Skip to content
CAI
Software that uses CAICheck a score

zotonic/zotonic

36.1

Weak · 6 August 2026

172.3k

lines of production code

Erlang

with JavaScript

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Zotonic is a modular Erlang/OTP web application framework that provides a comprehensive backend for content management, user authentication, and administrative control. It features a flexible access control system, a robust backup and migration infrastructure, and a modernized admin interface for managing resources, users, and system configuration. The system also includes specialized modules for handling media, file indexing, and real-time communication via MQTT and SMTP.

How it got here

2009–2017 — modularization and admin overhaul

209 changes.

The project underwent a major architectural shift, migrating from a monolithic structure to a modular OTP application layout with a Rebar3 build system. This period focused on replacing legacy components like Webmachine and ErlyDTL with modern alternatives such as Cowboy and Cotonic, while simultaneously rebuilding the administrative interface with granular access control and new management tools.

2018–2026 — Security, extensibility, and developer tooling

64 changes.

This period focused on hardening the platform's security posture by introducing two-factor authentication, rate limiting, file scanning, and robust password validation. It also significantly expanded the framework's extensibility through new behaviors and modules for OAuth2, Microsoft login, and server-side storage. Concurrently, developer experience was enhanced with live reload, template debugging, and a modernized admin interface using Bootstrap 3 and SCSS.

Features

Add 2FA model for TOTP provisioning and state management

Introduces the m\_auth2fa model, implementing the backend logic for two-factor authentication. This includes generating TOTP provisioning URLs and managing user secrets, checking if TOTP is enabled for a user, and enforcing site-wide 2FA modes (optional, ask, required, forced). The model also provides API endpoints to check clock skew for time-based codes and manage session states for the 2FA dialog.

_apps/zotonic\_mod\auth2fa/src/models · high confidence

Add ACL rules export controller

A new controller, controller\_admin\_acl\_rules\_export, has been added to the zotonic\_mod\_acl\_user\_groups application. This component enables administrators to export Access Control List (ACL) rules in a binary format (.dat file) that can be re-imported later. The controller handles authorization checks against the mod\_acl\_user\_groups module and sets appropriate headers for file download.

_apps/zotonic\_mod\_acl\_user\groups/src/controllers · high confidence

Add Apache 2.0 license and build configuration for mod\_authentication

The mod\_authentication module now includes an Apache 2.0 license file and a rebar3 build configuration. The build file defines dependencies on zotonic\_core and zotonic\_mod\_admin, and adds the termit library (version 2.0) as a dependency. This establishes the module's legal and build framework for distribution.

_apps/zotonic\_mod\authentication · high confidence

Add Apache 2.0 license and rebar3 build configuration for zotonic\_mod\_cron

The zotonic\_mod\_cron application now includes an Apache 2.0 license file and a rebar3 configuration file. The rebar3 config sets a minimum OTP version of 23, includes the erlcron dependency (version 1.2.3), and configures documentation generation using ex\_doc for Hex packages.

_apps/zotonic\_mod\cron · high confidence

Add Bootstrap integration module and application metadata

Introduced a new \mod\_bootstrap\ module and its corresponding \.app.src\ configuration, which integrates the Bootstrap CSS/JavaScript framework into the Zotonic platform. The module provides helper templates and assets for UI components, while the application metadata explicitly declares dependencies on \kernel\, \stdlib\, and \zotonic\_core\, and specifies the Apache-2.0 license.

_apps/zotonic\_mod\bootstrap/src · high confidence

Add CSS styles for the login and signup forms

A new stylesheet, logon.css, is introduced to define the visual presentation of the authentication interface. This includes styling for the login box, form elements, error messages, and external sign-up options, ensuring consistent formatting for user-facing authentication components.

_apps/zotonic\_mod\authentication/priv/lib/css · high confidence

Add CSV and XLSX file parsing and writing capabilities

The zotonic\_core application now includes new Erlang modules for handling spreadsheet data: z\_csv\_parser and z\_csv\_writer manage reading and writing CSV files, including automatic detection of separators and safe encoding of values to prevent CSV injection. Additionally, z\_xlsx\_parser is introduced to parse XLSX (Excel) files, with memory usage capped at 160MB by default to prevent excessive resource consumption. These modules provide the underlying functionality for importing and exporting data in these formats.

_apps/zotonic\core/src/csv · high confidence

Add CSV and XLSX import functionality to the admin interface

The zotonic\_mod\_import\_csv module now provides a new admin interface for importing data from CSV and XLSX files. Users can upload files via a new 'Import CSV or XLSX file' button in the admin menu, which opens a dialog to select and upload files. The module supports importing both resource data (pages) and edge definitions (relationships) from CSV files, as well as XLSX files. The import process runs in the background, and progress is reported in the admin log and via notifications. The module also watches the site's dropbox folder for incoming CSV/XLSX files and imports them automatically.

_apps/zotonic\_mod\_import\csv · high confidence

Add ClamAV support module and MS Office filtering

The ClamAV integration is now supported for scanning files and binary data, including specific filtering for MS Office documents that contain external links. This adds new capabilities for virus scanning and content filtering within the Zotonic mod\_clamav application.

_apps/zotonic\_mod\clamav/src/support · high confidence

Add ClamAV virus scanning for uploaded files

A new \mod\_clamav\ module has been added to scan all uploaded files for viruses and malware using ClamAV. The module checks files after mime type and access control are verified, returning an \infected\ error if a threat is detected. It also includes a periodic health check that logs warnings if the ClamAV daemon is unreachable. Configuration options are provided for the ClamAV server IP, port, maximum file size, and rejecting Microsoft Office files with external links.

_apps/zotonic\_mod\clamav/src · high confidence

Add EXIF metadata extraction and display for media uploads

The zotonic\_mod\_media\_exif module now extracts EXIF metadata from uploaded photos and stores it as resource properties, including GPS location, crop center, orientation, and date. A new template partial renders these EXIF values in the admin media details view, and a template filter formats raw EXIF data (such as GPS coordinates and exposure settings) into human-readable text for display.

_apps/zotonic\_mod\_media\exif · high confidence

Add Facebook authentication and login integration

Users can now log in to the site using their Facebook account. This change introduces a new \mod\_facebook\ module that integrates with the platform's authentication system, allowing administrators to configure Facebook App ID, Secret, and scopes in the admin panel. The module provides OAuth2-based login and account linking/disconnect features, rendering Facebook login buttons on the logon and user profile pages. It also includes a model for fetching Facebook profile data and search query handling.

_apps/zotonic\_mod\facebook · high confidence

Add GeoIP module for IP-to-location mapping

Introduces the zotonic\_mod\_geoip application, which maps IP addresses to geographical locations using the MaxMind database. The module provides filters to convert IP addresses into country codes, city, continent, and location data. It supports configuration of a MaxMind license key via the 'maxmind\_license\_key' config key or the 'locus' application environment.

_apps/zotonic\_mod\geoip · high confidence

Add LinkedIn authentication integration

The zotonic\_mod\_linkedin module is introduced to enable users to log in to the site using their LinkedIn account. Administrators can configure the LinkedIn App ID and Secret in the admin interface, and users will see a 'Log in with LinkedIn' button on the logon form. The module handles the OAuth 2.0 flow, fetching the user's profile data and email address from LinkedIn to authenticate the user.

_apps/zotonic\_mod\linkedin · high confidence

Add MQTT listener support

The application now includes a new MQTT listener, introducing the \zotonic\_listen\_mqtt\ module to start and manage TCP/SSL listeners for MQTT connections. The handler processes MQTT connect packets, manages session lifecycles, and forwards data to the \mqtt\_sessions\ application. Configuration options such as \mqtt\_listen\_ip\, \mqtt\_listen\_port\, and \mqtt\_listen\_ssl\_port\ control the listener behavior.

_apps/zotonic\_listen\mqtt/src · high confidence

Add MQTT messaging support with live update components and client storage models

The zotonic\_mod\_mqtt application is introduced, providing MQTT messaging capabilities that connect the server and browser. This includes a new \scomp\_mqtt\_live\ component for live-updating templates based on MQTT topic subscriptions, an \action\_mqtt\_publish\ action for publishing messages, and client-side storage models (\m\_client\_local\_storage\ and \m\_client\_session\_storage\) to interact with browser storage via MQTT topics. The module also includes JavaScript modules (\z.live.js\, \qlobber.js\) to handle client-side subscription and topic matching, enabling real-time updates and persistent client-side state management through the MQTT broker.

_apps/zotonic\_mod\mqtt · high confidence

Add Microsoft identity platform login support

The \zotonic\_mod\_microsoft\ application has been added to provide Microsoft/Azure authentication. Users can now log in using their Microsoft account by configuring an App registration in the Azure Portal. The module adds a new authentication service panel in the admin interface where administrators can set the Application ID, Client Secret, OAuth scope (defaulting to 'email profile'), and tenant (defaulting to 'common'). The login flow redirects users to Microsoft for authorization and handles the OAuth2 callback to create or link user accounts.

_apps/zotonic\_mod\microsoft · high confidence

Add SSL CA module with admin UI and documentation

The zotonic\_mod\_ssl\_ca application is introduced, providing support for SSL certificates from a Certificate Authority. This includes an admin UI panel (\_admin\_config\_ssl\_panel.mod\_ssl\_ca.tpl) that displays certificate information and guides users on adding certificates to the security directory. The module (mod\_ssl\_ca.erl) handles SSL options and certificate file scanning, while the app source (zotonic\_mod\_ssl\_ca.app.src) declares dependencies on kernel, stdlib, and zotonic\_core. Documentation is added via moduledoc and markdown files, and the project adopts the Apache 2.0 license.

_apps/zotonic\_mod\_ssl\ca · high confidence

Add TinyMCE-based rich text editor to the admin interface

The admin now includes a WYSIWYG editor powered by TinyMCE (version 5.10.2). Users can edit content using a rich text interface that supports media insertion (images, videos) and automatic link generation for Zotonic pages. The editor is initialized on textareas with the class \z\_editor-init\ and can be configured via the \tinyInit\ object or by providing a custom stylesheet at \priv/lib/css/tinymce-zotonic.css\. The module also exposes a \zmedia-props\ command to render a dialog for selecting media items.

_apps/zotonic\_mod\_editor\tinymce/src · high confidence

Add WordPress WXR import module

Users can now import WordPress content by uploading a .wxr (WordPress eXtended RSS) file. The new \zotonic\_mod\_import\_wordpress\ module parses the XML export, mapping posts, categories, tags, and authors into the Zotonic datamodel. The admin interface provides a dialog to select the file and an option to re-import previously deleted items. The module includes its own license file (Apache 2.0) and depends on \zotonic\_core\ and \zotonic\_mod\_wires\.

_apps/zotonic\_mod\_import\wordpress · high confidence

Add admin category management module

Introduces the new \mod\_admin\_category\ module, enabling administrators to edit and manage the category hierarchy through the admin interface. The module provides functionality to delete categories and their associated resources, as well as move resources between categories. It includes ACL checks to ensure users have the necessary permissions to view, edit, and delete categories, and handles the deletion of resources within a category by checking if the category is in use before allowing removal.

_apps/zotonic\_mod\_admin\category/src · high confidence

Add admin config editor controller

The admin config editor now displays a list of all configuration settings with string values. The new controller filters out non-string settings and metadata fields, presenting only the editable key/value pairs to the user.

_apps/zotonic\_mod\_admin\config/src/controllers · high confidence

Add admin config module for editing system configuration

A new module, mod\_admin\_config, has been introduced to allow administrators to edit and insert configuration keys with string values via the admin interface. This module provides a list of all configuration modules, keys, and textual values, enabling users to add, remove, and edit entries if they have the appropriate permissions. The module also supports SSL certificate configuration and email configuration, including the ability to send test emails. The module is registered in the application source file, specifying dependencies on kernel, stdlib, and zotonic\_core.

_apps/zotonic\_mod\_admin\config/src · high confidence

Add admin configuration routes for email and SSL settings

The dispatch file introduces three new routing rules for the admin interface: a general configuration overview, an email configuration page, and an SSL configuration page. Each route maps a specific admin path to a controller and template, enabling users to manage email and SSL settings through the admin panel.

_apps/zotonic\_mod\_admin\config/priv/dispatch · high confidence

Add admin interface for managing predicates and connections

A new dispatch configuration file introduces four URL routes for the admin module: an overview of all connections (edges), a graph view of those connections, a list of all predicates, and an edit page for individual predicates. These routes map to specific controllers and templates, enabling administrators to view and manage the site's predicate and connection structure through the admin interface.

_apps/zotonic\_mod\_admin\predicate/priv/dispatch · high confidence

Add admin interface for merging resources

The admin module now includes a new feature allowing administrators to merge two resources (e.g., pages) into a single page. Users can select a 'winner' and a 'loser'; all properties and connections from the loser are merged into the winner, after which the loser is deleted and its URL returns a 410 Gone status. The implementation includes a new \filter\_admin\_merge\_diff\ module for comparing resources and a \mod\_admin\_merge\ module that handles the UI, permission checks, and the background merge process.

