/pixelfed/commit/744e4536069d13886aaa4a673a7f44f2a45dd743))
- Add a FixPostCounts command mirroring admin:fixProfileCounts (single-id,
- --all --scope, --active, --type, --dry-run, --force). It reconciles the
- statuses likes_count, reblogs_count, and reply_count columns against
- source-of-truth tables.
- Add canonical recompute helpers and reconcileStatusCounts() to
- StatusService (mirroring AccountStatService), busting the status cache
- only when a column actually drifted.
- refactor: move admin:fix\*Counts commands to Admin/ ([73b8353da](https://github.com/pixelfed/pixelfed/commit/73b8353dab311843875069aef86649c871f30f68))
- FixProfileCounts and FixPostCounts use the admin: signature prefix and
- are operator-run maintenance tools, so move them from FixBugs/ to Admin/
- (namespace updated) and refresh the README tables to match.
- fix: display comments count as 0 instead of blank in admin:fixPostCounts ([d50024a57](https://github.com/pixelfed/pixelfed/commit/d50024a578d4a457108546c2169223299f585c27))
- reply_count is a nullable column, so NULL rendered as an empty string in
- the resync summary. Cast the summary output to int so a null/absent
- comment count prints as 0. No behavior change to the reconcile logic.
- fix: make admin:fixPostCounts summary report only changed metrics ([de850836c](https://github.com/pixelfed/pixelfed/commit/de850836cac44a6bb8b7f6c35ca9f358fa4d6240))
- The resynced summary printed all three counts unconditionally, which
- made an untouched metric (e.g. an already-correct comments count) look
- like it had been resynced. Drive the summary from the drifted set and
- show before->after values, so it matches the drift detection exactly.
- test: add feature tests for admin:fixPostCounts ([ec5be5241](https://github.com/pixelfed/pixelfed/commit/ec5be52418678fae8a417047f056a5e2df4a0e2e))
- Cover source-of-truth resync of likes/boosts/comments, dry-run, no-op on
- correct data, --type restriction, argument validation, and bulk --all
- mode. Includes regression tests for the two reporting bugs: the summary
- now lists only drifted metrics, and a null reply_count renders as 0.
- style: import DB facade in FixPostCounts test (pint) ([078380723](https://github.com/pixelfed/pixelfed/commit/078380723f8df98da5a04629146403d796295064))
- Port PR #6646 onto staging: add psalm/plugin-laravel with psalm.xml,
- a staging-generated baseline, and a CI workflow that emits GitHub
- annotations and uploads SARIF to Code Scanning. Fix the psalm.xml schema
- for Psalm 6.5 (drop unsupported ClassMustBeFinal handler) and ignore
- generated report artifacts in git/docker.
- ci(psalm): report findings but never fail the job ([2617211c1](https://github.com/pixelfed/pixelfed/commit/2617211c1f95fe281e7980eb54ff8549dfdcb1f6))
- ci(psalm): align workflow with php-\* conventions, test on PHP 8.5 ([6945277e2](https://github.com/pixelfed/pixelfed/commit/6945277e2ccb1e7c32ce4269e70d17f61f9a9706))
- Rename psalm.yml to php-psalm.yml to match sibling workflows, bump PHP
- 8.4 -> 8.5, use the shared checkout/setup-php/cache/composer steps and
- staging/dev/unstable triggers. Keeps report-only behavior and SARIF
- Code Scanning upload.
- ci(psalm): guarantee SARIF file exists and upgrade upload-sarif to v4 ([5cecde670](https://github.com/pixelfed/pixelfed/commit/5cecde67089f2f6d431f26b3a2019e7bb78daa7c))
- Add a fallback step that writes a minimal valid SARIF report when Psalm
- exits before producing one, so the Code Scanning upload never hard-fails
- the job. Bump github/codeql-action/upload-sarif v3 -> v4.
- ci(psalm): skip SARIF upload when report is missing ([aed7936e4](https://github.com/pixelfed/pixelfed/commit/aed7936e4efc78823becc596d3d1b3607cc1f8f4))
- Replace the blank-SARIF fallback with an existence check; uploading an
- empty SARIF would clear existing Code Scanning alerts. Now the upload is
- skipped (with a warning) when Psalm produced no report.
- ci(psalm): run analyzer on PHP 8.4 to avoid 8.5 crash ([25494c491](https://github.com/pixelfed/pixelfed/commit/25494c49110e6623b396c9894c5a2150ce65e5cd))
- Psalm 6.5.0 fatally crashes on PHP 8.5 (deprecated SplObjectStorage::attach
- escalated by its error handler) before analyzing anything. Pin the Psalm
- job to 8.4 so it runs and produces SARIF; revert to 8.5 once Psalm supports
- to collide on the unique indexes. Reverting until the data is
- de-duplicated first.
- chore: add composer psalm:report script for a full local txt report ([6eea565ba](https://github.com/pixelfed/pixelfed/commit/6eea565babaeea565d73848dbde9be05e21d9bd3))
- Adds a psalm:report script that ignores the baseline and writes a full
- human-readable report to psalm-report.txt, including informational issues,
- so all outstanding items to fix are surfaced in one file.
- chore: target PHP 8.4 in psalm config ([fb69275cd](https://github.com/pixelfed/pixelfed/commit/fb69275cd7443d0221f30016e8c191a536ff256b))
- Set phpVersion="8.4" so Psalm targets 8.4 explicitly instead of
- inferring 8.3 from composer.json's ^8.3|^8.4 constraint.
- chore: resolve psalm issues in admin commands and auth ([878775cab](https://github.com/pixelfed/pixelfed/commit/878775cab95be5a29649f6e35139ffd72c4c08c6))
- Add return type hints (void) and final class markers
- Guard null returns from newestBackup() and putFileAs() in BackupToCloud
- Type ask() default values as strings
- Fix uses_left fallback condition for null/zero max_uses
- Annotate AdminInvite::whereInviteCode and cast Str::uuid() to string
- Ignore local redis-data and mysql-9-data dev directories
- implement search by country ([129778ef2](https://github.com/pixelfed/pixelfed/commit/129778ef2e2bf90c43519f19c758931b47d8a24a))
- feat: migrate local story media to cloud storage ([9f110bb74](https://github.com/pixelfed/pixelfed/commit/9f110bb74c4ebcff72b3eba7fc9a645a713e4cf7))
- Ensure story media lands on and stays on cloud storage for S3 instances.
- StoryExpire: archive expiring story media on the same explicit disk the
- media lives on (S3 move is a server-side copy+delete), with error handling
- Add admin:StoryMoveStorageLocalToCloud to migrate local story media
- (active + story_archives) to cloud: copy, verify by size, then delete local
- --orphans option relocates untracked story_archives/ files to cloud using
- the same copy/verify/delete flow (media is moved, never discarded)
- Schedule it hourly alongside the media migration when cloud storage is on
- feat: store custom emoji on cloud storage when enabled ([fa76e1014](https://github.com/pixelfed/pixelfed/commit/fa76e1014a0cc5e75f1aa7d84b800e7827779384))
- Custom emoji were always written locally and served via hardcoded /storage
- URLs, so they never used S3 even on cloud instances.
- CustomEmoji: centralize URL + storage on the active disk (cloud when
- pixelfed.cloud_storage is enabled, else local public/ disk) via
- Route emoji writes/deletes and URL generation (scan, CustomEmojiService::all)
- through those helpers in ImportEmojis, CustomEmojiService::import and
- AdminController
- Add admin:EmojiMoveStorageLocalToCloud to migrate existing local emoji to
- cloud: copy, verify by size, delete local, bust caches
- Schedule it daily when cloud storage is enabled
- feat: migrate all local emoji to cloud in one pass by default ([979df6e39](https://github.com/pixelfed/pixelfed/commit/979df6e39e4ead7349a24600113d4209468f7b04))
- Change --limit default to 0 (no limit) so the emoji migration processes
- every local emoji in a single run instead of capping at 1000, and drop the
- limit from the scheduled invocation. Avoids a multi-run window where
- not-yet-migrated emoji resolve to missing cloud URLs.
- feat: add migration to move local emoji to cloud on deploy ([a945efbf7](https://github.com/pixelfed/pixelfed/commit/a945efbf74a26b8587c492acf2b7564ad6d6976c))
- Runs admin:EmojiMoveStorageLocalToCloud during migrate so existing local
- emoji are relocated to cloud as part of the upgrade, shrinking the window
- where emoji URLs resolve to cloud before the files are there. No-op unless
- Remove the deploy migration and its scheduler entry
- Media (and the already-reverted story) scheduler entries are untouched.
- chore: modernize service providers for Laravel 13 readiness ([3c6ba88e6](https://github.com/pixelfed/pixelfed/commit/3c6ba88e6e5cdc418e49d4f9f9b19144280e6eb6))
- Remove deprecated Foundation\\Support\\Providers\\AuthServiceProvider and
- EventServiceProvider base classes. Move policy and event listener
- registrations into AppServiceProvider using Gate::policy() and
- Event::listen(). Behavior is unchanged (verified via event:list and
- auth test suite).
- perf: fix N+1 queries; fix ComposeController lint and test namespace ([b52c3d765](https://github.com/pixelfed/pixelfed/commit/b52c3d7659dbcf97dd77f5fe9bed4a6b4582577c))
- Performance:
- TrendingHashtagService: batch-load hashtags with whereIn/keyBy instead
- of Hashtag::find() per trending row.
- DirectMessageController: eager-load status.media and read the in-memory
- collection instead of firstMedia() issuing a query per DM message.
- refactor: rename MigrateLocalS3MediaURL class and move media move-storage commands to unstable ([41c9b8830](https://github.com/pixelfed/pixelfed/commit/41c9b8830f2570198b1e2502d7a201131fdc415a))
- Rename App\\Console\\Commands\\Admin\\MigrateLocalS3MediaURL to MediaUpdateS3CDNUrl
- (class + filename only; the admin:MigrateLocalS3MediaURL signature is unchanged)
- Move the three MediaMoveStorage{LocalToCloud,CloudToLocal,CloudToCloud} commands
- into App\\Console\\Commands\\Admin\\Unstable and change their signatures from
- admin: to unstable:
- Update the scheduler in bootstrap/app.php, the command README, the
- config/filesystems.php reference comment, and the affected feature tests
- refactor: keep MediaMoveStorageLocalToCloud as a stable admin command ([a81270770](https://github.com/pixelfed/pixelfed/commit/a81270770cf4886b4c923acd3605241b4bbacd87))
- MediaMoveStorageLocalToCloud is stable, so move it back out of the Unstable
- namespace: restore App\\Console\\Commands\\Admin\\MediaMoveStorageLocalToCloud and
- its admin:MediaMoveStorageLocalToCloud signature, and update the scheduler,
- README, and feature test. CloudToLocal and CloudToCloud remain under unstable:.
- refactor: simplify storage:maintenance flags and make it quiet by default ([fce75030e](https://github.com/pixelfed/pixelfed/commit/fce75030e0c4298759f64800fa8a6f843ef26626))
- Drop --except (--only already covers task selection)
- Quiet by default; per-root/per-item and summary lines now require -v/--verbose
- Errors are always shown regardless of verbosity
- Document the command in the console README
- fix: delete superseded image/thumbnail files instead of orphaning them ([b6d645a4d](https://github.com/pixelfed/pixelfed/commit/b6d645a4d48cb36dd930b53742d24d5adc9508dd))
- Image::handleImageTransform derives the output filename from the current
- media_path and applies the encoder's output extension. When that differs from
- what is already stored (heic/avif -> jpg, or a thumbnail regenerated to a new
- extension), the new file landed at a different path and the previous file was
- left orphaned in the media directory — the source of the leftover \_thumb files
- under public/m/\_v2.
- Capture the path each transform supersedes and delete it after a successful
- write (only when the new output path differs, so we never delete what we just
- wrote). Remove the stale MediaDeleteLeafCleanupTest whose source change is not
- in the tree.
- Add domain-mismatch metadata to Announce status fetch and stop noisy ERROR logs ([0df4c7117](https://github.com/pixelfed/pixelfed/commit/0df4c7117d089c14b01533e2391170683edd728b))
- storeStatus() now throws with JSON metadata (checked id/url hosts, expected
- rule, and the full activity payload) when status domains mismatch. The Announce
- inbox handler catches this, logs the context at debug level, and returns
- gracefully instead of surfacing a full production ERROR stack trace.
- Add structured metadata to MediaDeletePipeline skip/failure logs ([d456b7b64](https://github.com/pixelfed/pixelfed/commit/d456b7b64a4fd3589a96da11f66de58d5c7809b2))
- Replace interpolated log strings with structured context (media/status/profile/
- user ids, mime, size, order, paths, hls_path, remote flag, timestamps) so
- operators can trace why orphan-purge deletions are skipped or fail.
- Add admin:resyncemoji command to re-download remote emoji locally ([9214e9680](https://github.com/pixelfed/pixelfed/commit/9214e9680ab8cdf4507574cb3d4f085ed4a5203a))
- Adds CustomEmojiService::resync() which re-fetches a remote custom emoji's
- media from its origin (image_remote_url) via the SSRF-hardened
- SecureMediaFetchService and stores it locally under public/{media_path},
- reusing the existing headCheck validation and cache busting.
- The admin:resyncemoji command takes a comma-separated list of emoji
- filenames, looks each up by media_path, and resyncs remote ones. Supports
- MediaDeletePipeline skips deletion when media->status_id is set. status_id has
- no FK/cascade, so deleting a status never clears it, and the delete jobs
- dispatched by the status-delete paths were always skipped, leaking media files.
- Detach media (status_id = null) before dispatching the delete in StatusDelete,
- RemoteStatusDelete and DeleteRemoteStatusPipeline, so the row is genuinely
- orphaned by the time the guard checks it and the deletion proceeds.
- Also adds a status:media diagnostic command that dumps all metadata for a
- media id (DB columns, computed URLs, attachment state, parent status including
- the dangling status_id case, owner, metadata, and an optional live URL check).
- Add media:maintenance command with orphanedMedia scope ([87dad44d0](https://github.com/pixelfed/pixelfed/commit/87dad44d092ab937eea1c385c1724ec732d103a2))
- media:maintenance --scope orphanedMedia cleans up media whose status_id
- references a status that no longer exists (hard-deleted) or is soft-deleted.
- These dangling references predate the delete-path fix and MediaDeletePipeline's
- attached guard would otherwise refuse to delete them, leaking files.
- Detaches (status_id = null) before dispatching deletion via MediaStorageService,
- so the guard sees a genuinely orphaned row. Supports --limit (batched),
- --dry-run, and --force. The --scope map is extensible for future routines.
- Add verbose output to media:maintenance ([48a1fe5e5](https://github.com/pixelfed/pixelfed/commit/48a1fe5e5e8f7088e9f1b2d515f2355c8cfb8631))
- With -v, print per-row detail (media_id, original status_id, remote_media,
- profile_id, mime, size, path) as each orphaned row is processed instead of the
- progress bar, and expand the dry-run table with extra columns. Uses Laravel's
- built-in verbosity flag.
- Add TODO.md; enhance media:maintenance with --server filter and state annotations ([838a6b999](https://github.com/pixelfed/pixelfed/commit/838a6b999cc710d3c91f55d84003f6fdc1b38cb6))
- TODO.md: capture follow-ups (centralized status media teardown, DM leak fix,
- Drop the TODO.md added in 838a6b9; keep the media:maintenance changes.
- Add --status and --profile state filters to media:maintenance ([4ad6e91ef](https://github.com/pixelfed/pixelfed/commit/4ad6e91ef92232d2f9ed5c84c53db04afd7c0e9b))
- --status live|soft|hard and --profile live|soft|hard narrow orphaned media by
- the lifecycle state of the referenced status/profile row. Filters are applied
- at the SQL level (whereExists/whereNotExists on deleted_at) so they compose
- correctly with --limit. --status=live short-circuits since orphaned media never
- has a live status. Options are validated up front.
