BookStackApp/BookStack
49.2
Weak · 5 August 2026
189.6k
lines of production code
TypeScript
with PHP, JavaScript
3
measurements over time
What this system is
This system is a comprehensive, self-hosted knowledge base and documentation platform designed for creating, organizing, and sharing structured content such as books, chapters, and pages. It provides a robust suite of features including a modernized WYSIWYG and Markdown editors, advanced user authentication with MFA and SSO support, and a flexible permission system. The application also supports content versioning, activity tracking, and external integrations via webhooks and a RESTful API.
How it got here
2015–2018 — Modernization and architectural refactoring
51 changes.
The project underwent a comprehensive modernization, migrating from the legacy 'Oxbow' namespace to 'BookStack' and upgrading to a modern PHP and JavaScript stack. This period focused on refactoring the codebase's architecture, including the HTTP layer, exception handling, and entity repositories, while simultaneously expanding test coverage and implementing a new role-based permission system.
2019–2021 — Modernization and UI overhaul
48 changes.
This period focused on modernizing the application's architecture and user interface, introducing a component-based frontend, a modular Blade template structure, and a new theme system. It also expanded API capabilities with documentation and token management, while significantly increasing test coverage across the codebase.
2022–2024 — Editor and Activity Overhaul
65 changes.
This period focused on replacing the WYSIWYG editor with a modern Lexical-based implementation and introducing a comprehensive activity tracking and notification system. The work also included significant refactoring of authentication, search, and export/import functionalities to improve modularity and testability.
2025–2026 — Editor and sorting features
13 changes.
This period focused on introducing new content organization and editing capabilities, specifically a flexible book sorting system and significant enhancements to the Markdown and WYSIWYG editors. The work included building pluggable input backends, adding UI decorators for diagrams and mentions, and expanding test coverage for search, themes, and utility functions.
Features
Add OpenSearch XML endpoint and refactor robots.txt handling
A new OpenSearch description XML endpoint has been added at /opensearch.xml, providing a standard XML feed for search engine integration, including translatable descriptions and image icons. Additionally, the robots.txt file has been moved to resources/views/misc/robots.blade.php and now conditionally controls whether all paths are disallowed based on the $allowRobots variable.
resources/views/misc · high confidence
Added API documentation and user API token management
Users can now view automatically generated documentation for the API endpoints via a new web interface. Additionally, users can create, edit, and delete API tokens through the My Account settings page, with the system handling token generation, validation, and activity logging.
app/Api · high confidence
Added API documentation page with interactive navigation
A new Blade view at resources/views/api-docs/index.blade.php introduces a dedicated API documentation page. It features a sticky sidebar for navigation, including a 'Getting Started' section with links to Authentication, Request Format, Listing Endpoints, Error Handling, Rate Limits, and Content Security. The main content area dynamically renders sections for each API model and its endpoints, providing a structured way to browse and understand the API.
resources/views/api-docs · high confidence
Added Arabic language support
The application now includes a complete set of Arabic translations for all user-facing text, including activity logs, authentication messages, common interface elements, and error states, enabling users to interact with the system in Arabic.
lang · high confidence
Added Docker-based database testing suite
A new automated testing environment has been introduced in the dev/docker/db-testing directory. This includes a Dockerfile, a run.sh script, and a readme, which together allow developers to run BookStack's test suite against multiple MySQL and MariaDB versions. The setup builds a containerized environment that cycles through each supported database version, performing migrations, seeding, and running the full PHP test suite to ensure compatibility.
dev/docker/db-testing · high confidence
Added MFA setup and verification views
The application now includes the necessary Blade templates to support multi-factor authentication (MFA) for users. This includes a central setup page where users can choose between TOTP and backup codes, a TOTP generation and verification page that displays a QR code and secret key, a backup code generation page that allows users to download their recovery codes, and a verification page that prompts users to enter a code from their chosen method. These views enable the complete user flow for configuring and using MFA.
resources/views/mfa · high confidence
Added WYSIWYG editor API for content manipulation and UI control
Introduced a new JavaScript API for the WYSIWYG editor, enabling programmatic control over editor content and the toolbar. The \EditorApi\ class exposes a \content\ module with an \insertHtml()\ method that supports inserting HTML at the 'start', 'end', or current 'selection' within the editor. Additionally, a \ui\ module provides methods to create toolbar buttons (\createButton()\) and access the main editor toolbar (\getMainToolbar()\), allowing developers to programmatically manage toolbar sections and button states. Comprehensive test coverage has been added for both the content and UI modules to ensure reliability.
resources/js/wysiwyg/api · high confidence
Added chapter management views for copy, create, delete, edit, move, permissions, references, and show
Introduced new Blade templates for chapter operations, enabling users to copy, create, delete, edit, move, and manage permissions for chapters. The show view displays chapter content and page lists, while the references view lists backlinks. These views integrate with the existing layout system and include breadcrumbs, forms, and sidebar components for a consistent user experience.
resources/views/chapters · high confidence
Added database factories for Uploads models
New factory classes have been introduced for the Uploads domain, specifically for the Attachment and Image models. These factories define default states for generating test data, including fields such as name, path, extension, and associated user or page references, enabling more convenient database seeding and testing for upload-related entities.
database/factories/Uploads · high confidence
Added database factories for entity models
New Laravel model factories have been introduced for the Book, Bookshelf, Chapter, Deletion, Page, PageRevision, and SlugHistory entities. These factories provide standardized, test-friendly ways to generate sample data for these models, supporting faster and more consistent database seeding during development and testing.
database/factories/Entities · high confidence
Added documentation for Blade view structure and removed legacy base template
A new readme.md file has been added to the views directory to document the conventions for organizing Blade templates, explaining how views are structured by domain area and how they can be overridden via the visual theme system. Additionally, the legacy base.blade.php template has been removed, indicating a shift away from the previous template inheritance structure.
resources/views · high confidence
Added dummy content and large content database seeders
New seeders (DummyContentSeeder, LargeContentSeeder) were added to the database/seeders directory to populate the application with sample data, including users, roles, books, chapters, pages, and API tokens. The DatabaseSeeder class was also moved from database/seeds to database/seeders and updated to use the new namespace.
database/seeders · high confidence
Added facades for Activity and Theme services
New facades have been introduced for the Activity and Theme services, allowing them to be accessed via static methods in templates and controllers. The Activity facade wraps the ActivityLogger, while the Theme facade provides access to the ThemeService, supporting the new backend theme system and activity logging features.
app/Facades · high confidence
Added webhook configuration form, list item, and format example view
Users can now configure webhooks via a new form that includes an active toggle, name, endpoint, and timeout settings, alongside a list item view displaying webhook status and tracked events, and a format example showing the JSON structure of webhook payloads.
resources/views/settings/webhooks/parts · medium confidence
Added webhook management interface
A new interface for managing webhooks has been added to the settings section. Users can now view a list of webhooks with search and sort capabilities, create new webhooks, edit existing ones, and delete them. The interface includes a list view, create and edit forms, and a delete confirmation page.
resources/views/settings/webhooks · high confidence
Adds new UI helper modules for dropdowns, mouse drag tracking, node resizing, and table interactions
The WYSIWYG editor now includes dedicated helper modules to manage user interface interactions. A new dropdown manager handles menu positioning and RTL support, while a mouse drag tracker abstracts complex pointer event handling. The editor now supports resizing images and media nodes via a dedicated node resizer, and provides visual markers and logic for resizing table columns and rows. Additionally, table selection handling and task list checkbox interactions are now managed by specialized handlers, enabling more robust editing behaviors for these content types.
resources/js/wysiwyg/ui/framework/helpers · high confidence
Automated license generation scripts for PHP and JS dependencies
Added new PHP scripts (gen-php-licenses, gen-js-licenses) and a shared utility (gen-licenses-shared.php) to automatically generate license and copyright information for all PHP and JavaScript dependencies. The scripts parse composer.lock and node\_modules to produce structured license files (php-library-licenses.txt, js-library-licenses.txt), streamlining the process of maintaining up-to-date attribution and licensing data for open-source components.
dev/licensing · high confidence
Centralized app metadata and homepage logic
The application's homepage rendering and core metadata endpoints have been consolidated into the app/App directory. A new System API endpoint now exposes instance details such as the version number, instance ID, and logo. The homepage controller has been refactored to handle different homepage types (default, books, shelves, specific page) using a new HomeController, while helper functions for user and permission checks have been moved to a shared helpers file. Additionally, a PWA manifest builder and versioning utility have been introduced to manage static assets and application metadata.
app/App · high confidence
Centralized configuration files for API, authentication, and application settings
Configuration options for the API (item counts, rate limits), authentication methods (standard, LDAP, SAML2, OIDC), and core application settings (cache, database, logging, mail, exports, filesystems, hashing, queue, and debug tools) are now managed through dedicated config files in the app/Config directory. These files expose environment-variable-driven settings that allow administrators to customize behavior, such as API throttling, authentication provider configurations, and logging channels, without modifying core code.
