Changelog
Every release, newest first. Subscribe: Atom Β· JSON Feed
Oct
2026
2026
admin@0.3.88 Β· core@0.3.21 Β· mcp@0.1.5 Β· integration@0.3.22 Β· client@0.1.4 Β· cli@0.3.15 β Latest
Two-factor sign-in, signed webhooks, key limits, version diff and media usage
- 2FA (TOTP) β turn it on under Account with any authenticator app. Eight one-time recovery codes, codes can't be replayed, and an admin can reset a locked-out user. Docs β
- Active sessions β see every signed-in device (browser, IP, time) and sign out one or all others.
- API key limits β restrict a key to collections, give it an expiry date or a requests-per-minute limit. Applies to the REST API and MCP. A new dialog replaces the prompt chain.
- Editor layout β custom fields now live in a collapsible βDetailsβ card in the main column (grouped, two per row, long inputs full width; remembers open/closed per collection) instead of small boxes in the sidebar, so the body stays the main content. Collections without a body field drop the block-editing tools. Also fixed: validation errors on publish were never shown, the long dock popups in Station mode (many collections / tools) now scroll instead of running off the screen, and the Schema page can be scrolled in Station mode again.
- Webhook recipes β tested receiver plus copy-paste handlers: Slack/Telegram on review, IndexNow, Cloudflare purge, Mastodon. Docs β
- AI translation of missing locales β one click in the editor creates the missing language versions as drafts (never overwrites, never publishes). Docs β
- Image variants + focal point β
/orbiter/media/<id>?w=800&fmt=webp&ar=16:9serves a resized, re-encoded or cropped version; crops keep the focal point you set in the media library. Bounded and cached. Docs β - Review workflow β optional. Editors submit entries for review; admins and the new reviewer role approve or request changes. Enforced on every publishing route. Docs β
- Preview links β the editor's Preview button now uses a one-hour token bound to that entry instead of the master preview token (which also fixes previews for editors, who only got a masked token before).
- Version diff β see field by field what a restore would change. Restoring now keeps the content it replaces, so a restore can be undone (previously the replaced content was lost, and the newest snapshot couldn't be restored at all).
- Media usage β each file shows where it is used; filter Unused files and Broken refs; deleting a file that is in use warns first.
- Signed webhooks β HMAC-SHA256 signatures, retries (5 s, 30 s, 5 min) and a delivery log, managed in Settings. Webhook URLs are now admin-only (editors could previously set them). Docs β
Oct
2026
2026
admin@0.3.87 Β· core@0.3.20 Β· mcp@0.1.4 Β· cli@0.3.14
Security check, encrypted secrets, draft-only agent keys, Terminal theme
orbiter doctor+ dashboard card β flags a pod tracked by git, plaintext credentials, an open Content API and more, with the fix next to each finding. Docs β- Encrypted secrets β set
ORBITER_SECRETand stored FTP/SMTP/AI/GitHub/S3 credentials are encrypted at rest (AES-256-GCM). Opt-in; nothing changes without it. - Draft-only keys for agents β an API key can be allowed to create and edit drafts over MCP. It can never publish or touch live entries.
- Terminal theme β a fourth palette: amber phosphor on near-black, with a warm paper light variant.
- Admin polish β Settings style cards show their active state, the style default matches the app, leaving the XFCE dock reloads cleanly, visible keyboard focus, and reduced-motion support.
Oct
2026
2026
admin@0.3.86 Β· core@0.3.19 Β· integration@0.3.21 Β· mcp@0.1.3
Security follow-up: uploaded files, URL imports, login limits, and what gets pushed to GitHub
A second pass over the admin and core packages after the previous release. Update @a83/orbiter-admin, @a83/orbiter-core and @a83/orbiter-integration together β the new media headers live in core.