- Drop live from --status on media:maintenance ([4dfb34de7](https://github.com/pixelfed/pixelfed/commit/4dfb34de75cfb02efae08dc3b72fd5ac948ec8ca))
- Orphaned media never references a live status, so --status only accepts soft
- and hard. --profile still accepts live/soft/hard. Removes the now-redundant
- live short-circuit and makes valid values per-option.
- Rename media:maintenance to media:filtercleanup ([d62c58988](https://github.com/pixelfed/pixelfed/commit/d62c58988193a081980ea5afbd1a2eb585947294))
- Rename the command signature (media:maintenance -> media:filtercleanup), class
- (MediaMaintenance -> MediaFilterCleanup), and file to match. Behavior
- unchanged.
- Rename status:post to status:statuses ([237ed61b5](https://github.com/pixelfed/pixelfed/commit/237ed61b5d2b5e1f9d32c07c25a1a1e2b3bf1e7a))
- Rename command signature (status:post -> status:statuses), class
- (StatusPost -> StatusStatuses), and file to match.
- Update Report endpoint, add support for optional message ([ccac8b31b](https://github.com/pixelfed/pixelfed/commit/ccac8b31bd11af192adeea234997f63c4bb46c26))
- Drop the no-op pf_type assignment in the group topic feed ([71cade540](https://github.com/pixelfed/pixelfed/commit/71cade540ac3b1e0b7f442b6185ee44bf2824d66))
- Update ApiV1Controller, fix napi in timelines ([4c4a457fe](https://github.com/pixelfed/pixelfed/commit/4c4a457fe4d7ce96a0c391036aec55ac557f5c37))
- chore(deps): bump ip-address from 10.2.0 to 10.7.0 ([66f8b61ef](https://github.com/pixelfed/pixelfed/commit/66f8b61ef76a9c1acc067c8f7738df6862a14170))
- Bumps \[ip-address\](https://github.com/beaugunderson/ip-address) from 10.2.0 to 10.7.0.
- chore(deps): bump browserslist from 4.28.2 to 4.28.8 ([ec8fa5f61](https://github.com/pixelfed/pixelfed/commit/ec8fa5f619da85f082dd1996dd29f32472549631))
- Bumps \[browserslist\](https://github.com/browserslist/browserslist) from 4.28.2 to 4.28.8.
- chore(deps)(deps-dev): bump laravel/telescope from 5.22.1 to 5.23.0 ([447b76fed](https://github.com/pixelfed/pixelfed/commit/447b76fedead7660477c52782ff68f40a749dc3c))
- Bumps \[laravel/telescope\](https://github.com/laravel/telescope) from 5.22.1 to 5.23.0.
- chore(deps)(deps): bump laravel/tinker from 2.11.1 to 3.0.2 ([7eded54f1](https://github.com/pixelfed/pixelfed/commit/7eded54f1c34570f3185f9850e6c44fcdd70f0ad))
- Bumps \[laravel/tinker\](https://github.com/laravel/tinker) from 2.11.1 to 3.0.2.
- chore(deps)(deps): bump blurhash from 1.1.5 to 2.0.5 ([f428ff6fb](https://github.com/pixelfed/pixelfed/commit/f428ff6fb5cbb8f68ff6c4cc662f336e880f940f))
- Bumps \[blurhash\](https://github.com/woltapp/blurhash) from 1.1.5 to 2.0.5.
- Fix silent failure in avatar upload endpoints ([29280cd95](https://github.com/pixelfed/pixelfed/commit/29280cd950cc3ddecc4262cadab2a7262b6fd2cc))
- AvatarController@store and BaseApiController@avatarUpdate wrapped the
- upload flow in an empty catch(\\Exception) block and returned a success
- response even when the upload or save failed.
- Log the exception and return a real error response (500 JSON for the
- API endpoint, a redirect with validation errors for the web endpoint).
- Adds regression tests covering the failure path, the success path, and
- non-image rejection.
- Mark direct messages read with a single bulk update ([fbfd26d77](https://github.com/pixelfed/pixelfed/commit/fbfd26d7759a67caa48b10e485ba3b2a6d95570d))
- DirectMessageController@read fetched every matching DirectMessage and
- saved each one individually in a loop, issuing one UPDATE per row. On an
- active thread this is N queries.
- Pluck the matching ids and perform a single bulk update, preserving the
- existing response (the list of affected message ids) and updated_at
- behaviour.
- Adds regression tests covering the marked-read ids, the status_id lower
- bound, and sender isolation.
- Add timeout, retry and error handling to remote auth HTTP calls ([2ad6e2831](https://github.com/pixelfed/pixelfed/commit/2ad6e28318731c5d34c4fff48495d8f7b06209f0))
- RemoteAuthService::getVerifyCredentials, getFollowing and getToken made
- outbound HTTP requests to a user-controlled remote instance during the
- Mastodon login flow with no timeout, no retry and no exception handling.
- A slow or hostile instance could hang the request or surface an uncaught
- exception.
- Wrap all three in timeout(20)->retry(3, 750) with try/catch that returns
- false on failure, matching the existing pattern in isDomainCompatible().
- Callers already treat a falsy return as a failure; add the missing guard
- at the one verify_credentials call site that accessed the result array
- without checking it first.
- Adds RemoteAuthServiceTest covering connection failure, server error and
- success paths.
- Compute Year-in-Review averages in SQL instead of in PHP ([cd873c897](https://github.com/pixelfed/pixelfed/commit/cd873c89764583168c871cb88eb710961afbc580))
- SeasonalController::getData computed the average posts/likes per profile
- by grouping in SQL, then pulling every grouped row into a collection and
- calling ->pluck('count')->avg() in PHP. This loaded one row per profile
- into memory just to average.
- Wrap the grouped per-profile counts in a subquery and let the database
- compute AVG(count), returning a single value. Also drops the invalid
- SELECT _ with GROUP BY (ONLY_FULL_GROUP_BY) by selecting count(_) only.
- Adds a test verifying the average-of-per-profile-counts and its
- exclusions (remote, wrong type, out-of-range date), plus the empty case.
- Extract duplicated blocked-id and duplicate-shortcode query patterns ([e4e12fad7](https://github.com/pixelfed/pixelfed/commit/e4e12fad7cffee99ef017c30d03037fafb9bfae3))
- Two query patterns were copy-pasted across several call sites:
- The 'users who blocked me, plus myself' list used to filter profile
- 'count(\*) > 1')) appeared three times in AdminController. Extracted to a
- CustomEmoji::duplicateShortcodes() query scope.
- Adds tests for both. No behaviour change.
- Remove dead debug methods that echoed the raw request ([661b84142](https://github.com/pixelfed/pixelfed/commit/661b841428f76aa5a1a5ab375622bf4737c40fe1))
- CollectionController::index and StoryComposeController::createPoll had no
- route mapping and simply returned $request->all(). Both are unreachable
- debug leftovers; remove them. The live poll route maps to
- ComposeController::createPoll, which is unaffected.
- Stream deletions with cursor and batch notification lookups in delete jobs ([c4e5b96d2](https://github.com/pixelfed/pixelfed/commit/c4e5b96d25bc1694c1469a79b7c71907f60dd426))
- The status- and account-deletion jobs loaded whole collections with
- ->get() and then looped, running a per-row Notification lookup inside
- each iteration.
- StatusDelete / RemoteStatusDelete: resolve associated DirectMessage and
- MediaTag ids, fetch their notifications in a single whereIn query,
- clear each via cursor (NotificationService::del must run per row for
- cache/redis cleanup), then bulk delete the DMs and media tags.
- DeleteAccountPipeline / DeleteRemoteProfilePipeline: stream Story and
- Collection deletions with cursor() instead of loading every row into
- memory. Per-row file unlink and item deletes are preserved.
- Adds StatusDeleteCleanupTest covering DM + notification cleanup, media
- tag + notification cleanup, and the no-associations case.
- Extract following-ids lookup into FollowerService::getFollowingIds ([667f6e2fc](https://github.com/pixelfed/pixelfed/commit/667f6e2fc9a5dbfbcc24b65771f25c2e83153eff))
- The Cache::remember('profile:following:'.$pid, ...) block that plucks
- following_id and appends the caller's own id was copy-pasted across four
- call sites, with inconsistent TTLs (1440 minutes vs 1209600 seconds).
- Add FollowerService::getFollowingIds($pid), which owns the cache key that
- add()/remove() already invalidate, and use it from InternalApiController,
- PublicApiController, ApiV1Controller and HashtagUnfollowPipeline. Removes
- the now-unused Follower/Cache imports left behind.
- Adds a test covering the followed-ids-plus-self result and the
- chore(deps): bump body-parser from 1.20.5 to 1.20.6 ([50ea4a9b4](https://github.com/pixelfed/pixelfed/commit/50ea4a9b4699a4d973a99569d17c747e15de86b1))
- Bumps \[body-parser\](https://github.com/expressjs/body-parser) from 1.20.5 to 1.20.6.
- Fix Larastan error: correct Status import in NotificationService ([ef7e485e7](https://github.com/pixelfed/pixelfed/commit/ef7e485e7d9109bdc0b5d4966b09da38c57faf38))
- Use App\\Models\\Status instead of the non-existent App\\Status class.
- Fix media storage migration crash when no .env file exists ([6b14b229d](https://github.com/pixelfed/pixelfed/commit/6b14b229d1e6275245c16c4ba20c1be5a965033b))
- The media storage migration commands read/parsed the .env file directly to
- check and flip PF_ENABLE_CLOUD. In containerized deploys there is no .env on
- disk (config is injected via env vars), so updateEnvFile() threw
- 'file_get_contents(.env): Failed to open stream' and the scheduled command
- exited 1.
- Check the live setting via config_cache('pixelfed.cloud_storage') like the
- rest of the app, instead of parsing .env.
- Make the .env write best-effort in ManagesMediaStorageEnv: skip gracefully
- when the file is missing or read-only, and still apply the runtime + DB
- config-cache updates (the load-bearing changes on a hot server).
- Apply the same fix to the sibling unstable:MediaMoveStorageCloudToLocal.
- Add a regression test covering the no-.env container scenario.
- Add per-file transfer output and --debug detail to MediaMoveStorageLocalToCloud ([b8ca4da3a](https://github.com/pixelfed/pixelfed/commit/b8ca4da3a6bdece89c7d89bf68cbe15c0565fa0d))
- chore: move resources/lang to top-level lang/ per Laravel 9+ convention ([9db2218ca](https://github.com/pixelfed/pixelfed/commit/9db2218ca62a547976d57b13c286958b8789566b))
- Relocate translation files from resources/lang to lang/ via git mv
- Update PHP references to use the lang_path() helper
- Convert string class references to ::class ([6d8ad3885](https://github.com/pixelfed/pixelfed/commit/6d8ad3885a8d90541d2363334abab8ed030f9309))
- Applies the ::class conversion from pixelfed-staging PR #9 (patch 1/21),
- formatted with Pint (short imported ::class form). Excludes the
- ModelNamespaceMigrationTest namespace assertions, which intentionally
- compare against literal namespace strings.
- Convert optional() to nullsafe operator ([042ab0a6e](https://github.com/pixelfed/pixelfed/commit/042ab0a6e42255eb87bfc3e74ff94c00405b6ea2))
- Applies patch 2/21 from pixelfed-staging PR #9: replaces optional($x)->y
- with $x?->y across 16 files. Pint-clean.
- Remove unnecessary $model property from factories ([8140ef7b0](https://github.com/pixelfed/pixelfed/commit/8140ef7b028ee1194101f6992723b11a7bb76017))
- Applies patch 3/21 from pixelfed-staging PR #9: removes the redundant
- protected $model property from 5 factories (Laravel resolves the model
- from the factory name). Unused imports dropped via Pint. Verified
- factories still resolve their models and affected tests pass.
- Convert route options to fluent methods ([c0f3469ee](https://github.com/pixelfed/pixelfed/commit/c0f3469ee2b1a45aaa9fbdcf40c28318680b3b3c))
- Laravel 8 adopts the tuple syntax for controller actions. Since the old options array is incompatible with this syntax, Shift converted them to use modern, fluent methods.
- In an effort to make upgrading the constantly changing config files easier, Shift defaulted them and merged your true customizations - where ENV variables may not be used.
- chore(deps-dev): bump larastan/larastan from 3.10.0 to 3.11.0 ([8f8b95e17](https://github.com/pixelfed/pixelfed/commit/8f8b95e170e08de4e69b5606a4ead51d8384e83a))
- Bumps \[larastan/larastan\](https://github.com/larastan/larastan) from 3.10.0 to 3.11.0.
