Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
302 commits
Select commit Hold shift + click to select a range
e32b796
feat(admin-settings): search, sticky save, collapsible sections, posi…
hokiepokedad2 Jun 8, 2026
fccd388
ci: bump docker/build-push-action from 5 to 7 (#333)
dependabot[bot] Jun 8, 2026
6f2f8f4
ci: bump actions/setup-python from 5 to 6 (#334)
dependabot[bot] Jun 8, 2026
652d61c
ci: bump actions/create-github-app-token from 2 to 3 (#335)
dependabot[bot] Jun 8, 2026
166373a
ci: bump dependabot/fetch-metadata from 2 to 3 (#336)
dependabot[bot] Jun 8, 2026
2ce2bd9
ci: bump actions/cache from 4 to 5 (#337)
dependabot[bot] Jun 8, 2026
5ce2e00
deps: bump the angular group across 1 directory with 13 updates (#338)
dependabot[bot] Jun 8, 2026
8d4f564
ci: batch dependency bumps into the release changelog cut (#368)
hokiepokedad2 Aug 5, 2026
2bd6a26
deps: Bump Microsoft.NET.Test.Sdk from 18.6.0 to 18.8.1 (#365)
dependabot[bot] Aug 5, 2026
f358b21
deps: Bump Microsoft.AspNetCore.Authentication.JwtBearer and 6 others…
dependabot[bot] Aug 5, 2026
877b8c4
deps: Bump Microsoft.EntityFrameworkCore and 4 others (#366)
dependabot[bot] Aug 5, 2026
69b377a
ci: consolidate the .NET dependabot groups into one (#371)
hokiepokedad2 Aug 5, 2026
b8027e4
deps: bump jest-preset-angular (#344)
dependabot[bot] Aug 5, 2026
f49736d
ci: stop auto-merging majors inside dependabot groups (#372)
hokiepokedad2 Aug 5, 2026
b240996
ci: bump actions/cache from 5 to 6 (#350)
dependabot[bot] Aug 5, 2026
95a3652
ci: bump actions/setup-python from 6 to 7 (#356)
dependabot[bot] Aug 5, 2026
40620cb
build: drop deprecated @angular/platform-browser-dynamic from the tes…
hokiepokedad2 Aug 5, 2026
6083544
deps: bump the angular group across 1 directory with 9 updates (#359)
dependabot[bot] Aug 5, 2026
fadffaf
build: remove unused prettier-eslint devDependency (#375)
hokiepokedad2 Aug 5, 2026
7f57f2d
ci: bump actions/setup-node from 6 to 7 (#357)
dependabot[bot] Aug 5, 2026
9dd6d74
fix: patch high-severity Microsoft.OpenApi advisory in the API host (…
hokiepokedad2 Aug 5, 2026
426b145
deps: bump the eslint group across 1 directory with 5 updates (#349)
dependabot[bot] Aug 5, 2026
eb0850a
ci: bump actions/checkout from 6 to 7 (#347)
dependabot[bot] Aug 5, 2026
7c25f2c
deps: upgrade @ngx-translate to v18 and migrate off TranslateModule (…
hokiepokedad2 Aug 5, 2026
b7c1906
ci: bump actions/setup-dotnet from 5 to 6 (#358)
dependabot[bot] Aug 5, 2026
76a5449
ci: add merge_group triggers so main can use a merge queue (#378)
hokiepokedad2 Aug 5, 2026
462dae2
fix: allowed_role_ids grants access on any listed role (#367) (#369)
hokiepokedad2 Aug 5, 2026
6024be3
fix(docker): install curl in the runtime image so the healthcheck pas…
hokiepokedad2 Aug 5, 2026
d4363d3
docs: remove stale AutoMapper references (#241) (#381)
hokiepokedad2 Aug 5, 2026
26d2a82
refactor: align ScannerDbContext with sibling *Context naming (#240) …
hokiepokedad2 Aug 5, 2026
5b0e9da
security: stop gym-picker images leaking a Referer to third-party hos…
hokiepokedad2 Aug 5, 2026
3f8d38a
security: tighten app-wide Referrer-Policy to same-origin (#383) (#384)
hokiepokedad2 Aug 5, 2026
e358375
feat: report the running build via GET /api/version (#385)
hokiepokedad2 Aug 5, 2026
9606eeb
docs: cut changelog for v2.12.0 (#386)
poracleweb-net-release[bot] Aug 5, 2026
87d8940
ci: drop --delete-branch from the changelog auto-merge (#387)
hokiepokedad2 Aug 5, 2026
d42e69f
fix: English UI rendered raw translation keys after the ngx-translate…
hokiepokedad2 Aug 5, 2026
281aef9
docs: cut changelog for v2.12.1 (#390)
poracleweb-net-release[bot] Aug 5, 2026
aaf4f5a
fix: upload the geofence submission map to Discord instead of linking…
hokiepokedad2 Aug 7, 2026
8500d9f
feat: make geofence review threads decidable at a glance (#393) (#394)
hokiepokedad2 Aug 7, 2026
14ad6fd
fix: implement two endpoints the SPA has always called but never had …
hokiepokedad2 Aug 7, 2026
1988127
security: stop leaking credentials via /api/settings and lock down qu…
hokiepokedad2 Aug 7, 2026
828f41d
fix: editing an alarm duplicated it instead of updating, on 7 of 10 t…
hokiepokedad2 Aug 7, 2026
c5567fc
security: enforce disable_areas/profiles/location server-side, not ju…
hokiepokedad2 Aug 7, 2026
50dd551
fix: editing a lure or invasion 500'd and discarded the change (#401)…
hokiepokedad2 Aug 7, 2026
370171f
fix: three non-functional admin features (#404, #405, #413) (#429)
hokiepokedad2 Aug 7, 2026
9b9ac65
fix: client input no longer returns 500 across nine endpoints (#418) …
hokiepokedad2 Aug 8, 2026
5073231
fix: retire the profile-filtered human lookup that 404'd on a stale c…
hokiepokedad2 Aug 8, 2026
e49d64b
docs: point self-hosters at a release tag, not main (#432)
hokiepokedad2 Aug 8, 2026
f01f4ff
docs: consolidate the Unreleased changelog sections before cutting a …
hokiepokedad2 Aug 8, 2026
b9fddaa
docs: cut changelog for v2.13.0 (#434)
poracleweb-net-release[bot] Aug 8, 2026
009a9ba
ci: add a develop branch so main tracks releases (#435)