_apps/zotonic\_mod\_admin\merge/src · high confidence

Add admin statistics module for viewing system metrics

Introduced a new admin module that allows administrators to view system statistics. The module registers an 'Admin Statistics' entry in the admin menu, providing access to dashboard metrics and related system data.

_apps/zotonic\_mod\_admin\statistics/src · high confidence

Add audio file support with metadata extraction and preview generation

A new 'mod\_audio' module has been introduced to handle audio media items. It intercepts audio file uploads to extract metadata (such as artist, album, and duration) using 'ffprobe' and generates a PNG preview image using 'ffmpeg'. The module extends the media viewer to render audio files and allows editing of extracted tags in the admin interface.

_apps/zotonic\_mod\audio/src · high confidence

Add cloud file store configuration and administration interface

The mod\_filestore module now provides a complete administrative interface for configuring and managing remote file storage. Administrators can configure S3-compatible cloud storage endpoints, FTP, and WebDAV services directly through the admin panel. The update introduces a new 'Cloud File Store' menu item in the system settings, allowing users to set credentials, enable/disable uploads, configure local file retention, and manage file deletion intervals. The system includes a credential testing feature to verify connectivity before saving settings. Additionally, the module now supports moving files between local and cloud storage, with statistics and queue management for uploaded and cached files.

_apps/zotonic\_mod\filestore · high confidence

Add comment module for user-generated content

The \zotonic\_mod\_comment\ application is introduced, providing a basic commenting system that allows users to add comments to any resource. The module includes an admin interface for reviewing and deleting comments, supports both authenticated and anonymous commenting, and integrates with the search and admin menu systems. It also handles the migration of old comment and rating tables to the new schema.

_apps/zotonic\_mod\comment/src · high confidence

Add contact form and email template for user submissions

Introduced a new contact form page and an accompanying email template. The form collects name, email, and message, while the email template formats the submitted data for notification. This adds a new user-facing capability to submit contact requests via the website.

_apps/zotonic\_mod\contact/priv · high confidence

Add contact form module for user-submitted email submissions

A new contact form module (mod\_contact) is introduced, allowing users to submit messages via a web form that are then emailed to a configured administrator address. The module handles form submission, validation, and delivery, with configurable email recipients and sender addresses. It also installs a default 'Contact' page at /contact.

_apps/zotonic\_mod\contact/src · high confidence

Add content group usage check model

A new model for content group memberships has been introduced, exposing an API path to check whether a specific content group (or any of its children) is currently in use by at least one resource. This allows users to query the system to determine if a content group is actively referenced in the database.

_apps/zotonic\_mod\_content\groups/src/models · high confidence

The new \mod\_copyright\ module provides an admin panel and templates to select and view copyrights attached to content items. It supports Creative Commons and RightsStatements.org licenses, with default values for rights, attribution, and year that can be overridden via configuration keys or by providing a custom \\_copyright.tpl\ template.

_apps/zotonic\_mod\copyright · high confidence

Add custom redirect module for domain and path redirection

Introduces the mod\_custom\_redirect module, enabling administrators to configure redirects for unknown hosts and paths. The module observes dispatch notifications to match incoming requests against a configurable list of domains and paths, supporting both permanent and temporary redirects. This adds a new capability to handle 404-style scenarios by redirecting users to specified locations.

_apps/zotonic\_mod\_custom\redirect/src · high confidence

Add detailed statistics panels for system, database, and dispatch metrics

The admin statistics interface now includes new panels for monitoring Erlang VM memory usage, system resource limits (atoms, ports, processes), database pool health, HTTP dispatch latency and throughput, and MQTT broker activity. These templates provide real-time visualizations and metrics for each subsystem, allowing administrators to monitor system health and performance directly from the admin dashboard.

_apps/zotonic\_mod\_admin\_statistics/priv/templates/stat\panel · high confidence

Add developer guide and license files for the TinyMCE editor module

The \apps/zotonic\_mod\_editor\_tinymce\ directory now includes a \DEVELOPER\ file that documents the step-by-step process for installing and configuring new versions of the TinyMCE editor, alongside \LICENSE\ (Apache 2.0) and \LICENSE-TINYMCE\ (LGPL 2.1) files that clarify the legal terms for the module and the embedded TinyMCE library.

_apps/zotonic\_mod\_editor\tinymce · high confidence

Add development tools: live reload, template graph, and variable debugging

The development module now supports live reloading of CSS, JavaScript, and template files, allowing developers to see changes instantly without a full page refresh. Additionally, a visual dependency graph of all templates is now available for navigation, and template variables can be live-debugged directly in the browser.

_apps/zotonic\_mod\development/priv/lib/js · high confidence

Add email receive module and restructure mailing list templates

Introduces a new \zotonic\_mod\_email\_receive\ module to handle inbound emails and route them to registered recipients, including a database model for managing email-to-user/resource mappings. Additionally, the mailing list module adds new admin templates for combining mailing list recipients, editing mailing list content and sidebar, viewing mailing status, and managing subscriptions, alongside updated routing for mailing list pages.

_apps/zotonic\_mod\mailinglist · high confidence

Add email relay capability for cross-server email handling

The \zotonic\_mod\_email\_relay\ application is introduced, enabling a Zotonic server to relay outbound emails to another Zotonic server, and conversely, to receive and process relayed emails and status reports from a remote server. Administrators can configure relay endpoints and shared secrets via the \mod\_admin\_config\ interface, and the module handles delivery status updates and recipient blocking synchronization between servers.

_apps/zotonic\_mod\_email\relay · high confidence

Add email status tracking and management for recipients

The zotonic\_mod\_email\_status module now tracks the delivery status of all outgoing emails, including successful sends, bounces, and errors. Administrators and users with appropriate permissions can view detailed status reports for any email address, including error counts, timestamps, and the most recent error message. The system allows users to manually clear error states or block/unblock email addresses to prevent sending to or receiving from specific addresses.

_apps/zotonic\_mod\_email\status · high confidence

Add export capabilities for CSV, JSON, XLSX, Atom, and iCalendar formats

The mod\_export module now provides a generic framework to export resources in multiple formats including CSV, JSON, XLSX, Atom, and iCalendar (ICS). Users can download data from the admin interface or via URL parameters, with support for customizing export fields and templates. The module registers content types for these formats and handles the streaming of export data, allowing users to export single resources, collections, or query results in various structured formats.

_apps/zotonic\_mod\export · high confidence

Add graph view for predicate management

The predicate administration interface now includes a visual graph view, allowing users to see and interact with the relationships between predicates and categories. This new feature includes a JavaScript implementation (admin-graph.js) and corresponding CSS styles (admin-graph.css) to render the graph, along with the inclusion of the Graphology library (graphology-0.26.0.umd.min.js) to support the graph visualization. Users can now explore connections, filter predicates within the graph, and manage hidden categories and predicates through this interactive view.

_apps/zotonic\_mod\_admin\predicate/priv/lib · high confidence

Add graph view for predicates with JS API and styling

The admin predicate module now includes a visual graph view that renders a directed resource graph using Sigma.js and Graphology. This adds a new interactive visualization where users can click resources to highlight incoming and outgoing edges, with incremental updates and pathfinding capabilities. The change introduces a public JavaScript API (exposed via the global \ResourceGraph\ object) for managing the graph, including methods to set, reset, add, and filter nodes and edges, as well as control path-only mode and hidden categories/predicates. Styling for the graph container and active resource panel is also added via new SCSS variables and layout rules.

_apps/zotonic\_mod\_admin\predicate · high confidence

Add license headers and build configuration to Zotonic modules

Each module in the \apps\ directory (including \zotonic\_mod\_acl\_mock\, \zotonic\_mod\_admin\, \zotonic\_mod\_admin\_category\, \zotonic\_mod\_admin\_config\, and \zotonic\_mod\_admin\_frontend\) now includes an Apache 2.0 LICENSE file and a \rebar.config\ file. The configuration enforces a minimum OTP version of 23, enables debug info, and sets up \ex\_doc\ for Hex documentation, preparing these applications for distribution as packages.

(repo-wide) · high confidence

Add localization and plugin logic for the TinyMCE zmedia editor plugin

The zmedia plugin for the TinyMCE editor now includes English, Dutch, and Russian translation files, enabling users to see the interface in their preferred language. The plugin's core JavaScript (plugin.min.js) has been added, implementing the logic for inserting and managing media items, including support for alignment, size, crop, link, and caption properties. This change provides the necessary infrastructure for the editor to handle Zotonic media items with full localization support.

_apps/zotonic\_mod\_editor\tinymce/priv/lib/js/tinymce-5.10.2/tinymce/plugins/zmedia · high confidence

Add m\_comment model for managing page comments

A new m\_comment model is introduced to handle comment operations, including listing comments by resource, counting them, retrieving individual comments, and inserting new ones. The model enforces access control by checking resource visibility and user permissions, and it caches comment listings and counts. It also provides an is\_deletable check to verify if a comment can be removed.

_apps/zotonic\_mod\comment/src/models · high confidence

Add media overlay for viewing larger media items

The mod\_wires module now includes a new media overlay feature that allows users to view larger versions of media items. This includes a new template (\_mediaoverlay.tpl) that renders media with navigation controls for previous/next items, a JavaScript module (mediaoverlay.js) to handle click events and notify the system, and corresponding CSS styles (mediaoverlay.scss/css) that define the overlay's appearance, including responsive adjustments for smaller screens. The media overlay is configured via a new mediaclass.config file.

_apps/zotonic\_mod\wires · high confidence

Add module management screen to the admin interface

A new module management screen has been added to the admin interface, allowing users to view, activate, and deactivate modules. The module list is sorted by status and priority, and modules with configuration options display a configuration button to open a dialog for setting required options.

_apps/zotonic\_mod\_admin\modules/src · high confidence

Add new JavaScript modules for HTTP ping, cryptography, hotkeys, and UI enhancements

The application now includes several new JavaScript modules in the \zotonic\_mod\_base\ library. These additions provide HTTP ping functionality for network latency and loss monitoring, cryptographic encoding/decoding (MD5, SHA1, Base64, XTEA), keyboard hotkey handling, loading masks for UI feedback, text shortening with HTML awareness, time picker support, scroll-based history management, UBF encoding, and enhanced autocomplete, clickable element, date picker, dialog, and feedback widgets. These modules expand the client-side capabilities for network monitoring, security, user interaction, and UI management.

_apps/zotonic\_mod\base/priv/lib/js/modules · high confidence

Add non-destructive image editing capabilities

The image edit module now provides a modal interface for non-destructive image adjustments including rotation, cropping, contrast, brightness, roll, tilt, and pan. These edits are stored as properties and applied when images are resized, leaving the original file untouched. The feature includes a new overlay-based UI, CSS styling, and backend logic to manage image edit settings.

_apps/zotonic\_mod\_image\edit · high confidence

Add page merge functionality to admin interface

The admin interface now includes a new page merge feature, allowing administrators to combine two pages into one. This includes a search and selection screen to find and choose the second page, a comparison view that displays differences between the two pages (including title, content, and now depiction/media), and a confirmation dialog where the user selects the 'winner' and 'loser' pages. The merge process also offers an option to add missing translations from the loser to the winner.

_apps/zotonic\_mod\_admin\merge/priv/templates · high confidence

Add password acceptability validator

A new \acceptable\_password\ validator is now available for validating password strength and length against site configuration. It checks minimum length, regex criteria, and optionally checks against known data breaches via the Have I Been Pwned service. The validator supports optional parameters like \allow\_empty\ and custom \failure\_message\.

_apps/zotonic\_mod\authentication/src/validators · high confidence

Add site update module for Git/Mercurial updates

A new module, mod\_site\_update, is introduced to allow administrators to update a site's code from a remote version control system (Git or Mercurial). This includes a new admin interface for configuring a webhook token, status buttons on the System -\> Status page to trigger updates, and a model API to check VCS status and handle webhook requests. The module also supports updating the Zotonic core itself via the status site.

_apps/zotonic\_mod\_site\update · high confidence

Add structured data (JSON-LD) and SEO admin interface

The mod\_seo module now generates Schema.org structured data in JSON-LD format for articles, events, videos, and other content types, enabling rich search results. An admin interface at /admin/seo allows configuring global SEO settings, including keywords, descriptions, and search engine verification codes for Google, Bing, Yandex, and Google Search Console. The module also supports Google Analytics, Google Tag Manager, and Plausible tracking scripts, with options to exclude pages or categories from search engine indexing.

_apps/zotonic\_mod\seo · high confidence

Add templates for rendering and editing page blocks

The admin interface now supports editing and displaying page blocks. For editing, new templates provide forms for header and text blocks, and a page block editor with connect/disconnect actions. For display, new templates render page blocks in various styles (header, text, quote, aside, inline, video, media) and handle the visual presentation of block content on the frontend.

_apps/zotonic\_mod\admin/priv/templates/blocks · high confidence

Add temporary resource filter for unowned resources

Introduced a new \filter\_temporary\_rsc\ module that creates temporary resources which are automatically deleted if unmodified after an hour. The filter supports both map and list-based property arguments, ensuring that only the session user who created the resource can edit it. This enables workflows where an intermediate title-dialog is skipped, with the system managing the resource's lifecycle via a background task.