app/Config · high confidence
Database schema expansion and permission system overhaul
The database schema was significantly expanded to support new features and a more granular permission model. New tables were added for comments, search indexing, page revisions, and activity tracking. The migration also introduces a refined role and permissions system, including a public role for unauthenticated access, and updates existing tables to track user ownership (created\_by/updated\_by) and support markdown content. Additionally, the schema now supports entity restrictions, view counts, and user avatars, while also cleaning up older full-text search indexes in favor of a dedicated search\_terms table.
database/migrations · high confidence
Enhanced editor interaction with auto-links, drag-and-drop, and keyboard shortcuts
The WYSIWYG editor now supports automatic link detection when typing or pressing enter/space, handles drag-and-drop of images and HTML content, and provides a comprehensive set of keyboard shortcuts for formatting (bold, italic, headers, lists) and navigation. Additionally, it includes improved selection handling, mention support, and mouse click behavior for inserting new paragraphs.
resources/js/wysiwyg/services · high confidence
Expanded WYSIWYG editor capabilities with new utility modules
The WYSIWYG editor now includes a comprehensive set of utility functions to support advanced editing features. This includes robust handling for lists (nesting, unnesting, and indentation), table operations (copy/paste for rows and columns, cell selection, and caption support), and diagram integration (DrawIO). The changes also introduce helper functions for HTML-to-Editor content conversion, link and image management, and RTL (right-to-left) layout support, all backed by new unit tests.
resources/js/wysiwyg/utils · high confidence
Expanded WYSIWYG editor toolbar with new formatting, layout, and table controls
The WYSIWYG editor toolbar now includes a comprehensive set of new buttons for text alignment and text direction (left, center, right, justify, LTR/RTL). Users can apply block-level formatting such as headings (H2-H5), callouts (info, danger, warning, success), blockquotes, and paragraphs. Inline text formatting options include bold, italic, underline, strikethrough, superscript, subscript, code, and color pickers for text and highlights. The toolbar also supports list indentation, image and media insertion, diagram integration, and extensive table management (insert/delete rows and columns, merge cells, copy/paste rows and columns, and property forms).
resources/js/wysiwyg/ui/defaults/buttons · high confidence
Introduce ZIP-based import and export functionality
Added a new ZIP-based import and export system for Books, Chapters, and Pages. The \ZipExportBuilder\ and \ZipExportFiles\ classes handle the creation of ZIP archives containing entity data, references, and associated files (attachments and images). Conversely, \ZipImportRunner\ and \ZipExportReader\ manage the validation, parsing, and insertion of these archives into the application. The system supports cross-referencing between entities and files, ensuring that links and media are correctly mapped during import.
app/Exports/ZipExports · high confidence
Introduce activity tracking, comment system, and webhook dispatching
Added new classes in the Activity namespace to support activity logging, comment management, and webhook dispatching. ActivityQueries provides methods to retrieve the latest activity, entity-specific activity, and user-specific activity, including filtering for similar items. ActivityType defines constants for various activity types (e.g., page, chapter, book, comment, user, webhook). CommentRepo handles CRUD operations for comments, including creation, update, archive, unarchive, and delete, with validation and activity logging. DispatchWebhookJob handles asynchronous webhook dispatching, including URL validation and HTTP request handling. WebhooksAllPaginatedAndSorted provides paginated and sorted listing of webhooks. TagRepo manages tag operations, including listing with totals, suggestions, and saving tags to entities. WatchLevels defines constants for notification watch levels (ignore, new, updates, comments) and provides utility methods for conversion and filtering based on entity type.
app/Activity · high confidence
Introduce backend theme system with module support and extensible events
A new backend theme system has been introduced, enabling users to extend BookStack's functionality through custom themes and modules. This includes a \ThemeService\ to manage theme state and dispatch events, a \ThemeModule\ class to represent individual theme modules, and a \ThemeModuleManager\ to handle loading and extraction of modules from ZIP files. The system supports registering custom HTML head content, serving public theme files, and injecting views before or after existing templates. Additionally, a comprehensive set of theme events (e.g., \ACTivity\_LOGGED\, \AUTH\_LOGIN\, \PAGE\_CONTENT\_POST\_RENDER\) allows for deep customization of application behavior.
app/Theming · high confidence
Introduce extensible model resolvers for cross-linking
A new \CrossLinkModelResolver\ interface and a set of concrete implementations (for attachments, images, books, bookshelves, chapters, and pages) are added to \app/References/ModelResolvers\. Each resolver parses a specific URL pattern to locate and return the corresponding model instance, enabling the system to resolve various internal and external links to their underlying data objects.
app/References/ModelResolvers · high confidence
Introduce pluggable markdown editor input implementations
The markdown editor now supports interchangeable input backends via a new \MarkdownEditorInput\ interface. This change adds a CodeMirror 6 implementation (\codemirror.ts\) and a native textarea implementation (\textarea.ts\) that includes custom undo/redo history management. Users can now switch between these input types, which standardizes how the editor handles text selection, line iteration, and event dispatching.
resources/js/markdown/inputs · high confidence
Introduced EntityProvider and BreadcrumbsViewComposer for entity navigation
Added the EntityProvider class to centralize access to core entity models (Book, Bookshelf, Chapter, Page, and PageRevision) and provide a unified way to retrieve them by type. Additionally, a new BreadcrumbsViewComposer was introduced to automatically inject the current book's shelf context into the breadcrumbs view data, improving navigation context for book-related pages.
app/Entities · high confidence
Introduced User, Role, and ownership tracking models
Added new Eloquent models for User and Role, including relationship definitions for roles, permissions, and ownership tracking (created\_by/updated\_by). The User model now implements interfaces for sluggable and loggable behavior, while the Role model manages permission associations. A new HasCreatorAndUpdater trait and OwnableInterface were introduced to standardize ownership tracking across models.
app/Users/Models · high confidence
Introduced UserRepo class to centralize user data access and operations
Added a new UserRepo class in the app/Users directory to handle user-related database queries and business logic. This includes methods for creating, updating, and deleting users, as well as retrieving users by email, ID, or slug. The implementation integrates with existing services like UserInviteService and SlugGenerator, and manages user-related activities and avatar cleanup.
app/Users · high confidence
Introduced WYSIWYG editor UI framework and context
Added a new UI layer for the WYSIWYG editor, establishing a central context object that manages the editor's DOM structure, handles text direction and dark mode styling, and provides translation and error reporting capabilities through a new EditorUIManager.
resources/js/wysiwyg/ui · high confidence
Introduced a new editable role management system
Users can now create, edit, and delete roles through a dedicated settings interface. The update adds new Blade templates for listing, creating, editing, and deleting roles, including a confirmation flow for deletion that handles user migration. The role index page includes search, sorting, and pagination, while the edit view allows copying a role and displays a list of users assigned to it.
resources/views/settings/roles · high confidence
Introduced new ExportFormatter and Import handling for PDF and ZIP exports/imports
The application now uses a dedicated ExportFormatter class to handle the conversion of pages, chapters, and books into self-contained HTML and PDF formats, supporting multiple PDF generation engines (Dompdf, Wkhtmltopdf, and custom commands) with improved font loading and temporary file cleanup. Additionally, a new Import model and repository were added to manage ZIP-based imports, including upload handling, validation, and the core import execution logic.
app/Exports · medium confidence
Introduced new WYSIWYG UI framework for editor components
The WYSIWYG editor now uses a new internal UI framework that provides reusable components for buttons, forms, modals, and toolbars. This introduces a structured way to build editor UI elements, including support for form fields, modal dialogs, and context-aware toolbars. Users will see improved consistency in editor interactions, such as form-based modals for editing and more responsive toolbar behavior.
resources/js/wysiwyg/ui/framework · high confidence
Introduced new activity and notification tools
Added a suite of new classes in the Activity namespace to support activity logging, comment threading, entity watching, and webhook formatting. The new tools include ActivityLogger for recording and dispatching activity events, CommentTree and CommentTreeNode for managing nested comment structures, EntityWatchers for managing user subscriptions to entity updates, and WebhookFormatter for structuring webhook payloads. These changes enable the system to log activities, manage comment threads, handle user notifications, and format data for external webhooks.
app/Activity/Tools · high confidence
Introduced new entity tools for content, cloning, and permissions
Added a suite of new classes in app/Entities/Tools to handle specific entity responsibilities. This includes PageContent for managing page HTML and base64 image extraction, Cloner for duplicating pages, chapters, and books with reference updates, and HierarchyTransformer for converting chapters to books and books to shelves. Additional tools were added for managing entity covers, default templates, HTML descriptions, and mixed entity loading. The PageIncludeParser and related classes enable a new system for parsing and rendering nested page includes. These changes support the new cloning capabilities, improved content filtering, and the new include tag parser.