- GitHub push no longer ships secrets β the GitHub push feature committed the whole
.pod, including live session tokens, password hashes and stored credentials (FTP, SMTP, AI and GitHub tokens). It now pushes a scrubbed copy. If you pushed before, rotate those credentials and check your repo history. - Uploaded files can't run script β media is served with
nosniffand a sandboxing CSP, and anything that isn't an image, video, audio or PDF is forced to download. Applies to the admin and the public/orbiter/mediaroute. - Server-side request forgery β importing or linking media by URL could be pointed at internal addresses (localhost, private networks, cloud metadata). Private and reserved targets are now blocked, redirects re-checked, downloads capped at 50 MB. Set
ORBITER_ALLOW_PRIVATE_FETCH=1if you need to import from your LAN in development. - Login rate limit β it trusted a client-supplied
X-Forwarded-Forheader, so it could be bypassed. The header is now only honoured when the connection comes from a reverse proxy on a private address. - Restricted editors β AI suggestions, the collection list/detail,
/api/infoand the quality report no longer expose collections an editor isn't allowed to see. Form-builder configs are admin-only. - Content API drafts β with the API enabled but no token set,
?status=drafton/orbiter/api/[collection]returned unpublished entries to anyone. Drafts now require a configured, matching token. - API token hashed β the optional single
api.tokenis now stored as a SHA-256 hash like API keys (existing plaintext values keep working and migrate on first use). - Desktop app β the embedded server only listens on loopback (it was reachable from your LAN), the window is sandboxed, only http(s) links are handed to the OS, and navigation away from the local admin is blocked.
- Smaller fixes β CSV export works again and neutralises spreadsheet formulas, the login no longer reveals which usernames exist through timing, WordPress media import is covered by the same SSRF protection, and
/healthno longer exposes the pod path. - Sessions and public endpoints β changing a password signs out all other sessions. The public form and analytics endpoints are rate-limited and size-capped, and notification mails are capped. The Content API token is compared in constant time.
Oct
2026
2026
admin@0.3.85 Β· core@0.3.18 Β· mcp@0.1.2 Β· client@0.1.3 Β· integration@0.3.20 Β· cli@0.3.13
Security hardening pass: 3 privately-disclosed bugs fixed, full-repo audit, 0 known dependency vulnerabilities
A researcher privately reported three vulnerabilities in the admin and core packages. All three are fixed and released. Finding them prompted a broader audit of the rest of the codebase, which turned up more of the same pattern β all fixed below, plus a dependency and process cleanup so the next one is easier to report and faster to close.
- Stored XSS β unescaped field names/IPs in the Inbox, unescaped media filenames and analytics paths from fully unauthenticated endpoints, and the same pattern in
apps/demo's public post/page/event pages. Fixed with consistent escaping (and DOMPurify on the demo frontend) everywhere user- or visitor-supplied text reachesinnerHTML. - Collection permission bypass β an editor restricted to specific collections could still reach draft content via the singleton endpoint, the terminal CSV/JSON export, search/calendar widgets, comments, and edit-locks. All now enforce the same
requireCollectionAccesscheck as the main entry routes. See the new permissions docs. - Path traversal β the local media backend's
folderparameter could write outside the configured media directory; the GitHub and S3 backends had the same unvalidated join. All three now resolve and reject anything that would escape the configured root. - Plaintext API keys β Bearer tokens for the Public Content API and MCP server were stored and compared in plaintext, inside a
.podfile that Orbiter's ownorbiter inittemplate commits to git by design. Now hashed (SHA-256, constant-time compare), with transparent migration for already-issued keys. - Missing/inverted access checks β
api-keysmanagement, schema field rename/delete, and the embeddable-widget endpoint (/api/widget/:collectionβ inverted logic made it allow-by-default instead of deny-by-default like every other API gate) each had a broken or missing permission check. All fixed. - Dependency audit β
npm auditwent from 40 vulnerabilities to 0: removed an unused, outdatedelectron-builderdevDependency pulling in most of them on its own, bumped nodemailer/sharp/adm-zip/electron to patched versions, and β the big one β Astro 5 β 7 and @astrojs/node 9 β 11 acrossapps/demo,apps/landing, and theorbiter initscaffold template, closing a critical RCE in Astro's AVIF image optimization. - Process β new SECURITY.md, GitHub private vulnerability reporting and Dependabot security updates turned on for the repo, and a weekly
npm auditCI check.