hokiepokedad2 Aug 8, 2026
76fc852
fix: the Cleaning page was broken three separate ways (#402) (#436)
hokiepokedad2 Aug 8, 2026
61bb013
security: GET /api/config disclosed the Poracle admin id list anonymo…
hokiepokedad2 Aug 8, 2026
c685a4f
fix: GET /api/masterdata/grunts returned 500 to every caller (#419) (…
hokiepokedad2 Aug 8, 2026
19b0aae
fix: "track all invasions" failed 100% of the time, in two places (#4…
hokiepokedad2 Aug 8, 2026
8450e92
fix: editing a Max Battle wiped its move and evolution filters (#412)…
hokiepokedad2 Aug 8, 2026
a67ce9f
fix: editing a quick-pick alarm made the quick pick unremovable (#403…
hokiepokedad2 Aug 8, 2026
eaf6b52
fix: approving a geofence unsubscribed the owner from all of theirs (…
hokiepokedad2 Aug 8, 2026
cdbeafe
fix: reject/delete stranded approved geofences in Koji (#409, #421) (…
hokiepokedad2 Aug 8, 2026
8fd7a54
fix: validate geofence polygons on create, and stop trusting stored o…
hokiepokedad2 Aug 8, 2026
82a998d
fix: approve accepted any geofence status, like reject used to (#409 …
hokiepokedad2 Aug 8, 2026
e897e3f
fix: alarms written during a JWT profile desync landed on the wrong p…
hokiepokedad2 Aug 8, 2026
d8c4d16
fix: profile rename was a no-op and profile numbers were guessed (#40…
hokiepokedad2 Aug 8, 2026
11ce5ce
fix: bulk distance and location accepted values the create path rejec…
hokiepokedad2 Aug 8, 2026
fe3d359
fix: a Koji rejection during geofence approval surfaced as an opaque …
hokiepokedad2 Aug 8, 2026
4b13c18
fix: make disable_nominatim real, remove the toggles that cannot be (…
hokiepokedad2 Aug 8, 2026
a62f925
fix: silent duplicate-profile-name failure, and remove the dead fort …
hokiepokedad2 Aug 8, 2026
2a9e988
fix: follow quick-pick uids through a bulk distance update (#443) (#454)
hokiepokedad2 Aug 8, 2026
43cf59c
fix: error toasts, 12 settings strings and the paginator were never t…
hokiepokedad2 Aug 8, 2026
251ae3f
fix: eight interface defects from the regression sweep (#426) (#456)
hokiepokedad2 Aug 8, 2026
25527d6
docs: auto-delete does not apply to fort changes (#458)
hokiepokedad2 Aug 8, 2026
1bab6d1
fix: the update reconciler trusted an insert counter over the uid (#4…
hokiepokedad2 Aug 8, 2026
faa46b9
fix: read what PoracleNG says it did with a create (#459, #462, #463,…
hokiepokedad2 Aug 8, 2026
b0b1a52
fix: cleaning rotated uids without following them, and took any int (…
hokiepokedad2 Aug 8, 2026
5bd4895
fix: profile import, duplicate and name validation (#465, #466, #467)…
hokiepokedad2 Aug 8, 2026
ed39c81
fix: ungated geofence toggles, and a language selector caught by the …
hokiepokedad2 Aug 8, 2026
55426e5
fix: geofence name collisions, GeoJSON import failures, point counts …
hokiepokedad2 Aug 8, 2026
f5e2ea1
fix: absent coordinates, orphaned profiles, half-written webhooks, un…
hokiepokedad2 Aug 8, 2026
901be25
fix: unsatisfiable Pokemon filters, and quick-pick applied state outl…
hokiepokedad2 Aug 8, 2026
b07419d
fix: quest summary editor showed the profile scheduler's empty state …
hokiepokedad2 Aug 8, 2026
cbd47f4
fix: a no-op alarm edit was reported as a collision with another alar…
hokiepokedad2 Aug 8, 2026
3ab3092
fix: deleting a user left their alarms, geofences, quick picks and de…
hokiepokedad2 Aug 8, 2026
4cf2690
fix: disable_areas took unrelated pages, dialogs and the dashboard do…
hokiepokedad2 Aug 8, 2026
6fdb908
fix: remove the ping control that never saved, and three UI fields th…
hokiepokedad2 Aug 8, 2026
bea0ac4
fix: alarm writes that destroyed, duplicated or misreported what they…
hokiepokedad2 Aug 8, 2026
575345e
fix: profile duplicate and import took the wrong geography and 500d o…
hokiepokedad2 Aug 8, 2026
2ce4f33
fix: a language change wiped last_checked, and four smaller reporting…
hokiepokedad2 Aug 8, 2026
68de666
fix: an edit could delete a different alarm, and re-apply could destr…
hokiepokedad2 Aug 8, 2026
8861a3a
fix: import bypassed every model rule, areas leaked private names, a …
hokiepokedad2 Aug 8, 2026
f230bc8
fix: quick picks lost track of their alarms, and accepted fields they…
hokiepokedad2 Aug 8, 2026
a757dcf
fix: geofence rename, raid/egg selection, duplicate-producing edits, …
hokiepokedad2 Aug 8, 2026
0922b70
fix: the collision guard refused legitimate edits, leaving alarms une…
hokiepokedad2 Aug 9, 2026
cf84ce0
fix: quick-pick id length, fort-change import, and the geofence renam…
hokiepokedad2 Aug 9, 2026
6519f1f
fix: an Add could take over an existing alarm, and the merge rule now…
hokiepokedad2 Aug 9, 2026
0d85280
fix: lure duplicates, new-profile geography, quick-pick validation, d…
hokiepokedad2 Aug 9, 2026
e31c2cf
docs: write down the three PoracleNG invariants that cost fixes today…
hokiepokedad2 Aug 9, 2026
25f90c2
fix: complete the collision guard's field table, and stop it swallowi…
hokiepokedad2 Aug 9, 2026
8ab7744
fix: bulk radius collapse, blank profiles page, reapply ordering, and…
hokiepokedad2 Aug 9, 2026
58967f0
fix: forgeable rate-limit partition, deleted-session 500s, and four s…