_apps/zotonic\_mod\admin/src/filters · high confidence

Add test sandbox site for automated testing

A new test sandbox site is introduced, providing a dedicated environment for automated testing. This includes a configuration file (zotonic\_site.config) that defines the site's modules and database schema, along with a controller and templates for testing web interactions, postbacks, and UI effects. The setup also includes a basic test suite to verify the sandbox is active and its default modules are running.

_apps/zotonic\_site\testsandbox · high confidence

Add timezone and localization configuration to the admin interface

The admin interface now includes a dedicated configuration page for localization settings, allowing administrators to set a default timezone and choose whether to fix the timezone for all users. This is supported by new templates for the admin panel, a dispatch rule for the admin controller, and a JavaScript library (jstz) for client-side timezone detection. Additionally, translation files for date and time strings in multiple languages (Irish, Indonesian, Japanese, Dutch, Polish, Portuguese, Russian) have been added to support the localization features.

_apps/zotonic\_mod\l10n · high confidence

Add two-factor authentication (2FA) module

The new \zotonic\_mod\_auth2fa\ module introduces two-factor authentication using TOTP. This adds a configuration option to enforce 2FA on login or require it once after logon, and provides admin controls to manage user group settings and remove 2FA from accounts.

_apps/zotonic\_mod\auth2fa/src · high confidence

Add video embed support for YouTube, Vimeo, and other services

The zotonic\_mod\_video\_embed application is introduced to handle embedding videos as media pages. It allows users to paste YouTube, Vimeo, or other service URLs in the admin's create media/page dialog, which then generates the correct embed code. The module stores embed information in the medium table and provides templates to render the embedded video with responsive wrappers. Admin users can view and manage video embed details such as service, ID, author, and canonical URL.

_apps/zotonic\_mod\_video\embed · high confidence

Added Hello World controller for server health checks

A new Erlang controller, \controller\_hello\_world\, has been added to the Zotonic development module. This controller serves the string "Hello, World!" and is intended to be used as a dispatch rule to verify that the server is responding.

_apps/zotonic\_mod\development/src/controllers · high confidence

Added QR code generation and base32 encoding support

The 2FA module now includes a complete QR code generation implementation, adding new support files for QR encoding, matrix manipulation, masking, and Reed-Solomon error correction. Additionally, a new base32 encoding module and bit manipulation utilities have been introduced to support the QR functionality.

_apps/zotonic\_mod\auth2fa/src/support · high confidence

Added ability to disconnect authentication methods

Users can now disconnect specific authentication methods from their account. This new action allows for the removal of linked identities, providing greater control over account security and connected services.

_apps/zotonic\_mod\authentication/src/actions · high confidence

Added admin statistics controller for system statistics

A new Erlang controller, controller\_admin\_statistics, has been added to handle requests for the admin statistics page. This controller manages access control via the mod\_admin\_statistics ACL module and renders the admin\_statistics template to display system statistics in the admin interface.

_apps/zotonic\_mod\_admin\statistics/src/controllers · high confidence

Added base64url encoding and text diffing utilities

The application now includes a new Erlang module, base64url.erl, which provides functions for encoding and decoding data using the base64url alphabet (RFC 4648). Additionally, the backup module incorporates JavaScript libraries for generating text diffs: wdiff.js and jsdiff.js implement word-based and character-based diffing algorithms, which are utilized by the z.make\_diff.js module to render visual differences in text content.

_apps/zotonic\_core/src/base64url, apps/zotonic\_mod\backup/priv/lib · high confidence

Added build scripts and configuration to integrate Cotonic assets

The zotonic\_mod\_base app now includes shell scripts (cotonic-fetch.sh, cotonic-update.sh, cotonic-clean.sh) and a rebar.config file to manage the download and placement of Cotonic JavaScript files (cotonic.js, cotonic-worker.js, cotonic-service-worker.js) into the priv/lib/cotonic directory. This change establishes the build-time process for bundling these frontend assets, supported by an Apache 2.0 LICENSE file.

_apps/zotonic\_mod\base · high confidence

Added dispatch rules for ACL rule management and testing

The application now maps specific URL paths to controllers and templates for managing Access Control List (ACL) rules. This includes endpoints for viewing and editing rules for resources, collaboration, modules, uploads, and options, as well as a dedicated test interface for ACL rules. These routes enable administrators to configure and test ACL policies through the admin interface.

_apps/zotonic\_mod\_acl\_user\groups/priv/dispatch · high confidence

Added dispatch rules for the admin frontend edit page

The admin frontend module now includes a dispatch configuration that maps the 'edit' URL pattern to the 'page' controller. This setup renders the 'page\_admin\_frontend\_edit.tpl' template, enforces authentication, applies SEO noindex headers, disables caching, and handles both static and dynamic (by ID) edit routes.

_apps/zotonic\_mod\_admin\frontend/priv/dispatch · high confidence

Added email and username uniqueness validators

New validators have been introduced for the admin identity module to check if an entered email address or username is unique within the system. The email validator (\validator\_admin\_identity\_email\_unique\) verifies uniqueness by querying the \m\_identity\ table, supporting an optional \id\ parameter to exclude the current user's record during editing. The username validator (\validator\_admin\_identity\_username\_unique\) similarly checks for uniqueness, including a check against reserved names, and provides a user-friendly error message when a username is already in use. Both validators support an \id\ argument to allow editing without triggering a conflict for the current user.

_apps/zotonic\_mod\_admin\identity/src/validators · high confidence

Added email normalization filter for identity management

A new filter, \filter\_normalize\_email\, has been introduced to the admin identity module. This component is responsible for normalizing email addresses used as keys in the identity table. It processes the input by lowercasing and trimming the email address, ensuring consistent formatting for identity lookups.

_apps/zotonic\_mod\_admin\identity/src/filters · medium confidence

Added hasedge validator for checking resource edges

A new 'hasedge' validator is now available to verify that a resource has a specific number of edges with a given predicate. This allows forms to enforce minimum or maximum edge counts (e.g., requiring at least one author or keyword) during form submission, with success or error messages displayed based on the validation result.

_apps/zotonic\_mod\admin/src/validators · high confidence

The TinyMCE editor now supports inserting internal links to Zotonic pages directly within the body text. This change introduces a new 'zlink' plugin for TinyMCE 5.10.2, adding a 'Zotonic Link' button and menu item that trigger a dialog for selecting internal links. The plugin includes localization files for English, Dutch, and Russian to support the 'Insert internal link' and 'Insert an internal link' labels.

_apps/zotonic\_mod\_editor\_tinymce/priv/lib/js/tinymce-4.9.3/tinymce/plugins/zlink, apps/zotonic\_mod\_editor\tinymce/priv/lib/js/tinymce-5.10.2/tinymce/plugins/zlink · high confidence

Added language profile data for automatic language detection

The translation module now includes n-gram profile data for multiple languages (including Afrikaans, Arabic, Belarusian, etc.) to support automatic language detection. This data is used by the system to guess the language of a resource when no language is explicitly set, enabling better automatic translation and URL handling for multilingual sites.

_apps/zotonic\_mod\translation · high confidence

Added loadmore model for dynamic content loading

A new 'loadmore' model has been introduced to handle loading additional content via button presses. This model supports silent URL replacement and flexible argument handling, allowing users to dynamically load and replace content templates based on message payloads.

_apps/zotonic\_mod\base/priv/lib/js/models · high confidence

Added localization files and core plugin logic for the Zotonic media plugin

The zmedia plugin for the TinyMCE editor now includes English, Dutch, and Russian translation files that map 'Insert a media item' and 'Insert media item' to their respective languages. The plugin's main JavaScript file (plugin.min.js) was added, implementing the logic to insert, display, and manage media items within the editor, including handling properties dialogs and click events for media elements.

_apps/zotonic\_mod\_editor\tinymce/priv/lib/js/tinymce-4.9.3/tinymce/plugins/zmedia · high confidence

Added manifest.json template and robots.txt for site configuration

A new manifest.json template is introduced to define the web application's metadata, including title, scope, display mode, and icon sizes (144, 192, 512). Additionally, a robots.txt file is added to restrict search engine access to admin and language selection URLs, while allowing all other URLs.

_apps/zotonic\_mod\base/priv/lib/misc · high confidence

Added mock ACL module for testing

A new mock ACL module (mod\_acl\_mock) has been added to the Zotonic framework to provide minimal dependencies for running the testsandbox. This module is explicitly marked as a mock for testing purposes and should not be used in production environments.

_apps/zotonic\_mod\_acl\mock/src · high confidence

Added module management actions for activation, deactivation, and rescanning

The admin module now includes new actions to manage module states. Administrators can now activate or deactivate modules via the admin interface, with checks for cyclic dependencies and missing prerequisites. Additionally, a new 'module rescan' action allows administrators to force a rescan of all modules, actions, and templates, ensuring the dispatcher reloads all dispatch rules after changes.

_apps/zotonic\_mod\_admin\modules/src/actions · high confidence

The \z.icons\ module now includes a new icon font and associated CSS/JS resources, providing a set of 25 glyphs for common UI actions (edit, ok, minus, plus, help, info, user, cross, grab/drag, logo) and social media platforms (Google Plus, LinkedIn, Instagram, Twitter, Facebook, GitHub). This adds visual assets for navigation, status indicators, and social sharing links within the Zotonic application.

_apps/zotonic\_mod\base/priv/lib/css/z.icons · high confidence

Added source SVGs for the application favicon

New SVG source files (favicon.svg and z.svg) were added to the images directory, providing the original vector assets for the site's favicon.

_apps/zotonic\_mod\base/priv/lib/images · high confidence

Admin backup management and revision control

The admin interface now provides a dedicated backup management screen where administrators can download nightly backups, configure backup settings, and restore resources. Additionally, a new revision control feature allows users to view differences between resource versions and revert to previous states, with access controlled by the mod\_backup and mod\_admin permissions.

_apps/zotonic\_mod\backup/src/controllers · high confidence

Admin config model exposes SSL, security dir, and module settings via new API

A new model \m\_admin\_config\ is introduced to expose admin configuration data through a structured API. Admin users can now retrieve SSL certificate metadata, the resolved security directory path, and a list of available module configurations with their default values. Non-admin users receive empty or undefined responses for these endpoints, ensuring that sensitive configuration details remain restricted to administrators.

_apps/zotonic\_mod\_admin\config/src/models · high confidence

Admin identity model exposes configuration endpoints for password and user defaults

A new Erlang model, m\_admin\_identity, has been added to expose configuration values for admin identity settings. This model provides read-only access to the password validation regex, as well as the default category and content group for newly created users, allowing these settings to be retrieved via specific API paths.

_apps/zotonic\_mod\_admin\identity/src/models · high confidence

Admin interface for managing OAuth2 apps and consumers

The OAuth2 module now provides a complete admin interface for managing OAuth2 applications and consumers. Administrators can create, edit, and delete OAuth2 apps (for authentication and API access control) and consumers (for importing content and authenticating users from external sites). The new dialogs allow configuring app details, redirect URLs, client credentials, and token permissions. This enables easier management of OAuth2 integrations directly from the admin panel.

_apps/zotonic\_mod\oauth2 · high confidence

Admin interface for managing custom redirects

The ZMod custom\_redirect module now provides a dedicated admin interface for managing domain and path-based redirects. Administrators can view, add, and delete redirect rules via a new template (admin\_custom\_redirect.tpl) and a corresponding dispatch route at /admin/custom-redirect. The interface allows configuration of host, path, and redirect destination, with support for permanent (301) redirects.

_apps/zotonic\_mod\_custom\redirect/priv · high confidence

Admin interface for managing edge predicates

A new admin module has been added to allow users to edit, delete, and move edge predicates directly from the admin interface. This includes a dedicated page for listing all defined predicates, with support for bulk deletion and moving edges to a new predicate. The module hooks into the resource update process to save predicate-specific fields (subject/object lists) and ensures caches are properly flushed when predicate metadata changes.

_apps/zotonic\_mod\_admin\predicate/src · high confidence

Admin interface module and app definition added

The mod\_admin module and its application source file are introduced, establishing the core administrative backend for content editing and site administration. The module provides documentation on extending the admin menu, customizing the edit page with sidebar and content widgets, overriding TinyMCE options, and customizing the admin overview page with category-specific information and sorting.

_apps/zotonic\_mod\admin/src · high confidence

Admin module routing rules added

The admin module now includes a dispatch configuration that maps URL paths to specific controllers and templates. This enables navigation to the admin overview, media, edit, referrers, and status pages within the admin interface.

_apps/zotonic\_mod\admin/priv/dispatch · high confidence

Admin widgets now support collapsible panels with persistent state

The admin interface now allows users to collapse and expand widget panels. Each panel's expanded/collapsed state is saved in the browser's session storage, so the last used state is remembered across page loads. The widget header includes a toggle icon that lets users minimize or maximize the content area, improving the admin UI by reducing visual clutter.