app/Entities/Tools · high confidence
Introduction of a centralized notification dispatch system
A new NotificationManager class has been added to the application to centralize the dispatching of activity-based notifications. This manager registers specific handlers for page creation, page updates, and comment creation/updates, routing activity events to the appropriate notification logic.
app/Activity/Notifications · high confidence
Major overhaul of the TinyMCE editor with new plugins and improved table handling
The WYSIWYG editor has been significantly refactored, introducing several new capabilities and improvements. Users can now insert and edit code blocks, create diagrams using Draw.io, and utilize collapsible details blocks. The update also adds a dedicated 'About' dialog, a custom horizontal rule, and enhanced task list functionality with checkbox support. Additionally, table editing has been improved with new tools to clear formatting and resize cells, while drag-and-drop and paste handling have been rewritten to better support image uploads and template insertion.
resources/js/wysiwyg-tinymce · high confidence
Migrated the WYSIWYG editor to the Lexical framework
The existing WYSIWYG editor has been replaced with the Lexical framework. This change introduces a new, modern architecture for handling rich text editing, including improved support for complex content types like tables, lists, and media, as well as better handling of selection, clipboard operations, and keyboard events. Users will experience more stable and consistent editing behavior, particularly when dealing with nested lists, table captions, and media resizing.
resources/js/wysiwyg/lexical · high confidence
Modernizes development environment and tooling configuration
The project has replaced the legacy Gulp build system with a modern TypeScript and Jest-based testing infrastructure, introducing a new \jest.config.ts\ and \tsconfig.json\ for the frontend. Development is now supported via a \docker-compose.yml\ setup using MySQL 8.4 and Node 22. Configuration is standardized through a new \.env.example.complete\ file that documents all available environment variables, while \.env.example\ is simplified to core settings. Additionally, the repository has migrated from GitHub to Codeberg, updated its license year to 2026, and updated the \phpstan.neon.dist\ to target PHP 8.2–8.5.
(repo-wide) · high confidence
New API and internal classes for managing content-level permissions
A new \ContentPermissionApiController\ is introduced to expose content-level permission management via the API, allowing users to read and update permission overrides for pages, books, chapters, and bookshelves. This change is supported by new internal classes including \EntityPermissionEvaluator\ and \MassEntityPermissionEvaluator\ for evaluating entity permissions, \JointPermissionBuilder\ for managing pre-computed permission tables, and new Eloquent models (\EntityPermission\, \JointPermission\, \RolePermission\) to support the updated permission system.
app/Permissions · high confidence
New API and web route definitions for all major entities
The application now exposes a comprehensive RESTful API and structured web routes for all core entities, including pages, books, chapters, and shelves. This change introduces endpoints for creating, reading, updating, and deleting these entities, as well as specialized actions like exporting to various formats (HTML, PDF, Markdown, ZIP) and managing permissions. The web routes also support user profile access, image and attachment management, comment handling, and search functionality, providing a complete interface for interacting with the system's content and metadata.
routes · high confidence
New My Account section for user self-management
Users can now manage their profile, authentication settings, notification preferences, and keyboard shortcuts from a dedicated 'My Account' area. This includes updating personal details and avatars, changing passwords, managing multi-factor authentication and social account connections, configuring notification triggers, and customizing interface shortcuts.
resources/views/users/account · high confidence
New RESTful API endpoints for Books, Shelves, Chapters, and Pages
The application now exposes dedicated API controllers for Books, Bookshelves, Chapters, and Pages, enabling programmatic management of these entities. Users can now create, read, update, and delete these items via the API, with support for sorting, filtering, and pagination. The API responses include detailed metadata, such as cover images, descriptions, and hierarchical content structures. Additionally, the API supports moving chapters and pages between parents, managing comments, and accessing page revisions. This provides a comprehensive interface for integrating with external systems or building custom clients.
app/Entities/Controllers · high confidence
New Settings sub-pages for Audit Log, Maintenance, and Layout
Added new Blade templates for the Settings area: a dedicated Audit Log view that allows filtering activities by user, event type, date range, and IP address; a Maintenance page featuring tools for clearing the recycle bin, cleaning up unused images, sending test emails, and regenerating references; and a shared layout template that structures the Settings navigation and sidebar. These changes introduce new user-facing interfaces for reviewing system activity and performing administrative maintenance tasks.
resources/views/settings · high confidence
New WYSIWYG UI framework components for toolbar and form fields
The WYSIWYG editor's UI framework has been expanded with new components to support a richer toolbar and form interactions. A color picker and color field allow users to select and apply colors, while a table creator provides a grid-based interface for inserting tables with custom column widths. The toolbar now includes a format menu that dynamically displays the active format, buttons with dropdown menus for extended options, and an overflow container to manage crowded toolbars. Additionally, a link field with header autocompletion and an external content loader have been introduced to enhance content editing capabilities.
resources/js/wysiwyg/ui/framework/blocks · high confidence
New ZIP import and export templates for books, chapters, and pages
The application now provides dedicated Blade templates for exporting books, chapters, and pages, rendering their titles, HTML descriptions, and hierarchical contents. Additionally, a new import workflow has been introduced, featuring a file upload interface for .zip files with validation error display, a pending imports list, and a detailed import review page that allows users to select parent entities and run or delete imports.
resources/views/exports · high confidence
New activity management and integration endpoints
This update introduces several new controllers in the Activity module, enabling new user-facing capabilities. A new Audit Log API and UI allow administrators to view system activity logs. A comprehensive Comment API and UI provide full CRUD operations for page comments, including tree structures and archiving. The Favourite feature is expanded with endpoints to list, add, and remove items from user favourites. A new Watch controller allows users to configure notification levels for entities. Additionally, a Webhook controller enables administrators to create, edit, and delete webhooks for external integrations.
app/Activity/Controllers · high confidence
New activity tracking and management models
The application introduces a comprehensive set of new Eloquent models to support activity tracking, comments, favorites, tags, views, and webhooks. This includes the Activity model for logging changes, Comment for user discussions, Favourite and Favouritable for bookmarking content, Tag for content organization, View for tracking content popularity, Watch for subscription management, and Webhook/WebhookTrackedEvent for external integrations. These models provide the backend structure for these new features.
app/Activity/Models · high confidence
New and updated Artisan commands for system maintenance and content management
The application introduces a suite of new Artisan commands to assist with system maintenance and content management. Administrators can now manage user avatars (RefreshAvatar), clear activity logs (ClearActivity), and manage user accounts including creation (CreateAdmin), deletion (DeleteUsers), and MFA reset (ResetMfa). Content and system state can be regenerated or updated via commands for permissions (RegeneratePermissions), references (RegenerateReferences), and search indexing (RegenerateSearch). Additional commands allow for bulk URL updates (UpdateUrl), database encoding upgrades (UpgradeDatabaseEncoding), and shelf permission cascading (CopyShelfPermissions). The suite also includes commands for cleaning up unused images (CleanupImages), clearing page revisions (ClearRevisions) and view counts (ClearViews), assigning sort rules to books (AssignSortRule), and installing theme modules (InstallModule).
app/Console/Commands · high confidence
New auth views for password reset, email confirmation, and social login registration
Added new Blade templates for the user invitation password reset flow (invite-set-password), email confirmation states (register-confirm, register-confirm-accept, register-confirm-awaiting), and the main registration page (register) which now supports social account linking. The login page (login) and login initiation page (login-initiate) have also been introduced to handle standard and auto-initiated login flows, including social authentication buttons.
resources/views/auth · high confidence
New book sorting and sort rule management
Introduced a new sorting system for books and pages, allowing users to define and apply 'sort rules' that automatically order content by name, date, or chapter position. The change adds a dedicated \app/Sorting\ directory containing controllers (\BookSortController\, \SortRuleController\) and classes (\BookSorter\, \SortRule\, \SortRuleOperation\) that handle the logic for manual reordering and automatic sorting based on user-defined rules. This includes the ability to create, edit, and delete sort rules, as well as apply them to books to automatically sort their contents.
app/Sorting · high confidence
New common UI components for activity feeds, sorting, and status indicators
The application now includes a set of new reusable Blade templates in the common views directory, providing standardized UI elements for the user interface. This includes components for rendering activity items and lists, a reusable confirm-dialog popup, a dark-mode toggle, paginated and non-paginated detailed listing layouts, a loading icon, a list sorting control with accessibility attributes, and a status indicator. These templates establish a consistent visual and functional baseline for these features across the application.
resources/views/common · high confidence
New component-based frontend architecture
The frontend JavaScript codebase has been refactored from a mix of Vue.js and ad-hoc scripts into a unified, component-based system. This introduces a new base Component class and converts numerous existing features—including the page editor, image manager, and attachment list—into reusable, isolated components. This change improves code maintainability, reduces global state dependencies, and provides a more consistent pattern for adding new interactive elements across the application.