hokiepokedad2 Aug 9, 2026
7492d1f
docs: consolidate the Unreleased changelog into one section per kind …
hokiepokedad2 Aug 9, 2026
ddf4e6c
fix: template take-over, unenforced block, unselected-alarm rewrite, …
hokiepokedad2 Aug 9, 2026
4ac08c3
fix: stale delegate access, aborted bulk delete, unusable saved picks…
hokiepokedad2 Aug 9, 2026
182d696
fix: the collision guard now mirrors PoracleNG's ordering, and blocki…
hokiepokedad2 Aug 9, 2026
73df6c4
fix: bound three inputs that reached the database unchecked (#611, #6…
hokiepokedad2 Aug 9, 2026
d1a63b4
fix: six defects across raids, auth, geofence review and settings (#6…
hokiepokedad2 Aug 9, 2026
8980985
chore: clear the SQLitePCLRaw high-severity advisory in the test proj…
hokiepokedad2 Aug 9, 2026
3273771
docs: record the PoracleNG v2 API review and migration assessment (#623)
hokiepokedad2 Aug 9, 2026
299020d
fix: a token re-issue no longer renews the session or its admin claim…
hokiepokedad2 Aug 9, 2026
85b36ca
fix: end a session properly when a 401 discards it (#625, #627, #628)…
hokiepokedad2 Aug 9, 2026
32e73c3
fix: seven defects across admin settings and quick picks (#629-#634, …
hokiepokedad2 Aug 9, 2026
69de99a
fix: five defects across the alarm lists and areas (#639-#643) (#644)
hokiepokedad2 Aug 9, 2026
87dc9b4
fix: seven geofence and profile defects (#645-#651) (#652)
hokiepokedad2 Aug 9, 2026
7aa2a5a
docs: record why fixes kept causing the next defect, and how to stop …
hokiepokedad2 Aug 9, 2026
737bc34
fix: editing a quick pick no longer drops its zero-valued filters (#6…
hokiepokedad2 Aug 9, 2026
488e2cc
fix: eight regressions introduced by today's own fixes (#656-#663) (#…
hokiepokedad2 Aug 9, 2026
342596b
fix: five regressions from the first regression pass (#665-#669) (#670)
hokiepokedad2 Aug 9, 2026
2af076b
fix: a type change no longer resets a quick pick's clean bits (#671, …
hokiepokedad2 Aug 9, 2026
4bf0230
fix: three more type-agnostic keys survive a quick-pick type change (…
hokiepokedad2 Aug 9, 2026
0267868
chore: save the regression lens as a slash command (#676)
hokiepokedad2 Aug 9, 2026
6fe7c72
fix: the nightly prune was deleting released images, including :lates…
hokiepokedad2 Aug 9, 2026
ca07ca3
docs: bring the documentation back in line with the code before the r…
hokiepokedad2 Aug 9, 2026
5f250d2
docs: refresh the user-menu help screenshot and document SSO logout (…
hokiepokedad2 Aug 9, 2026
9c66cf3
docs: correct how a release actually reaches production (#680)
hokiepokedad2 Aug 9, 2026
d9fb0dc
Merge pull request #681 from PGAN-Dev/develop
hokiepokedad2 Aug 9, 2026
31552a5
docs: cut changelog for v2.14.0 (#682)
poracleweb-net-release[bot] Aug 9, 2026
e072e5e
feat: let deployments set the OAuth callback URL with PUBLIC_URL (#688)
hokiepokedad2 Aug 10, 2026
7366906
deps: bump jsdom in /Applications/Pgan.PoracleWebNet.App/ClientApp (#…
dependabot[bot] Aug 10, 2026
320b2eb
ci: point Dependabot at develop instead of main (#690)
hokiepokedad2 Aug 10, 2026
839accf
Merge remote-tracking branch 'origin/main' into develop
hokiepokedad2 Aug 10, 2026
6f86eab
docs: say where the OAuth callback URL comes from in the setup guides…
hokiepokedad2 Aug 10, 2026
86750ba
fix: unbrand the help screenshots and let them open full size (#696)
hokiepokedad2 Aug 10, 2026
71c0a2b
fix: open the areas map on your selection, not the whole feed (#695)
hokiepokedad2 Aug 10, 2026
e4a9ba1
docs: unbrand the documentation screenshots (#698)
hokiepokedad2 Aug 10, 2026
7e93233
Merge pull request #699 from PGAN-Dev/develop
hokiepokedad2 Aug 10, 2026
44be008
docs: cut changelog for v2.15.0
hokiepokedad2 Aug 10, 2026
395e1f2
Merge pull request #700 from PGAN-Dev/changelog/v2.15.0
poracleweb-net-release[bot] Aug 10, 2026
49c6de4
deps: bump the angular group (#701)
dependabot[bot] Aug 10, 2026
22ae328
Merge pull request #703 from PGAN-Dev/main
hokiepokedad2 Aug 10, 2026
3e0bcfd
ci: stop Dependabot proposing Microsoft.OpenApi 3.x (#704)
hokiepokedad2 Aug 10, 2026
5d3f542
deps: bump @types/leaflet (#705)
dependabot[bot] Aug 10, 2026
7f982d2
fix: OIDC session cleanup never ran on MariaDB (#707) (#708)
hokiepokedad2 Aug 13, 2026
443e6fb
fix: inspecting a blocked user no longer signs the admin out (#709)
hokiepokedad2 Aug 13, 2026
32efce5
Merge pull request #710 from PGAN-Dev/develop
hokiepokedad2 Aug 13, 2026
5cc4494
deps: Bump the dotnet group with 12 updates (#711)
dependabot[bot] Aug 13, 2026
1536057
docs: record the dependency bumps since v2.15.0
hokiepokedad2 Aug 13, 2026
dfa7363
Merge pull request #712 from PGAN-Dev/develop
hokiepokedad2 Aug 13, 2026
e54c283
docs: cut changelog for v2.15.1
hokiepokedad2 Aug 13, 2026
8268ed2
Merge pull request #713 from PGAN-Dev/changelog/v2.15.1
poracleweb-net-release[bot] Aug 13, 2026
cabf012
docs: drop the duplicated dependency block from 2.15.1
hokiepokedad2 Aug 13, 2026
dc02084
Merge pull request #714 from PGAN-Dev/fix/changelog-dedupe
hokiepokedad2 Aug 13, 2026
fa39127
Merge pull request #715 from PGAN-Dev/main