- Change default log stack from 'single' to 'daily' ([0200c9e0c](https://github.com/pixelfed/pixelfed/commit/0200c9e0cd82cb699f579476eb499834943f7d79))
- Update default mailer configuration to use MAIL_DRIVER ([1d712e147](https://github.com/pixelfed/pixelfed/commit/1d712e14782eb08efa3be0c343d3544a46e7b37c))
- Update password validation rule to include string and min length ([c2a568a5c](https://github.com/pixelfed/pixelfed/commit/c2a568a5cc0dc3e928f4f672bf0d25dad75d50d6))
- Change 2FA code validation to require 6 digits ([76d4e1ab2](https://github.com/pixelfed/pixelfed/commit/76d4e1ab23c49f29032d2c3b7b1fc4e39555918d))
- Fix StatusDelete crashing on soft-deleted owning profile ([6e7419bb9](https://github.com/pixelfed/pixelfed/commit/6e7419bb96374bf1f3c3662c5a1d9d90ad95516b))
- Fix admin instance stats endpoint 404 on Postgres via strict is_admin check ([df1e771f9](https://github.com/pixelfed/pixelfed/commit/df1e771f930f9520099a9fb681294d98cffe3d5b))
- Validate publicKey.id host on inbox actor ingest to prevent key_id poisoning ([1905da723](https://github.com/pixelfed/pixelfed/commit/1905da723d0507ebe0364337c0178f6fdb3c0053))
- Guard hashtag follow against null profile for soft-deleted accounts ([8258a5a5f](https://github.com/pixelfed/pixelfed/commit/8258a5a5f88807ca29d8c063136331f95b0836fa))
- Harden remote status update media fetch against SSRF ([856f2f8f2](https://github.com/pixelfed/pixelfed/commit/856f2f8f2d2225ab7df64aa0e2d9d08a8ca8ce7a))
- Fix favourites pagination skipping one favourite per page boundary ([e79135a77](https://github.com/pixelfed/pixelfed/commit/e79135a771fd529e4d3dad54558a6f1eba7b531b))
- Scope reclaim-username profile deletion and fail on surviving orphan ([a1724a4b1](https://github.com/pixelfed/pixelfed/commit/a1724a4b1cbb8b5ca4116082439f1c58732d618d))
- Enforce poll scope authorization on vote endpoint ([a8a7a430d](https://github.com/pixelfed/pixelfed/commit/a8a7a430d77af79a6886cf66cc951c81b1e5bf5a))
- Require visibility on collection store to match NOT NULL schema ([a28650962](https://github.com/pixelfed/pixelfed/commit/a286509622370d56d354c6e7abe73c73c409639e))
- Fix login activity groupBy returning stale rows and 500 on strict DBs ([3cb5b6e1f](https://github.com/pixelfed/pixelfed/commit/3cb5b6e1fff7fffdec443d0b2797388137238624))
- Enforce pat_enabled kill-switch on personal access token renew ([d2b11a71b](https://github.com/pixelfed/pixelfed/commit/d2b11a71b37df32da638f09eb75dfdd370fb713b))
- Fix isDomainCompatible throwing on non-json beagle response ([d51cf4ccc](https://github.com/pixelfed/pixelfed/commit/d51cf4ccc91ff5bdd4b213f02939d420c092f439))
- Route StoryFetch outbound requests through SSRF-hardened fetch service ([9e84ad261](https://github.com/pixelfed/pixelfed/commit/9e84ad261d375cf8761615f2518dc79d25e6d511))
- Fix registration form redirecting when max_users is falsy ([afcb68c18](https://github.com/pixelfed/pixelfed/commit/afcb68c183cb393a25b9ab869e2874415a1d4cac))
- Fix custom filter rate-limit counter never expiring ([63e3c95fa](https://github.com/pixelfed/pixelfed/commit/63e3c95faead959b08ef89b005d597732738239a))
- Invalidate latest-story cache on remote story expiry and null-guard latest() ([9850aac67](https://github.com/pixelfed/pixelfed/commit/9850aac676bf60d770c95d4aa1d1160a6092b4b3))
- Detect OOB oauth client when redirect_uri omitted on authorize ([462b4bc0d](https://github.com/pixelfed/pixelfed/commit/462b4bc0da6770d2433d88dbb249d265375014d0))
- Ignore own row when validating email update uniqueness ([53ad34b32](https://github.com/pixelfed/pixelfed/commit/53ad34b321f480c70c909c5735b6c3e9047539e5))
- Send Pixelfed User-Agent on federated account deletion deliveries ([327348be0](https://github.com/pixelfed/pixelfed/commit/327348be02fe27499bcd7575cfd89f8bbd4cb72b))
- Drop Instagram import job when profile is missing instead of crashing ([922d7f766](https://github.com/pixelfed/pixelfed/commit/922d7f766e851c0710e039dc908e76d60ff911dc))
- Only dispatch SharePipeline for newly-created reblogs ([d190ba7b6](https://github.com/pixelfed/pixelfed/commit/d190ba7b66452b8546c65e24e281ef248805550e))
- Use ILIKE for case-insensitive search on PostgreSQL ([613cf413d](https://github.com/pixelfed/pixelfed/commit/613cf413de1b76abc8f0d7594e10f4454271e5fd))
- Escape user-provided content in curated register admin emails ([4df40cb77](https://github.com/pixelfed/pixelfed/commit/4df40cb77264ac4f2d5dd99b4736b06728ea3daa))
- Check media blocklist before storing uploads to prevent orphaned files ([ec6827bae](https://github.com/pixelfed/pixelfed/commit/ec6827bae2f49f1ddaefaf7a4abb84480e3577f9))
- Rate limit and audit-log 2FA checkpoint verification ([8cebb24c0](https://github.com/pixelfed/pixelfed/commit/8cebb24c04806501a7fbc65957aabc9fc803f42c))
- Apply Pint lint fixes to session test files ([eb9bd1130](https://github.com/pixelfed/pixelfed/commit/eb9bd113034c0ccf0a5924b0881c436e6d0a3cc7))
- Federate unlike before deleting Like so retries can deliver ([1ffda3eba](https://github.com/pixelfed/pixelfed/commit/1ffda3eba9768c3e323b6c7e4e16d7d6bad818c4))
- Use intended-redirect session for authorize_interaction guest login ([0234a305a](https://github.com/pixelfed/pixelfed/commit/0234a305ae98704cf5e212744a8dee03a82a2f04))
- Deterministically keep earliest status per uri in dedupe command ([e360fab61](https://github.com/pixelfed/pixelfed/commit/e360fab61982e74086cbe7ed6b7f12eb3d3d577a))
- Trigger StatusHashtag observer on deletion to keep cached_count accurate ([444c796ba](https://github.com/pixelfed/pixelfed/commit/444c796bac5e618f9fcfe523f65f7fee87d805aa))
- Fall back to stored profile when remote refresh fails ([73fb5ed69](https://github.com/pixelfed/pixelfed/commit/73fb5ed6963bd22dae1d732d33c43b525d35429b))
- Filter null-account statuses from non-cached network timeline ([917a13d4a](https://github.com/pixelfed/pixelfed/commit/917a13d4a7cffe41dfebede849a26d4d7d64ca30))
- Scope DangerZone OIDC sudo bypass to OIDC-registered users ([7483a4b05](https://github.com/pixelfed/pixelfed/commit/7483a4b05b45f93c5f87950c27f8090b4fd53c3d))
- Clear 2FA session state on forced logout after failed attempts ([97f1a097f](https://github.com/pixelfed/pixelfed/commit/97f1a097ff122377e725abb9322033575bf15b0f))
- Exclude private profiles from public directory and clear suggestable on going private ([158186309](https://github.com/pixelfed/pixelfed/commit/1581863093fa5d18142b893f54d2d3a867736659))
- Require dangerzone sudo mode on curated register, shadow filter and page admin controllers ([742c1a6bc](https://github.com/pixelfed/pixelfed/commit/742c1a6bc82e0fcd8a44e01ea160cbd08bff4fc4))
- Deliver posts regardless of profile no_autolink flag ([9e1415122](https://github.com/pixelfed/pixelfed/commit/9e141512283340399a75859e9f71850b4f8aa025))
- Use indexed query for media blocklist lookups and allow removing inactive hashes ([e8f2b06af](https://github.com/pixelfed/pixelfed/commit/e8f2b06afe0cea77899a81ac8eda10dd44dc5e36))
- Invalidate session on DangerZone forced logout to clear 2FA state ([58e8a4922](https://github.com/pixelfed/pixelfed/commit/58e8a4922dc684766cb7b46449797ca9b7ccb7df))
- Refactor comments in DangerZone middleware ([519b1b94d](https://github.com/pixelfed/pixelfed/commit/519b1b94dc57668ce206056fd01ffd048bcbbd3b))
- Removed redundant comments to clarify code functionality.
- Fix account storage limit not freeing on media deletion ([#7169](https://github.com/pixelfed/pixelfed/pull/7169))
- users.storage_used only ever grew: uploads incremented it but no deletion
- path decremented it, so users hit the account size limit even when their
- real media usage was well below it.
- Decrement storage_used in MediaDeletePipeline when media is removed
- Add UserStorageService::increaseStorageUsed / decrementStorageUsed as the
- fast, symmetric hot-path counter updates (floor-based, clamped at zero)
- Refactor the 6 upload call sites to use increaseStorageUsed instead of
- duplicated inline writes (also fixes ceil/floor drift vs the reconciler)
- Add (user_id, size) covering index so per-user SUM(size) is not a full
- table scan (INPLACE/LOCK=NONE, skipped on sqlite)
- Add user:storage:recalculate command to repair affected accounts, with a
- daily --stale=168 scheduled reconciler to correct any drift
- Add regression tests for the pipeline and UserStorageService
- Self-heal stale storage_used on upload/delete hot path ([26d3e8bb8](https://github.com/pixelfed/pixelfed/commit/26d3e8bb8efa69788406bd1b1e990361e0e2e76e))
- Make increaseStorageUsed/decrementStorageUsed recalculate from source when
- the cached counter is older than STALE_AFTER_HOURS (168h) or never
- calculated, so an affected user is corrected the next time they upload or
- delete without waiting for the nightly reconciler. Callers save/delete the
- media row before calling these, so the from-source recalc already reflects
- the change and the incremental delta is skipped on the recalc path.
- Add UserStorageService::STALE_AFTER_HOURS and isStale() helper (no extra
- query: reads the already-loaded model), with defensive Carbon parsing
- Cast users.storage_used_updated_at to datetime so freshness comparisons
- work on a Carbon instance
- Add tests for stale/fresh/never-calculated increase and decrement paths
- Remove unused CACHE_KEY constant from UserStorageService ([f467dc04d](https://github.com/pixelfed/pixelfed/commit/f467dc04d55ad060883388115d746bd4d52eb9b6))
- The constant was never referenced; the service reads and writes the
- storage_used column directly on the User model rather than via cache.
- Fix larastan noAuthFacadeInRequestScope in LoginController ([10559c23e](https://github.com/pixelfed/pixelfed/commit/10559c23e3f2f1f980fb501d7a54043c6209c2a0))
- Replace Auth::check() with $request->user() !== null in confirmEmail(),
- which already has the request in scope, and drop the now-unused Auth
- facade import. Resolves the 2 remaining project-wide larastan errors.
- Self-heal stale storage_used on read to unblock stuck accounts ([61a1c3075](https://github.com/pixelfed/pixelfed/commit/61a1c30756f89dd8e0b3bcc78129525aa32c0a17))
- UserStorageService::get() now recalculates from source when the cached
- counter is missing or older than STALE_AFTER_HOURS, instead of returning a
- possibly-inflated cached value. This is what unblocks a user stuck at the
- account size limit: the limit check on their next upload attempt reads the
- freshly recalculated real usage rather than the drifted value (#7169).
- The upload flow reads get() and enforces the limit BEFORE the write-path
- heal runs, so a blocked user could never self-heal via upload/delete alone.
- Healing on read closes that gap and makes the scheduled reconciler a
- belt-and-suspenders safety net rather than a requirement.
- A fresh counter is still trusted as-is (no per-read SUM). Adds tests for the
- stale-get recompute and fresh-get trust paths.
- Run storage recalculate reconciler weekly instead of daily ([28573e863](https://github.com/pixelfed/pixelfed/commit/28573e863f36ec10466a7708e977679bc46951d3))
- Now that the upload/delete hot path and get() self-heal stale counters, the
- scheduled reconciler is a background drift safety net rather than the primary
- unblock mechanism, so weekly is sufficient.
- Backfill storage_used on upgrade via queued job + data migration ([5a9c23592](https://github.com/pixelfed/pixelfed/commit/5a9c235922e1dfb094c14e56e34fb78295c42dfe))
- Repair accounts whose storage counter drifted before the self-heal logic
- existed (#7169). A data migration dispatches RecalculateAllUserStoragePipeline
- to the low queue so the deploy is not blocked while every user is recomputed
- from source. The job is unique and idempotent, so re-runs are harmless.
- RecalculateAllUserStoragePipeline: chunked recalc of all active users
- Migration dispatches the job (no inline heavy work during deploy)
- Test covers bulk recalculation from actual media
- Expand test coverage for storage_used improvements ([007f97f98](https://github.com/pixelfed/pixelfed/commit/007f97f98731ed9cda1896627d203d0f472329c4))
- Suspended/missing user guards for get, increase, decrement, recalculate
- Staleness window boundary (fresh at N-1h, stale at N+1h)
- Sub-1000-byte rounding on increase/decrement (floor to KB)
- Command --stale filter (only recomputes stale/never-calculated users) and
- missing --user id failure
- Migration dispatches the backfill job to the low queue (Bus::fake)
- Gate storage reconciler schedule behind a disabled-by-default flag ([4f284e089](https://github.com/pixelfed/pixelfed/commit/4f284e089388b9299da8d30e5da3f62b59fd5cf2))
- The upload/delete/read paths now self-heal stale storage_used counters and
- the upgrade backfill migration repairs existing accounts, so the weekly
- reconciler is no longer required. Gate it behind pixelfed.account*storage*
- reconcile (ACCOUNT_STORAGE_RECONCILE), defaulting off, so operators can opt
- in to the background hygiene job without editing source.
- Extract scheduled tasks into routes/scheduledtasks.php ([61c087e56](https://github.com/pixelfed/pixelfed/commit/61c087e56009e2b19489552f3992114282a3adf5))
- Move the schedule definitions out of the withSchedule() closure in
- bootstrap/app.php into a dedicated routes/scheduledtasks.php, required with
- the Schedule instance in scope. Behavior-preserving; verified with
- schedule:list.
- Move account_storage_reconcile flag to config/scheduledtasks.php ([219ce0ca2](https://github.com/pixelfed/pixelfed/commit/219ce0ca2b006f24845bc8507769ae47f1034ccf))
- Introduce a dedicated config/scheduledtasks.php for scheduled-task toggles
- and relocate the reconciler flag there (ACCOUNT_STORAGE_RECONCILE), reading
- it via config() in routes/scheduledtasks.php. Removed the setting from
- config/pixelfed.php. Verified both states with schedule:list.
- Move scheduled tasks file from routes/ to bootstrap/ ([cc183ec8a](https://github.com/pixelfed/pixelfed/commit/cc183ec8abb7fb5b885dadb10471f7923ed535dc))
- The schedule definitions are bootstrap wiring, not route definitions, so
- bootstrap/scheduledtasks.php is a better home. Updated the require path in
- Rewrite 2FA tests for the pending-login refactor ([08a442e66](https://github.com/pixelfed/pixelfed/commit/08a442e6617e05b26c890d9b47400f2e2767e984))
- The 2FA flow moved from a middleware-gated i/auth/checkpoint model to a
- pending-login model (auth.pending session, POST /login/2fa, /login?step=2fa
- challenge). The old tests referenced the removed route and dead session keys
- (2fa.session.active, 2fa.attempts) and failed with 404s.
- Rewritten against the new code as source of truth:
- Checkpoint test: throttle assertion retargeted to the login/2fa route;
- failed-verification audit log now driven through a pending 2FA session.
- Logout-session test: asserts auth.pending is cleared and the user stays a
- guest after MAX_2FA_ATTEMPTS failures (replacing the old flag cleanup).
- TwoFactorTest: challenge-redirect and challenge-page cases rewritten around
- the login flow; setup/recovery password-confirmation cases unchanged.
- MiddlewarePipelineTest: 2FA is enforced at login, not per-request, so an
- authenticated 2FA user browses normally.
- Full suite: 715 passed.
- Fix index migrations to support PostgreSQL and MariaDB ([cd4d9e5f3](https://github.com/pixelfed/pixelfed/commit/cd4d9e5f3615d64ccf93110ebf83965e0b51c381))
- The three recent index migrations used raw MySQL-only DDL (backtick
- identifiers, ADD INDEX inside ALTER TABLE, ALGORITHM=INPLACE/LOCK=NONE)
- guarded only against sqlite, so PostgreSQL instances failed with
- SQLSTATE\[42601\] on migrate (#7177).