resources/js/components · high confidence
New controllers for email confirmation, password reset, MFA, and authentication flows
The application introduces a suite of new controllers in the Access namespace to handle user authentication and security workflows. This includes a ConfirmEmailController for verifying email addresses, a ForgotPasswordController and ResetPasswordController for password recovery, and dedicated controllers for Multi-Factor Authentication (MfaController, MfaTotpController, MfaBackupCodesController). Additionally, the codebase adds controllers for OpenID Connect (OidcController), SAML 2.0 (Saml2Controller), and Social Login (SocialController), alongside a UserInviteController for managing new user invitations. These changes centralize and modernize the handling of login, registration, and security verification processes.
app/Access/Controllers · high confidence
New decorators for code blocks, diagrams, and mentions
The WYSIWYG editor now supports dedicated UI decorators for code blocks, diagrams, and user mentions. Code blocks are rendered with a dynamic height and an interactive editor, while diagrams gain click and double-click interactions to open the drawing editor. User mentions now feature a searchable, keyboard-navigable dropdown that fetches and caches user results, allowing users to select a user to complete the mention.
resources/js/wysiwyg/ui/decorators · high confidence
New email notification classes for email confirmation, password reset, and user invitations
The application now includes dedicated notification classes for email confirmation, password reset, and user invitations. Each class handles the construction of the corresponding email, utilizing locale-aware translations for subjects, greetings, and action buttons. This change introduces the underlying structure for these three key user-facing email templates.
app/Access/Notifications · high confidence
New email notification templates for pages and comments
Users will now receive structured email notifications for new or updated pages and comments. Each email includes the page title, its location in the site hierarchy, and the relevant user details, with links to view the content directly. This replaces the previous notification system with a more detailed, template-based approach for page and comment activity.
app/Activity/Notifications/Messages · high confidence
New export and import controllers for books, chapters, pages, and ZIP operations
Added new controllers in app/Exports/Controllers to handle content export and import operations. For exports, BookExportController and BookExportApiController provide endpoints to export books, chapters, and pages as PDF, HTML, plain text, markdown, and ZIP files. The controllers enforce the ContentExport permission and apply a 'throttle:exports' rate limit middleware to the web controller. For imports, ImportController and ImportApiController manage uploading, validating, and running ZIP-based imports, requiring the ContentImport permission. These changes introduce the specific API and web endpoints for these operations.
app/Exports/Controllers · high confidence
New forms for editing images, links, media, and table cells
The WYSIWYG editor now provides dedicated forms for managing content. Users can edit image properties (source, alt text, dimensions) and link details (URL, text, title, target) via modals. Media elements are handled through a new media form. Additionally, table formatting is supported with cell and row property editors that allow adjustments to dimensions, alignment, borders, and background colors.
resources/js/wysiwyg/ui/defaults/forms · high confidence
New help pages for editor shortcuts and software licenses
Added new help pages documenting keyboard shortcuts for the WYSIWYG editors (TinyMCE and Lexical) and a dedicated page listing all software licenses and copyright notices used by the application. Users can now access a comprehensive list of editor shortcuts and view the legal licensing information for third-party libraries like TinyMCE, Lexical, and PHP libraries.
resources/views/help · high confidence
New layout partials for theming and header structure
Added new Blade template files in the layouts/parts directory to support the visual theme system and improve header organization. Placeholder files (base-body-start/end, export-body-start/end, header-links-start) were added to allow users to inject custom HTML head content and body-end scripts. A new custom-head template enables users to insert arbitrary HTML into the document head. The header was refactored into modular components (header, header-logo, header-search, header-links, header-user-menu) to simplify customization. The header also now includes a skip-to-content link for accessibility, and the footer was added to display configured footer links.
resources/views/layouts/parts · high confidence
New notification handler framework for activity events
A new notification system has been introduced to manage activity-based alerts, starting with handlers for page creation, page updates, comment creation, and comment mentions. The \BaseNotificationHandler\ enforces permission checks (ensuring users have access to the related content) and respects individual user notification preferences. Specific handlers implement logic such as deduplicating updates within 15 minutes, preventing duplicate mention notifications via history tracking, and filtering out the activity initiator from receiving their own notifications.
app/Activity/Notifications/Handlers · high confidence
New query classes for listing and counting user content
Four new query classes have been added to the application's user management system. RolesAllPaginatedAndSorted handles paginated, sorted, and searchable retrieval of all system roles. UsersAllPaginatedAndSorted performs the same for user accounts, including last activity and MFA status. UserContentCounts and UserRecentlyCreatedContent provide aggregated counts and recent activity lists for individual users, respectively. These changes introduce new capabilities for administrators to view and sort user and role data.
app/Users/Queries · high confidence
New reference tracking and updating system
A new reference management system has been introduced to track and update internal links across the application. This includes a Reference model to store bidirectional links between entities, a ReferenceStore to index and rebuild outgoing references from HTML content, and a ReferenceUpdater to automatically update all internal links when an entity's URL or permalink changes. The system also provides a ReferenceFetcher to query incoming references and a ReferenceController to display them on entity pages.
app/References · high confidence
New settings and maintenance management system
The application's settings and maintenance functionality has been restructured into a new, dedicated namespace (BookStack\\Settings). This introduces a new AppSettingsStore to handle saving and updating application-wide settings, including the ability to upload and manage a custom app logo and icon (favicon). A new MaintenanceController provides a centralized hub for system maintenance tasks, including cleaning up unused images, sending test emails, and regenerating the reference index. Additionally, user-specific notification preferences and keyboard shortcut mappings are now managed through dedicated classes (UserNotificationPreferences, UserShortcutMap) that store and retrieve user-specific settings.
app/Settings · high confidence
New settings pages for app customization, features, registration, and sorting
Added four new settings pages in the admin panel: customization (app name, editor, logo, icon, color scheme, homepage, footer links, and custom HTML), features (public access, secure images, disable comments), registration (enable, default role, domain restriction, email confirmation), and sorting (page limits for shelves/books/search, default book sort rule, and sort rule management). These views provide the UI for configuring these application-wide options.
resources/views/settings/categories · high confidence
New shelf management views for create, edit, delete, permissions, and references
Added new Blade templates for shelf management, including create, edit, delete, permissions, and references pages. The shelf show page now supports both grid and list views for books, with a toggle to switch between them. The delete view includes a confirmation step, and the permissions view allows copying permissions to all books on the shelf. The index page displays shelves with sidebar sections for recent, popular, and new shelves.
resources/views/shelves · high confidence
New user and role management controllers
Added new controllers for managing users and roles, including API endpoints (UserApiController, RoleApiController) and web interfaces (UserController, RoleController, UserAccountController, UserPreferencesController, UserProfileController, UserSearchController). These controllers handle user listing, creation, updates, deletion, and profile management, as well as role CRUD operations and user preference settings.
app/Users/Controllers · high confidence
New user management and profile views
Added new Blade templates for user management and profile pages, including views for creating, editing, and deleting users, as well as a dedicated profile page displaying recent activity and content counts. The user list view now includes search, sorting, and pagination controls, while the edit view incorporates multi-factor authentication (MFA) settings and social account management.
resources/views/users · high confidence
New views for page management and display
Added new Blade templates for page operations including copy, delete, edit, move, and permissions, as well as dedicated views for page revisions, references, and the main page show page. These templates provide the user interface for creating, modifying, and organizing pages within the application.
resources/views/pages · high confidence
Redesigned book management views with tri-column layout and new management pages
The book views have been significantly redesigned to use a three-column layout (header, left sidebar, right sidebar) for better organization. The main book show page now features a sticky left sidebar for search, tags, and activity, while the right sidebar displays details and actions. New dedicated views have been added for managing books, including a copy form, a delete confirmation page, a permissions editor, a references list, and a sort interface. The book creation and editing forms have been updated to match the new design, and the book index page now includes sidebar sections for recent, popular, and new books.
resources/views/books · high confidence
Replaced the legacy WYSIWYG editor with a new Lexical-based editor
The WYSIWYG editor has been replaced with a new implementation based on the Lexical framework. This introduces a modernized editing experience with improved support for block content, tables, and mentions. The new editor is configured for three distinct contexts: page content, basic descriptions, and comments (which includes mention support). The change includes a new entry point and node configuration that registers various editor features such as history, shortcuts, and auto-links, while also providing a public API for accessing the editor instance.
resources/js/wysiwyg · high confidence
Restructured attachment manager with drag-and-drop and link insertion
The attachment manager has been restructured into a new set of Blade templates that support drag-and-drop file uploads, insertion of attachment links into pages, and a unified interface for managing existing attachments. Users can now drag files to upload, insert links to attachments directly into page content, and manage files through a consolidated manager view that includes edit and delete controls gated by permissions.