hokiepokedad2 Aug 13, 2026
c963dd9
deps: Bump the test group with 2 updates
dependabot[bot] Aug 17, 2026
e28247e
deps: bump the angular group (#716)
dependabot[bot] Aug 17, 2026
dfdef80
deps: bump the eslint group (#718)
dependabot[bot] Aug 17, 2026
9d76782
Merge pull request #717 from PGAN-Dev/dependabot/nuget/Tests/Pgan.Por…
hokiepokedad2 Aug 18, 2026
1548ad1
fix: skip Discord re-authorization prompt for returning users (#720)
hokiepokedad2 Aug 18, 2026
6f2974c
Merge pull request #721 from PGAN-Dev/develop
hokiepokedad2 Aug 18, 2026
cd96228
docs: clarify PoracleNG is required; PoracleJS not tested (#722) (#723)
hokiepokedad2 Aug 18, 2026
f53ea77
Merge pull request #724 from PGAN-Dev/develop
hokiepokedad2 Aug 18, 2026
76f05da
docs: cut changelog for v2.15.2
hokiepokedad2 Aug 18, 2026
ec73404
Merge pull request #725 from PGAN-Dev/changelog/v2.15.2
poracleweb-net-release[bot] Aug 18, 2026
3c5e69b
docs: remove PoracleJS references from all documentation (#726) (#727)
hokiepokedad2 Aug 18, 2026
9126c92
Merge pull request #728 from PGAN-Dev/develop
hokiepokedad2 Aug 18, 2026
e7ebf94
docs: cut changelog for v2.15.3
hokiepokedad2 Aug 18, 2026
d25bba6
Merge pull request #729 from PGAN-Dev/changelog/v2.15.3
poracleweb-net-release[bot] Aug 18, 2026
e5c19d6
fix: preserve alarm fields PoracleWeb does not model on write (#730) …
hokiepokedad2 Aug 19, 2026
e94e4d7
feat: per-alarm delivery scope, including user-drawn geofences (#732)
hokiepokedad2 Aug 19, 2026
4351412
feat(where): the shared control for an alarm's delivery scope (#733)
hokiepokedad2 Aug 19, 2026
4a2b4a4
feat(where): the remaining nine alarm types, and translations (#734)
hokiepokedad2 Aug 19, 2026
3c66f0c
feat(where): default place for new alarms, and mega PVP (#735)
hokiepokedad2 Aug 19, 2026
6846e07
fix(where): Places belongs in the nav, not the user menu (#736)
hokiepokedad2 Aug 19, 2026
c39156f
fix(where): Places matches the site, and places can be made in place …
hokiepokedad2 Aug 19, 2026
af3441d
refactor(where): Areas and Places are one surface (#738)
hokiepokedad2 Aug 19, 2026
4abf26c
fix(where): cleared pin, map framing, My pin label, alert language (#…
hokiepokedad2 Aug 19, 2026
c9b6b13
feat(where): one scope control, and alert language as flag rows (#740)
hokiepokedad2 Aug 19, 2026
b359fb6
fix(where): edit dialogs use the shared picker, and a usable map (#741)
hokiepokedad2 Aug 19, 2026
4074bba
fix(i18n): real messages instead of raw keys, and 380 translations (#…
hokiepokedad2 Aug 19, 2026
3a33f55
fix(where): quick picks, one dialog size, and a picker that reads its…
hokiepokedad2 Aug 19, 2026
c4c4179
fix(where): stop the Set Location dialog scrolling sideways (#744)
hokiepokedad2 Aug 19, 2026
701c27f
fix(pvp): style the mega evolution fieldset like its sibling (#745)
hokiepokedad2 Aug 19, 2026
f0d1c3c
fix(ui): spacing and overflow, verified in a browser (#746)
hokiepokedad2 Aug 19, 2026
0773816
fix(ui): stop My Geofences and Help overflowing a phone screen (#747)
hokiepokedad2 Aug 19, 2026
d487223
feat(pokemon): store the mega evolution choice, and filter on time le…
hokiepokedad2 Aug 19, 2026
1004255
feat(quests): stardust rewards and minimum amounts (#749)
hokiepokedad2 Aug 19, 2026
adadcf3
fix(ui): give the time-left hint room, and fit five reward tabs (#750)
hokiepokedad2 Aug 19, 2026
dfb53d1
fix(pvp): let the edit dialog reach the mega evolution picker (#751)
hokiepokedad2 Aug 19, 2026
259719d
fix(quests): let the minimum amount and stardust floor be edited (#752)
hokiepokedad2 Aug 19, 2026
da8566b
fix(i18n): translate the Max Battle and Fort Change copy (#753)
hokiepokedad2 Aug 19, 2026
592b55e
feat(forts): watch description changes, and cover all ten types (#754)
hokiepokedad2 Aug 19, 2026
703a84d
chore: sync main's released changelog sections back to develop (#756)
hokiepokedad2 Aug 19, 2026
283d3e0
Merge remote-tracking branch 'origin/main' into chore/merge-main-into…
hokiepokedad2 Aug 19, 2026
d7182cb
Merge pull request #757 from PGAN-Dev/chore/merge-main-into-develop
hokiepokedad2 Aug 19, 2026
a65ffe5
feat(admin): detect the PoracleNG version and refuse to guess (#758)
hokiepokedad2 Aug 19, 2026
f7b15de
fix(admin): put the server card where it can be seen (#759)
hokiepokedad2 Aug 19, 2026
fbfc16a
feat(admin): say when PoracleWeb or PoracleNG is behind (#760)
hokiepokedad2 Aug 19, 2026
9aa59ce
fix(admin): show this site's version on the versions card (#761)
hokiepokedad2 Aug 19, 2026
08c72bf
fix(ui): first-child, not first-of-type, for dialog headings (#762)
hokiepokedad2 Aug 20, 2026
4235178
docs: catch the documentation up with what the site does (#763)
hokiepokedad2 Aug 20, 2026
a2e9f12
chore: drop the mkdocs build output that was committed by mistake (#764)
hokiepokedad2 Aug 20, 2026
fa6c365
docs(geofences): record why the delete is not feature-gated (#765)
hokiepokedad2 Aug 20, 2026
b31c10f
docs: use a generic identity in the screenshots (#766)
hokiepokedad2 Aug 20, 2026
ae50bda
Merge pull request #755 from PGAN-Dev/develop
hokiepokedad2 Aug 20, 2026