- Each migration now branches on the driver:
- mysql/mariadb keep the online-DDL fast path (non-blocking on large
- instances)
- other drivers use the portable Schema::table builder
- Table names, index names, and columns are unchanged so already-migrated
- Update StoryService and add has_story to AccountTransformer ([bbd7618c4](https://github.com/pixelfed/pixelfed/commit/bbd7618c46da7f274dd9442da57a8f598e52a129))
- Update Status storage, add SanitizerService to fix spacing in html stripped content ([3686c9212](https://github.com/pixelfed/pixelfed/commit/3686c9212))
- OIDC Support ([#5608](https://github.com/pixelfed/pixelfed/pull/5608)) ([c72fa0529](https://github.com/pixelfed/pixelfed/commit/c72fa0529))
- Avif, HEIC, webp, libvips support + Preserve ICC color profiles ([ab9c13fe0](https://github.com/pixelfed/pixelfed/commit/ab9c13fe0))
- Added StoryIndexService, an optimized fan-out-on-write service for story carousel generation/rendering ([950fc0474](https://github.com/pixelfed/pixelfed/commit/950fc0474))
- Update PublicApiController, use pixelfed entities for /api/pixelfed/v1/accounts/id/statuses with bookmarked state ([5ddb6d842](https://github.com/pixelfed/pixelfed/commit/5ddb6d842))
- Update ReportController, fix type validation ([ccc7f2fc6](https://github.com/pixelfed/pixelfed/commit/ccc7f2fc6))
- Update footer to use legalNotice i18n ([0e59098da](https://github.com/pixelfed/pixelfed/commit/0e59098da))
- Update sidebar with gap padding for footer links ([dbd8289fe](https://github.com/pixelfed/pixelfed/commit/dbd8289fe))
- Update translations for Stories ([0a4dc7724](https://github.com/pixelfed/pixelfed/commit/0a4dc7724))
- Update translations for Auth ([756102696](https://github.com/pixelfed/pixelfed/commit/756102696))
- Update HttpSignatures, auto generate instance actor if missing ([bb16c95b1](https://github.com/pixelfed/pixelfed/commit/bb16c95b1))
- Update CreateNote to use cached MediaService attachments ([6a7307104](https://github.com/pixelfed/pixelfed/commit/6a7307104))
- Update ComposeController, fix cache invalidation order ([ae47ba73d](https://github.com/pixelfed/pixelfed/commit/ae47ba73d))
- Update ApiV1Controller, fix cache invalidation order ([4747266b0](https://github.com/pixelfed/pixelfed/commit/4747266b0))
- Update CreateNote, improve media attachement handling by leveraging the MediaService cache ([7ae61a74a](https://github.com/pixelfed/pixelfed/commit/7ae61a74a))
- Update ActivityPub attachements, use Document type by default ([51ce7e1f0](https://github.com/pixelfed/pixelfed/commit/51ce7e1f0))
- Update MediaService, improve activitypub format ([837014e06](https://github.com/pixelfed/pixelfed/commit/837014e06))
- Update ApiV1Dot1Controller, add story report support ([f5dced0f7](https://github.com/pixelfed/pixelfed/commit/f5dced0f7))
- Update StoryView resource, include viewed_at timestamp ([d361b0dca](https://github.com/pixelfed/pixelfed/commit/d361b0dca))
- Update AP Inbox, handle Story View with the new StoryIndexService markSeen method ([ab8d0ff46](https://github.com/pixelfed/pixelfed/commit/ab8d0ff46))
- Update StoryFetch pipeline job, make more robust and add StoryIndexService indexStory support ([fd3df358b](https://github.com/pixelfed/pixelfed/commit/fd3df358b))
- Update StoryExpire pipeline job, add StoryIndexService removeStory support ([5a263e89e](https://github.com/pixelfed/pixelfed/commit/5a263e89e))
- Update StoryController, add StoryIndexService s markSeen support for webUI endpoint ([44914a514](https://github.com/pixelfed/pixelfed/commit/44914a514))
- Update StoryApiV1Controller, add new v1.2 endpoints ([97badbbdd](https://github.com/pixelfed/pixelfed/commit/97badbbdd))
- Update StoryIndexService, improve predis/phpredis support ([53b74bf16](https://github.com/pixelfed/pixelfed/commit/53b74bf16))
- Update StoryApiV1Controller, improve text overlay validation regex for improved support ([8fb44e316](https://github.com/pixelfed/pixelfed/commit/8fb44e316))
- Update Status caption logic, stop storing duplicate html caption in db and defer to cached StatusService rendering ([9eeb7b67](https://github.com/pixelfed/pixelfed/commit/9eeb7b67))
- Update StatusStatelessTransformer, refactor the caption field to be compliant with the MastoAPI. Fixes #5364 ([79039ba5](https://github.com/pixelfed/pixelfed/commit/79039ba5))
- Update mailgun config, add endpoint and scheme ([271d5114](https://github.com/pixelfed/pixelfed/commit/271d5114))
- Update search and status logic to fix postgres bugs ([8c39ef4](https://github.com/pixelfed/pixelfed/commit/8c39ef4))
- Update hashtag component, fix missing video thumbnails ([witten](https://github.com/witten)) ([#5427](https://github.com/pixelfed/pixelfed/pull/5427))
- Update AP Status Transformer, fix inReplyTo. Fixes #5409 ([83cc932f](https://github.com/pixelfed/pixelfed/commit/83cc932f))
- Update Data Export, refactor following/follower and statuses exports to allow accounts of any size with api entity instead of ap ([0d25917c](https://github.com/pixelfed/pixelfed/commit/0d25917c))
- Update oauth/token, fix scope to be space separated string instead of array ([4ce6e610](https://github.com/pixelfed/pixelfed/commit/4ce6e610))
- Fix GroupController, move groups enabled check to each method to fix route:list ([f260572e](https://github.com/pixelfed/pixelfed/commit/f260572e))
- Update MediaStorageService, handle local media deletes after successful S3 upload ([280f63dc](https://github.com/pixelfed/pixelfed/commit/280f63dc))
- Update status twitter:card to summary_large_image for images/albums ([9a5a9f55](https://github.com/pixelfed/pixelfed/commit/9a5a9f55))
- Update CuratedOnboarding, add new app:curated-onboarding command, extend email verification window to 7 days and fix resend verification mails ([49604210](https://github.com/pixelfed/pixelfed/commit/49604210))
- Update ApiV1Controller, return empty statuses feed for private accounts instead of 403 response ([cce657d9c](https://github.com/pixelfed/pixelfed/commit/cce657d9c))
- Update DM config, allow new users to send DMs by default, with a new env variable to enforce a 72h limit ([717f17cde](https://github.com/pixelfed/pixelfed/commit/717f17cde))
- Update ApiV1Controller, add pagination to conversations endpoint with min/max/since id pagination and link header support ([244e86bad](https://github.com/pixelfed/pixelfed/commit/244e86bad))
- Update Direct message component, fix pagination ([e6ef64857](https://github.com/pixelfed/pixelfed/commit/e6ef64857))
- Update ApiV1Controller, send UndoFollow when cancelling a follow request on remote accounts ([2cf301181](https://github.com/pixelfed/pixelfed/commit/2cf301181))
- Update instance config, update network cache feed max_hours_old falloff to 90 days instead of 6 hours to allow for less active instances to have more results ([c042d135](https://github.com/pixelfed/pixelfed/commit/c042d135))
- Update ApiV1Dot1Controller, add new single media status create endpoint ([b03f5cec](https://github.com/pixelfed/pixelfed/commit/b03f5cec))
- Update AdminSettings component, add link to Custom CSS settings ([958daac4](https://github.com/pixelfed/pixelfed/commit/958daac4))
- Update ApiV1Controller, fix v1/instance stats, force cast to int ([dcd95d68](https://github.com/pixelfed/pixelfed/commit/dcd95d68))
- Update BeagleService, disable discovery if AP is disabled ([6cd1cbb4](https://github.com/pixelfed/pixelfed/commit/6cd1cbb4))
- Update ActivityPubFetchService, reduce cache ttl from 1 hour to 7.5 mins and add uncached fetchRequest method ([21da2b64](https://github.com/pixelfed/pixelfed/commit/21da2b64))
- Update UserAccountDelete command, increase sharedInbox ttl from 12h to 14d ([be02f48a](https://github.com/pixelfed/pixelfed/commit/be02f48a))
- Update DirectMessageController, add 72 hour delay for new accounts before they can send a DM ([61d105fd](https://github.com/pixelfed/pixelfed/commit/61d105fd))
- Update AdminCuratedRegisterController, increase message length from 1000 to 3000 ([9a5e3471](https://github.com/pixelfed/pixelfed/commit/9a5e3471))
- Update ApiV1Controller, add pe (pixelfed entity) support to /api/v1/statuses/{id}/context endpoint ([d645d6ca](https://github.com/pixelfed/pixelfed/commit/d645d6ca))
- Update CollectionsController, add new self route ([bc2495c6](https://github.com/pixelfed/pixelfed/commit/bc2495c6))
- Update FederationController, add webfinger support for actor uri. Fixes #5068 ([24194f7d](https://github.com/pixelfed/pixelfed/commit/24194f7d))
- Update FetchNodeinfoPipeline, set last_fetched_at timestamp ([a7fce91e](https://github.com/pixelfed/pixelfed/commit/a7fce91e))
- Update task scheduler, add weekly instance scan to check nodeinfo for known instances ([dc6b9f46](https://github.com/pixelfed/pixelfed/commit/dc6b9f46))
- Update AP fetch service and domain service ([42915ff9](https://github.com/pixelfed/pixelfed/commit/42915ff9))
- Update ApiV1Controller, add settings to verify_credentials endpoint ([3f4e0b94](https://github.com/pixelfed/pixelfed/commit/3f4e0b94))
- Update ApiController, add pe support to like/unlike endpoints ([679ef677](https://github.com/pixelfed/pixelfed/commit/679ef677))
- Update ApiV1Dot1Controller, fix username to id endpoint ([4d6cea9a](https://github.com/pixelfed/pixelfed/commit/4d6cea9a))
- Update StatusController, cache AP object ([a75b89b2](https://github.com/pixelfed/pixelfed/commit/a75b89b2))
- Update status embed, add support for album carousels ([f4898db9](https://github.com/pixelfed/pixelfed/commit/f4898db9))
- Update profile embeds, add support for albums ([4fd156c4](https://github.com/pixelfed/pixelfed/commit/4fd156c4))
- Update DirectMessageController, add timestamps to threads ([b24d2554](https://github.com/pixelfed/pixelfed/commit/b24d2554))
- Update DirectMessageController, add carousel entity to threads ([96f24f33](https://github.com/pixelfed/pixelfed/commit/96f24f33))
- Update and refactor total local post count logic, cache value and schedule updates twice daily to eliminate the perf issue on larger instances ([4f2b8ed2](https://github.com/pixelfed/pixelfed/commit/4f2b8ed2))
- Update Media model, fix broken thumbnail/gray thumbnail bug ([e33643c2](https://github.com/pixelfed/pixelfed/commit/e33643c2))
- Update StatusController, fix unlisted post guest/ap access bug ([83098428](https://github.com/pixelfed/pixelfed/commit/83098428))
- Update discover, add network trending using Beagle API ([2cae8b48](https://github.com/pixelfed/pixelfed/commit/2cae8b48))
- Update ApiV1Dot1Controller, fix in app registration bug that prevents proper auth flow due to missing oauth scopes ([cbf996c9](https://github.com/pixelfed/pixelfed/commit/cbf996c9))
- Update ConfigCacheService, fix database race condition and fallback to file config and enable by default ([60a62b59](https://github.com/pixelfed/pixelfed/commit/60a62b59))
- Update ProfileController, preserve deleted actor objects for federated account deletion and use more efficient account cache lookup ([853a729f](https://github.com/pixelfed/pixelfed/commit/853a729f))
- Update SiteController, add curatedOnboarding method that gracefully falls back to open registration when applicable ([95199843](https://github.com/pixelfed/pixelfed/commit/95199843))
- Update AP transformers, add DeleteActor activity ([bcce1df6](https://github.com/pixelfed/pixelfed/commit/bcce1df6))
- Update commands, add user account delete cli command to federate account deletion ([4aa0e25f](https://github.com/pixelfed/pixelfed/commit/4aa0e25f))
- Update web-api popular accounts route to its own method to remove the breaking oauth scope bug ([a4bc5ce3](https://github.com/pixelfed/pixelfed/commit/a4bc5ce3))
- Update VideoPresenter component, add webkit-playsinline attribute to video element to prevent the full screen video player ([ad032916](https://github.com/pixelfed/pixelfed/commit/ad032916))
- Update VideoPlayer component, add playsinline attribute to video element ([8af23607](https://github.com/pixelfed/pixelfed/commit/8af23607))
- Update StatusController, refactor status embeds ([9a7acc12](https://github.com/pixelfed/pixelfed/commit/9a7acc12))
- Update Inbox, cast live filters to lowercase ([d835e0ad](https://github.com/pixelfed/pixelfed/commit/d835e0ad))
- Update federation config, increase default timeline days falloff to 90 days from 2 days. Fixes #4905 ([011834f4](https://github.com/pixelfed/pixelfed/commit/011834f4))
- Update cache config, use predis as default redis driver client ([ea6b1623](https://github.com/pixelfed/pixelfed/commit/ea6b1623))
- Update .gitattributes to collapse diffs on generated files ([ThisIsMissEm](https://github.com/pixelfed/pixelfed/commit/9978b2b9))
- Update api v1/v2 instance endpoints, bump mastoapi version from 2.7.2 to 3.5.3 ([545f7d5e](https://github.com/pixelfed/pixelfed/commit/545f7d5e))
- Update ApiV1Controller, implement better limit logic to gracefully handle requests with limits that exceed the max ([1f74a95d](https://github.com/pixelfed/pixelfed/commit/1f74a95d))
- Update AdminCuratedRegisterController, show oldest applications first ([c4dde641](https://github.com/pixelfed/pixelfed/commit/c4dde641))
- Update Directory logic, add curated onboarding support ([59c70239](https://github.com/pixelfed/pixelfed/commit/59c70239))
- Update Inbox and StatusObserver, fix silently rejected direct messages due to saveQuietly which failed to generate a snowflake id ([089ba3c4](https://github.com/pixelfed/pixelfed/commit/089ba3c4))
- Update Curated Onboarding dashboard, improve application filtering and make it easier to distinguish response state ([2b5d7235](https://github.com/pixelfed/pixelfed/commit/2b5d7235))
- Update AdminReports, add story reports and fix cs ([767522a8](https://github.com/pixelfed/pixelfed/commit/767522a8))
- Update AdminReportController, add story report support ([a16309ac](https://github.com/pixelfed/pixelfed/commit/a16309ac))
- Update ApiV1Controller, update Notifications endpoint to filter notifications with missing activities ([a933615b](https://github.com/pixelfed/pixelfed/commit/a933615b))
- Update ApiV1Controller, fix public timeline scope, properly support both local + remote parameters ([d6eac655](https://github.com/pixelfed/pixelfed/commit/d6eac655))