resources/views/attachments · medium confidence
Search engine refactored with new option classes and API endpoint
The search functionality has been refactored to use a new \SearchOption\ hierarchy (\TermSearchOption\, \ExactSearchOption\, \TagSearchOption\, \FilterSearchOption\) that standardizes how search terms, exact matches, tags, and filters are parsed and processed. This change introduces a dedicated \SearchApiController\ that exposes the search functionality via a JSON API, allowing programmatic access to search results. The \SearchIndex\ and \SearchRunner\ classes have been updated to work with this new structure, improving how search terms are tokenized, scored, and matched against entities.
app/Search · high confidence
Removals
Removed BookRepo class
The BookRepo class, which previously handled book retrieval and manipulation via the Oxbow namespace, has been removed from the application.
app/Repos · high confidence
Removed legacy Oxbow controllers
The legacy Oxbow namespace controllers (BookController, PageController, and the base Controller class) have been removed from the application. This cleanup eliminates outdated routing and controller logic, ensuring that book and page interactions now rely on the modernized, feature-based controller structure.
app/Http/Controllers · high confidence
Removed legacy Oxbow namespace models
The application has removed the legacy \Book\, \Job\, and \User\ model classes that were part of the previous \Oxbow\ namespace. This cleanup removes outdated code that is no longer used in the current \BookStack\ namespace, ensuring the codebase only contains active, relevant components.
app · high confidence
Security
Introduces comprehensive content filtering and CSP headers
Adds a suite of new utility classes in app/Util to enforce stricter security and content standards. This includes a new CspService for generating Content Security Policy headers, an HtmlContentFilter that removes dangerous elements (scripts, forms, bad HTML) and filters URLs, and an HtmlDescriptionFilter for sanitizing description fields. Additionally, the update introduces an SsrUrlValidator to restrict server-side requests to allowed hosts, a UrlFilter to sanitize links, and a WebSafeMimeSniffer to ensure only safe file types are served. These changes collectively harden the application against XSS, SSRF, and unsafe content rendering.
app/Util · high confidence
API
API request examples added for core resources
Added JSON and HTTP request examples for creating, updating, and deleting resources including attachments, books, chapters, comments, content permissions, image galleries, imports, pages, roles, shelves, tags, and users. These files serve as reference documentation for the API, illustrating the expected request payloads for each operation.
dev/api/requests · high confidence
New API endpoints for managing attachments and images
A new Attachment API controller provides endpoints to list, create, read, update, and delete attachments, including support for uploading files and linking external URLs. Additionally, new API controllers have been introduced for managing gallery images and Draw.io diagrams, offering endpoints to list, create, read (including raw data), update, and delete images. These changes expose the underlying upload and image management capabilities via a structured JSON API, allowing clients to interact with attachments and images programmatically.
app/Uploads/Controllers · high confidence
Architecture
Refactored entity repositories into a shared base class with specialized implementations
The entity repository logic has been restructured to use a new BaseRepo class that handles common operations like creating, updating, and managing cover images, slugs, and references. This base class is then extended by specialized repositories for Books, Bookshelves, Chapters, Pages, and Revisions, each implementing their own specific logic while reusing the shared functionality. This change improves code organization and consistency across entity types.
app/Entities/Repos · high confidence
Refactored image and attachment upload handling
The \app/Uploads\ directory has been restructured into a new set of dedicated classes to manage uploads more cleanly. A new \Attachment\ model and \AttachmentService\ handle file uploads, links, and ordering for page attachments. Image handling has been split into \Image\, \ImageRepo\, \ImageService\, and \ImageResizer\ classes, which manage image storage, resizing, and thumbnail generation. Additionally, \FaviconHandler\ and \UserAvatars\ classes have been introduced to manage site icons and user profile pictures respectively, replacing the previous monolithic \UploadService\ and ad-hoc logic.
app/Uploads · high confidence
Restructured and extracted access control logic into dedicated service classes
The authentication and access control logic has been reorganized into a set of dedicated service classes within the \app/Access\ namespace. This includes new files for handling email confirmation (\EmailConfirmationService\), external user provisioning (\ExternalBaseUserProvider\), LDAP integration (\Ldap\, \LdapService\), SAML2 (\Saml2Service\), social authentication (\SocialAuthService\, \SocialDriverManager\), and user invitations (\UserInviteService\). The refactoring extracts specific responsibilities—such as token generation (\UserTokenService\), group synchronization (\GroupSyncService\), and login flow control (\LoginService\)—into their own classes, improving code modularity and testability while maintaining the same underlying functionality for user registration, login, and external identity management.
app/Access · high confidence
Unified entity model structure for books, chapters, and pages
The application's data layer has been refactored to use a unified 'entities' database table with a single-table inheritance pattern. New Eloquent models (Book, Chapter, Page, and their associated data classes) now share a common base structure, allowing for more efficient querying and consistent handling of shared attributes like descriptions, templates, and covers. This change simplifies how the system manages content hierarchy and permissions across all document types.
app/Entities/Models · high confidence
Behavioural changes
API documentation templates restructured and expanded
The API documentation views have been reorganized into dedicated Blade template files (endpoint.blade.php, getting-started.blade.php) to improve structure and readability. The 'Getting Started' section now includes updated links to the BookStack api-scripts repository on Codeberg, along with detailed explanations of authentication, request formats (including JSON and form-encoded data), and listing endpoint parameters. The endpoint template now supports multi-paragraph descriptions, displays body parameters in a table, and provides collapsible sections for example requests and responses.
resources/views/api-docs/parts · high confidence
Add sort rule creation and editing interfaces
Users can now create and edit sort rules through new Blade templates (create, edit, and form partials) that provide a UI for managing sorting configurations. The edit view includes a delete action for existing rules, and the form includes a component for managing sort rule operations.
database/factories/Sorting, resources/views/settings/sort-rules · medium confidence
Added checksums for system CLI vendor dependencies
A new .gitignore file and a vendor checksum file have been added to the dev/checksums directory. The .gitignore ensures the vendor directory is tracked, and the vendor file contains a SHA-256 hash (22e02ee7...) for verifying the integrity of the system CLI's vendor dependencies.
dev/checksums · medium confidence
Added plaintext email template for notifications
A new plaintext email template (email-plain.blade.php) has been introduced for email notifications, ensuring that users receive a simple, text-based version of their notification emails. This change supports the re-enabling of plaintext views for email notifications, providing a fallback or alternative format alongside the existing HTML templates.
resources/views/vendor/notifications · high confidence
Application namespace and bootstrap structure updated
The application's root namespace has been changed from 'Oxbow' to 'BookStack', updating the kernel and exception handler class references in the bootstrap configuration. Additionally, the legacy 'bootstrap/autoload.php' file has been removed, and a new 'bootstrap/phpstan.php' configuration file was added to support static analysis scanning.
bootstrap · medium confidence
Centralized entity query logic into dedicated query classes
The application's entity retrieval logic has been refactored into a set of dedicated query classes (BookQueries, ChapterQueries, PageQueries, etc.) that implement a common interface. A central EntityQueries class now routes requests to the appropriate entity-specific query class, providing a unified way to find, list, and filter entities like books, chapters, and pages. Additionally, new query classes (QueryPopular, QueryRecentlyViewed, QueryTopFavourites) have been introduced to handle specific user-facing lists, separating the concerns of data retrieval from the main entity models.
app/Entities/Queries · high confidence
Converted core JavaScript services to TypeScript
The JavaScript services in the application, including HTTP, DOM, animations, translations, and event management, have been converted from plain JavaScript to TypeScript. This migration introduces static typing and improved code structure for these core utilities, enhancing maintainability and reducing runtime errors. Additionally, a new test suite was added to verify the behavior of the translations service.
resources/js/services · high confidence
Hardened HTML sanitization with stricter URL and protocol filtering
The HTML purifier has been refactored into a new ConfiguredHtmlPurifier class that enforces stricter security controls. A custom filter now restricts the file:// protocol to anchor hrefs only, preventing potential network-triggered content loading on other elements. Additionally, the srcset attribute is now validated to block dangerous protocols (javascript, vbscript, data, and file). The configuration also explicitly allows the object, embed, and checkbox input elements, and enables HTML5 support for attributes like drawio-diagram and target blank on links.
app/Util/HtmlPurifier · medium confidence
Improved HTML to Markdown conversion and Markdown rendering
The HTML to Markdown conversion now supports checkboxes, draw.io diagrams, and callout classes, while the Markdown renderer adds support for task lists and strikethrough formatting. These changes improve the fidelity of content conversion and rendering, ensuring that specific HTML elements and Markdown syntax are preserved or rendered correctly.
app/Entities/Tools/Markdown · high confidence
Introduce structured data models for ZIP export validation
The ZIP export system now uses dedicated model classes (ZipExportModel and its children like ZipExportPage, ZipExportBook, etc.) to handle serialization and validation of export data. These models define strict validation rules for each entity type, ensuring that exported content adheres to expected formats. This change improves the reliability of the export process by validating data before it is written to the ZIP file.