dde48b1
docs: cut changelog for v2.16.0
hokiepokedad2 Aug 20, 2026
e7eee95
Merge pull request #767 from PGAN-Dev/changelog/v2.16.0
poracleweb-net-release[bot] Aug 20, 2026
3daed8d
chore: sync the 2.16.0 changelog cut back to develop
hokiepokedad2 Aug 20, 2026
8662c42
Merge pull request #768 from PGAN-Dev/chore/sync-2.16.0-and-fix-claim
hokiepokedad2 Aug 20, 2026
0ad6285
fix: serve Pokemon names, types and forms in the display language
hokiepokedad2 Aug 21, 2026
3f20475
fix: match the lone base form by prefix now that form names are trans…
hokiepokedad2 Aug 21, 2026
4213318
Merge pull request #771 from PGAN-Dev/fix/localized-pokemon-names
hokiepokedad2 Aug 21, 2026
b61c94d
feat: honour Poracle's own disable_* flags as a floor under the site …
hokiepokedad2 Aug 21, 2026
9a5163e
Merge pull request #772 from PGAN-Dev/feat/769-poracle-disable-flags
hokiepokedad2 Aug 21, 2026
3d2c69a
feat: default the display and alert language to Poracle's locale (#770)
hokiepokedad2 Aug 21, 2026
519c4e9
test: pin the signed-out bootstrap path to the anonymous settings end…
hokiepokedad2 Aug 21, 2026
cb73440
Merge pull request #773 from PGAN-Dev/feat/770-poracle-locale-default
hokiepokedad2 Aug 21, 2026
22b1a6f
fix: stop reconciling the alert language on the login page
hokiepokedad2 Aug 21, 2026
400c01d
chore: delete the orphaned language-selector component
hokiepokedad2 Aug 21, 2026
766a211
Merge pull request #776 from PGAN-Dev/fix/775-login-page-language-call
hokiepokedad2 Aug 21, 2026
59c080c
Merge pull request #777 from PGAN-Dev/chore/774-remove-dead-language-…
hokiepokedad2 Aug 21, 2026
c388a76
fix: drop the three admin settings groups that render nothing
hokiepokedad2 Aug 21, 2026
e8ecb19
Merge pull request #779 from PGAN-Dev/fix/empty-admin-settings-groups
hokiepokedad2 Aug 21, 2026
35d9de8
fix: refuse writes to the poracle_locale projection, and stop renderi…
hokiepokedad2 Aug 21, 2026
0ba6f1c
feat: show Poracle's locale read-only beside Allowed UI Languages
hokiepokedad2 Aug 21, 2026
dd393ba
docs: say plainly what Poracle's locale does
hokiepokedad2 Aug 21, 2026
a64527f
Merge pull request #781 from PGAN-Dev/fix/poracle-locale-editable
hokiepokedad2 Aug 21, 2026
340c656
docs: name the project PoracleWeb.NET in the unreleased changelog
hokiepokedad2 Aug 21, 2026
625f63b
docs: state facts on their own terms instead of citing the predecessor
hokiepokedad2 Aug 21, 2026
c0a1711
Merge pull request #782 from PGAN-Dev/docs/name-poracleweb-net
hokiepokedad2 Aug 21, 2026
a93f814
docs: update for localized game data, upstream feature gating and the…
hokiepokedad2 Aug 21, 2026
1f1b074
Merge pull request #783 from PGAN-Dev/docs/update-for-language-and-ga…
hokiepokedad2 Aug 21, 2026
b4721be
feat: a disabled alarm type is read-and-delete, not hidden
hokiepokedad2 Aug 21, 2026
c8fd65e
docs: correct the entries that described a disabled type as hidden
hokiepokedad2 Aug 21, 2026
73f9f05
Merge pull request #784 from PGAN-Dev/feat/read-only-disabled-alarm-t…
hokiepokedad2 Aug 21, 2026
8f07862
fix: quest summary schedules are read-and-delete when quests are off
hokiepokedad2 Aug 21, 2026
89df18b
Merge pull request #785 from PGAN-Dev/fix/summary-schedule-read-and-d…
hokiepokedad2 Aug 21, 2026
84a0085
fix: resolve managed webhooks live in /api/auth/me
hokiepokedad2 Aug 21, 2026
f8add66
Merge pull request #786 from PGAN-Dev/fix/live-managed-webhooks
hokiepokedad2 Aug 21, 2026
f75fd69
fix: address the impersonation banner to whoever is actually looking
hokiepokedad2 Aug 21, 2026
4891591
Merge pull request #787 from PGAN-Dev/fix/impersonation-banner-wording
hokiepokedad2 Aug 21, 2026
b00da3e
docs: write down webhooks and delegation
hokiepokedad2 Aug 21, 2026
b97ed86
Merge pull request #788 from PGAN-Dev/docs/webhooks-and-delegates
hokiepokedad2 Aug 21, 2026
49d5a9f
Merge pull request #789 from PGAN-Dev/develop
hokiepokedad2 Aug 21, 2026
e21e5c4
docs: cut changelog for v2.17.0
hokiepokedad2 Aug 21, 2026
c9c04eb
Merge pull request #790 from PGAN-Dev/changelog/v2.17.0
poracleweb-net-release[bot] Aug 21, 2026
930494e
Merge pull request #791 from PGAN-Dev/main
hokiepokedad2 Aug 21, 2026
87669af
fix: hide a disabled alarm type from the sidebar, keep its dashboard …
hokiepokedad2 Aug 21, 2026
2899e67
fix: a disabled alarm type disappears completely
hokiepokedad2 Aug 21, 2026
1bf4aac
Merge pull request #793 from PGAN-Dev/fix/792-hide-disabled-alarm-nav
hokiepokedad2 Aug 21, 2026
ce55eb6
Merge pull request #794 from PGAN-Dev/develop
hokiepokedad2 Aug 21, 2026
47a1666
docs: cut changelog for v2.17.1
hokiepokedad2 Aug 21, 2026
2f2c58c
Merge pull request #795 from PGAN-Dev/changelog/v2.17.1
poracleweb-net-release[bot] Aug 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
80 changes: 80 additions & 0 deletions .claude/commands/regression-lens.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,80 @@
---
description: Audit recent merges for defects the fixes themselves introduced
argument-hint: "[commit-ish or PR range, e.g. 4bf0230 or 'last 20 hours']"
---