_apps/zotonic\_mod\admin/priv/lib/js/modules · high confidence

Automated Hex package publishing and release preparation

The release process now includes automated scripts to prepare and publish all Zotonic applications to the Hex package manager. The new \release/prepare-release.sh\ script updates version numbers across the codebase, while \release/hex-publish.sh\ handles the build and publication of core dependencies, file handlers, and other modules in a specific order to ensure correct dependency resolution and index updates.

release · high confidence

Backup module introduces encryption, replication, and granular retention controls

The mod\_backup module has been significantly enhanced with new capabilities for data protection and recovery. Users can now encrypt backups via a new configuration option, securing stored data. The module also supports data replication and failover by allowing a server in 'backup' mode to download and import the latest backup from a filestore, automatically restoring the database, configuration, and files. Additionally, the module now tracks per-resource revision logs, enabling individual resource rollback and recovery, with configurable retention periods for general resources (18 months), user resources (90 days), and deleted user data (30 days).

_apps/zotonic\_mod\backup/src · high confidence

Content group management in the admin interface

The admin interface now supports assigning and filtering by content groups. A new sidebar widget allows editors to select a content group when creating or editing a page. A filter panel on the content overview lets users filter the list by content group. A bulk update dialog includes a content group selector. The delete confirmation dialog now offers the option to move pages to another content group or delete them entirely.

_apps/zotonic\_mod\_content\groups/priv · medium confidence

Default ACL rules and support modules for user groups

The mod\_acl\_user\_groups application now includes a new set of support modules in the src/support directory, introducing default access control rules and management utilities. This includes acl\_default\_rules.erl, which defines standard permissions for anonymous, member, editor, and manager groups across default and system content groups; acl\_user\_group\_rebuilder.erl, which handles the expansion and caching of ACL rules in ETS tables; acl\_user\_group\_checks.erl, which provides the core logic for verifying permissions such as insert, update, and move actions; and admin\_acl\_rules.erl, which exposes the administrative interface for managing these rules. These changes establish the foundational structure for user-group-based access control within the application.

_apps/zotonic\_mod\_acl\_user\groups/src/support · high confidence

Extract HTTP listener into a dedicated zotonic\_listen\_http application

The HTTP listener functionality has been extracted from the core into a new, standalone application named zotonic\_listen\_http. This new module manages the lifecycle of HTTP and HTTPS listeners using the cowmachine library, providing explicit start and stop controls for IPv4 and IPv6 connections. Additionally, a dedicated metrics callback module (zotonic\_listen\_http\_metrics) has been introduced to capture and record HTTP request performance data, including duration, status codes, and payload sizes, into the z\_stats system.

_apps/zotonic\_listen\http/src · high confidence

Filehandler and filewatcher apps now include Apache 2.0 license and build configs

The zotonic\_filehandler and zotonic\_filewatcher applications now include Apache License 2.0 files and rebar3 configuration files. The filehandler's build configuration specifies dependencies on zotonic\_filewatcher, zotonic\_fileindexer, zotonic\_stdlib (\~\> 1.20), erlexec (\~\> 2.0), jobs (0.10.0), and buffalo (\~\> 2.0). The filewatcher's build configuration specifies dependencies on zotonic\_notifier and erlexec (\~\> 2.0).

_apps/zotonic\filehandler · high confidence

Introduce DKIM email signing for outgoing messages

The mod\_email\_dkim module now automatically signs outgoing emails with DomainKeys Identified Mail (DKIM) signatures, improving email authentication and deliverability. The module generates an RSA keypair on first install and provides an admin panel at /admin/email/dkim to display the required DNS TXT record for configuration. It signs standard headers (From, To, Subject, etc.) and includes List-Unsubscribe headers as required by RFC 8058.

_apps/zotonic\_mod\_email\dkim · high confidence

Introduce a new search view with autocomplete and faceted search UI

The search module now includes a new search view that provides an autocomplete interface for text search and supports faceted search with alternative counts per facet. This change adds the necessary CSS styles for the search results list, JavaScript for handling input and navigation, and templates for rendering search results and list items. Additionally, a status endpoint is added to check the health of the search facet table, and a button is provided in the admin status to rebuild search facets.

_apps/zotonic\_mod\search · high confidence

Introduce content group management module

Added the \mod\_content\_groups\ module, which enables hierarchical content grouping and access-control rules on resources. This new feature allows administrators to categorize content into a hierarchical structure, with built-in ACL checks to prevent deletion of content groups that still contain resources. The module handles admin menu integration, resource updates, and provides callbacks for managing content group data and schema.

_apps/zotonic\_mod\_content\groups/src · high confidence

The Zotonic platform now includes a new \mod\_cookie\_consent\ module that manages user consent for cookies, specifically targeting embedded content like media, iframes, JavaScript, and CSS. This feature allows the platform to hide or show elements based on user preferences for functional, statistics, or all cookies. The module provides templates and attributes (e.g., \data-cookie-consent\) to wrap external content so it is only loaded if the user has consented. It also includes a data model for cookie consent preferences and handles the \observe\_media\_viewer\_consent\ event to render consent placeholders.

_apps/zotonic\_mod\_cookie\consent/src · high confidence

The \zotonic\_mod\_cookie\_consent\ module is added, providing a system to manage user consent for cookies before loading external content. This includes a JavaScript library (\z.cookie\_consent.js\) that handles the consent dialog, CSS styles for the consent banner and preview states, and templates (\\_cookie\_consent.tpl\, \\_media\_cookie\_consent.tpl\) that wrap external media and scripts in a way that delays their execution until consent is given. The module also adds an admin widget for editing cookie consent text and configuration.

_apps/zotonic\_mod\_cookie\consent/priv · high confidence

Introduce m\_acl\_rule and m\_acl\_user\_group models for ACL rule and user-group management

Adds the m\_acl\_rule and m\_acl\_user\_group model files, exposing a structured API for inspecting and managing ACL rules and user-group memberships. Users can now query ACL rule states, check insertion and movement permissions, retrieve upload size and MIME type defaults, and verify collaboration group usage through dedicated model endpoints.

_apps/zotonic\_mod\_acl\_user\groups/src/models · medium confidence

Introduce mod\_admin\_frontend for simplified content editing

Added a new 'mod\_admin\_frontend' module that provides a streamlined, Bootstrap-based interface for editing pages, menu trees, and collections. This module is designed for non-admin users, offering a subset of the full admin capabilities to reduce complexity. The implementation includes the main Erlang module (mod\_admin\_frontend.erl) handling postback events and template rendering, along with the application source file (zotonic\_mod\_admin\_frontend.app.src) which declares dependencies on kernel, stdlib, and zotonic\_core.

_apps/zotonic\_mod\_admin\frontend/src · high confidence

Introduce mod\_authentication module for user authentication

The mod\_authentication module is introduced to handle user authentication and identification. It provides controllers for logon and logoff, implements various hooks for access control, and supports configuration options such as password length, one-step logon, and remember-me functionality. The module also includes event handling for admin menu, client logon/switch user, and hourly maintenance tasks.

_apps/zotonic\_mod\authentication/src · high confidence

Introduce mod\_base as the new base module for Zotonic

The mod\_base module is introduced as the central container for basic Zotonic components, including dispatch rules, actions, and template components. This new module provides foundational configuration options for site titles, pagination, session management, and email handling, while also managing core events like content type dispatching and edge hierarchy updates.

_apps/zotonic\_mod\base/src · high confidence

Introduce model API for backup configuration and revision management

The backup module now exposes a structured model API for managing backup settings and revision data. Administrators can query backup configuration (e.g., encryption status, daily dump settings, directory paths) and manage resource revisions (e.g., listing, title retrieval, retention periods) through specific model paths. Access to most backup model endpoints is restricted to users with the 'use' permission on mod\_backup, ensuring that sensitive backup metadata and revision history are only accessible to authorized users.

_apps/zotonic\_mod\backup/src/models · high confidence

Introduce modular access control for user groups and content groups

The zotonic\_mod\_acl\_user\_groups module is introduced to provide rule-based access control, allowing administrators to define permissions for user groups (anonymous, members, editors, managers) and content groups (default, system, collaboration). This enables granular control over resource visibility, insertion, updates, and deletions, as well as file upload restrictions (size and MIME types) and property-level privacy settings for sensitive fields like email and address. The module also supports module-level access rules and manages ACL state via a new schema version.

_apps/zotonic\_mod\_acl\_user\groups/src · high confidence

Introduce periodic task scheduling and tick notifications

The mod\_cron module now provides a built-in mechanism for scheduling regular jobs and emitting periodic tick notifications. It registers scheduled jobs using the erlcron library and emits tick events (tick\_1s, tick\_1m, tick\_5m, tick\_10m, tick\_15m, tick\_30m, tick\_1h, tick\_2h, tick\_3h, tick\_4h, tick\_6h, tick\_12h, and tick\_24h) via the notifier. Modules can define periodic jobs using the -mod\_cron\_jobs attribute, which are then managed by mod\_cron, allowing for automated background tasks and time-based event observation.

_apps/zotonic\_mod\cron/src · high confidence

Introduce server-side session storage for client and server data

Adds a new server-side storage mechanism tied to the client's session ID, allowing applications to store and retrieve data on the server. The feature includes a public API for standard key-value storage and a separate secure API for sensitive data like OAuth secrets, which is not accessible from the client. Storage is managed by background processes that expire after 900 seconds of inactivity and are limited to 100 KB of data. Configuration keys \mod\_server\_storage.storage\_expire\ and \mod\_server\_storage.storage\_maxsize\ allow tuning the timeout and size limits.

_apps/zotonic\_mod\_server\storage · high confidence

Introduce the zotonic\_notifier application for event-driven notifications

Adds the zotonic\_notifier application, providing a notification system that allows components to register observers for specific events. The system supports synchronous and asynchronous notifications, priority-based execution order, and operations to map, fold, or retrieve observers. It includes a supervisor for managing notifier instances and workers that handle the actual event dispatching, enabling decoupled communication between different parts of the application.

_apps/zotonic\notifier · high confidence

Introduce token management module for authentication

A new module, z\_authentication\_tokens, has been added to handle the creation, decoding, and caching of authentication tokens and cookies. This introduces a centralized mechanism for managing auth cookies, autologon cookies, and onetime tokens, including specific expiration times (e.g., 30 seconds for onetime tokens) and caching strategies for request handling.

_apps/zotonic\_mod\authentication/src/support · high confidence

Introduce web worker-based file uploader with drag-and-drop support

The file uploader has been refactored to use a dedicated web worker (zotonic.fileuploader.worker.js) that uploads files in parallel 128KB blocks for improved performance and responsiveness. This change adds drag-and-drop upload support in the admin interface (z.fileuploader-admin.js), allowing users to drop files directly onto the page. The backend (controller\_fileuploader.erl, m\_fileuploader.erl, z\_fileuploader.erl) now handles block-based uploads via MQTT topics, supporting features like upload cancellation, progress tracking, and error handling. The module also includes a new license file (Apache 2.0) and associated header/template files to wire the new client-side and server-side components together.

_apps/zotonic\_mod\fileuploader · high confidence

Introduce zotonic\_apps package for simplified dependency management

A new 'zotonic\_apps' package has been added to the 'apps/zotonic\_apps' directory, providing a single dependency that includes all core Zotonic applications. This allows users to easily fetch and manage all core applications from Zotonic by adding 'zotonic\_apps' to their 'rebar.config' dependencies, simplifying the setup process for new projects.

_apps/zotonic\apps · high confidence

Introduce zotonic\_fileindexer application

Added the zotonic\_fileindexer application, which provides a fileindex record for directory indices. The new module includes an Apache 2.0 license, a header file defining the fileindex record structure, and a rebar3 configuration that declares a dependency on zotonic\_notifier.

_apps/zotonic\fileindexer · high confidence

Introduce zotonic\_fileindexer for recursive file indexing

A new zotonic\_fileindexer application has been added to index files within application directories. It provides a caching layer (zotonic\_fileindexer\_cache) and a recursive scanner (zotonic\_fileindexer\_scan) to find files matching specific patterns, with support for flushing the cache to force a rescan.

_apps/zotonic\fileindexer/src · high confidence

Introduce zotonic\_launcher application for server lifecycle management

The zotonic\_launcher application is introduced to manage the startup, shutdown, and configuration loading for the Zotonic server. It provides functions to start and stop the server, handle configuration files, and coordinate the lifecycle of dependent applications. The launcher also includes a supervisor to manage child processes like HTTP, SMTP, and MQTT listeners, ensuring proper initialization and cleanup.

_apps/zotonic\launcher/src · high confidence

Introduces shared admin JavaScript utilities

A new \admin-common.js\ file is added to the admin interface, providing shared JavaScript utilities for the admin panel. This includes an \adminLinkedTable\ widget that makes table rows and cells clickable, an \autofocus\ widget for form fields, a scroll listener that adds a 'scrolled' class to the body, a keyboard shortcut (Ctrl+S) to submit forms, and helper functions for managing block names and media selection.