app/Exports/ZipExports/Models · high confidence
Introduced dedicated MFA service classes and rate limiting
The MFA logic has been refactored into specific service classes: BackupCodeService for managing backup codes, TotpService for TOTP generation and verification, and MfaSession for tracking verification status. A new MfaValue model handles encrypted storage of MFA values. Additionally, MfaVerificationLimiter was added to enforce rate limiting on MFA attempts, restricting users to 5 attempts per minute and the IP to 60 attempts per minute to prevent brute-force attacks.
app/Access/Mfa · high confidence
Introduced new authentication guard classes for external and LDAP logins
Added new authentication guard classes to handle external and LDAP-based login flows. The base class, ExternalBaseSessionGuard, provides a simplified session guard implementation that removes 'remember' functionality and basic auth to support asynchronous external authentication processes. The LdapSessionGuard extends this base to handle LDAP-specific validation, user creation, and group syncing. These changes restructure how authentication is managed, separating the core guard logic from the standard Laravel flow to better support async external auth mechanisms.
app/Access/Guards · high confidence
Markdown editor converted to TypeScript with modular architecture
The Markdown editor has been refactored into a modular TypeScript codebase, separating concerns into distinct classes for actions, display, settings, and event handling. This change introduces a new input abstraction layer, allowing the editor to dynamically switch between a CodeMirror-based rich editor and a plain text textarea based on user settings. The refactoring also adds support for task lists via the 'markdown-it-task-lists' plugin and implements keyboard shortcuts for common formatting actions like inserting links, images, and code blocks.
resources/js/markdown · high confidence
Migrated build system to esbuild with native livereload support
The project's build process has been replaced with esbuild, a faster JavaScript bundler, which now handles the compilation of application, code, legacy-modes, markdown, and wysiwyg entry points. This change introduces a new hot-reload mechanism via a dedicated \livereload.js\ script that injects live-reload logic into the browser during development, replacing the previous library. Additionally, a Jest transformer for SVG files has been added to handle test coverage for static assets.
dev/build · high confidence
Migrated core JavaScript application entry point and global type definitions to TypeScript
The main application entry point (app.ts) and global type definitions (global.d.ts, custom.d.ts) have been converted to TypeScript. This change introduces strict typing for global window properties ($http, $events, $trans, $components) and utility functions (baseUrl, importVersioned), ensuring that the core application initialization and service registration are now type-safe.
resources/js · high confidence
Migrated to Laravel 5.5 console command registration
The application's console kernel has been updated to follow Laravel 5.5's new convention for registering Artisan commands. Instead of defining commands in the \$commands\ array, the \Kernel\ class now uses the \commands()\ method to dynamically load commands from the \Commands\ directory. This change also includes renaming the namespace from \Oxbow\ to \BookStack\.
app/Console · high confidence
Modularized chapter sidebar and list components
The chapter sidebar and list views have been refactored into separate, reusable Blade template parts. This includes extracting the chapter list item, child menu, and sidebar sections (actions, details, tags) into dedicated files under resources/views/chapters/parts. Users will see a more consistent and modular sidebar interface for chapters, with separate components for editing, permissions, and content listing.
resources/views/chapters/parts · medium confidence
New book sorting and sidebar components
The books index and show pages now use new, modular sidebar sections (for actions, details, activity, shelves, and tags) and a dedicated sort box that lets users reorder books, chapters, and pages by name, creation date, update date, or chapter position. A new 'convert to shelf' part provides a confirmation flow for converting a book to a shelf, and the book list view now supports both list and grid layouts with pagination.
resources/views/books/parts · high confidence
New entity view components and UI structure
The entity views have been reorganized into a new modular structure, introducing dedicated Blade templates for entity metadata, tag management, and watch controls. This includes new components for entity selection, search results, and list rendering, alongside updated templates for breadcrumbs, export menus, and sibling navigation. These changes support a more consistent and accessible user interface for browsing and managing content.
resources/views/entities · high confidence
New search filter and suggestion components
The search interface now uses dedicated Blade templates for rendering boolean, date, and type filters, as well as lists for search terms and entity suggestions. These components standardize the search experience by providing consistent, reusable UI parts for applying and displaying search filters and results.
resources/views/search/parts · medium confidence
New settings UI components for color and navigation
The settings interface now includes dedicated Blade templates for managing color schemes and navigation. A new 'setting-color-picker' component allows users to customize colors for the app, links, and content types (bookshelf, book, chapter, page, page-draft) for both light and dark modes. Additionally, a 'navbar' template provides a responsive navigation menu for settings sections, and a 'footer-links' template enables dynamic management of footer links. These components support the new responsive layout for the settings area.
resources/views/settings/parts · medium confidence
New unified search interface with advanced filtering
A new 'all' search page has been introduced, consolidating search functionality into a single view. Users can now apply advanced filters for content type (pages, chapters, books, bookshelves), exact matches, tags, and user-specific options like 'viewed by me' or 'created by me'. The interface includes a main search bar, a results list with tags, and pagination, replacing the previous fragmented search implementations.
resources/views/search · high confidence
Overhaul of translation loading and locale management
The application now uses a custom translation file loader that supports overriding translations via the theme system and loads translations from modules. A new locale management system has been introduced, including a LocaleManager that maps internal locale codes to ISO standards and handles automatic locale detection. Additionally, pluralization logic has been corrected to handle non-standard locale identifiers like 'de\_informal' by stripping suffixes before selecting the correct plural form.
app/Translation · medium confidence
Pagination component now uses theme colors
The default pagination view has been updated to apply theme colors to the active page link, specifically by adding a 'primary-background' CSS class to the currently active page element. This change ensures that the active state of the pagination controls visually aligns with the application's primary color scheme.
resources/views/vendor/pagination · high confidence
Prevent directory listing for public uploads
Added a .htaccess file to the public/uploads directory that disables directory indexing (Options -Indexes). This ensures that if the server is configured to list directory contents by default, users will not be able to browse or download all uploaded files by navigating to the uploads folder URL. Additionally, a .gitignore file was added to the uploads directory to prevent tracking of uploaded files in version control, while allowing the .htaccess and .gitignore files themselves to be committed.
public/uploads · high confidence
Recycle bin list items now display hierarchical content and parent context
The recycle bin interface has been updated to show a more detailed, responsive list of deleted items. Each entry now displays the entity type icon, name, and parent container (if applicable). For books and chapters, it also shows the count of associated pages or chapters. This change improves visibility into what is being deleted and restores a structured, hierarchical view of deleted content.
resources/views/settings/recycle-bin/parts · high confidence
Redesigned API tokens management interface
The API tokens section has been updated with a new responsive layout. The form for creating or editing tokens now uses a two-column grid for the name and expiry date fields. The list of existing tokens has been restructured into a card-based view that displays the token name, ID, and expiration date in a more compact, responsive format.
resources/views/users/api-tokens/parts · high confidence
Redesigned Docker development environment
The development Docker setup has been rewritten to use PHP 8.3 and Apache, with an entrypoint that automatically installs Composer dependencies, runs database migrations, and starts the web server. The environment now includes LDAP and GD extensions, Git safe directory configuration, and support for Xdebug and Node.js watch mode.
dev/docker · high confidence
Redesigned comment interface with nested threads and tabbed archive view
The comment section has been restructured to support nested, threaded discussions. A new \comment-branch\ template renders child comments recursively, while the main \comments\ view now uses a tabbed interface to separate active and archived comments. Each comment card (\comment.blade.php\) now displays full action buttons (reply, edit, archive, delete) with appropriate permission checks, and includes a reply-to indicator and content reference links. The creation form (\create.blade.php\) has been updated to support replying to specific comments and attaching content references.
resources/views/comments · high confidence
Redesigned error pages with consistent layout and improved content
The 404, 500, 503, and debug error views have been updated to use a new, consistent card-based layout that aligns with the application's current design system. The 404 page now includes links to log in or return home, and displays popular pages, books, and chapters for logged-in or public users. The 500 error page has been simplified to show the error message and a home link. The 503 maintenance page has been simplified to show a 'Be right back' message. A new debug view has been added to display detailed error information, environment details, and helpful resources when the application is in debug mode. The not-found text has been extracted into a separate partial view.
resources/views/errors · high confidence
Redesigned home page layout and sidebar components
The home page views have been reorganized into a new structure: a 'default' dashboard layout for the main content area, and reusable 'parts' for the sidebar and expand/collapse functionality. The sidebar now consistently displays recent drafts, favorites, recently viewed/updated items, and activity feeds across books, shelves, and specific page views. A new 'expand-toggle' component allows users to expand or collapse sections on the home page, with the state persisted per user. The default home view now uses a grid layout for better responsiveness, and the sidebar is shared across different home page templates (books, shelves, specific page) to provide consistent navigation and actions.