Run a **regression lens** over this repository.

This is not a bug hunt. It audits **the fixes themselves**, asking only what they broke and which
siblings they missed. It exists because roughly one in five defects found in this codebase's audit
sweeps was caused by an earlier fix in the same campaign, and nothing else looks for those.

## Scope

Audit: **$ARGUMENTS**

If that is empty, audit everything merged to `develop` in the last 24 hours (`git log --oneline
--since="24 hours ago"`). Read each diff in full with `git show <sha>`, then read the **current** state
of every file touched — a later commit may already have changed it.

Keep the scope tight. One pass over one batch of fixes finds more than one pass over everything.

## The only two questions

1. **What did this fix break?** Did it tighten or loosen a rule — validation, guard, allowlist, filter,
cache, default, lifetime, error path, order of operations — without accounting for a legitimate case
that depended on the previous behaviour?
2. **Which siblings did it miss?** This codebase has sets of ten (alarm types, list components, edit
dialogs, services, `*Create`/`*Update` DTO pairs) and eleven (locale files). A fix applied to one
member is suspect until the others are checked.

## Calibration — the shapes this keeps finding

Give the auditor these, so it knows what it is looking for:

- **A constraint added, the bad case verified refused, the legitimate cases never enumerated.** A live
resolution locked out users configured elsewhere (#601 → #626). Save-time validation broke seeding,
because two presets carry empty filters on purpose (#604 → #637). An allowlist would have refused
`blanche` and `npc 0`, both live in production.
- **A claim wider than its evidence.** `isAdmin` made live without distinguishing "not an admin" from
"could not ask", so an outage de-admined live sessions (#624 → #656). A comment asserting one key was
the only type-agnostic one, when the repo's own whitelist listed four (#671 → #674).
- **Validation in the wrong place.** Checks added *after* the thing they guard is created, so a refusal
answers 400 and leaves an orphan behind (#647 → #665).
- **One member of a set of ten.** `bulkDelete` hardened, `bulkUpdateDistance` left (#603 → #641). Create
DTO bounded, Update DTO not (#612 → #660).

## Ground rules for the auditor

- Verify against the code. `git show` the diff, then read the current file. Never reason from a commit
message.
- Check any PoracleNG claim against `E:/PGAN/pogogit/PoracleNG`, pinned to the commit production runs —
see the "Keep the PoracleNG Checkout Pinned To What Prod Runs" section of `CLAUDE.md`.
- Read "Fixing Defects Without Causing Them" in `CLAUDE.md` first.
- Before claiming a value should be refused, query production for what currently satisfies the loose
rule. Connection details are in `.env`.
- Do **not** report defects in code the audited commits did not touch. That is a different lens's job.
- Do **not** re-report findings from earlier passes.
- **A clean result is the expected and desired outcome.** Say so plainly and stop. Manufacturing a
marginal finding to appear thorough costs real work, because every finding gets acted on.

Report each finding with the commit that introduced it, the legitimate case now broken (or the sibling
now missed), a demonstrable failure case, and what should happen instead. Then list what was checked
and cleared.

## Run it until it comes back empty

One pass is not enough — its own fixes can introduce the next round. Re-run, scoping each pass to the
previous pass's fixes, until a pass reports nothing.

Observed convergence when this was first run: **8 → 5 → 2 → 1 → 0**. Pass one held a severe defect (an
outage de-admining a live session); pass two another (an orphan profile left behind a 400); by pass four
the only finding was an overclaiming comment. Expect roughly that shape. Stopping at pass one would have
left five defects live.