- Update ApiV1Controller, handle public feed parameter bug to gracefully fallback to min_id=1 when max_id=0 ([e3826c58](https://github.com/pixelfed/pixelfed/commit/e3826c58))
- Update ApiV1Controller, fix hashtag feed to include private posts from accounts you follow or your own, and your own unlisted posts ([3b5500b3](https://github.com/pixelfed/pixelfed/commit/3b5500b3))
- Update navbar.vue, removes the 50px limit ([#4969](https://github.com/pixelfed/pixelfed/pull/4969)) ([7fd5599](https://github.com/pixelfed/pixelfed/commit/7fd5599))
- Update ComposeModal.vue, add an informative UI error message when trying to create a mixed media album ([#4886](https://github.com/pixelfed/pixelfed/pull/4886)) ([fd4f41a](https://github.com/pixelfed/pixelfed/commit/fd4f41a))
- Update public/network timelines, fix non-redis response and fix reblogs in home feed ([8b4ac5cc](https://github.com/pixelfed/pixelfed/commit/8b4ac5cc))
- Update Federation, use proper Content-Type headers for following/follower collections ([fb0bb9a3](https://github.com/pixelfed/pixelfed/commit/fb0bb9a3))
- Resilient Media Storage ([#4665](https://github.com/pixelfed/pixelfed/pull/4665)) ([fb1deb6](https://github.com/pixelfed/pixelfed/commit/fb1deb6))
- Video WebP2P ([#4713](https://github.com/pixelfed/pixelfed/pull/4713)) ([0405ef12](https://github.com/pixelfed/pixelfed/commit/0405ef12))
- Added user:2fa command to easily disable 2FA for given account ([c6408fd7](https://github.com/pixelfed/pixelfed/commit/c6408fd7))
- Added `avatar:storage-deep-clean` command to dispatch remote avatar storage cleanup jobs ([c37b7cde](https://github.com/pixelfed/pixelfed/commit/c37b7cde))
- Added S3 command to rewrite media urls ([5b3a5610](https://github.com/pixelfed/pixelfed/commit/5b3a5610))
- Experimental home feed ([#4752](https://github.com/pixelfed/pixelfed/pull/4752)) ([c39b9afb](https://github.com/pixelfed/pixelfed/commit/c39b9afb))
- Added `app:hashtag-cached-count-update` command to update cached_count of hashtags and add to scheduler to run every 25 minutes past the hour ([1e31fee6](https://github.com/pixelfed/pixelfed/commit/1e31fee6))
- Added `app:hashtag-related-generate` command to generate related hashtags ([176b4ed7](https://github.com/pixelfed/pixelfed/commit/176b4ed7))
- Added Mutual Followers API endpoint ([33dbbe46](https://github.com/pixelfed/pixelfed/commit/33dbbe46))
- Added User Domain Blocks ([#4834](https://github.com/pixelfed/pixelfed/pull/4834)) ([fa0380ac](https://github.com/pixelfed/pixelfed/commit/fa0380ac))
- Added S3 IG Import Media Storage support ([#4891](https://github.com/pixelfed/pixelfed/pull/4891)) ([081360b9](https://github.com/pixelfed/pixelfed/commit/081360b9))
- Update FollowerService, add forget method to RelationshipService call to reduce load when mass purging ([347e4f59](https://github.com/pixelfed/pixelfed/commit/347e4f59))
- Update StatusService, hydrate accounts on request instead of caching them along with status objects ([223661ec](https://github.com/pixelfed/pixelfed/commit/223661ec))
- Update Status model, improve thumb logic ([d969a973](https://github.com/pixelfed/pixelfed/commit/d969a973))
- Update Status model, allow unlisted thumbnails ([1f0a45b7](https://github.com/pixelfed/pixelfed/commit/1f0a45b7))
- Update StatusTagsPipeline, fix object tags and slug normalization ([d295e605](https://github.com/pixelfed/pixelfed/commit/d295e605))
- Update Note and CreateNote transformers, include attachment blurhash, width and height ([ce1afe27](https://github.com/pixelfed/pixelfed/commit/ce1afe27))
- Update ap helpers, store media attachment width and height if present ([8c969191](https://github.com/pixelfed/pixelfed/commit/8c969191))
- Update Sign-in with Mastodon, allow usage when registrations are closed ([895dc4fa](https://github.com/pixelfed/pixelfed/commit/895dc4fa))
- Update AP helpers, adjust RemoteAvatarFetch ttl from 24h to 3 months ([36b23fe3](https://github.com/pixelfed/pixelfed/commit/36b23fe3))
- Update AvatarPipeline, improve refresh logic and garbage collection to purge old avatars ([82798b5e](https://github.com/pixelfed/pixelfed/commit/82798b5e))
- Update CreateAvatar job, add processing constraints and set `is_remote` attribute ([319ced40](https://github.com/pixelfed/pixelfed/commit/319ced40))
- Update RemoteStatusDelete and DecrementPostCount pipelines ([edbcf3ed](https://github.com/pixelfed/pixelfed/commit/edbcf3ed))
- Update lexer regex, fix mention regex and add more tests ([778e83d3](https://github.com/pixelfed/pixelfed/commit/778e83d3))
- Update StatusTransformer, generate autolink on request ([dfe2379b](https://github.com/pixelfed/pixelfed/commit/dfe2379b))
- Update ComposeModal component, fix multi filter bug and allow media re-ordering before upload/posting ([56e315f6](https://github.com/pixelfed/pixelfed/commit/56e315f6))
- Update ApiV1Dot1Controller, allow iar rate limits to be configurable ([28a80803](https://github.com/pixelfed/pixelfed/commit/28a80803))
- Update ApiV1Dot1Controller, add domain to iar redirect ([1f82d47c](https://github.com/pixelfed/pixelfed/commit/1f82d47c))
- Update Inbox handler, fix missing object_url and uri fields for direct statuses ([a0157fce](https://github.com/pixelfed/pixelfed/commit/a0157fce))
- Update DirectMessageController, deliver direct delete activities to user inbox instead of sharedInbox ([d848792a](https://github.com/pixelfed/pixelfed/commit/d848792a))
- Update DirectMessageController, dispatch deliver and delete actions to the job queue ([7f462a80](https://github.com/pixelfed/pixelfed/commit/7f462a80))
- Update Inbox, improve story attribute collection ([06bee36c](https://github.com/pixelfed/pixelfed/commit/06bee36c))
- Update DirectMessageController, dispatch local deletes to pipeline ([98186564](https://github.com/pixelfed/pixelfed/commit/98186564))
- Update StatusPipeline, fix Direct and Story notification deletion ([4c95306f](https://github.com/pixelfed/pixelfed/commit/4c95306f))
- Update Notifications.vue, fix deprecated DM action links for story activities ([4c3823b0](https://github.com/pixelfed/pixelfed/commit/4c3823b0))
- Update ComposeModal, fix missing alttext post state ([0a068119](https://github.com/pixelfed/pixelfed/commit/0a068119))
- Update FollowerService, add $silent param to remove method to more efficently purge relationships ([1664a5bc](https://github.com/pixelfed/pixelfed/commit/1664a5bc))
- Update AP ProfileTransformer, add published attribute ([adfaa2b1](https://github.com/pixelfed/pixelfed/commit/adfaa2b1))
- Update meta tags, improve descriptions and seo/og tags ([fd44c80c](https://github.com/pixelfed/pixelfed/commit/fd44c80c))
- Update api routes, add DeprecatedEndpoint middleware. For more info, visit [pixelfed.org/kb/10404](https://pixelfed.org/kb/10404) ([a8453e77](https://github.com/pixelfed/pixelfed/commit/a8453e77))
- Update config, re-add `PF_MAX_USERS` .env variable to limit max users to 1000 by default ([a6d10f03](https://github.com/pixelfed/pixelfed/commit/a6d10f03))
- Update TransformImports command, improve handling of imported posts that already exist or are from deleted accounts ([892907d5](https://github.com/pixelfed/pixelfed/commit/892907d5))
- Update ImportService, filter deleted posts from getImportedPosts endpoint ([10dd348c](https://github.com/pixelfed/pixelfed/commit/10dd348c))
- Update FixStatusCount, improve command and support remote count resync ([04f4f8ba](https://github.com/pixelfed/pixelfed/commit/04f4f8ba))
- Update StatusRemoteUpdatePipeline, fix missing mime and size attributes that cause empty media previews on our mobile app ([ea54413e](https://github.com/pixelfed/pixelfed/commit/ea54413e))
- Update ComposeModal.vue, fix scroll issue and dont hide scrollbar ([2d959fb3](https://github.com/pixelfed/pixelfed/commit/2d959fb3))
- Update AccountImport, add select first 100 posts button ([625a76a5](https://github.com/pixelfed/pixelfed/commit/625a76a5))
- Update ApiV1Controller, add include_reblogs attribute to home timeline ([37fd0342](https://github.com/pixelfed/pixelfed/commit/37fd0342))
- Update Services, use zpopmin on predis ([4b2c66f5](https://github.com/pixelfed/pixelfed/commit/4b2c66f5))
- Update Inbox, allow storing Create->Note activities without any local followers, disabled by default ([9fa6b3f7](https://github.com/pixelfed/pixelfed/commit/9fa6b3f7))
- Update AP Helpers, preserve admin unlisted state before adding to NetworkTimelineService ([0704c7e0](https://github.com/pixelfed/pixelfed/commit/0704c7e0))
- Update SearchApiV2Service, improve resolve query logic to better handle remote posts/profiles and local posts/profiles ([c61d0b91](https://github.com/pixelfed/pixelfed/commit/c61d0b91))
- Update TransformImports command, increment status_count on profile model ([ba7551d8](https://github.com/pixelfed/pixelfed/commit/ba7551d8))
- Update AP Helpers, improve url validation and add optional dns verification, disabled by default ([2bef3e41](https://github.com/pixelfed/pixelfed/commit/2bef3e41))
- Update admin users blade view, show last_active_at and other info ([e0b48b29](https://github.com/pixelfed/pixelfed/commit/e0b48b29))
- Update MediaStorageService, improve head header handling ([3590adbd](https://github.com/pixelfed/pixelfed/commit/3590adbd))
- Update admin user view, improve previews ([ff2c16fe](https://github.com/pixelfed/pixelfed/commit/ff2c16fe))
- Update FanoutDeletePipeline, fix AP object ([0d802c31](https://github.com/pixelfed/pixelfed/commit/0d802c31))
- Added `following_since` attribute to `/api/v1/accounts/relationships` endpoint when `_pe=1` (pixelfed entity) parameter is present ([992d910b](https://github.com/pixelfed/pixelfed/commit/992d910b))
- Added `/api/v1.1/accounts/app/settings` endpoint and UserAppSettings model to store app specific settings ([a2305d5f](https://github.com/pixelfed/pixelfed/commit/a2305d5f))
- Added [/api/v1/followed_tags](https://docs.joinmastodon.org/methods/followed_tags/) api endpoint ([175a8486](https://github.com/pixelfed/pixelfed/commit/175a8486))
- Added [/api/v1/tags/:id/follow](https://docs.joinmastodon.org/methods/tags/#follow) and [/api/v1/tags/:id/unfollow](https://docs.joinmastodon.org/methods/tags/#unfollow) api endpoints ([4d997bb9](https://github.com/pixelfed/pixelfed/commit/4d997bb9))
- Added [/api/v1/tags/:id](https://docs.joinmastodon.org/methods/tags/) api endpoint ([521b3b4c](https://github.com/pixelfed/pixelfed/commit/521b3b4c))
- Added `only_media` support to /api/v1/timelines/tag/:id api endpoint ([b5fe956a](https://github.com/pixelfed/pixelfed/commit/b5fe956a))
- Added /api/v2/instance api endpoint ([167dbcdd](https://github.com/pixelfed/pixelfed/commit/167dbcdd))
- Removed api endpoint cloud ip block logic ([6a2daf1f](https://github.com/pixelfed/pixelfed/commit/6a2daf1f))
- Added idempotency-key support to /api/v1/statuses endpoint ([c54cdd3e](https://github.com/pixelfed/pixelfed/commit/c54cdd3e))
- Update instance config, enable config cache by default ([970f77b0](https://github.com/pixelfed/pixelfed/commit/970f77b0))
- Update Admin Dashboard, allow admins to designate an admin account for the landing page and instance api endpoint ([6ea2bdc7](https://github.com/pixelfed/pixelfed/commit/6ea2bdc7))
- Update config, enable oauth by default ([6a2e9e8f](https://github.com/pixelfed/pixelfed/commit/6a2e9e8f))
- Update MediaTagService, fix ProfileService to soft fail on missing or deleted accounts ([df444851](https://github.com/pixelfed/pixelfed/commit/df444851))
- Update LikeService, improve likedBy logic to soft fail on missing or deleted accounts ([91ba1398](https://github.com/pixelfed/pixelfed/commit/91ba1398))
- Update StatusTransformers, fix ProfileService to soft fail on missing or deleted accounts ([43d3aa2b](https://github.com/pixelfed/pixelfed/commit/43d3aa2b))
- Update atom view, fix atom feed bug ([63b72c42](https://github.com/pixelfed/pixelfed/commit/63b72c42))
- Update StatusController, disable post embeds from spam accounts ([c167af43](https://github.com/pixelfed/pixelfed/commit/c167af43))
- Update ProfileController, require login to view spam accounts, and disable profile embeds and atom feeds for spam accounts ([dd2f5bb9](https://github.com/pixelfed/pixelfed/commit/dd2f5bb9))
- Update Settings, allow users to disable atom feeds ([3662d3de](https://github.com/pixelfed/pixelfed/commit/3662d3de))
- Update ApiV1Controller, filter muted/blocked accounts from tag timeline ([f42c1140](https://github.com/pixelfed/pixelfed/commit/f42c1140))
- Update admin moderation logic, only re-add top level posts ([c6ffda96](https://github.com/pixelfed/pixelfed/commit/c6ffda96))
- Update admin dashboard, add mass account deletes ([b8426cce](https://github.com/pixelfed/pixelfed/commit/b8426cce))
- Update scheduler, fix S3 media garbage collection not being executed when cloud storage is enabled via dashboard without .env/config being enabled ([adb070f1](https://github.com/pixelfed/pixelfed/commit/adb070f1))
- Update MediaController, add fallback for local files that are later stored on S3 but still are referenced in cached objects remotely ([4973cb46](https://github.com/pixelfed/pixelfed/commit/4973cb46))
- Update AP Inbox, fix delete handling ([2800c888](https://github.com/pixelfed/pixelfed/commit/2800c888))
- Update login/register views and captcha config, enable login or register captchas or both ([c071c719](https://github.com/pixelfed/pixelfed/commit/c071c719))
- Update login form, allow admins to enable captcha after X failed attempts. Admins can set the number of attempts before captcha is shown, default is 2 attempts before captcha is required ([221ddce0](https://github.com/pixelfed/pixelfed/commit/221ddce0))
- New media:fix-nonlocal-driver command. Fixes s3 media created with invalid FILESYSTEM_DRIVER=s3 configuration ([672cccd4](https://github.com/pixelfed/pixelfed/commit/672cccd4))
- New landing page design ([09c0032b](https://github.com/pixelfed/pixelfed/commit/09c0032b))
- Add cloud ip bans to BouncerService (disabled by default) ([50ab2e20](https://github.com/pixelfed/pixelfed/commit/50ab2e20))
- Update app.js, add title attribute to iframe embeds to comply with accessibility requirements ([4d72b9e3](https://github.com/pixelfed/pixelfed/commit/4d72b9e3))
- Update MediaPathService, fix story path ([aebbad96](https://github.com/pixelfed/pixelfed/commit/aebbad96))