Aug
2026
2026
mcp@0.1.0 Β· admin@0.3.81
MCP server for AI agents, Public Content API, JSON-LD, API keys
@a83/orbiter-mcpβ new MCP server package.list_collections,get_entries,get_entry,search_contenttools for Claude Desktop and other MCP clients. stdio for local trusted access,--httpfor remote (same auth as the Public Content API).- Public Content API β
/api/public/[collection]read-only JSON endpoints, opt-in per collection, CORS enabled. - API keys β generate/revoke Bearer tokens in Settings, optional enforcement on the Public Content API and MCP HTTP transport, hit counters and last-used tracking.
- JSON-LD / schema.org β
BlogPostingandWebSitestructured data on published HTML, both themes. - OpenAPI spec + API discovery β auto-generated spec and a discovery endpoint listing available collections and auth requirements.
- Admin panel routing fix β clean extensionless URLs (
/login,/dashboard, etc.) now redirect correctly.
Jun
2026
2026
admin@0.3.78 Β· cli@0.3.9
Team-ready: content validation, permissions, quality dashboard, encryption, SvelteKit
- Content validation β schema fields support
required,min,max, andregex. Drafts always save freely. Publish/Schedule shows an inline error banner. Server enforces the same rules via 422. - Collection permissions β restrict editor users to specific collections. Configured per-user in a checkbox modal. Admins are always unrestricted.
- Content quality dashboard β sidebar panel scans all published entries for missing body, short body, no image, and no SEO metadata. Issue counts at a glance.
- Schema migration β rename a field including all entry data in one atomic transaction. Also: change-type and delete-field routes.
- Multi-pod dashboard β link multiple pod files, see published count, collections, size, and last modified across all projects in one page.
orbiter encrypt/decryptβ AES-256-GCM with scrypt key derivation. Commit the.pod.encto git, decrypt in CI with a secret.orbiter syncβ rsync push/pull in one command.orbiter statusβ pod health in the terminal.- SvelteKit support β
@a83/orbiter-clientopens the pod directly from any Node.js framework.<OrbiterImage>Astro component with auto lazy, alt, and dimensions.
Jun
2026
2026
Content Layer + Publish HTML + Suggestions v2
Standard astro:content API, static site generator, AI suggestions, CLI, UI polish
- Astro Content Layer β
orbiterLoader()for build-time,orbiterLiveLoader()for SSR. UsegetCollection()fromastro:contentinstead of the custom virtual module. Auto Zod schema, hot reload on pod changes. - Smart Suggestions v2 β multi-section panel with tags, cross-collection related entries, AI SEO title & description, content quality hints,
suggestedPrompts. Manualβ¦ Suggestbutton grouped withβ¦ AI. - Publish HTML β one-click static site. Two themes: Orbit (modern) and Canvas (editorial whiteboard). Dark mode, responsive, OG tags, reading time.
- CLI β
orbiter publishgenerates HTML from terminal,orbiter backupcreates timestamped pod copy. - UI polish β dashboard greeting, live word count, pulsing autosave dot, favicon badge, pod size in sidebar, collection color dots, relative timestamps, shortcut hints.
Jun
2026
2026
admin@0.3.74
Calendar view, Simple Analytics, cross-pod copy & desktop auto-update
- Calendar view β full month-grid page with color-coded entries (scheduled/expiring/published/draft). Click a day to see entries, filter by status, keyboard nav. Dashboard widget with mini calendar + upcoming list.
- Simple Analytics β privacy-friendly pageview tracking stored in the POD. No cookies, no external scripts, <500 bytes. Bot detection (GPTBot, ClaudeBot, etc). Dashboard with daily chart, top pages, referrers. Human vs. agent traffic split.
- Cross-pod import/export β export all collections + entries as JSON. Import from a
.podfile or JSON export. Collections created automatically, skip or overwrite duplicates. - Desktop auto-update β the Electron app downloads new releases from GitHub in the background. Universal macOS DMG (M1 + Intel in one file). One-click backup (
ββ§S). - Table field β mini-spreadsheet as a schema field type. Header row, data rows, add/remove rows and columns, Tab navigation. Stored as
string[][]. - Dashboard widget toggles β enable/disable Calendar, Recently Edited, Collections, Notes & To-Do in Settings.