## Fixing what it finds

Follow `CLAUDE.md`. In particular: give every guard a **legitimate-case-still-passes** test beside the
refusal test, and **revert the fix and confirm the new test goes red** before trusting it. A test written
alongside a fix encodes that fix's own assumptions and passes either way — one spec in this repo was
asserting a broken request shape, so the suite was defending the bug.
2 changes: 1 addition & 1 deletion .editorconfig
Original file line number Diff line number Diff line change
Expand Up @@ -311,7 +311,7 @@ csharp_space_between_empty_square_brackets = false
csharp_space_between_square_brackets = false
# Wrap options
# https://docs.microsoft.com/visualstudio/ide/editorconfig-formatting-conventions#wrap-options
csharp_preserve_single_line_statements = false
csharp_preserve_single_line_statements = true
csharp_preserve_single_line_blocks = false

##########################################
Expand Down
80 changes: 80 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -68,13 +68,62 @@ DISCORD_BOT_TOKEN=your_discord_bot_token
# Forum channel for geofence submission threads (optional)
# DISCORD_GEOFENCE_FORUM_CHANNEL_ID=

# Public URL where users reach this site, no trailing slash (optional).
# Used to link geofence review threads straight to the admin review page.
# The link is omitted when this is unset.
# PUBLIC_URL=https://alerts.example.com

# ═══════════════════════════════════════════════════════════════════════════════
# TELEGRAM (optional)
# ═══════════════════════════════════════════════════════════════════════════════
TELEGRAM_ENABLED=false
# TELEGRAM_BOT_TOKEN=
# TELEGRAM_BOT_USERNAME=

# ═══════════════════════════════════════════════════════════════════════════════
# EXTERNAL SSO / OIDC (optional — delegate login to your own OAuth2/OIDC provider)
# ═══════════════════════════════════════════════════════════════════════════════
# Point PoracleWeb at any OAuth2/OIDC provider (Keycloak, Authentik, Auth0, Okta, …) for SSO.
# The provider's userinfo endpoint must return a claim holding the user's Poracle id
# (a Discord/Telegram id) — set OIDC_IDENTITY_CLAIM to that claim name.
# Enabled is auto-inferred when ClientId + the three URLs are all set; set explicitly to override.
# Replace the example URLs below with your provider's actual endpoints.
# OIDC_ENABLED=true
# OIDC_PROVIDER_NAME=My SSO
# OIDC_AUTHORIZATION_URL=https://sso.example.com/authorize
# OIDC_TOKEN_URL=https://sso.example.com/oauth/token
# OIDC_USERINFO_URL=https://sso.example.com/oauth/userinfo
# OIDC_CLIENT_ID=your_oidc_client_id
# OIDC_CLIENT_SECRET=your_oidc_client_secret
# OIDC_SCOPES=openid profile email
# OIDC_IDENTITY_CLAIM=discord_id
# OIDC_USERNAME_CLAIM=preferred_username
# OIDC_AVATAR_CLAIM=picture
# OIDC_IDENTITY_TYPE=discord:user
# OIDC_USE_PKCE=true
#
# --- Refresh tokens (optional, opt-in) — silent session renewal + revocation propagation ---
# When OFF (default) the provider's tokens are discarded after login and the internal session
# JWT lives its full Jwt:ExpirationMinutes (24h); users re-auth at expiry. When ON, PoracleWeb
# brokers the provider's refresh token SERVER-SIDE (encrypted at rest, never sent to the browser),
# silently renews the session, and propagates provider-side disable/logout. Requires the provider
# to actually issue a refresh token. Fully provider-agnostic — see docs/configuration/oidc-refresh-tokens.md.
# OIDC_USE_REFRESH_TOKENS=true
# OIDC_ACCESS_TOKEN_MINUTES=30 # internal JWT lifetime for refresh-backed OIDC sessions only
# OIDC_REFRESH_TOKEN_LIFETIME_DAYS=30 # PoracleWeb-side absolute session cap before a real re-login
# OIDC_SESSION_REVOKED_RETENTION_DAYS=2 # how long revoked/rotated session rows are kept (replay detection) before cleanup deletes them
# OIDC_OFFLINE_ACCESS_SCOPE=offline_access # appended to the authorize scope so the provider issues an RT; empty to disable
# OIDC_TOKEN_AUTH_METHOD=client_secret_post # client_secret_post (body) | client_secret_basic (HTTP Basic)
#
# Per-provider notes (token auth method / offline scope / identity claim):
# PogoAlerts : OIDC_OFFLINE_ACCESS_SCOPE=offline_access OIDC_TOKEN_AUTH_METHOD=client_secret_post OIDC_IDENTITY_CLAIM=discord_id
# Keycloak : OIDC_OFFLINE_ACCESS_SCOPE=offline_access OIDC_TOKEN_AUTH_METHOD=client_secret_basic OIDC_IDENTITY_CLAIM=sub
# Authentik : OIDC_OFFLINE_ACCESS_SCOPE=offline_access OIDC_TOKEN_AUTH_METHOD=client_secret_post OIDC_IDENTITY_CLAIM=sub
# Auth0 : OIDC_OFFLINE_ACCESS_SCOPE=offline_access OIDC_TOKEN_AUTH_METHOD=client_secret_post OIDC_IDENTITY_CLAIM=sub
# Okta : OIDC_OFFLINE_ACCESS_SCOPE=offline_access OIDC_TOKEN_AUTH_METHOD=client_secret_basic OIDC_IDENTITY_CLAIM=sub
# Azure/Entra: OIDC_OFFLINE_ACCESS_SCOPE=offline_access OIDC_TOKEN_AUTH_METHOD=client_secret_post OIDC_IDENTITY_CLAIM=sub
# Google : OIDC_OFFLINE_ACCESS_SCOPE= (empty) and append ?access_type=offline to OIDC_AUTHORIZATION_URL

# ═══════════════════════════════════════════════════════════════════════════════
# PORACLE API — your running PoracleNG instance
# ═══════════════════════════════════════════════════════════════════════════════
Expand All @@ -101,6 +150,37 @@ KOJI_PROJECT_NAME=YourProjectName
# Set to the URL you access PoracleWeb.NET from. Not required in development mode.
# CORS_ORIGIN=http://192.168.1.50:8082