- Update Story v1.1 api endpoints ([855e9626](https://github.com/pixelfed/pixelfed/commit/855e9626))
- Update ApiV1Controller, filter mute/blocks on statuses/context and statuses/replies endpoints ([73aa01e8](https://github.com/pixelfed/pixelfed/commit/73aa01e8))
- Update filesystems, store all files as public by default and add default permissions. Fixes #4273, #4275. Closes #3825 ([22da2647](https://github.com/pixelfed/pixelfed/commit/22da2647))
- Update filesystem config, change FILESYSTEM_DRIVER env variable to DANGEROUSLY_SET_FILESYSTEM_DRIVER and remove from default env configs. Changing the default filesystem should be avoided, use FILESYSTEM_CLOUD for s3 support, otherwise you can break things ([573c88d7](https://github.com/pixelfed/pixelfed/commit/573c88d7))
- Update RegisterController, improve max_users calculation and add kb page to redirect to if conditions are met ([1bbee6d0](https://github.com/pixelfed/pixelfed/commit/1bbee6d0))
- Update SecuritySettings, remove imagick depdency for 2FA qr code generation image ([506f95c6](https://github.com/pixelfed/pixelfed/commit/506f95c6))
- Update ForgotPasswordController, add captcha support, improve security and a new redesigned view ([f6e7ff64](https://github.com/pixelfed/pixelfed/commit/f6e7ff64))
- Update ResetPasswordController, add captcha support, improve security and a new redesigned view ([0ab5b96a](https://github.com/pixelfed/pixelfed/commit/0ab5b96a))
- Update Inbox, remove handleCreateActivity logic that rejected posts from accounts without followers ([a93a3efd](https://github.com/pixelfed/pixelfed/commit/a93a3efd))
- Update ApiV1Controller and DiscoverController, fix postgres hashtag search ([055aa6b3](https://github.com/pixelfed/pixelfed/commit/055aa6b3))
- Update StatusTagsPipeline, deduplicate hashtags on postgres ([867cbc75](https://github.com/pixelfed/pixelfed/commit/867cbc75))
- Update SearchApiV2Service, fix postgres hashtag search and prepend wildcard operator to improve results ([6e20d0a6](https://github.com/pixelfed/pixelfed/commit/6e20d0a6))
- Update HomeSettings controller, bail earlier when attempting to update email that already exists ([399bf5f8](https://github.com/pixelfed/pixelfed/commit/399bf5f8))
- Update ProfileController, cache actor object and atom feed ([8665eab1](https://github.com/pixelfed/pixelfed/commit/8665eab1))
- Update NotificationTransformer, fix mediaTag and modLog types ([b6c06c4b](https://github.com/pixelfed/pixelfed/commit/b6c06c4b))
- Update landing view, add `app.name` and `app.short_description` for better customizability ([bda9d16b](https://github.com/pixelfed/pixelfed/commit/bda9d16b))
- Update AvatarSync, fix sync skipping recently fetched avatars by setting last_fetched_at to null before refetching ([a83fc798](https://github.com/pixelfed/pixelfed/commit/a83fc798))
- Refactor AvatarStorage to support migrating avatars to cloud storage, fix remote avatar refetching and merge AvatarSync commands and add deprecation notice to avatar:sync command ([223aea47](https://github.com/pixelfed/pixelfed/commit/223aea47))
- Update FederationController, add instance actor profile to webfinger ([6e3c8097](https://github.com/pixelfed/pixelfed/commit/6e3c8097))
- Update MediaService, add summary attribute for better alt text federation ([a12712cc](https://github.com/pixelfed/pixelfed/commit/a12712cc))
- Update AvatarObserver, fix cloud delete bug by checking if cloud storage is enabled ([9f7672f5](https://github.com/pixelfed/pixelfed/commit/9f7672f5))
- Update DeleteAccountPipeline, dispatch on low queue ([6eabe07c](https://github.com/pixelfed/pixelfed/commit/6eabe07c))
- Update DeleteAccountPipeline, handle flysystem v3 changes by checking files exist before attempting to delete ([23e2998f](https://github.com/pixelfed/pixelfed/commit/23e2998f))
- Update FollowerService, use redis sorted sets for follower relations ([356cc277](https://github.com/pixelfed/pixelfed/commit/356cc277))
- Update FollowerService, use redis sorted sets for following relations ([f46b01af](https://github.com/pixelfed/pixelfed/commit/f46b01af))
- Update PublicApiController, refactor follower/following api endpoints to consume FollowerService instead of querying database ([b39f91b4](https://github.com/pixelfed/pixelfed/commit/b39f91b4))
- Update follower/following profile layout, optimized for mobile devices and use FollowerService ([78a5575d](https://github.com/pixelfed/pixelfed/commit/78a5575d))
- Update sidebar menu, when clicking on the active feed/timeline buttons force a reload and scroll to top of feed ([78a5575d](https://github.com/pixelfed/pixelfed/commit/78a5575d))
- Update InboxPipeline, increase timeout from 60s to 300s ([d1b888b5](https://github.com/pixelfed/pixelfed/commit/d1b888b5))
- Update FederationController, add two new queues (follow, shared) to prioritize follow request handling ([8ba33864](https://github.com/pixelfed/pixelfed/commit/8ba33864))
- Dispatch follow accept/reject pipeline jobs to follow queue ([aaed2bf6](https://github.com/pixelfed/pixelfed/commit/aaed2bf6))
- Update MediaStorageService, improve support for pleroma .blob avatars ([66226658](https://github.com/pixelfed/pixelfed/commit/66226658))
- Update InboxPipeline, add inbox job queue and separate http sig validation from activity handling ([e6c1604d](https://github.com/pixelfed/pixelfed/commit/e6c1604d))
- Update InboxPipeline, dispatch Follow/Accept Follow jobs to follow queue ([f62d2494](https://github.com/pixelfed/pixelfed/commit/f62d2494))
- Add MediaS3GarbageCollector command to clear local media after uploaded to S3 disks after 12 hours ([b8c3f153](https://github.com/pixelfed/pixelfed/commit/b8c3f153))
- Update MediaS3GarbageCollector command, disable logging by default and optimize huge invocations ([a14af93b](https://github.com/pixelfed/pixelfed/commit/a14af93b))
- Update MediaStorageService, clear MediaService and StatusService caches after localToCloud ([de56b0f0](https://github.com/pixelfed/pixelfed/commit/de56b0f0))
- Add CloudMediaMigrate command to migrate older local media to cloud storage ([382d00d9](https://github.com/pixelfed/pixelfed/commit/382d00d9))
- Fix CustomEmoji, properly handle shortcode updates and delete old copy in case the extension changes ([bc29073a](https://github.com/pixelfed/pixelfed/commit/bc29073a))
- Update database config, use single transaction and skip lock tables for mysql dump ([936f1e7a](https://github.com/pixelfed/pixelfed/commit/936f1e7a))
- Update database config, add sticky flag https://laravel.com/docs/9.x/database#the-sticky-option ([10b65980](https://github.com/pixelfed/pixelfed/commit/10b65980))
- Update profile audience to filter blocked instances ([e0c3dae3](https://github.com/pixelfed/pixelfed/commit/e0c3dae3))
- Update ApiV1Controller, allow description (alt text) updates after status is published ([869c3ed1](https://github.com/pixelfed/pixelfed/commit/869c3ed1))
- Update AdminApiController, fix postgres support ([84fb59d0](https://github.com/pixelfed/pixelfed/commit/84fb59d0))
- Update ComposeModal, add Alt Text button to caption screen ([4db48188](https://github.com/pixelfed/pixelfed/commit/4db48188))
- Update AccountService, fix actor cache invalidation ([498b46f7](https://github.com/pixelfed/pixelfed/commit/498b46f7))
- Update SharePipeline, fix share handling and notification generation ([83e1e203](https://github.com/pixelfed/pixelfed/commit/83e1e203))
- Update SharePipeline, fix ReblogService and undo handling ([016c6e41](https://github.com/pixelfed/pixelfed/commit/016c6e41))
- Update AP Helpers, fix media validation bug that would reject media with alttext/name longer than 255 chars and store remote alt text if set ([a7f58349](https://github.com/pixelfed/pixelfed/commit/a7f58349))
- Update MentionPipeline, store non-local mentions ([17149230](https://github.com/pixelfed/pixelfed/commit/17149230))
- Update Like model, increase rate limit to 500 likes per day ([ab7676f9](https://github.com/pixelfed/pixelfed/commit/ab7676f9))
- Update AP helpers, ingest attachments in replies ([c504e643](https://github.com/pixelfed/pixelfed/commit/c504e643))
- Update Media model, use cloud filesystem url if enabled instead of cdn_url to easily update S3 media urls ([e6bc57d7](https://github.com/pixelfed/pixelfed/commit/e6bc57d7))
- Update ap helpers, fix unset media name bug ([083f506b](https://github.com/pixelfed/pixelfed/commit/083f506b))
- Update ApiV1Controller, use cursor pagination for favourited_by and reblogged_by endpoints ([e1c7e701](https://github.com/pixelfed/pixelfed/commit/e1c7e701))
- Update ApiV1Controller, fix favourited_by and reblogged_by follows attribute ([1a130f3e](https://github.com/pixelfed/pixelfed/commit/1a130f3e))
- Update notifications component, improve UX with exponential retry and loading state ([937e6d07](https://github.com/pixelfed/pixelfed/commit/937e6d07))
- Update likeModal and shareModal components, use new pagination logic and re-add Follow/Unfollow buttons ([b565ead6](https://github.com/pixelfed/pixelfed/commit/b565ead6))
- Update ApiV1Controller, add BookmarkService logic to bookmark endpoints ([29b1af10](https://github.com/pixelfed/pixelfed/commit/29b1af10))
- Update ApiV1Controller, filter conversations without last_status ([e8a6a8c7](https://github.com/pixelfed/pixelfed/commit/e8a6a8c7))
- Update ApiV1Controller and BookmarkController, fix api differences and allow unbookmarking regardless of relationship ([e343061a](https://github.com/pixelfed/pixelfed/commit/e343061a))
- Update ApiV1Controller, add pixelfed entity support to bookmarks endpoint ([94069db9](https://github.com/pixelfed/pixelfed/commit/94069db9))
- Update PostReactions, reduce bookmark timeout to 2s from 5s ([a8094e6c](https://github.com/pixelfed/pixelfed/commit/a8094e6c))
- Update ComposeController, fix add to collection logic ([9f8957b9](https://github.com/pixelfed/pixelfed/commit/9f8957b9))
- Update v1.1 api, add post moderation endpoint ([9bbd6dcd](https://github.com/pixelfed/pixelfed/commit/9bbd6dcd))
- Update StatusService, on purge remove from NetworkTimelineService cache ([18940cb2](https://github.com/pixelfed/pixelfed/commit/18940cb2))
- Update mute/block logic with admin defined limits and improved filtering to skip deleted accounts ([5b879f01](https://github.com/pixelfed/pixelfed/commit/5b879f01))
- Update FollowPipeline, fix followers_count and following_count counters ([6153b620](https://github.com/pixelfed/pixelfed/commit/6153b620))
- Update ApiV1Controller, fix media update. Fixes #4196 ([f3164650](https://github.com/pixelfed/pixelfed/commit/f3164650))
- Update ApiV1Controller, allow optional mastodonMode on v2/search endpoint. ([f4a69631](https://github.com/pixelfed/pixelfed/commit/f4a69631))
- Update ApiV1Controller, add cursor pagination and pagination link headers to account/{id}/followers and account/{id}/following endpoints with legacy support for `page=` simple pagination ([713aa5fd](https://github.com/pixelfed/pixelfed/commit/713aa5fd))
- Update legacy Profile component to use new cursor pagination for following/follower modals ([7a1495e6](https://github.com/pixelfed/pixelfed/commit/7a1495e6))
- Update ApiV1Controller, fix link header pagination in /api/v1/statuses/{id}/favourited_by ([adc82eca](https://github.com/pixelfed/pixelfed/commit/adc82eca))
- Update ApiV1Controller, fix link header pagination in /api/v1/statuses/{id}/reblogged_by ([e346b675](https://github.com/pixelfed/pixelfed/commit/e346b675))
- Update ApiV1Controller, fix following/follower entities, use masto schema by default and update components accordingly ([4716c280](https://github.com/pixelfed/pixelfed/commit/4716c280))
- Update queue config, set "after_commit" to true ([304ea956](https://github.com/pixelfed/pixelfed/commit/304ea956))
- Update ApiV1Controller, fix home timeline bug ([a8ec8445](https://github.com/pixelfed/pixelfed/commit/a8ec8445))
- Update ApiV1Controller, increase home timeline max limit to 100 to fix compatibility with mastoapi ([5cf9ba78](https://github.com/pixelfed/pixelfed/commit/5cf9ba78))
- Update ApiV1Controller, preserve album order. Fixes #3708 ([deb26971](https://github.com/pixelfed/pixelfed/commit/deb26971))
- Update site config endpoint ([f9be48d6](https://github.com/pixelfed/pixelfed/commit/f9be48d6))
- Update Portfolios, add ActivityPub + RSS support, light mode, style customization and more ([5ad0d883](https://github.com/pixelfed/pixelfed/commit/5ad0d883))
- Update atom feed, improve cache expiry and fix double encoding bug. Fixes #4121 ([467c9d75](https://github.com/pixelfed/pixelfed/commit/467c9d75))
- Update email settings, add dangerzone middleware to prompt for password before you can change your email address. Fixes #4101 ([186ba7f0](https://github.com/pixelfed/pixelfed/commit/186ba7f0))
- Update ap helpers, fix album order bug by setting media order ([871f798c](https://github.com/pixelfed/pixelfed/commit/871f798c))
- Update image pipeline, dispatch jobs to mmo queue and add "replace_id" param to v2/media endpoint to dispatch delayed MediaDeletePipeline job for original media id to improve media gc on supported clients ([5a67e9f9](https://github.com/pixelfed/pixelfed/commit/5a67e9f9))
- Update admin instance management, improve filtering/sorting and add import/export support ([d5d9500d](https://github.com/pixelfed/pixelfed/commit/d5d9500d))
- Update Post component, show state error when status account is null or missing ([e6dc6234](https://github.com/pixelfed/pixelfed/commit/e6dc6234))
- Update private profile view, add rel=me support, hide avatar/bio when not logged in and add robots meta tag to block search engine indexing on private profiles ([ab4bb9a0](https://github.com/pixelfed/pixelfed/commit/ab4bb9a0))
- Update settings, set maxlength on name and bio inputs. Fixes #4248 ([558700fc](https://github.com/pixelfed/pixelfed/commit/558700fc))
- Update api routes, add post method support to /api/v1/accounts/update_credentials to properly handle binary form data (avatars). Fixes #4250 ([1ae19ea5](https://github.com/pixelfed/pixelfed/commit/1ae19ea5))
- Replaced `predis` with `phpredis` as default redis driver due to predis being deprecated, install [phpredis](https://github.com/phpredis/phpredis/blob/develop/INSTALL.markdown) if you're still using predis.