resources/views/home · medium confidence
Redesigned password reset and email forms
The password reset and email views have been updated with a new card-based design, utilizing the 'layouts.simple' template and CSS classes like 'card' and 'stretch-inputs'. Text content has been externalized into language files via the 'trans' helper, and the form actions now use the 'url' helper instead of a custom 'baseUrl' function.
resources/views/auth/passwords · high confidence
Redesigned shelf management interface with improved sorting and modularity
The shelf management interface has been redesigned to improve usability and maintainability. A new form for editing shelves includes a dedicated section for sorting and reordering books within a shelf, allowing users to drag-and-drop or use up/down controls to manage book order. The sidebar sections for the shelf index and show pages have been reorganized into modular, reusable Blade components, enhancing consistency across the application. Additionally, the shelf list item template has been updated to display book covers and associated books more effectively.
resources/views/shelves/parts · high confidence
Redesigned tag listing and item views
The tag index page has been updated with a new responsive layout. The main index view now uses a flexbox-based structure for search and sorting controls, and the individual tag list items have been redesigned to display usage statistics (pages, chapters, books, shelves) in a horizontal row with icons. This change improves the visual presentation and usability of the tags management interface.
resources/views/tags · high confidence
Refactored HTTP layer with new base controllers and response factories
The application's HTTP handling has been restructured to use new base classes for controllers and responses. A new \ApiController\ abstract class provides a standardized \apiListingResponse\ method for paginated JSON listings, while the main \Controller\ base class now includes helper methods for permission checks, notifications, and activity logging. Additionally, a \DownloadResponseFactory\ has been introduced to manage file downloads and inline content streaming with range request support. The \routes.php\ file has been removed in favor of modern route definition patterns, and the \Kernel\ class has been updated to use the new \BookStack\ namespace and updated middleware groups.
app/Http · high confidence
Refactored MFA verification views and enabled one-time code autofill
The MFA verification interface has been restructured into dedicated Blade templates for TOTP and backup code verification. This change introduces the HTML structure for the verification forms, including error handling and confirmation buttons. Additionally, the input fields for both TOTP and backup codes now include the 'autocomplete="one-time-code"' attribute, which enables automatic code autofill on supported devices, and the autocomplete attribute is explicitly disabled on the form to prevent browser interference.
resources/views/mfa/parts · high confidence
Refactored OIDC authentication with dedicated token and claim handling classes
The OIDC authentication flow has been refactored to use dedicated classes for handling access tokens, ID tokens, and user details. A new \OidcAccessToken\ class validates the token structure and extracts the ID token. The \OidcIdToken\ class performs strict validation of ID token claims (issuer, audience, expiration, etc.) as per OIDC specs. User details (external ID, email, name, groups, picture) are now managed via the \OidcUserDetails\ class, which supports multi-claim name resolution and optional avatar fetching. The \OidcUserinfoResponse\ class handles both JSON and JWT-encoded UserInfo responses, normalizing content types. These changes improve security by enforcing stricter token validation and provide more robust handling of OIDC claims and user data.
app/Access/Oidc · medium confidence
Refactored Recycle Bin views into dedicated template files
The Recycle Bin settings interface has been restructured into specific Blade templates (destroy, index, and restore) to improve code organization and support per-item actions. This change introduces a confirmation screen for permanently deleting items, displays the parent entity and a link to restore the parent when restoring an item, and provides individual delete and restore buttons for each entry in the list.
resources/views/settings/recycle-bin · high confidence
Refactored and expanded HTTP middleware for authentication, security, and localization
The middleware layer has been significantly restructured and expanded. Authentication is now handled by dedicated middleware classes including ApiAuthenticate for API access control, AuthenticatedOrPendingMfa for multi-factor authentication checks, and CheckEmailConfirmed to enforce email verification. Security is enhanced with ApplyCspRules for Content Security Policy headers and ThrottleApiRequests for API rate limiting. The system now supports configurable proxy trust settings via TrustProxies, enforces user permissions via CheckUserHasPermission, and manages localization through the Localization middleware. Additionally, session handling has been customized in StartSessionExtended and StartSessionIfCookieExists to exclude specific paths from history tracking and cookies, while other standard Laravel middlewares (TrimStrings, EncryptCookies, VerifyCsrfToken) have been updated to the BookStack namespace.
app/Http/Middleware · high confidence
Refactored and standardized UI component styles
The SASS codebase has been restructured into modular, reusable components. New styles have been introduced for buttons, cards, forms, headers, and the editor interface, providing a more consistent visual language across the application. This refactoring supports the broader dark mode implementation and improves the overall design of interactive elements like dropdowns, modals, and navigation bars.
resources/sass · medium confidence
Refactored application service providers for Laravel 11 compatibility
The application's service providers have been restructured to align with Laravel 11's new default directory structure, moving all provider classes into the new app/App/Providers directory. This refactoring includes registering custom authentication guards (API token, LDAP, and async external session guards), setting up the theme system with dynamic view registration, configuring rate limiters for API and export endpoints, and registering custom validation rules and blade directives. These changes ensure the application runs correctly on the upgraded framework while maintaining existing functionality.
app/App/Providers · high confidence
Refactored exception handling and added new exception classes
The application's exception handling has been refactored to use a new set of specific exception classes in the \app/Exceptions\ directory, including \ApiAuthException\, \HttpFetchException\, \JsonDebugException\, \LdapException\, \NotifyException\, \PrettyException\, and others, each implementing interfaces like \Responsable\ or \HttpExceptionInterface\ to control HTTP responses. The main exception handler (\Handler.php\) has been updated to route API requests to a dedicated JSON error response format, handle validation and authentication exceptions specifically for the API, and support out-of-memory error handling. This change improves how errors are reported to users and developers, providing more structured error messages for API consumers and cleaner error pages for web users.
app/Exceptions · high confidence
Refactored user management UI into reusable Blade components
The user management interface has been restructured to improve consistency and maintainability. The user list item has been extracted into a dedicated template, and the user form has been split into distinct sections for details, roles, and password settings. Additionally, a new language selection option has been added to the user creation form, allowing administrators to set a preferred language for new users.
resources/views/users/parts · medium confidence
Removed default English language files for pagination and password reset
The default English language files for pagination (pagination.php) and password reset messages (passwords.php) have been removed from the application's resources/lang/en directory. This means the application will no longer use these specific default translation strings for pagination links and password-related notifications.
resources/lang · high confidence
Removed empty vendor views directory placeholder
The empty placeholder file (.gitkeep) in the vendor views directory has been removed. This cleanup reflects the migration to Laravel 5.3, where the structure of vendor view overrides has changed, making the previous empty directory placeholder unnecessary.
resources/views/vendor · medium confidence
Removed legacy CSS stylesheet and source map
The \public/css/app.css\ file and its associated source map have been deleted from the project. This removal eliminates the previous set of global styles, including the CSS reset, typography, grid system, and component styling that were previously served from this single compiled file.
public/css · high confidence
Removed legacy Laravel 5.2 configuration files
The application has removed the default configuration files for the framework's core services, including app, auth, cache, database, filesystems, mail, queue, session, and view settings. This cleanup reflects a shift away from the default Laravel 5.2 configuration structure, likely as part of a broader upgrade or refactoring of the application's configuration management.
config · high confidence
Removed legacy Laravel service providers
The default service providers (AppServiceProvider, EventServiceProvider, and RouteServiceProvider) have been removed from the application. This change eliminates the boilerplate registration of application services, event listeners, and route groups, reflecting a shift in how the framework's core components are bootstrapped or configured.
app/Providers · high confidence
Removed legacy SCSS stylesheets
The legacy SCSS files for layout blocks, buttons, forms, grid, HTML elements, mixins, text, and variables have been removed from the project's assets.
resources/assets · high confidence
Removed legacy authentication controllers
The \AuthController\ and \PasswordController\ classes, which previously handled user registration, login, and password reset functionality using Laravel traits, have been removed from the application.
app/Http/Controllers/Auth · high confidence
Removed legacy model factory and seed placeholders
The legacy ModelFactory.php file, which defined default attributes for the User model, has been removed from the codebase. Additionally, the empty .gitkeep placeholder in the database/seeds directory has been deleted, indicating a cleanup of outdated or unused database seeding infrastructure.
database/factories · high confidence
Restructured export templates into modular partials
The export view logic has been reorganized into separate Blade partials for better maintainability. This includes new templates for rendering book and chapter menus, individual page and chapter items, and a dedicated import item template. Additionally, the custom head content and metadata display have been extracted into their own partials, while export styles are now handled via a dedicated styles template that injects CSS and applies PDF-specific color patches.