# ═══════════════════════════════════════════════════════════════════════════════
# PUBLIC URL — the address users reach this instance on
# ═══════════════════════════════════════════════════════════════════════════════
# Sets the OAuth callback URLs (Discord and OIDC) outright instead of guessing them
# from each incoming request. Set this if sign-in fails with an invalid redirect_uri,
# or just set it anyway — it is the one value your identity provider must also have
# registered, so stating it here keeps the two in step.
#
# Origin only: no trailing path, no query. A bad value stops the app at startup.
# Leave it blank to keep the old behaviour of following the incoming request, which
# is correct for a direct-exposed instance or one whose proxy is declared below.
# PUBLIC_URL=https://poracle.example.com

# ═══════════════════════════════════════════════════════════════════════════════
# REVERSE PROXY — required if anything sits in front of PoracleWeb.NET
# ═══════════════════════════════════════════════════════════════════════════════
# Nginx, Caddy, Traefik, Cloudflare Tunnel and friends terminate TLS themselves and
# announce the original request with X-Forwarded-For and X-Forwarded-Proto. Those
# headers are only believed from addresses named here — a forgeable header would let
# any caller hand itself a fresh rate-limit allowance on the sign-in endpoints.
#
# Leave both blank only if the app is exposed directly. Behind an undeclared proxy the
# app sees every request as plain HTTP from the proxy's address, which means all users
# share one rate-limit bucket AND OAuth callback URLs are built as http:// — Discord
# and OIDC providers then reject the sign-in with "Invalid redirect_uri". (PUBLIC_URL
# above fixes the sign-in on its own; only these settings fix the rate-limit bucket.)
#
# Comma-separated. Use the address the proxy connects FROM, as the container sees it.
# PROXY_KNOWN_PROXIES=10.0.3.20
# PROXY_KNOWN_NETWORKS=172.18.0.0/16,10.0.0.0/8

# ═══════════════════════════════════════════════════════════════════════════════
# PORACLE CONFIG (optional — for DTS template previews)
# ═══════════════════════════════════════════════════════════════════════════════
Expand Down
55 changes: 47 additions & 8 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@ updates:
# .NET (backend)
- package-ecosystem: nuget
directory: /
# main only moves when a release is merged (see CLAUDE.md), so bumps land on
# develop first and reach released code with the release that carries them.
target-branch: develop
schedule:
interval: weekly
day: monday
Expand All @@ -13,19 +16,46 @@ updates:
- dependencies
commit-message:
prefix: deps
ignore:
# Microsoft.OpenApi 3.x cannot be used while Microsoft.AspNetCore.OpenApi targets the 2.x
# object model. Its source generator assigns IOpenApiMediaType.Example, which became
# read-only in 3.0, so the build fails in generated code no edit here can reach:
# OpenApiXmlCommentSupport.generated.cs: error CS0200: Property or indexer
# IOpenApiMediaType.Example cannot be assigned to -- it is read only
#
# The direct reference exists only to clear GHSA-v5pm-xwqc-g5wc, which
# Microsoft.AspNetCore.OpenApi 10.0.10 reintroduces by pinning 2.0.0 transitively (see the
# comment in Pgan.PoracleWebNet.Api.csproj). Minor and patch updates inside 2.x still come
# through, so a later advisory is not masked.
#
# Drop this once Microsoft.AspNetCore.OpenApi ships a release built against 3.x -- at which
# point the direct reference should go too. See #702.
- dependency-name: Microsoft.OpenApi
update-types:
- version-update:semver-major
groups:
microsoft:
# One group for the whole .NET platform. These packages ship as a single versioned set:
# Microsoft.EntityFrameworkCore 10.0.x transitively requires Microsoft.Extensions.* at
# >= the same 10.0.x, so any grouping that splits them produces a PR that cannot restore.
#
# The previous `microsoft` / `aspnetcore` / `ef-core` split did exactly that, and the
# patterns overlapped besides -- `Microsoft.*` is a superset of both `Microsoft.AspNetCore.*`
# and `Microsoft.EntityFrameworkCore*`. It yielded three PRs carving up one package set,
# of which only the widest could build. See #366: EF Core went to 10.0.10 while
# Microsoft.Extensions.* stayed at 10.0.8, giving `NU1605: Detected package downgrade`
# (a hard error under the .NET 10 SDK, not a warning).
#
# MySql.EntityFrameworkCore belongs here too: it version-locks to
# Microsoft.EntityFrameworkCore.Relational and drags the same Extensions floor with it.
dotnet:
patterns:
- 'Microsoft.*'
- 'System.*'
aspnetcore:
patterns:
- 'Microsoft.AspNetCore.*'
- 'Microsoft.Extensions.*'
ef-core:
patterns:
- 'Microsoft.EntityFrameworkCore*'
- 'MySql.EntityFrameworkCore'
exclude-patterns:
# Test-only and versioned independently of the platform (18.x, not 10.0.x).
# Kept in the `test` group so a runtime bump and a test-tooling bump stay separable.
- 'Microsoft.NET.Test.Sdk'
test:
patterns:
- 'xunit*'
Expand All @@ -36,6 +66,9 @@ updates:
# Angular frontend
- package-ecosystem: npm
directory: /Applications/Pgan.PoracleWebNet.App/ClientApp
# main only moves when a release is merged (see CLAUDE.md), so bumps land on
# develop first and reach released code with the release that carries them.
target-branch: develop
schedule:
interval: weekly
day: monday
Expand Down Expand Up @@ -91,6 +124,9 @@ updates:
# GitHub Actions
- package-ecosystem: github-actions
directory: /
# main only moves when a release is merged (see CLAUDE.md), so bumps land on
# develop first and reach released code with the release that carries them.
target-branch: develop
schedule:
interval: weekly
day: monday
Expand All @@ -106,6 +142,9 @@ updates:
# Dockerfile base images
- package-ecosystem: docker
directory: /
# main only moves when a release is merged (see CLAUDE.md), so bumps land on
# develop first and reach released code with the release that carries them.
target-branch: develop
schedule:
interval: weekly
day: monday
Expand Down
Loading
Loading