_apps/zotonic\_mod\admin/priv/lib/js/apps · high confidence

Introduction of a typed key/value store module

A new typed key/value store module (mod\_tkvstore) is introduced, providing a high-performance, low-latency interface for storing and retrieving structured data. The module implements a gen\_server that serializes get/put/delete operations and persists them to a PostgreSQL table. It includes a corresponding model (m\_tkvstore) that exposes API paths for reading and writing values, along with initialization logic to ensure the required database table exists. The implementation uses the standard Erlang logger for structured logging and depends on zotonic\_core.

_apps/zotonic\_mod\tkvstore · high confidence

Introduction of new CLI launcher and documentation generation scripts

The 'bin' directory now includes three new executable scripts: 'zotonic', a shell-based launcher that sets up the ZOTONIC environment variable and delegates to the Erlang-based 'zotonic\_launcher'; 'generate\_edoc.escript', an escript that generates EDoc documentation for core and module apps; and 'mergepot', a disabled shell script for translation file merging. These scripts provide new entry points for documentation generation and command-line interaction.

bin · high confidence

Introduction of the zotonic\_mod\_artwork module for icons and images

A new module, zotonic\_mod\_artwork, has been added to provide a collection of icons and images for sites and modules. This includes Font Awesome 4 and 3, Material Design Iconic Font, and various image assets such as emoticons, country flags, and social media icons. The module is configured with an Apache-2.0 license and depends on the standard kernel and stdlib applications.

_apps/zotonic\_mod\artwork/src · high confidence

New CLI commands for site management, backups, and debugging

The zotonic\_launcher command-line interface gains a suite of new commands to improve site lifecycle management and operational visibility. Administrators can now create new sites with the \addsite\ command, which supports options for skeletons, database configuration, and umbrella structures. Backup management is enhanced with \backup\ commands to list, start, restore, and download backups, alongside a \decrypt\ command for encrypted backup files. Operational tasks are expanded with \compile\ and \compilefile\ for recompilation, \config\ and \configtest\ for inspecting and validating configuration, and \connectdb\ to verify database connectivity. Additionally, \debug\ starts the node in the foreground, \etop\ provides process monitoring, \flush\ clears caches, \load\ reloads modules, and \logtail\ follows log files. These commands collectively provide deeper control over the running system.

_apps/zotonic\launcher/src/command · high confidence

New Docker development environment for Zotonic

A new Docker-based development environment has been introduced, providing a containerized setup for running Zotonic alongside PostgreSQL. The change includes a new Dockerfile.dev based on Erlang 27.3.4, a docker-entrypoint.sh script that handles user/group ID mapping (fixing macOS permission issues), and configuration files (erlang.config, zotonic-docker.config) that configure logging and database connections. This allows developers to run the application in a consistent, isolated environment with proper file ownership and logging.

docker · high confidence

New LESS styles for icons, modals, and bridge status

Added new LESS source files to compile CSS for icon integration (supporting Zotonic, Font Awesome, and Material Design icons), modal dialog styling (including multi-level overlay support), and a visual warning for bridge connection status.

_apps/zotonic\_mod\base/priv/lib-src/less · high confidence

New SEO sitemap module with manual rebuild and per-page priority/frequency settings

The \zotonic\_mod\_seo\_sitemap\ app is introduced to generate and manage site sitemaps for search engine indexing. Administrators can now manually trigger a sitemap rebuild via a new button in the SEO settings and status pages. Additionally, content editors can set the sitemap priority and change frequency for individual pages and categories through the admin interface, allowing fine-grained control over how search engines index the site.

_apps/zotonic\_mod\_seo\sitemap · high confidence

New admin configuration and email management interface

The admin interface now features a dedicated System Configuration page that lists all available configuration keys, their default values, and descriptions. Administrators can create, edit, and delete configuration entries directly from this list. Additionally, the Email configuration section has been expanded to include a test email form, allowing admins to send test messages and view their status. The SSL certificates page has also been updated to display certificate details and expiration information for all active modules.

_apps/zotonic\_mod\_admin\config/priv/templates · high confidence

New admin controllers and Gravatar filter for comment moderation

Added new Erlang controllers for the comment module: \controller\_admin\_comments\ provides an admin interface to moderate, delete, and toggle the visibility of comments, while \controller\_admin\_comments\_settings\ allows authorized users to save comment form settings. Additionally, a new \filter\_gravatar\_code\ filter was introduced to generate MD5 hashes for email addresses, enabling Gravatar image display.

_apps/zotonic\_mod\comment/src/controllers · high confidence

New admin identity module for user management

A new \mod\_admin\_identity\ module has been added to the admin interface, providing a user interface to create new users, manage passwords, and handle identity verification. The module supports configuring password complexity rules via a \password\_regex\ configuration key, assigns new users to a configurable category and content group, and includes documentation on migrating legacy password hashes.

_apps/zotonic\_mod\_admin\identity/src · high confidence

New admin interface and templates for comment moderation

The comment module now provides a dedicated admin section for managing user-submitted comments. Administrators can view recent comments in a table, view the original page, toggle comment visibility (publish/unpublish), and delete comments. A settings page allows administrators to enable or disable comment moderation. The public comment form includes fields for name, email, and message, with optional moderation notices. Avatar images are now loaded over HTTPS.

_apps/zotonic\_mod\comment/priv · high confidence

New admin interface for managing and sorting categories

A new controller has been added to provide an editable overview of all categories, allowing users to rearrange the category tree, add new categories, or remove existing ones through the admin interface.

_apps/zotonic\_mod\_admin\category/src/controllers · high confidence

New admin interface for managing user identities and credentials

The admin interface for managing user identities has been significantly restructured and expanded. A new dedicated 'Users' overview page allows administrators to list, search, and filter users by email or name. Administrators can now set, change, or delete usernames and passwords directly from the user edit sidebar and overview, with a confirmation dialog for deletions. The user creation flow has been updated to include fields for name, email, category, and username/password. Email verification is managed via a new table in the user edit page, allowing admins to verify, delete, or view the status of email addresses. Additionally, the admin can log in as a specific user, and the system now supports sending welcome emails to new users.

_apps/zotonic\_mod\_admin\identity/priv/templates · high confidence

New admin interface for requesting Let's Encrypt SSL certificates

Administrators can now request and manage Let's Encrypt SSL certificates directly from the Zonotic admin panel. This change introduces a dedicated configuration panel that displays the current certificate status, including validity, expiration, and alternative names (SANs). The interface includes a form to request new certificates, validates hostnames and reachability before submission, and provides clear error messages if port 80 or 443 are not correctly configured. The status template also links to external debugging tools like letsdebug.net to assist with certificate issuance issues.

_apps/zotonic\_mod\_ssl\letsencrypt · high confidence

New admin log views for UI errors, email status, and CSP reports

The logging module now provides dedicated admin UI pages for viewing browser-side UI errors, email delivery status, and Content-Security-Policy violations. A new JavaScript client-side error handler posts errors to the server, which are stored in a ring buffer to prevent overload. The email log displays the status of sent and received emails, including sending, sent, relayed, bounce, failed, retry, blocked, and received states. The CSP log shows the latest 100 unique Content-Security-Policy violation reports, including directives, blocked URLs, and source locations. All logs are accessible via the admin interface under the 'Log' section.

_apps/zotonic\_mod\logging · high confidence

New admin menu item and separator record definitions

A new header file, admin\_menu.hrl, was added to the admin module, introducing Erlang records for menu\_item and menu\_separator. These records define the structure for admin menu entries, including fields for id, parent, label, url, icon, visiblecheck, and sort order, as well as a separator record with parent, visiblecheck, and sort fields.

_apps/zotonic\_mod\admin/include · high confidence

New admin routes for user management, identity verification, and resource merging

Administrators can now access new endpoints for managing users and verifying identities, as well as merging and comparing resources. Specifically, the identity module adds routes for listing users and verifying identity keys, while the merge module adds routes for editing and comparing merged resources.

_apps/zotonic\_mod\_admin\_identity/priv/dispatch, apps/zotonic\_mod\_admin\merge/priv/dispatch · high confidence

New admin statistics page with real-time system metrics

The admin statistics page has been introduced to display real-time system metrics, including memory usage, IO, database status, and filezcache stats. The new template structure includes reusable components for stat rows and panels, along with JavaScript logic to update values via MQTT subscriptions to 'bridge/origin/$SYS/statistics' and 'bridge/origin/$SYS/erlang' topics.

_apps/zotonic\_mod\_admin\statistics/priv/templates · high confidence

New admin status and configuration model endpoints

The admin module now exposes a comprehensive set of read-only model endpoints for system diagnostics and configuration paths. The status model provides access to the running Zotonic and Erlang/OTP versions, database server version, and various directory paths (config, security, log, data, cache, work, and files). It also exposes OS memory statistics, disk space information, TCP connection counts, and SSL application configuration status. Additionally, the admin model introduces endpoints for the pivot queue count, new-resource dialog defaults (published, dependent, hide\_dependent), edge list length, auto-connect settings, and referer tracking. The admin menu model now serves the full hierarchical menu tree, and the admin note model allows viewing and editing editorial notes attached to resources.

_apps/zotonic\_mod\admin/src/models · high confidence

New admin support modules for resource diffing, media import, and reference tracking

The admin module now includes new support files: \admin\_rsc\_diff.erl\ to format resource records for browser-side diffing, \z\_admin\_media\_discover.erl\ to handle embedding and importing media from URLs, \z\_admin\_refers.erl\ to automatically track resource references via 'refers' edges, and \z\_admin\_rsc\_import.erl\ to support re-importing non-authoritative resources. These changes enhance the admin interface's ability to display resource differences, import external media, maintain data integrity through reference tracking, and manage remote resource imports.

_apps/zotonic\_mod\admin/src/support · high confidence

New and updated base components for charts, debugging, and UI

The \scomps\ directory now includes several new components: \scomp\_base\_chart\_pie\ and \scomp\_base\_chart\_pie3d\ provide simplified interfaces for generating Google pie charts; \scomp\_base\_debug\ allows developers to inspect template variables; \scomp\_base\_inplace\_textbox\ renders editable text fields; \scomp\_base\_lazy\ handles lazy loading of content; \scomp\_base\_loremipsum\ generates placeholder text; \scomp\_base\_spinner\ adds an AJAX activity indicator; \scomp\_base\_tabs\ enables jQuery UI tabbed interfaces; and \scomp\_base\_worker\ initializes web workers. Additionally, \scomp\_base\_google\_chart\ and \scomp\_base\_pager\ have been updated to support these new capabilities and improve existing functionality.

_apps/zotonic\_mod\base/src/scomps · high confidence

New authentication controllers for login, logout, and post-login redirection

The authentication module now exposes three new HTTP controllers to handle user sessions: \controller\_authentication.erl\ manages the primary login flow (including password expiration handling), \controller\_logoff.erl\ handles session termination and cookie cleanup, and \controller\_logon\_done.erl\ manages post-login redirection. These controllers provide the backend endpoints for the browser's \auth\ module to perform authentication, logoff, and redirect users to the correct page after a successful login.

_apps/zotonic\_mod\authentication/src/controllers · high confidence

New authentication model API for password and identity management

The m\_authentication model now exposes a structured HTTP API for managing authentication state and password workflows. Users can now validate passwords against site policies (minimum length, leak checks), check authentication status, and trigger password reset reminders or identity verification emails via dedicated endpoints. The model also supports remember-me functionality and one-step logon configuration checks, providing a centralized backend for identity-related operations.

_apps/zotonic\_mod\authentication/src/models · high confidence

New base templates and UI components for the web and email clients

The base application now provides a comprehensive set of reusable templates and components, including a new \base\_noscript.tpl\ and \base.tpl\ structure that initializes the Cotonic JavaScript framework and manages script loading with Content-Security-Policy nonces. The update introduces dedicated templates for action dialogs, search results, and pagination, while also adding an email template (\email\_base.tpl\) with improved styling and preheader support. Additionally, the \base\_simple.tpl\ and \directory\_index.tpl\ templates are added to support headless or simplified page rendering and file browsing, and a \security.txt\ template is introduced to expose security contact information.

_apps/zotonic\_mod\base/priv/templates · high confidence

New base templates for email rendering

A new set of base email templates has been introduced to standardize the structure and styling of outgoing emails. The update includes a reusable button component for call-to-action links, a media handler for displaying images and videos within email bodies, and layout blocks for headers, text, and page content. These templates provide a consistent visual foundation for email communications, ensuring proper spacing, typography, and media handling across all email templates.

_apps/zotonic\_mod\base/priv/templates/email · high confidence

New blog site template with full content and styling

The 'blog' site skeleton has been significantly expanded with a complete set of templates, stylesheets, and sample content. Users creating a new blog site will now receive a fully styled home page, article listing, and individual article pages, along with a contact form template and sidebar components. The template also includes CSS for the default blog layout and sample HTML data for articles, keywords, and media, providing a more robust starting point for new sites.