- Update exp config, enforce mastoapi compatibility by default ([a160b233](https://github.com/pixelfed/pixelfed/commit/a160b233))
- Update home timeline, redirect to /i/web unless force_old_ui is present ([5ff4730f](https://github.com/pixelfed/pixelfed/commit/5ff4730f))
- Update adminReportController, fix mail verification request 500 bug by changing filter precedence to catch deleted users that may still be cached in AccountService ([3f322e29](https://github.com/pixelfed/pixelfed/commit/3f322e29))
- Update AP Helpers, fix getSensitive and getScope missing parameters ([657c66c1](https://github.com/pixelfed/pixelfed/commit/657c66c1))
- Fix mastodon api compatibility ([#3499](https://github.com/pixelfed/pixelfed/pull/3499))
- Add ffmpeg config, disable logging by default ([108e3803](https://github.com/pixelfed/pixelfed/commit/108e3803))
- Refactor AP profileFetch logic to fix race conditions and improve updating fields and avatars ([505261da](https://github.com/pixelfed/pixelfed/commit/505261da))
- Update network timeline api, limit falloff to 2 days ([13a66303](https://github.com/pixelfed/pixelfed/commit/13a66303))
- Update Inbox, store follow request activity ([c82f2085](https://github.com/pixelfed/pixelfed/commit/c82f2085))
- Update UserFilterService, improve cache strategy by using in-memory state via UserFilterObserver for empty lists with a ttl of 90 days ([9c17def4](https://github.com/pixelfed/pixelfed/commit/9c17def4))
- Update ApiV1Controller, add network timeline support via NetworkTimelineService ([f54fd6e9](https://github.com/pixelfed/pixelfed/commit/f54fd6e9))
- Bump max_collection_length default to 100 from 18 ([65cf9cca](https://github.com/pixelfed/pixelfed/commit/65cf9cca))
- Improve follow request flow, federate rejections and delete rejections from database to properly handle future follow requests from same actor ([4470981a](https://github.com/pixelfed/pixelfed/commit/4470981a))
- Update follower counts on follow_request approval ([e97900a0](https://github.com/pixelfed/pixelfed/commit/e97900a0))
- Update ApiV1Controller, improve local/remote logic in public timeline endpoint ([4ff179ad](https://github.com/pixelfed/pixelfed/commit/4ff179ad))
- Fix remote avatar urls when not using cloud storage ([672f7c8c](https://github.com/pixelfed/pixelfed/commit/672f7c8c))
- Update ResetPasswordController redirectTo path to /i/web as /home is deprecated ([8803c6de](https://github.com/pixelfed/pixelfed/commit/8803c6de))
- Fix v1 api block/mute endpoints, refresh RelationshipService cache after relationship changes ([54a5c3be](https://github.com/pixelfed/pixelfed/commit/54a5c3be))
- Fix NotificationService bug returning html response on /api/v1/notifications endpoint when a notification id belonging to a deleted account is rendered by checking AccountService before NotificationTransformer. ([734b30e5](https://github.com/pixelfed/pixelfed/commit/734b30e5))
- Hydrate `favourited` and `reblogged` state on v1 context endpoint ([abb4f7e1](https://github.com/pixelfed/pixelfed/commit/abb4f7e1))
- Improve admin dashboard by moving expensive stats to its page and loading stats and recent data async on the dashboard home page ([9d52b9c2](https://github.com/pixelfed/pixelfed/commit/9d52b9c2))
- Update unfollow api endpoint to only decrement when appropriate, fixes #3539 ([44de1ad7](https://github.com/pixelfed/pixelfed/commit/44de1ad7))
- Improve cache invalidation after processing VideoThumbnail to eliminate "No Preview Available" on grid feeds ([47571887](https://github.com/pixelfed/pixelfed/commit/47571887))
- Use poster in VideoPresenter component ([a3cc90b0](https://github.com/pixelfed/pixelfed/commit/a3cc90b0))
- Fix mastoapi notification type casting to include comment and share (mention and reblog) notifications ([eba84530](https://github.com/pixelfed/pixelfed/commit/eba84530))
- Fix email verification requests filtering to gracefully handle deleted accounts and accounts already verified ([b57066d1](https://github.com/pixelfed/pixelfed/commit/b57066d1))
- Add configuration to v1/instance endpoint. Fixes #3605 ([2fb18b7d](https://github.com/pixelfed/pixelfed/commit/2fb18b7d))
- Fix remote account post counts ([149cf9dc](https://github.com/pixelfed/pixelfed/commit/149cf9dc))
- Enforce blocks on incoming likes, shares, replies and follows on all endpoints ([1545e37c](https://github.com/pixelfed/pixelfed/commit/1545e37c))
- Fix unlisted post web redirect and api response ([6033d837](https://github.com/pixelfed/pixelfed/commit/6033d837))
- Remove quilljs from admin page editor, fixes #3616 ([75fbd373](https://github.com/pixelfed/pixelfed/commit/75fbd373))
- Remove remote posts from NetworkTimelineService when processing Tombstones ([2e4f2377](https://github.com/pixelfed/pixelfed/commit/2e4f2377))
- Limit NotificationService to 400 items ([f6ed560e](https://github.com/pixelfed/pixelfed/commit/f6ed560e))
- Refactor discover accounts endpoint, cache popular accounts and remove following check as most invocations are from new accounts ([016b11f3](https://github.com/pixelfed/pixelfed/commit/016b11f3))
- Fix cache invalidation in AdminSettingsController when updating rules ([fe6787f7](https://github.com/pixelfed/pixelfed/commit/fe6787f7))
- Update AP helpers, remove cache lock from profileUpdateOrCreate method and move webfinger + key_id to unique constraints to fix sql duplicate errors ([bc2bbc14](https://github.com/pixelfed/pixelfed/commit/bc2bbc14))
- Add migrations to fix webfinger profiles ([66aa8bf9](https://github.com/pixelfed/pixelfed/commit/66aa8bf9))
- Update ap helpers, move remote_url constraint ([acd8f5bb](https://github.com/pixelfed/pixelfed/commit/acd8f5bb))
- Update ApiV1Controller, fix typo in statavouriteById method ([c91a6a75](https://github.com/pixelfed/pixelfed/commit/c91a6a75))
- Fix profile masonry layout on mobile. Fixes #3203 ([fdf90f2d](https://github.com/pixelfed/pixelfed/commit/fdf90f2d))
- Add search bar to mobile breakpoints and adjust avatar size when necessary ([77b9b6bd](https://github.com/pixelfed/pixelfed/commit/77b9b6bd))
- Improved profile layout on mobile breakpoints ([77b9b6bd](https://github.com/pixelfed/pixelfed/commit/77b9b6bd))
- New Discover layout with My Hashtags, My Memories, Account Insights, Find Friends and Server Timelines ([0b680099](https://github.com/pixelfed/pixelfed/commit/0b680099))
- Fix private profile feed not loading for owner ([e950b3b2](https://github.com/pixelfed/pixelfed/commit/e950b3b2))
- Add "Shared by" link to posts that opens a list of accounts that reblogged the post ([e4b4bfc1](https://github.com/pixelfed/pixelfed/commit/e4b4bfc1))
- Updated ComposeController, add collection support to compose endpoint. ([ec2cfaf5](https://github.com/pixelfed/pixelfed/commit/ec2cfaf5))
- Updated instance config, match default oauth settings in AuthServiceProvider. ([52f25ff1](https://github.com/pixelfed/pixelfed/commit/52f25ff1))
- Updated ComposeModal.vue, fix redirect after posting. Fixes #3254. ([5db64e94](https://github.com/pixelfed/pixelfed/commit/5db64e94))
- Updated StatusController, redirect status view for authed users to Metro 2.0 UI. ([71dff472](https://github.com/pixelfed/pixelfed/commit/71dff472))
- Updated ProfileController, redirect profile view for authed users to Metro 2.0 UI. ([7f8129a7](https://github.com/pixelfed/pixelfed/commit/7f8129a7))
- Updated ComposeModal, fix post redirect on old UI. ([160e32a5](https://github.com/pixelfed/pixelfed/commit/160e32a5))
- Updated LikeService, improve caching logic and add profile id to likedBy method to fix #3271. ([6af842eb](https://github.com/pixelfed/pixelfed/commit/6af842eb))
- Updated admin diagnostics, add more configuration data to help diagnose potential issues. ([eab96fc3](https://github.com/pixelfed/pixelfed/commit/eab96fc3))
- Updated MediaTransformer, fix type case bug. Fixes #3281. ([c1669253](https://github.com/pixelfed/pixelfed/commit/c1669253))
- Updated SpaController, redirect web ui hashtags to legacy page for unauthenticated users. ([a44b812b](https://github.com/pixelfed/pixelfed/commit/a44b812b))
- Updated PublicApiController, disable legacy public access to local timeline. ([6ba7d433](https://github.com/pixelfed/pixelfed/commit/6ba7d433))
- Updated DiscoverController, cache public tag feed and only include local posts for unauthenticated users. ([0541aed5](https://github.com/pixelfed/pixelfed/commit/0541aed5))
- Updated DiscoverController, improve tag feed performance. ([d8ff40eb](https://github.com/pixelfed/pixelfed/commit/d8ff40eb))
- Updated AP fanout, added Content-Type and User-Agent for activity delivery. ([@noellabo](https://github.com/noellabo)) ([209c125](https://github.com/pixelfed/pixelfed/commit/209c125))
- Updated DirectMessageController to support new Metro 2.0 UI DMs. ([a4659fd2](https://github.com/pixelfed/pixelfed/commit/a4659fd2))
- Updated Like model, bump max likes per day from 100 to 200. ([71ba5fed](https://github.com/pixelfed/pixelfed/commit/71ba5fed))
- Updated HashtagService, use sorted set for followed tags. ([153eb6ba](https://github.com/pixelfed/pixelfed/commit/153eb6ba))
- Updated Discover component, fixed post side effects (fixes #3409). ([fe5a92b2](https://github.com/pixelfed/pixelfed/commit/fe5a92b2))
- Added UI Settings modal and fixed height media previews setting ([f2467e71](https://github.com/pixelfed/pixelfed/commit/f2467e71))
- Set max-width of 1440px for larger screens ([af68872a](https://github.com/pixelfed/pixelfed/commit/af68872a))
- Add link to sidebar profile card ([85964510](https://github.com/pixelfed/pixelfed/commit/85964510))
- Improved search bar, now resolves (and imports) remote accounts and posts, including webfinger addresses ([c8a667f2](https://github.com/pixelfed/pixelfed/commit/c8a667f2))
- Added user facing changelog at `/i/web/whats-new` ([e61dc66a](https://github.com/pixelfed/pixelfed/commit/e61dc66a))
- Cloud Backups, a command to store backups on S3 or compatible filesystems. [#3037](https://github.com/pixelfed/pixelfed/pull/3037) ([3515a98e](https://github.com/pixelfed/pixelfed/commit/3515a98e))
- Web UI Localizations + Crowdin integration. ([f7d9b40b](https://github.com/pixelfed/pixelfed/commit/f7d9b40b)) ([7ff120c9](https://github.com/pixelfed/pixelfed/commit/7ff120c9))
- Store remote avatars locally if S3 not enabled. ([b4bd0400](https://github.com/pixelfed/pixelfed/commit/b4bd0400))
- Updated FederationController, move well-known to api middleware and cache webfinger lookups. ([4505d1f0](https://github.com/pixelfed/pixelfed/commit/4505d1f0))
- Updated InstanceActorController, improve json seralization by not escaping slashes. ([0a8eb81b](https://github.com/pixelfed/pixelfed/commit/0a8eb81b))
- Refactor following & relationship logic. Replace FollowerObserver with FollowerService and added RelationshipService to cache results. Removed NotificationTransformer includes and replaced with cached services to improve performance and reduce database queries. ([80d9b939](https://github.com/pixelfed/pixelfed/commit/80d9b939))
- Updated PublicApiController, use AccountService in accountStatuses method. ([bef959f4](https://github.com/pixelfed/pixelfed/commit/bef959f4))
- Updated Timeline component, apply block/mute filters client side for local and network timelines. ([be194b8a](https://github.com/pixelfed/pixelfed/commit/be194b8a))
- Updated public timeline api, use cached sorted set and client side block/mute filtering. ([37abcf38](https://github.com/pixelfed/pixelfed/commit/37abcf38))
- Updated public timeline api, add experimental cache. ([192553ff](https://github.com/pixelfed/pixelfed/commit/192553ff))
- Updated dark mode styles, fix black box on stories. Closes #2982. ([3169f68e](https://github.com/pixelfed/pixelfed/commit/3169f68e))
- Updated verify_credentials api endpoint to improve performance. ([7df3540b](https://github.com/pixelfed/pixelfed/commit/7df3540b))
- Updated Localization util, filter out .DS_Store. ([0107e8fd](https://github.com/pixelfed/pixelfed/commit/0107e8fd))
- Updated Status model, use AccountService to generate urls instead of loading profile relation. ([2ae527c0](https://github.com/pixelfed/pixelfed/commit/2ae527c0))
- Updated Autospam service, add mark all as read and mark all as not spam options and filter active, spam and not spam reports. ([ae8c7517](https://github.com/pixelfed/pixelfed/commit/ae8c7517))
- Updated SearchApiV2Service, improve performance and include hashtag post counts when applicable ([fbaed93e](https://github.com/pixelfed/pixelfed/commit/fbaed93e))
- Updated AccountTransformer, add note_text and location fields. ([98f76abb](https://github.com/pixelfed/pixelfed/commit/98f76abb))
- Updated UserSetting model, cast compose_settings and other as json. ([03420278](https://github.com/pixelfed/pixelfed/commit/03420278))
- Updated ApiV1Controller, improve settings and add discoverPosts endpoint. ([079804e6](https://github.com/pixelfed/pixelfed/commit/079804e6))
- Updated StatusEntityLexer, prevent boosts and replies from being added to PublicTimelineService. ([32707372](https://github.com/pixelfed/pixelfed/commit/32707372))
- Updated SpaController, persist web language changes. ([7bc684e5](https://github.com/pixelfed/pixelfed/commit/7bc684e5))
- Updated LoginController, bump decayMinutes from 1 to 60. ([6bf92bed](https://github.com/pixelfed/pixelfed/commit/6bf92bed))
- Updated SPA, rewrite autolink urls to SPA when applicable. ([0837b410](https://github.com/pixelfed/pixelfed/commit/0837b410))
- Updated site config, increase ttl and enable SPA by default. ([469d49d8](https://github.com/pixelfed/pixelfed/commit/469d49d8))
- Updated status api, autolink caption before returning response. ([b00a453b](https://github.com/pixelfed/pixelfed/commit/b00a453b))
- Updated Timeline, add new ui promo in timelines that can be hidden using localstorage. ([e13959ae](https://github.com/pixelfed/pixelfed/commit/e13959ae))
- Updated FederationController, increase webfinger cache ttl from 12 hours to 14 days. ([745c3580](https://github.com/pixelfed/pixelfed/commit/745c3580))
- Updated DiscoverController, add yearly option and increase limit from 15 to 30 posts. ([10b6058c](https://github.com/pixelfed/pixelfed/commit/10b6058c))
- Updated RemoteAvatarFetch job, fixed bug preventing new avatars from being stored. ([92bc2845](https://github.com/pixelfed/pixelfed/commit/92bc2845))
- WebP Support ([069a0e4a](https://github.com/pixelfed/pixelfed/commit/069a0e4a))
- Auto Following support for admins ([68aa2540](https://github.com/pixelfed/pixelfed/commit/68aa2540))
- Mark as spammer mod tool, unlists and applies content warning to existing and future post ([6d956a86](https://github.com/pixelfed/pixelfed/commit/6d956a86))
- Diagnostics for error page and admin dashboard ([64725ecc](https://github.com/pixelfed/pixelfed/commit/64725ecc))
- Default media licenses and media license sync ([ea0fc90c](https://github.com/pixelfed/pixelfed/commit/ea0fc90c))
- Customize media description/alt-text length limit ([072d55d1](https://github.com/pixelfed/pixelfed/commit/072d55d1))
- Federate Media Licenses ([14a1367a](https://github.com/pixelfed/pixelfed/commit/14a1367a))
- Updated landing page, use config_cache. ([54920294](https://github.com/pixelfed/pixelfed/commit/54920294))
- Updated Timeline, implement suggested post opt out. ([66750d34](https://github.com/pixelfed/pixelfed/commit/66750d34))
- Updated Notification component, add at (@) symbol for remote profiles and local urls for remote posts and profile. ([aafd6a21](https://github.com/pixelfed/pixelfed/commit/aafd6a21))
- Updated Activity component, add at (@) symbol for remote profiles and local urls for remote posts and profile. ([a2211815](https://github.com/pixelfed/pixelfed/commit/a2211815))
- Updated Profile, add linkified bio, joined date, follows you label and improved website handling. ([8ee10436](https://github.com/pixelfed/pixelfed/commit/8ee10436))
- Updated Timeline, disable new post update checker and hide reaction bar on network timeline. ([1e3d3a69](https://github.com/pixelfed/pixelfed/commit/1e3d3a69))
- Updated StatusEntityLexer, only add specific status types to PublicTimelineService. ([1fdcbe5b](https://github.com/pixelfed/pixelfed/commit/1fdcbe5b))