- OG Image picker β media picker modal in the SEO panel instead of a dropdown. Image preview + clear button.
Jun
2026
2026
Desktop v0.2.2
Desktop App for macOS & Windows β pick a template, start editing.
- Templates on first launch β choose Blog, Portfolio, Business, or Events. The app creates all collections and fills them with demo content so you can see how everything works right away.
- macOS β DMG installer, drag to Applications, double-click. Apple Silicon (arm64) and Intel (x64).
- Windows β NSIS installer wizard, optional install directory. x64.
- Self-contained β Electron bundles the full admin server. Runs locally, no internet required after install.
- Multi-site switching β File β Switch POD (
βO) switches to a different content database and restarts instantly.
Jun
2026
2026
v0.3.47 β New
Station dock overhaul β command palette, keyboard nav, notification center & more
- Command palette β
βKor/opens a full-screen palette. Opens with recent entries pre-loaded. Type>to enter command mode:> ls,> go,> new,> search,> build,> export,> random,> = expr(math evaluator). Command history with β/β. - Vim keyboard navigation β press
gthen a letter to jump to any page:g ddashboard,g mmedia,g hHUD,g ssettings,g bbuild, and more. Animatedg βΊindicator in the status bar while waiting for the second key. - Notification center β bell icon in the status bar. Every save, build trigger, and export is logged automatically. Dropdown panel with unread badge, relative timestamps, and clear-all.
- HUD panel expanded β Drafts section (last 10 drafts, clickable to editor) and Activity feed (last 8 events as a live timeline). Opens with
g hor the dock button. - Zen / focus mode β
ββ§Fhides the dock and status bar for distraction-free writing. Persists across reloads. Toast hint on enter. - Shortcut cheatsheet β
?key or?button in the status bar opens a two-column modal with every shortcut and palette command. - Live build status β status bar shows β buildingβ¦ with a pulse animation while a build is running, polling every 4 seconds until done.
- Breadcrumb in status bar β when inside a collection, the center shows Collection βΊ Entries with a clickable link back.
- Left dock mode β toggle dock position between bottom and left side. All popups, overlays, and magnification axis adapt automatically.
- Hover preview cards β hovering a collection in the dock shows a card with the 3 most recent entries and quick-action buttons (new entry, view all, export).
Jun
2026
2026
v0.3.20
Space Station mode, multilingual i18n & settings overhaul
- Space Station mode β a distinct admin layout: floating magnification dock (macOS-style), HUD status-bar panel with stats and notes, frosted glass page headers with contextual action buttons. Toggle in Settings β Interface β Layout.
- Mobile tab bar β in Station mode, the dock collapses to a native-feeling bottom tab bar on screens under 768 px. Stats stack to a 2Γ2 grid; cards resize automatically.
- Multilingual (i18n) β per-entry locale variants using a dedicated
localecolumn (not slug suffixes). Configure locales in Settings β Language; locale tabs appear in the editor automatically.getLocaleCollection()andgetLocaleEntry()inorbiter:collectionswith automatic fallback to the default locale. - Settings two-column layout β settings groups reflow into a responsive two-column grid to reduce scrolling. Save button pinned to the page header and repeated at the bottom.
Jun
2026
2026
v0.3.14
Scheduled publishing, comments, RSS/sitemap, entry locking & email notifications
- Scheduled publishing β set a
publish_atdate on any entry. A server-side scheduler auto-publishes and fires the build webhook. Also supportsunpublish_atto revert published entries to draft at a future date. - Content comments β per-entry editorial comment thread directly in the editor. Post, resolve/unresolve, and delete comments. Stored in a
_commentstable, never mixed with entry data. - RSS feeds & XML sitemap β
/orbiter/rss/[collection].xmland/orbiter/sitemap.xmlinjected automatically by the integration. No configuration needed. - Schema export & import β download any collection's schema as JSON, re-import to another collection or pod. Export/Import buttons in the schema edit panel.
- CSV import & export β bulk entry management. Export all entries as CSV, import to create or update by slug.