_apps/zotonic\_mod\_zotonic\_site\management · high confidence

New controllers for API, file serving, and error handling

The controllers/controller\_api.erl, controller\_csp\_report.erl, controller\_file.erl, controller\_file\_id.erl, controller\_http\_error.erl, controller\_id.erl, controller\_keyserver\_key.erl, controller\_mqtt\_transport.erl, controller\_nocontent.erl, and controller\_page.erl have been added to the codebase. These new controllers provide endpoints for handling REST API requests, processing Content Security Policy reports, serving and redirecting files, managing HTTP errors, handling resource IDs, retrieving public keys, managing MQTT transport, returning no-content responses, and displaying HTML pages with SEO headers.

_apps/zotonic\_mod\base/src/controllers · high confidence

New date and list manipulation template filters

The template language gains several new filters for date manipulation and list processing. Date filters include add\_day, add\_hour, add\_month, add\_week, and add\_year to adjust dates by specific time units, as well as date\_range to format date ranges and datediff to calculate differences between dates. List manipulation includes after and before to find adjacent elements, and element to extract items from tuples or lists. These additions expand the built-in capabilities for formatting and transforming data in templates.

_apps/zotonic\_mod\base/src/filters · high confidence

New development model API for diagnostics and tracing

A new model file, m\_development.erl, has been added to provide a structured API for development and diagnostics. This includes endpoints to check and enable database query tracing, function tracing, and template trace relations (parents, children, and filename menus). It also exposes configuration flags for cache flushing, recompilation, and reindexing, alongside inspection of registered observers and dispatch rules. Access to most of these features requires admin or development permissions, ensuring that sensitive diagnostic data is protected.

_apps/zotonic\_mod\development/src/models · high confidence

New development module for template, function, and database tracing

A new 'Development' module has been added to provide comprehensive debugging tools for site development. It introduces function call tracing (sending output via MQTT), database query tracing, and template compilation/selection debugging. The module also supports live reloading of CSS, JS, and template files in the browser, and includes a floating trace button to debug the current page. Configuration options allow enabling/disabling these features, and the module handles file watcher events to automatically recompile and load changed files.

_apps/zotonic\_mod\development/src · high confidence

New development tools for debugging templates, dispatching, and database queries

Added four new support modules to the development module: z\_development\_dbtrace for toggling database query tracing, z\_development\_dispatch for explaining request dispatching, z\_development\_template for template selection debugging, and z\_development\_template\_xref for checking template cross-references and missing includes. These tools provide developers with detailed insights into template dependencies, request routing, and database interactions, with the template graph module also generating DOT format graphs of template relationships.

_apps/zotonic\_mod\development/src/support · medium confidence

New development tools for tracing, debugging, and inspecting templates

The development module now provides a suite of new tools for debugging and inspecting templates. Administrators can view a live dependency graph of all templates, perform cross-reference checks to find missing includes or syntax errors, and trace template rendering in real-time. Additionally, a floating button allows quick access to template traces, and the debug pane is now resizable. These features are accessible via the new 'Site Development' admin page.

_apps/zotonic\_mod\development/priv/templates · high confidence

New dialog for creating predicates in the admin interface

The admin interface now includes a dedicated dialog for creating new predicates. This feature allows users to define a new predicate via a form, with the system handling the creation, redirecting to the edit page upon success, and displaying appropriate error messages for duplicate names or permission issues.

_apps/zotonic\_mod\_admin\predicate/src/actions · high confidence

New dispatch rules for static assets, API endpoints, and Cotonic integration

The application now serves several new static resources and API routes. Standard library files (CSS, JS, images) are accessible via /lib, /lib-min, and /lib-nocache paths. New endpoints include /api/\* for API access, /manifest.json for site information, /.zotonic/ping for health checks, and /.zotonic/csp\_report for Content-Security-Policy violation logs. Additionally, a /test/connection page is exposed for connection testing, and Cotonic-specific routes are added for the service worker, key server, and MQTT transport.

_apps/zotonic\_mod\base/priv/dispatch · high confidence

New filters for formatting dispatch rules and path elements

Two new filter modules have been added to the development module to improve the display of dispatch rules in the admin interface. The \filter\_format\_dispatch\_controller\_option\ module formats controller options (such as id, acl, and template) into styled HTML labels, while \filter\_format\_dispatch\_path\_element\ formats path elements, distinguishing between variables and exact matches with appropriate HTML markup. These changes enhance the readability of the site's dispatch configuration in the admin UI.

_apps/zotonic\_mod\development/src/filters · high confidence

New form validation types: acceptance, confirmation, custom, date, email, email\_unique, format, json, length, name\_unique, numericality, page\_path\_unique, postback, and presence

The \zotonic\_mod\_base\ application now includes a comprehensive set of form validators, each implemented as a dedicated module in the \src/validators\ directory. These new validators allow users to enforce specific input constraints directly in their templates. The additions include \acceptance\ for boolean checks, \confirmation\ for matching fields, \custom\ for JavaScript-based validation, \date\ for format validation, \email\ and \email\_unique\ for address validation and uniqueness, \format\ for regular expression matching, \json\ for valid JSON strings, \length\ for string length limits, \name\_unique\ and \page\_path\_unique\ for resource uniqueness checks, \numericality\ for integer/float ranges, \postback\ for server-side callbacks, and \presence\ to ensure fields are not empty. Each validator provides both client-side (JavaScript) and server-side (Erlang) validation logic.

_apps/zotonic\_mod\base/src/validators · high confidence

New frontend edit templates for the admin interface

The admin frontend now uses a dedicated set of templates (\_admin\_frontend\_edit.tpl, \_admin\_frontend\_editor.tpl, etc.) that provide a lighter, more modern UI for editing resources. This includes a redesigned edit form with tabbed navigation for content, language, and access control, alongside a custom TinyMCE initialization script that configures the editor with specific plugins (lists, searchreplace, etc.) and a custom valid elements list. The layout also integrates a sidebar menu and a fixed-top navbar with save/cancel buttons, ensuring the edit experience is consistent with the new admin frontend architecture.

_apps/zotonic\_mod\_admin\frontend/priv/templates · high confidence

New header and record definitions for core, logging, and wired events

The \zotonic\_core\ application introduces a new set of header files (\zotonic.hrl\, \zotonic\_deprecated.hrl\, \zotonic\_file.hrl\, \zotonic\_log.hrl\, \zotonic\_notifications.hrl\, \zotonic\_release.hrl\, and \zotonic\_wired.hrl\) that define the internal data structures and macros for the framework. These include the main \\#context\ record, logging macros, filestore request records, and notification records for HTTP, modules, and user identity. Additionally, a \zotonic\_deprecated.hrl\ is added to mark the \\#z\_msg\_v1\ record as deprecated, signaling that the legacy transport system is being phased out in favor of the new MQTT-based architecture.

_apps/zotonic\core/include · high confidence

New i18n infrastructure for translations and language management

The i18n subsystem has been refactored with new modules to handle translations and language configuration. A new \z\_trans\ module provides functions for looking up and merging translations, backed by a \z\_trans\_server\ that manages an ETS table of all translations. Language handling is now managed by \z\_language\ and \z\_language\_data\, which provide APIs for fetching language info, checking validity, and managing the list of enabled/editable languages. Additionally, \z\_gettext\ and \z\_gettext\_compile\ handle parsing and generating .po/.pot files for the translation workflow.

_apps/zotonic\core/src/i18n · high confidence

New interface for managing page connections and predicates

The admin interface now includes a dedicated 'Page connections' section that allows administrators to view, filter, and manage relationships between pages. This update introduces a new list view for all page connections, enabling filtering by subject, object, and predicate, as well as a new graph-based visualization for exploring connections from a specific page. Additionally, administrators can now create new predicates, delete them (with options to handle existing connections), and configure detailed settings for each predicate, such as valid categories, connection direction, and search indexing behavior.

_apps/zotonic\_mod\_admin\predicate/priv/templates · high confidence

New model API endpoints for core data access

The zotonic\_core models (m\_acl, m\_category, m\_config, m\_dispatch, m\_edge, m\_hierarchy, m\_identity, m\_media, m\_rsc, m\_search, m\_site, m\_trans, m\_predicate, m\_post, m\_delete) now expose structured API paths for programmatic access. This allows templates and external clients to query user identity, access control status, category trees, configuration values, resource edges, and search results via predictable URL patterns, replacing the need for direct function calls or less structured data access.

_apps/zotonic\core/src/models · high confidence

New model, observer, and scomp behaviours for extensibility

Three new behaviours are introduced to standardize extension points in the framework. The \zotonic\_model\ behaviour defines callbacks for handling GET, POST, and DELETE operations via templates, MQTT, and the API, allowing modules to implement custom data models. The \zotonic\_observer\ behaviour provides a typed interface for handling various system notifications, including dispatch routing, content security header modification, and CSP report handling. Additionally, the \zotonic\_scomp\ behaviour defines the interface for screen components, specifying how they render content and manage caching via the \render\ and \vary\ callbacks.

_apps/zotonic\core/src/behaviours · high confidence

New multi-step email-based signup flow with code verification

The \zotonic\_mod\_signup\ module now implements a new, structured signup process that requires email verification. Users enter their email address, receive a one-time code via email, and must enter that code to proceed to the final registration form. The flow includes steps for email entry, code verification, and final account creation with name, username, and password fields. The module also provides a separate confirmation flow for publishing and verifying accounts via email links.

_apps/zotonic\_mod\signup · high confidence

New pivot templates for search indexing

Added new template files in the pivot directory to define how resources are indexed for search. The main pivot template now includes separate blocks for title text, main body text, block text, and related text, allowing for more granular control over what content is indexed. Additionally, specific templates for titles, addresses, names, dates, and related IDs have been introduced to support the search indexing process.

_apps/zotonic\_mod\base/priv/templates/pivot · high confidence

New rate-limiting module for authentication attempts

A new \zotonic\_mod\_ratelimit\ module has been added to enforce rate limits on authentication and password reset flows. It tracks failed attempts per username or email, blocking the account for an hour after five failures. To prevent false positives from different devices, it uses a signed device-ID cookie, allowing each known browser its own set of five attempts. Administrators can reset these counters via a new button in the admin status template.

_apps/zotonic\_mod\ratelimit · high confidence

New record types for file handler notifications

Three new record types are introduced to structure file handler events: zotonic\_filehandler\_categorize for mapping files to categories, zotonic\_filehandler\_map for defining file actions, and zotonic\_filehandler\_filechange for tracking file modifications. These records define the data structures used by the file handler to process and react to file system changes.

_apps/zotonic\filehandler/include · high confidence

New ticket-based authentication for out-of-band MQTT posts via HTTP

A new model \m\_mqtt\_ticket\ has been added to provide a ticketing system for handling out-of-band MQTT actions via HTTP. This allows users to create one-time use tickets that store the current MQTT client context (including client ID, topic, ACL user ID, and other settings) for up to 30 seconds. These tickets can then be used in subsequent HTTP requests to authenticate and route MQTT messages, with the system automatically transferring the stored context to the new request. The model exposes API endpoints to create (\/new\) and delete/invalidate (\/+ticket\) these tickets.

_apps/zotonic\_mod\base/src/models · high confidence

New zotonic\_listen\_smtp app for SMTP handling

The SMTP listener functionality has been split into a dedicated \zotonic\_listen\_smtp\ application, containing the server logic, email reception, spam checking, and auto-reply/bounce detection modules. This new app depends on \gen\_smtp\ and \zotonic\_core\, and includes configuration for listening on an IP and port, TLS options, and size limits for received emails.

_apps/zotonic\_listen\smtp/src · high confidence

OEmbed support for embedding external media

The oembed module now enables embedding media from external URLs (such as YouTube, Vimeo, Spotify, and others) using the OEmbed protocol. Administrators can paste URLs in the admin interface to automatically fetch and display embedded content, including thumbnails, titles, and provider information. The module includes templates for rendering embedded content with responsive wrappers and provides an admin tool to fix previously failed embeds.

_apps/zotonic\_mod\oembed · high confidence

Redesigned connect and media upload dialogs in the admin interface

The admin interface now features a redesigned, tabbed dialog for connecting and creating resources, as well as uploading media. The new \\_action\_dialog\_connect.tpl\ provides a unified interface with tabs for finding, creating, and uploading content, while \\_action\_dialog\_media\_upload.tpl\ handles file uploads and URL embedding. These changes replace the previous single-purpose dialogs with a more flexible, multi-tabbed approach that supports various content types and improves the user experience for linking and managing resources.

_apps/zotonic\_mod\admin/priv/templates · high confidence

Standardize build system with Rebar3 and modernize project configuration

The project now uses Rebar3 as the primary build system, replacing the previous Makefile-based approach. This change introduces a standardized \rebar.config\ and \rebar.lock\ file to manage dependencies, ensuring consistent builds across different environments. Additionally, the repository now includes a \.dockerignore\ file to optimize Docker builds, an \.editorconfig\ for consistent coding styles, and a \crowdin.yml\ to streamline translation workflows. The \zotonic.tmproj\ (TextMate project file) has been removed as it is no longer needed.