resources/views/exports/parts · high confidence
Restructured layout templates with new base, export, plain, simple, and tri-layouts
The application's view layer has been reorganized into distinct layout templates: a new base layout (base.blade.php) that centralizes head, meta, icons, and script loading; an export layout (export.blade.php) for document generation; a plain layout (plain.blade.php) for minimal pages; a simple layout (simple.blade.php) that extends the base; and a tri-layout (tri.blade.php) that extends the base and provides a three-column structure with sidebar support. These changes provide a more modular and consistent foundation for all page types.
resources/views/layouts · high confidence
Restructured role permissions interface into modular components
The role management interface has been restructured into separate Blade view components (e.g., \asset-permissions-row\, \checkbox\, \form\) to improve code organization and maintainability. This change introduces a new, consistent layout for managing permissions, including specific controls for content export/import, editor changes, and notifications, while also adding a dedicated section for managing user and role system permissions.
resources/views/settings/roles/parts · high confidence
Reworked page editor and image manager interfaces
The page editor interface has been restructured into modular Blade components, introducing a new code editor popup with language selection and history, a refactored editor toolbar with draft and changelog management, and a tabbed editor toolbox for tags, attachments, templates, and comments. Additionally, the image manager has been redesigned with a grid-based layout, a popup interface for image selection, and improved handling for uploads, replacements, and dependent page warnings.
resources/views/pages/parts · high confidence
Standardized form input components and error handling
The form input components (checkbox, date, number, password, text, textarea, etc.) have been refactored into dedicated Blade templates, each now consistently rendering validation error messages below the respective input field. Additionally, the \delete-button\ component was removed, and CSS classes were updated from 'neg' to 'text-neg' for error states.
resources/views/form · high confidence
Standardized login form templates for all authentication methods
The login forms for LDAP, OIDC, SAML2, and standard authentication have been extracted into dedicated partials under resources/views/auth/parts. Each method now has its own Blade template (login-form-ldap.blade.php, login-form-oidc.blade.php, login-form-saml2.blade.php, login-form-standard.blade.php) that renders the specific login UI for that provider. Additionally, placeholder templates (login-message.blade.php, register-message.blade.php) have been added to support the visual theme system, making it easier for users to customize login and register messages via themes.
resources/views/auth/parts · medium confidence
Updated TinyMCE icon set
The default icon set for the TinyMCE editor has been updated, introducing new SVG icons for features such as AI prompts, accordion controls, and table operations, which refreshes the visual appearance of the editor's toolbar and menus.
public/libs/tinymce · high confidence
Updated TinyMCE to version 6.8.4
The TinyMCE editor library has been upgraded from version 6.8.3 to 6.8.4. This update includes the latest versions of the autolink and nonbreaking plugins, which may contain bug fixes and improvements to how automatic link detection and non-breaking spaces are handled within the editor.
public/libs/tinymce/plugins/autolink, public/libs/tinymce/plugins/nonbreaking · high confidence
Updated TinyMCE to version 6.8.4
The TinyMCE rich text editor library has been upgraded to version 6.8.4. This update includes updated plugin implementations for anchor, autoresize, code, directionality, insertdatetime, pagebreak, save, and visualblocks, which may bring bug fixes and internal improvements to the WYSIWYG editing experience.
(repo-wide) · high confidence
Updated public entry point and server configuration
The public/index.php entry point was modernized to use explicit class imports and the Composer autoloader, while .htaccess was updated to handle Authorization headers and trailing slash redirects, and a new web.config was added for IIS URL Rewrite support.
public · high confidence
Upgraded code blocks to CodeMirror 6 for improved editing and syntax highlighting
The code block editor and syntax highlighting have been upgraded from the legacy CodeMirror implementation to CodeMirror 6. This change introduces a modern, modular editor experience with better theme support (including dark mode), dynamic language loading, and enhanced features like a copy-to-clipboard button, text direction support, and improved line highlighting. The update also adds support for additional programming languages such as SAS, R, and Clojure, while maintaining compatibility with existing code blocks through a legacy mode fallback.
resources/js/code · medium confidence
WYSIWYG editor default UI configuration
The default configuration for the WYSIWYG editor's user interface has been updated to include new modal definitions and toolbar button layouts. Users will see a reorganized toolbar with additional formatting, table, and insert options, alongside new modal dialogs for editing links, images, media, and tables.
resources/js/wysiwyg/ui/defaults · medium confidence
Fixes
Add SQL initialization script for the test database
A new SQL file (01.sql) has been added to the Docker initialization directory. This script creates the 'bookstack-test' database and grants all privileges to the 'bookstack-test' user, ensuring the test environment is properly configured for PHP tests.
dev/docker/init.db · low confidence
Added API token factory for testing
A new factory for the ApiToken model has been added to the database/factories/Api directory. This provides a standardized way to generate test data for API tokens, including token ID, secret, name, expiration, and associated user, which supports the fix for failing delete-based webhook events by ensuring consistent test fixtures.
database/factories/Api · medium confidence
Added missing database factories for User and Role models
The test suite was failing because the database factories for the User and Role models were missing after a controller/file reshuffle. This change restores the \UserFactory\ and \RoleFactory\ in \database/factories/Users/Models/\, ensuring that test data generation for these models works correctly again.
database/factories/Users · medium confidence
Test coverage
API testing coverage expanded across core endpoints; Added automated sorting and content movement tests; Added comprehensive permission tests for entity ownership, role-based access, and export restrictions; Added comprehensive test coverage for all export and import formats; Added comprehensive test coverage for uploads, images, and avatars; Added comprehensive test coverage for user management, preferences, and search functionality; Added comprehensive tests for authentication and account management; Added database factories for Activity models; Added factory for Import model; Added test coverage for WYSIWYG editor services; Added test data files for upload and image handling tests; Added tests for URL and date formatting utilities; Added tests for activity, comments, and webhooks; Added tests for entity and role permission scenarios; Added tests for meta-related endpoints and settings; Added tests for multiple Artisan commands; Added tests for settings and maintenance features; Added tests for the reference tracking system; Added tests for theme system functionality; Added unit tests for configuration, OIDC, and page includes; Expanded and organized search test coverage; Expanded automated test coverage for core application features; Expanded test coverage for entity management and content filtering; New test helper classes for entities, files, OIDC, and permissions.
Dependencies
Updated PHP and JavaScript dependencies
The project's dependencies have been updated to modernize the stack. PHP dependencies were upgraded to require PHP 8.2 and include newer versions of packages such as Laravel 12, PHPUnit 11, and various socialite providers. On the JavaScript side, the build system was migrated from Gulp to esbuild, and dependencies were updated to include CodeMirror 6, ESLint 10, Jest 30, and TypeScript 6, while removing older libraries like Gulp and Bootstrap-Sass.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 49.
Lenses
- Code Health 70
- Architecture 42
- Maturity 56
- Readiness 53
- Security 74
- Domain Modelling 53
Changes since last survey
- 300 commits — 266 feature/other, 34 fixes
By area
- (root) — 49 commits
- (repo) — 40 commits
- resources/js — 36 commits
- app/Entities — 18 commits
- app/Util — 11 commits
- .forgejo/workflows — 8 commits
- app/Uploads — 8 commits
- .github/translators.txt — 7 commits
- app/Activity — 7 commits
- app/Theming — 7 commits
- dev/docs — 7 commits
- tests/Entity — 7 commits
- app/Access — 6 commits
- app/App — 6 commits
- app/Exports — 6 commits
- app/Search — 6 commits
- resources/views — 6 commits
- dev/docker — 5 commits
- resources/sass — 5 commits
- app/Console — 4 commits
Notable commits
- fix: CI: Attempted to fix snyk workflow
- fix: Comment Mentions: Fixed and tweaks during review of changes
- fix: Comment mentions: Fixed CI and test scenarios
- fix: Copying: Fixed issue with non-page links to page permalinks
- fix: Deps: Updated PHP packages, fixed some types for phpstan
- fix: Exports: Fixed scope of pages in chapter MD export
- fix: Fix PDF heading font fallback for export
- fix: Lexical: Fixed actions not applying on empty state
- fix: Lexical: Fixed diagrams not updating on edit
- fix: Lexical: Fixed in-editor content drag and drop
- fix: Lexical: Fixed undefined entity selector value
- fix: Lexical: Fixed updating of TextNode text on export
- fix: Maintenance: Fixed type and CI issues
- fix: Maintenance: Fixed type issue, updated translator list
- fix: Mentions: Fixed some users not showing in mention selector
- fix: Merge branch 'fix/pdf-export-heading-fonts' of github.com:alexwoo-awso/BookStack into alexwoo-awso-fix/pdf-export-heading-fonts
- fix: Merge pull request #5969 from shaoliang123456/fix/git-safe-directory-in-docker
- fix: Meta: Updated issue template labels, fixed minor issues
- fix: Meta: Updated readme shields and fixed workflow value
- fix: Meta: Updated security info and fixed some tests/links
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
BookStackApp/BookStack was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 5 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6107161275b3594e17847d9f5362b9786fa8bf09 — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.