- Entry locking β when you open an entry, the editor claims a lock. If another user is already editing, a warning banner appears. Lock expires after 90 s without a heartbeat.
- Email notifications β configure SMTP in Settings. Get an email on publish and/or new comment. Powered by nodemailer, always async.
- Required field validation β fields marked
requiredin the schema block saves (non-autosave) until filled. - Image optimization β uploaded images are resized and compressed automatically via sharp. Max-width and quality configurable per pod in Settings.
May
2026
2026
v0.3.9
Trash, activity log & draft preview
- Trash / soft delete β deleted entries move to a recoverable Trash tab. Restore to draft or permanently delete. Bulk restore and bulk purge supported.
- Activity log β every create, update, publish, unpublish, delete, and restore is recorded with the acting user and timestamp. Visible in the editor's meta panel.
- Draft preview β generate a preview token in Settings β API and attach it to your preview URL.
getPreviewEntry()inorbiter:collectionsreads any draft directly from the pod, bypassing the published-only snapshot. - Schema field drag-sort β reorder fields in the schema editor with a drag handle. Order is preserved in the stored schema.
- Rate limiting β login endpoint is limited to 5 attempts per 15 minutes per IP. Returns 429 with a human-readable message.
- TypeScript types β
orbiter-env.d.tsis auto-generated at build time with per-collection interfaces and typed overloads for all query functions.
May
2026
2026
v0.3.3
Singletons, drag-sort, editor blocks & version display
- Singleton collections β mark a collection as singleton to skip the entries list and go straight to the one record. Good for site settings, about pages, or any single-document content.
- Drag-to-sort entries β reorder entries manually with a drag handle. Order persists in the pod and is reflected in
getCollection()output. - Callout blocks β type
/notein the block picker to insert a tinted info/warning box inline with prose. - Table blocks β type
/tblfor an editable 2Γ2 table. Tab to navigate cells, toolbar to add/remove rows and columns. - Boolean field β on/off toggle field type for schema definitions.
- Preview URL per collection β set a URL template with
{slug}in Schema; an β Preview button appears in the editor topbar. - Version display β admin sidebar footer now shows Orbiter vX.Y.Z Β· pod vN so you always know what's running.
Apr
2026
2026
v0.3.1
S3 backends, docs & auto-webhook
- S3-compatible media backend β store uploads on Cloudflare R2, Backblaze B2, AWS S3, or any S3-compatible endpoint. Config via Settings β Media.
- External media links β reference a Dropbox, Drive, or CDN URL directly without fetching the file. Third tab in the image picker.
- Auto-publish webhook β fires automatically when an entry transitions from draft to published, no manual trigger needed.
- Docs site β full reference at orbiter.sh/docs: quick start, collections, media, API, deployment, CLI.
May
2025
2025
Editor
Images, Video & Cloud Import
- Inline image blocks β float left, right, center, or full width. Text wraps naturally, travel-blog style.
- Video embedding β paste a YouTube, Vimeo, or direct
.mp4URL. The editor auto-embeds in a responsive 16:9 player. - Cloud URL import β paste a share link from Dropbox, Google Drive, or OneDrive. The server fetches it and stores it in your pod. No CORS, no manual download.
- Block picker β
/imgand/vidshortcuts to insert media blocks from the keyboard.
Mar
2025
2025
Themes
Three Themes & Glass Layout
- Space β dark space station HUD, light solar command ice blue.
- Zen β Japandi aesthetic: slate, mauve, moss, warm neutrals.
- Catppuccin β Mocha (dark) and Latte (light) from the popular palette.
- Glass layout β frosted panels, backdrop blur, animated gradient orbs. Ships as the default; classic grid still available.
Jan
2025
2025
v0.2.0 β v0.2.2
Now on npm
- Published to npm β
orbiter-core,orbiter-integration,orbiter-admin,orbiter-cli. - Block editor with live preview, autosave, version history, and draft/published toggle.
- i18n β per-entry locale variants,
getLocaleCollection(), locale fallback. - Relations β resolved at build time into full Entry objects.
- WordPress importer, Git sync mode, JSON API, multi-user auth, PWA.