(repo-wide) · high confidence

Survey module restructured with new admin UI and feedback features

The survey module has been restructured to provide a modernized admin interface for creating and editing surveys. A new tabbed layout organizes survey editing into Description, Settings, Questions, and Results. The question editor now supports drag-and-drop reordering of pages and questions, allowing administrators to easily rearrange the survey flow. Additionally, the module now supports test/quiz functionality, enabling administrators to define correct/incorrect feedback for questions and track user scores and pass/fail status in the results view.

_apps/zotonic\_mod\survey · high confidence

Two-factor authentication (2FA) configuration and management templates

The 2FA module now provides dedicated templates for configuring and managing two-factor authentication. Administrators can set a global 2FA policy (optional, ask on login, nag on every page, or force) and override it per user group. Users see their 2FA status in the admin sidebar and user info, and can enable, disable, or remove 2FA via new dialog and action templates that handle QR codes, passcode entry, and confirmation prompts.

_apps/zotonic\_mod\auth2fa/priv/templates · high confidence

Unsaved changes warning for edit pages

The admin frontend now intercepts navigation away from edit pages to warn users about unsaved changes. This is implemented in the new \admin-frontend.js\ module, which registers handlers for link clicks and internal menu events to trigger a confirmation dialog before discarding changes.

_apps/zotonic\_mod\_admin\frontend/priv/lib/js · high confidence

Updated TinyMCE editor to version 4.9.3 with new plugins and styles

The TinyMCE editor has been updated to version 4.9.3, introducing several new plugins: advlist, anchor, autolink, autoresize, autosave, bbcode, charmap, code, codesample, colorpicker, and compat3x. Additionally, the codesample plugin now includes Prism.js CSS for syntax highlighting. These changes enhance the editor's capabilities by adding features like automatic link detection, code sample insertion with syntax highlighting, and backward compatibility with older TinyMCE APIs.

(repo-wide) · high confidence

Zotonic launcher app initialized with updated dependencies

The zotonic\_launcher application has been introduced, establishing the build configuration and licensing for the HTTP and SMTP listener components. The project now requires OTP 23 or higher and includes dependencies on yamerl (version 0.8.1) and cowmachine (version 1.8), alongside internal Zotonic libraries.

_apps/zotonic\launcher · high confidence

Removals

Removal of TinyMCE table and Safari compatibility plugins

The TinyMCE editor's table management capabilities and Safari-specific compatibility patches have been removed. This includes the deletion of the table plugin's JavaScript and source files, the associated CSS stylesheets, and the HTML templates for the cell and row editing dialogs. Additionally, the 'safari' plugin, which provided workarounds for WebKit rendering issues in TinyMCE, has been removed along with its associated JavaScript files. Users will no longer have access to table insertion, editing, and formatting features within the editor, nor will the editor apply specific styling fixes for Safari/WebKit browsers.

(repo-wide) · high confidence

Removal of Webmachine demo application and core library files

The Webmachine demo application files (including \webmachine\_demo\, \webmachine\_demo\_app\, \webmachine\_demo\_resource\, \webmachine\_demo\_sup\, and \demo\_fs\_resource\) have been removed from the \deps/webmachine/demo\ directory. Additionally, the core Webmachine library files (including \webmachine.app\, \webmachine.erl\, \webmachine\_app.erl\, \webmachine\_decision\_core.erl\, \webmachine\_deps.erl\, \webmachine\_dispatcher.erl\, \webmachine\_error\_handler.erl\, \webmachine\_host.erl\, \webmachine\_logger.erl\, \webmachine\_mochiweb.erl\, \webmachine\_multipart.erl\, and \webmachine\_perf\_logger.erl\) have been deleted from the \deps/webmachine/src\ directory. This removes the example resources and the main Webmachine framework code from the dependency tree.

deps/webmachine · high confidence

Removal of legacy admin modules and templates

The legacy admin module (mod\_admin) and its associated resources, actions, and templates have been removed from the codebase. This includes the deletion of Erlang modules for handling admin pages (such as resource\_admin, resource\_admin\_edit, and resource\_admin\_logon), action handlers for dialogs (like action\_admin\_dialog\_link and action\_admin\_dialog\_new\_rsc), and related CSS/JS assets. This change eliminates the old admin interface implementation, likely as part of a broader refactoring or migration to a new admin architecture.

_modules/mod\admin · high confidence

Removal of legacy search module and helper

The \mod\_search\ module and the \search\_all\_bytitle\ helper have been removed from the codebase. This change eliminates the legacy search implementation that previously handled basic content searches, including features like featured resource listing, latest/upcoming item retrieval, and title-based sorting. Users relying on these specific search capabilities will need to use the updated search infrastructure.

_modules/mod\search · high confidence

Removal of legacy sitemap module

The 'SEO Sitemap' module has been removed from the system. This eliminates the previous implementation that generated a static XML sitemap for search engines, which previously relied on a gen\_server process and a specific template for crawling. Users relying on this specific module will need to use alternative methods for sitemap generation.

_modules/mod\_seo\sitemap · high confidence

Removal of video embed module

The mod\_video\_embed module and its associated templates have been removed from the system. This eliminates the ability to embed videos from services like YouTube and Vimeo as media pages, as well as the associated admin forms and UI components for creating and editing embedded video content.

_modules/mod\_atom\_feed, modules/mod\_video\embed · high confidence

Removed ErlyDTL template engine

The ErlyDTL template engine and its associated modules (including the compiler, parser, scanner, and filters) have been removed from the codebase. This eliminates the legacy template rendering system, requiring the use of the current template engine for all template processing.

src/erlydtl · high confidence

Removed admin config module

The admin config module, which allowed administrators to edit system configuration keys with string values, has been removed. This includes the associated action handlers, resource files, and templates for creating, editing, and deleting configuration entries. Administrators can no longer manage configuration settings through this specific interface.

_modules/mod\_admin\config · high confidence

Removed default site and Emacs mode test fixtures

The default site implementation (including templates, dispatch rules, and the default gen\_server module) has been removed from the repository. Additionally, the Emacs mode test fixtures (zotonic-tpl-mode.el, zotonic-tpl-mode-tests.tpl, and zotonic-tpl-mode-highlight.tpl) have been deleted, indicating a cleanup of the development and default site assets.

priv · high confidence

Removed deprecated Erlang OAuth dependency

The \erlang-oauth\ dependency has been removed from the project. This eliminates the \oauth\ application and all associated Erlang modules (including \oauth\, \oauth\_client\, \oauth\_hmac\_sha1\, \oauth\_http\, \oauth\_plaintext\, \oauth\_rsa\_sha1\, \oauth\_unix\, and \oauth\_uri\) from the \deps\ directory, reducing the codebase by deleting these files and the application definition.

deps/erlang-oauth · high confidence

Removed deprecated base action modules

The \mod\_base\ module has removed a large number of deprecated action modules, including \action\_base\_add\_class\, \action\_base\_alert\, \action\_base\_animate\, \action\_base\_buttonize\, \action\_base\_confirm\, \action\_base\_dialog\, \action\_base\_dialog\_close\, \action\_base\_dialog\_open\, \action\_base\_disable\, \action\_base\_effect\, \action\_base\_enable\, \action\_base\_event\, \action\_base\_fade\_in\, \action\_base\_fade\_out\, \action\_base\_growl\, \action\_base\_hide\, \action\_base\_insert\_bottom\, \action\_base\_insert\_top\, \action\_base\_jquery\_effect\, \action\_base\_logoff\, \action\_base\_postback\, \action\_base\_redirect\, and \action\_base\_reload\. These removals streamline the codebase by eliminating legacy implementations that are no longer supported.

_modules/mod\base · high confidence

Removed deprecated database installation modules

The legacy database installation modules (z\_install, z\_install\_data, z\_installer) have been removed from the src/install directory. This cleanup eliminates outdated code responsible for initial database schema creation and default data seeding, reflecting a shift toward modern, modular installation processes.

src/install · high confidence

Removed deprecated module management actions and templates

The \mod\_admin\_modules\ module's legacy implementation has been removed, specifically deleting the \action\_admin\_modules\_module\_rescan\ and \action\_admin\_modules\_module\_toggle\ actions, along with the \mod\_admin\_modules\ gen\_server, the \resource\_admin\_module\_manager\ resource, and the associated templates (\admin\_modules.tpl\, \\_admin\_menu\_module.tpl\). This removes the old-style module activation/deactivation and manual rescan interface from the admin panel.

_modules/mod\_admin\modules · high confidence

Removed development module and its associated services

The mod\_development module, the z\_development\_server, and the service\_development\_recompile service have been removed from the codebase. This eliminates the automatic recompilation and hot-reloading of Erlang modules during development, meaning developers will no longer have their code changes automatically compiled and loaded into the running system.

_modules/mod\development · high confidence

Removed legacy PostgreSQL driver and connection pool

The custom \pgsql\ and \epgsql\_pool\ modules, along with their associated test suites, schema definitions, and documentation, have been removed from the \src/dbdrivers/postgresql\ directory. This change eliminates the previous PostgreSQL database driver implementation, indicating a shift to a different database driver or connection management strategy.

src/dbdrivers · high confidence

Removed legacy SEO module and admin interface

The mod\_seo module, its gen\_server, dispatch rules, and admin UI templates have been removed. This eliminates the previous centralized SEO configuration interface and associated backend logic, reflecting a shift away from the legacy SEO management approach.

_modules/mod\seo · high confidence

Removed legacy TinyMCE 3.3.2a theme files

The 'advanced' theme files for TinyMCE (version 3.3.2a) have been removed from the application. This includes the main theme JavaScript (\editor\_template.js\), the source file (\editor\_template\_src.js\), and all associated HTML templates and JavaScript logic for dialogs such as the about, anchor, charmap, color picker, and image insertion windows. This cleanup removes the deprecated theme implementation, likely to prevent browser caching issues or to prepare for a newer editor version.

_modules/mod\base/lib/js/modules/tinymce · high confidence

Removed legacy category management actions and templates

The legacy category management actions (add, delete, sorter) and their associated templates have been removed from the admin interface. This cleanup eliminates the old gen\_server-based module and associated dispatch rules, streamlining the admin category editing workflow.

_modules/mod\_admin\category · high confidence

Removed legacy menu editor and associated components

The legacy menu editor interface and its supporting components have been removed from mod\_menu. This includes the dispatch route for the admin menu, the gen\_server implementation, the resource handler for the admin menu, the scomp for rendering menus, and all associated templates (including the menu view, module header, typeahead results, and the main admin page). This cleanup removes the old drag-and-drop menu management system in favor of newer approaches.

_modules/mod\menu · high confidence

Removed legacy model modules from the codebase

The legacy model modules (m\_acl, m\_category, m\_config, m\_edge, m\_group, m\_identity, m\_media, m\_predicate, and m\_rsc) have been removed. This change eliminates the old data access layer, requiring the system to use the updated resource and edge handling logic.

src/models · high confidence

Removed legacy user management actions and templates

The 'mod\_admin\_identity' module's legacy user management actions and templates have been removed. This includes the deletion of Erlang action modules (e.g., \action\_admin\_identity\_delete\_username\, \action\_admin\_identity\_dialog\_set\_username\_password\), the \mod\_admin\_identity\ gen\_server, and associated templates (e.g., \\_action\_dialog\_user\_add.tpl\, \admin\_users.tpl\). This change eliminates the old dialog-based interface for managing usernames and passwords, likely as part of a broader refactoring of the admin interface.

_modules/mod\_admin\identity · high confidence

Removed obsolete TinyMCE zmedia plugin

The TinyMCE editor plugin for Zotonic media items (zmedia) has been removed. This plugin previously handled the insertion and editing of media items within the editor, including opening property dialogs and managing image alignment. Its removal indicates that this specific integration is no longer supported or has been replaced by a different mechanism.

_modules/mod\base/lib/js/modules/tinymce/plugins/zmedia · high confidence

Removed obsolete gen\_model behaviour

The gen\_model behaviour module has been removed from the codebase. This cleanup eliminates an obsolete abstraction layer that was no longer required for the application's data model implementation.

src/support · high confidence

Removed predicate management from the admin interface

The \mod\_admin\_predicate\ module and all its associated files have been removed from the codebase. This includes the main module, dispatch rules, resource handlers, action controllers, and templates that previously allowed administrators to create, edit, and delete predicates directly through the admin panel.

_modules/mod\_admin\predicate · high confidence

Removed the legacy mod\_oauth module

The legacy OAuth module (mod\_oauth) and all its associated files have been removed. This includes the dispatch rules, the main gen\_server, model files for application and permission management, Webmachine resource handlers, and all related templates. This change eliminates the older OAuth implementation in favor of a newer authentication system.

_modules/mod\oauth · high confidence

Architecture

Core support modules reorganized into the support directory

The Zotonic core support modules (z, z\_acl, z\_auth, z\_config, z\_config\_files, z\_context, z\_controller\_helper) have been moved to the apps/zotonic\_core/src/support directory. This change restructures the application's internal codebase, grouping these foundational utilities together for better organization and maintainability.