- Updated ap helpers, set text type when appropriate. ([9f4f983f](https://github.com/pixelfed/pixelfed/commit/9f4f983f))
- Updated StatusCard, add text support. ([ed14ee48](https://github.com/pixelfed/pixelfed/commit/ed14ee48))
- Updated PublicApiController, filter out text replies on home timeline. ([86219b57](https://github.com/pixelfed/pixelfed/commit/86219b57))
- Updated RemotePost.vue, improve text only post UI. ([b0257be2](https://github.com/pixelfed/pixelfed/commit/b0257be2))
- Updated Timeline, make text-only posts opt-in by default. ([0153ed6d](https://github.com/pixelfed/pixelfed/commit/0153ed6d))
- Updated LikeController, add UndoLikePipeline and federate Undo Like activities. ([8ac8fcad](https://github.com/pixelfed/pixelfed/commit/8ac8fcad))
- Updated Settings, add default license and enforced media descriptions. ([67e3f604](https://github.com/pixelfed/pixelfed/commit/67e3f604))
- Updated Compose Apis, make media descriptions/alt text length limit configurable. Default length: 1000. ([072d55d1](https://github.com/pixelfed/pixelfed/commit/072d55d1))
- Updated ApiV1Controller, add StatusService del calls to update likes_count, reblogs_count and reply_count. ([05b9445c](https://github.com/pixelfed/pixelfed/commit/05b9445c))
- Updated Like, Status and Comment controllers to add StatusService del() method to update counts. ([eab4370c](https://github.com/pixelfed/pixelfed/commit/eab4370c))
- Updated ComposeController, use placeholder image for video media. Fixes #2595. ([789ed4b4](https://github.com/pixelfed/pixelfed/commit/789ed4b4))
- Updated DiscoverController, change api schema. ([2eea0409](https://github.com/pixelfed/pixelfed/commit/2eea0409))
- Updated StatusDelete pipeline, call StatusService::del() to remove status from cache. ([3f772ff8](https://github.com/pixelfed/pixelfed/commit/3f772ff8))
- Updated filesystems config, add backup driver to store backups on other filesystems. ([ae90eef9](https://github.com/pixelfed/pixelfed/commit/ae90eef9))
- Updated Embeds. Fix Profile + Status embeds, remove following count and improve cache invalidation and hidden follower counts. ([5ac9d0e8](https://github.com/pixelfed/pixelfed/commit/5ac9d0e8))
- Updated InboxPipeline, fail earlier for invalid public keys. Fixes ([#2648](https://github.com/pixelfed/pixelfed/issues/2648)). ([d1c5e9b8](https://github.com/pixelfed/pixelfed/commit/d1c5e9b8))
- Updated Status model, refactor liked and shared methods to fix cache invalidation bug. ([f05c3b66](https://github.com/pixelfed/pixelfed/commit/f05c3b66))
- Updated MediaStorageService, improve head checks to fix failed jobs. ([1769cdfd](https://github.com/pixelfed/pixelfed/commit/1769cdfd))
- Updated user admin, remove expensive db query and add search. ([8feeadbf](https://github.com/pixelfed/pixelfed/commit/8feeadbf))
- Updated Compose apis, prevent private accounts from posting public or unlisted scopes. ([f53bfa6f](https://github.com/pixelfed/pixelfed/commit/f53bfa6f))
- Updated font icons, use font-display:swap. ([77d4353a](https://github.com/pixelfed/pixelfed/commit/77d4353a))
- Updated ComposeModal, limit visibility scope for private accounts. ([001d4105](https://github.com/pixelfed/pixelfed/commit/001d4105))
- Updated ComposeController, add autocomplete apis for hashtags and mentions. ([f0e48a09](https://github.com/pixelfed/pixelfed/commit/f0e48a09))
- Updated StatusController, invalidate profile embed cache on status delete. ([9c8a87c3](https://github.com/pixelfed/pixelfed/commit/9c8a87c3))
- Updated AdminInstanceController, invalidate banned domain cache when updated. ([35393edf](https://github.com/pixelfed/pixelfed/commit/35393edf))
- Updated AP Helpers, use instance filtering. ([66b4f8c7](https://github.com/pixelfed/pixelfed/commit/66b4f8c7))
- Updated ApiV1Controller, add missing instance api attributes. ([64b86546](https://github.com/pixelfed/pixelfed/commit/64b86546))
- Updated story garbage collection, handle non active stories and new ephemeral story media directory. ([c43f8bcc](https://github.com/pixelfed/pixelfed/commit/c43f8bcc))
- Updated Stories, add crop and duration settings to composer. ([c8edca69](https://github.com/pixelfed/pixelfed/commit/c8edca69))
- Updated StatusController, add cache invalidation for timeline cursor. ([f3bf2fd4](https://github.com/pixelfed/pixelfed/commit/f3bf2fd4))
- Updated PublicApiController, add recent feed support to home timeline. ([1e230e80](https://github.com/pixelfed/pixelfed/commit/1e230e80))
- Updated Inbox, fix reply/comment bug by moving attachment validation to Note with attachments. ([28df9f7e](https://github.com/pixelfed/pixelfed/commit/28df9f7e))
- Direct Messages ([d63569c](https://github.com/pixelfed/pixelfed/commit/d63569c))
- ActivityPubFetchService for signed GET requests ([8763bfc5](https://github.com/pixelfed/pixelfed/commit/8763bfc5)) ([3ee1215a](https://github.com/pixelfed/pixelfed/commit/3ee1215a))
- Custom content warnings for remote posts ([6afc61a4](https://github.com/pixelfed/pixelfed/commit/6afc61a4))
- Updated NotificationCard.vue component, add follow requests at top of card, remove card-header ([5e48ffca](https://github.com/pixelfed/pixelfed/commit/5e48ffca))
- Updated RemoteProfile.vue component, add warning for empty profiles and last_fetched_at ([66f44a9d](https://github.com/pixelfed/pixelfed/commit/66f44a9d))
- Updated ApiV1Controller, enforce public timeline setting ([285bd485](https://github.com/pixelfed/pixelfed/commit/285bd485))
- Updated SearchController, fix self search bug and rank local matches higher ([f67fada2](https://github.com/pixelfed/pixelfed/commit/f67fada2))
- Updated Profile.vue, add atom feed link to context menu. Fixes ([#2313](https://github.com/pixelfed/pixelfed/issues/2313)). ([89f29072](https://github.com/pixelfed/pixelfed/commit/89f29072))
- Updated status embed, allow photo albums. Fixes ([#2374](https://github.com/pixelfed/pixelfed/issues/2374)). ([d11fac0d](https://github.com/pixelfed/pixelfed/commit/d11fac0d))
- Updated RegisterController, make the minimum user password length configurable. ([09479c02](https://github.com/pixelfed/pixelfed/commit/09479c02))
- Updated AuthServiceProvider, added support for configurable OAuth tokens and refresh tokens lifetime. ([7cfae612](https://github.com/pixelfed/pixelfed/commit/7cfae612))
- Updated EmailService, make case insensitive. ([1b41d664](https://github.com/pixelfed/pixelfed/commit/1b41d664))
- Updated horizon config, add new default values. ([90c8a721](https://github.com/pixelfed/pixelfed/commit/90c8a721))
- Updated ComposeModal, add maxlength attribute to alt text input. Fixes ([#2490](https://github.com/pixelfed/pixelfed/issues/2490)). ([526b5531](https://github.com/pixelfed/pixelfed/commit/526b5531))
- Updated PublicApiController, add state endpoint. ([9fc5a80c](https://github.com/pixelfed/pixelfed/commit/9fc5a80c))
- Updated DiscoverController, improve trending api performance. ([d8d3331f](https://github.com/pixelfed/pixelfed/commit/d8d3331f))
- Updated InboxWorker, fix race condition in account deletes. ([4a4d8f00](https://github.com/pixelfed/pixelfed/commit/4a4d8f00))
- Updated StoryItemTransformer, increase story duration from 5 seconds to 10 seconds. ([5b0b14fc](https://github.com/pixelfed/pixelfed/commit/5b0b14fc))
- Updated StatusController, restrict edits to 24 hours ([ae24433b](https://github.com/pixelfed/pixelfed/commit/ae24433b))
- Updated RateLimit, add max post edits per hour and day ([51fbfcdc](https://github.com/pixelfed/pixelfed/commit/51fbfcdc))
- Updated Timeline.vue, move announcements from sidebar to top of timeline ([228f5044](https://github.com/pixelfed/pixelfed/commit/228f5044))
- Updated lexer autolinker and extractor, add support for mentioned usernames containing dashes, periods and underscore characters ([f911c96d](https://github.com/pixelfed/pixelfed/commit/f911c96d))
- Updated Story apis, move FE to v0 and add v1 for oauth clients ([92654fab](https://github.com/pixelfed/pixelfed/commit/92654fab))
- Updated DeleteAccountPipeline, fixes [#2016](https://github.com/pixelfed/pixelfed/issues/2016), a bug affecting account deletion.
- Updated PlaceController, fixes [#2017](https://github.com/pixelfed/pixelfed/issues/2017), a postgres bug affecting country pagination in the places directory ([dd5fa3a4](https://github.com/pixelfed/pixelfed/commit/dd5fa3a4))
- Added `BANNED_USERNAMES` .env var, an optional comma separated string to ban specific usernames from being used ([6cdd64c6](https://github.com/pixelfed/pixelfed/commit/6cdd64c6))
- Added RestrictedAccess middleware for Restricted Mode ([17c1a83d](https://github.com/pixelfed/pixelfed/commit/17c1a83d))
- Fixed settings page default language ([4223a11e](https://github.com/pixelfed/pixelfed/commit/4223a11e))
- Fixed DeleteAccountPipeline bug that did not use proper media paths ([578d2f35](https://github.com/pixelfed/pixelfed/commit/578d2f35))
- Fixed mastoapi StatusTransformer, fix in_reply_to_id cast to string instead of int ([6ed00c94](https://github.com/pixelfed/pixelfed/commit/6ed00c94))
- Added Force MetroUI labs experiment ([#1889](https://github.com/pixelfed/pixelfed/pull/1889))
- Added Stories, to enable add `STORIES_ENABLED=true` to `.env` and run `php artisan config:cache && php artisan cache:clear`. If opcache is enabled you may need to reload the web server.
- Removed `relationship` from `AccountTransformer` ([4d084ac5](https://github.com/pixelfed/pixelfed/commit/4d084ac5))
- Updated `notification` api endpoint to use `NotificationService` ([f4039ce2](https://github.com/pixelfed/pixelfed/commit/f4039ce2)) ([6ef7597](https://github.com/pixelfed/pixelfed/commit/6ef7597))
- Update footer to use localization for the `Places` link ([39712714](https://github.com/pixelfed/pixelfed/commit/39712714))
- Updated ComposeModal.vue, added a caption counter. Fixes [#1722](https://github.com/pixelfed/pixelfed/issues/1722). ([009c6ee8](https://github.com/pixelfed/pixelfed/commit/009c6ee8))
- Updated Notifications to use the NotificationService ([f4039ce2](https://github.com/pixelfed/pixelfed/commit/f4039ce218f93a5578225dfdba66f0359c8fc72c))
- Updated PrivacySettings controller, clear cache after updating ([d8d11d7b](https://github.com/pixelfed/pixelfed/commit/d8d11d7b))
- Updated BaseApiController, add timestamp to signed media previews for client side cache invalidation ([73c08987](https://github.com/pixelfed/pixelfed/commit/73c08987))
- Updated AdminInstanceController, remove db transaction from instance scan ([5773434a](https://github.com/pixelfed/pixelfed/commit/5773434a))
- Updated Help Center view, added outdated warning ([0e611d00](https://github.com/pixelfed/pixelfed/commit/0e611d00))
- Updated language view, added English version of language names ([ebb998d2](https://github.com/pixelfed/pixelfed/commit/ebb998d2))
- Updated app.js, added App.utils like `.format.count`, `.filters` and `.emoji` ([34c13b6e](https://github.com/pixelfed/pixelfed/commit/34c13b6e))
- Updated CollectionCompose.vue component, fix api namespace change ([71ed965c](https://github.com/pixelfed/pixelfed/commit/71ed965c))
- Updated PostComponent, mark caption sensitive if post is and use util.emoji ([35d51215](https://github.com/pixelfed/pixelfed/commit/35d51215))
- Updated Profile.vue component, use formatted counts ([30f14961](https://github.com/pixelfed/pixelfed/commit/30f14961))
- Updated Timeline.vue component, use formatted counts, util.emoji and increase pagination limit to 5 ([abfc9fe7](https://github.com/pixelfed/pixelfed/commit/abfc9fe7))
- Updated album presenters, use better carousel ([31b114cc](https://github.com/pixelfed/pixelfed/commit/31b114cc)) ([0617fada](https://github.com/pixelfed/pixelfed/commit/0617fada)) ([767fc887](https://github.com/pixelfed/pixelfed/commit/767fc887))
- Updated Timeline.vue component, remove tap for lightbox as it conflicts with new carousel ([96e25ad2](https://github.com/pixelfed/pixelfed/commit/96e25ad2))
- Updated ComposeModal.vue, added album support, editing and UI tweaks ([3aaad81e](https://github.com/pixelfed/pixelfed/commit/3aaad81e))
- Updated InternalApiController, increase license limit to 140 to match UI counter ([b3c18aec](https://github.com/pixelfed/pixelfed/commit/b3c18aec))
- Updated album carousels, fix height bug ([8380822a](https://github.com/pixelfed/pixelfed/commit/8380822a))
- Updated MediaController, add timestamp to signed preview url ([49efaae9](https://github.com/pixelfed/pixelfed/commit/49efaae9))
- Reverted `strict` Same-Site Cookies to `null` to fix 2FA/session expiry [#1667](https://github.com/pixelfed/pixelfed/pull/1667)
- Fixed AP errors by storing ActivityPub object id and url [#1668](https://github.com/pixelfed/pixelfed/pull/1668) [#1683](https://github.com/pixelfed/pixelfed/pull/1683)
- Fixed content warnings that had filter applied [#1669](https://github.com/pixelfed/pixelfed/pull/1669)
- Remote follows! Search for an actor URI, send AP Follow, plus handle incoming AP Accept Follow
- Compose UI v4: a rework of the v3 flow to allow basic cropping and better support future post types
- Profile badges show if a user is following you or is an admin
- Show confirmation message when muting or blocking a user from a post
- Allow "read more" to be disabled on posts [#1545](https://github.com/pixelfed/pixelfed/pull/1545)
- Loops! Discover short videos
- Preliminary support for profile PropertyValue metadata
- Preliminary support for Direct Messages
- Places! Run the artisan task `import:cities`
- Emails are now validated and banned email domains are disallowed at signup. Artisan task `email:bancheck` will validate existing users.
- .env vars `REDIS_SCHEME` and `REDIS_PATH` allow for using Redis over a Unix socket instead of TCP [#1602](https://github.com/pixelfed/pixelfed/pull/1602)
- .env var `IMAGE_DRIVER` allows using imagick instead of gd
- Add Configuration Editor to Admin Dashboard [#1388](https://github.com/pixelfed/pixelfed/pull/1388), [323dca1](https://github.com/pixelfed/pixelfed/commit/323dca1)
- Add Migration, adding profile_id to users table [#1388](https://github.com/pixelfed/pixelfed/pull/1388), [bdfe633](https://github.com/pixelfed/pixelfed/commit/bdfe633)
- Add Media configuration [#1414](https://github.com/pixelfed/pixelfed/pull/1414)
- Add Content Warnings to comments [#1430](https://github.com/pixelfed/pixelfed/pull/1430), [42d81fc](https://github.com/pixelfed/pixelfed/commit/42d81fc) [8d4b3bd](https://github.com/pixelfed/pixelfed/commit/8d4b3bd) [73e162e4](https://github.com/pixelfed/pixelfed/commit/3e162e4)
- Add new rate limits [#1436](https://github.com/pixelfed/pixelfed/pull/1436) [1f1df2d](https://github.com/pixelfed/pixelfed/commit/1f1df2d)
- Add RegenerateThumbnails command to force thumbnail regeneration [#1437](https://github.com/pixelfed/pixelfed/pull/1437) [a3be4cd](https://github.com/pixelfed/pixelfed/commit/a3be4cd)
- Update SearchController, fix AP verb typo [#1387](https://github.com/pixelfed/pixelfed/pull/1387), [dc8acf9](https://github.com/pixelfed/pixelfed/commit/dc8acf9)
- Update StatusTransformer, increase media cache ttl to 14 days [#1387](https://github.com/pixelfed/pixelfed/pull/1387), [f35718b](https://github.com/pixelfed/pixelfed/commit/f35718b)
- Update Image Optimization to not store EXIF by default [#1414](https://github.com/pixelfed/pixelfed/pull/1414)
- Update Settings, hide OAuth/Developer pages when not enabled [#1413](https://github.com/pixelfed/pixelfed/pull/1413)
- Update Presenter Components, move alt tag and filters to `<img>` element [#1415](https://github.com/pixelfed/pixelfed/pull/1415)
- Update Api Controllers, add missing caption limit to `composePost()` and missing `is_nsfw` attribute to comment queries [#1429](https://github.com/pixelfed/pixelfed/pull/1429), [1cff278](https://github.com/pixelfed/pixelfed/commit/1cff278)
- Update instances admin view, add scan button to find new instances [#1436](https://github.com/pixelfed/pixelfed/pull/1436) [a94a3ee](https://github.com/pixelfed/pixelfed/commit/a94a3ee)
- Update registration page, add links to terms and privacy pages [#1488](https://github.com/pixelfed/pixelfed/pull/1488)
COSTAR is a filtering system that allows admins to define environment variables that will dynamically apply certain policies to posts of a defined scope, similar to Pleroma's MRF system.