_apps/zotonic\core/src/support · high confidence

Behavioural changes

Add default CSS styles for the TinyMCE editor iframe

A new stylesheet, tinymce-zotonic.css, has been added to define the visual appearance of the TinyMCE editor's editable area. This includes styling for body text, paragraphs, and specifically images (with classes for alignment and size) and aside elements, ensuring consistent formatting within the editor.

_apps/zotonic\_mod\_editor\tinymce/priv/lib/css · high confidence

Add module reinstallation capability to the admin module manager

The admin module manager now includes a button to re-install a module's data model. When a user triggers this action, the system attempts to re-run the module's schema management, providing feedback via a growl notification indicating whether the reinstallation was successful or if the module lacks the necessary schema management function.

_apps/zotonic\_mod\_admin\modules/src/controllers · medium confidence

Added Zotonic launcher configuration and placeholder

Introduced a new header file, zotonic\_command.hrl, which defines default node names for the Zotonic application and test sandbox, along with a wait-time constant. Additionally, an empty placeholder file was added to the apps\_user directory.

_apps/zotonic\_launcher/include, apps\user · low confidence

Added admin modules dispatch rule

A new dispatch rule has been added to map the 'admin\_modules' module to the '/admin/modules' path, utilizing the 'controller\_admin\_module\_manager' controller with 'seo\_noindex' configuration.

_apps/zotonic\_mod\_admin\modules/priv/dispatch · high confidence

Added category management and deletion UI

The admin interface now includes a dedicated page for managing the category hierarchy, allowing administrators to drag and drop categories to reorder them. A new confirmation dialog has been added for deleting categories, which offers the option to move associated pages to another category or delete all pages within the categories being removed. Additionally, a dispatcher has been added to route requests to the category sorter controller.

_apps/zotonic\_mod\_admin\category/priv · medium confidence

Added release notes and documentation assets

Added release notes for versions 0.01.0 through 0.08.0, documenting new features, modules, and bug fixes for each release. Also added the BrowserStack logo as an SVG image in the documentation assets.

doc · high confidence

Adds new CSS styles for UI components and updates asset paths

The mod\_base module now includes several new CSS files to support various UI features: a loading mask overlay, a time picker, syntax highlighting for code blocks (PrismJS), bridge connection status warnings, toast notifications, a comprehensive icon font system (Zotonic, FontAwesome, Material Design), and multi-level modal dialogs. Additionally, the existing datepicker stylesheet was moved and its internal image URLs were updated to use the new /lib/images/ path structure.

_apps/zotonic\_mod\base/priv/lib/css · high confidence

Admin UI styling overhaul and form control updates

The admin interface receives a comprehensive visual update, including a lighter UI theme, improved button visibility, and better hover states for muted text. Form controls now feature floating labels that display on focus or when content is present, with specific styling for invalid/valid states and error highlighting. The layout for media details, menu editing, and dialog boxes has been refined, including fixes for Safari 17.4.1 word-break issues and margin adjustments for buttons and tabs.

_apps/zotonic\_mod\admin/priv/lib/css · high confidence

Admin UI updated to use Bootstrap 3 with custom styling

The admin interface now uses Bootstrap 3 (via the bootstrap-sass 3.4.1 library) to generate the admin CSS. This includes a new Makefile to compile the SCSS sources, a main SCSS file that imports Bootstrap components and applies custom color variables (such as $brand-primary: \#0fa2db) and font families, and the necessary font and license files for the icon set.

_apps/zotonic\_mod\admin/priv/lib-src/admin-bootstrap3 · high confidence

Admin config actions migrated to OTP app structure with updated ACL checks

The configuration management actions in the admin interface have been reorganized into the new OTP app structure (apps/zotonic\_mod\_admin\_config/src/actions). This includes the addition of new actions for toggling config values and creating new config entries, alongside refactored actions for editing and deleting configurations. A key behavioral change is the replacement of the strict \z\_acl:has\_role(admin, Context)\ check with the more granular \z\_acl:is\_admin\_editable(Context)\ check, allowing a broader set of users to modify configurations. Additionally, the edit dialog now dynamically titles the dialog with the module and key being edited, and the edit action now supports renaming the module and key of a configuration entry.

_apps/zotonic\_mod\_admin\config/src/actions · medium confidence

Admin controllers restructured into dedicated modules

The admin interface's backend logic has been reorganized into separate controller modules for specific functions: the main admin dashboard, resource editing, media previewing, and referrer listing. This separation clarifies the responsibilities of each controller and improves maintainability of the admin panel's core features.

_apps/zotonic\_mod\admin/src/controllers · high confidence

Admin interface styles migrated from LESS to SCSS

The admin interface's styling has been refactored from LESS to SCSS. This migration updates the visual presentation of the admin panel, including the navbar, buttons, forms, and various widgets, ensuring consistent styling across the application.

_apps/zotonic\_mod\admin/priv/lib-src/zotonic-admin/scss · high confidence

Admin module actions restructured and modernized

The \mod\_admin\ actions have been migrated from \modules/mod\_admin/actions\ to \apps/zotonic\_mod\admin/src/actions\, modernized with Erlang 20+ syntax (e.g., \\#postback\ records instead of tuples), and enriched with \moduledoc\ documentation. This change also standardizes error and success messages to use the internationalization function \?\\_()\ for translation support, and updates copyright headers to 2026.

_apps/zotonic\_mod\admin/src/actions · high confidence

Admin statistics route reconfigured

The dispatch rule for the admin interface has been moved from the configuration module to the statistics module. The route previously mapped to 'admin/config' and 'resource\_admin\_config' now maps to 'admin/statistics' and 'controller\_admin\_statistics', effectively changing the URL path and the controller handling the request.

_apps/zotonic\_mod\_admin\statistics/priv/dispatch · high confidence

Audio media editing and display enhancements

The audio module now provides a dedicated admin interface for editing audio metadata, including fields for album, artist, composer, genre, track, copyright, and compilation status. Additionally, the media metadata view displays the audio bit rate in kbps for rates above 1024 bps, and lists all audio tags. A new audio viewer template enables playback of audio files with optional autoplay and preload controls.

_apps/zotonic\_mod\audio/priv · high confidence

Backup module refactored with new support files for config, creation, encryption, and restore

The backup module's support logic has been reorganized into dedicated Erlang modules: backup\_config.erl centralizes all configuration retrieval (including encryption, retention, and admin panel settings); backup\_create.erl handles the backup creation process, including database dumps, file archiving, and optional encryption; backup\_file\_crypto.erl provides the encryption/decryption utilities for backup files; backup\_restore.erl manages the restoration of backups, including database, file, security, and config restoration; and backup\_rsc\_upload.erl handles resource uploads during backup operations. This refactoring improves modularity and maintainability of the backup feature.

_apps/zotonic\_mod\backup/src/support · high confidence

Centralized configuration for logging, SSL, and application settings

The zotonic\_launcher app now provides centralized configuration templates for Erlang and Zotonic runtime settings. The new erlang.config.in file configures the Erlang logger with handlers for console, file, and Logstash output, alongside SSL session caching and disk usage monitoring. The zotonic.config.in template introduces global settings for HTTP/HTTPS/MQTT listeners, security headers, database defaults, and SMTP relay options, allowing administrators to customize the server's behavior and security posture.

_apps/zotonic\launcher/priv · high confidence

Complete refactoring of the email sending subsystem

The email sending functionality has been completely refactored into a new modular structure. The core logic for sending emails is now in \z\_email.erl\, which handles recipient formatting, admin email retrieval, and the main send interface. A new \rfc2047.erl\ module provides RFC 2047 encoding for email headers. Image embedding is handled by a dedicated \z\_email\_embed.erl\ module, which respects a 1MB size limit for embedded images. The \z\_email\_server.erl\ module manages the email queue, connection pooling, and delivery logic, introducing configurable limits on simultaneous senders and domain connections. This change improves code organization, robustness, and maintainability of the email system.

_apps/zotonic\core/src/smtp · high confidence

Core application structure and startup logic reorganized

The Zotonic core application has been restructured to follow OTP conventions, moving the main application module and supervisor into the standard \src\ directory. This change introduces a new \zotonic\_core.app.src\ file that explicitly lists all core dependencies, including \mnesia\, \ranch\, \cowboy\, and various internal modules. The \zotonic\_core\ module now handles initial setup tasks such as loading applications, configuring environment variables, and ensuring the Mnesia schema is created in a node-specific directory. The \zotonic\_core\_sup\ supervisor manages key background processes like job queues, side jobs, and file watchers. This reorganization improves the reliability of the startup sequence and ensures consistent directory structures for data and logs.

_apps/zotonic\core/src · high confidence

Custom redirect model exposes API and enforces path validation

The \m\_custom\_redirect\ model now exposes a structured API for managing custom redirects, including \list\, \get\, \insert\, \update\, and \delete\ operations. The model enforces that the \path\ field must be a valid UTF-8 string before querying the database, preventing errors on production sites. Additionally, the model explicitly prevents redirects for paths starting with \.zotonic\ or \.well-known\ to ensure these system paths are not redirected.

_apps/zotonic\_mod\_custom\redirect/src/models · medium confidence

Customized error pages and updated build configuration

The default HTTP error pages for 400, 500, and 503 status codes have been replaced with custom, user-friendly HTML templates. Additionally, the project's build configuration (rebar.config) has been updated to specify a minimum Erlang/OTP version of 23 and includes an updated list of dependencies.

_apps/zotonic\core · high confidence

Database layer refactored with new z\_db modules and codec

The database abstraction has been restructured into dedicated modules: z\_db (core interface), z\_db\_pgsql (PostgreSQL pool worker), z\_db\_pgsql\_codec (binary/JSONB/datetime encoding), z\_db\_pool (connection pooling), z\_db\_table (DDL operations), and z\_db\_worker (worker behavior). This introduces support for binary keys, JSONB decoding, and structured logging, while fixing issues with connection timeouts, stale connections, and error handling for SQL failures.

_apps/zotonic\core/src/db · high confidence

Enhanced backup management with encryption, filestore support, and revision controls

The backup module's admin interface has been significantly updated. The backup list now displays encryption status and filestore upload status, with download links for encrypted or standard archives. A new template renders a side-by-side diff view for comparing page revisions, and the main backup page now shows the backup directory path. Configuration options allow administrators to enable daily database-only backups, toggle backup encryption, and control the retention period for revisions. The sidebar and edit pages now feature a 'Revert to earlier version' link, and deleted pages can be recovered directly from the admin panel.

_apps/zotonic\_mod\backup/priv/templates · high confidence

Enhanced debug pane with resizable layout and template variable inspection

The development module's debug pane now supports a resizable layout, allowing users to drag a splitter to adjust the width of the template code and data viewer. This change introduces CSS styles for a new template debugging overlay, including a grid-based layout with a source code panel, a resizable splitter, and a data viewer that displays template variables with collapsible nodes and syntax highlighting. Additionally, styles for trace status indicators and graph visualization are added to support the floating trace button feature.

_apps/zotonic\_mod\_development/priv/lib-src, apps/zotonic\_mod\development/priv/lib/css · medium confidence

Enhanced module management in the admin interface

The admin modules overview now displays each module's version number alongside its title and description, and includes a 'Reinstall' button to restore a module's datamodel. Additionally, the interface now warns about uninstalled or missing modules and provides confirmation dialogs when activating or deactivating modules that have dependencies, ensuring users are aware of the impact on other modules.

_apps/zotonic\_mod\_admin\modules/priv/templates · high confidence

Filehandler app structure and compilation logic

The zotonic\_filehandler application is restructured with a new app.src manifest declaring dependencies on kernel, stdlib, erlexec, jobs, buffalo, zotonic\_notifier, and zotonic\_filewatcher. The module zotonic\_filehandler now exposes functions to compile all files, reload modules, and send terminal notifications. The handler serializes file change events, maps them to actions (compile, load, etc.), and triggers recompilation or reloading as needed.

_apps/zotonic\filehandler/src · high confidence

Filewatcher refactored into a standalone application

The filewatcher functionality has been refactored into its own dedicated application, \zotonic\_filewatcher\. This change introduces a new application structure with its own supervision tree, including workers for the file handler, beam reloader, and monitor. The implementation now supports multiple file system monitoring backends (inotify, fswatch, and a polling-based fallback) with automatic fallback and backoff on errors. The application also includes a new \zotonic\_filewatcher\_monitor\ module for polling-based file status changes, and the \zotonic\_filewatcher\_sup\ supervisor manages the lifecycle of these components. This separation improves modularity and allows for more robust error handling and configuration of file watching behavior.

_apps/zotonic\filewatcher/src · high confidence

Fix TinyMCE editor overlay obscuring save buttons

The admin frontend CSS has been updated to correct the layout of the editor interface. Specifically, the TinyMCE editor's auxiliary container is now hidden (height: 0) to prevent it from overlapping with the save buttons. Additional styling adjustments were made to the navbar checkboxes, buttons, and meta-data sections to improve visual consistency and spacing.

_apps/zotonic\_mod\_admin\frontend/priv/lib/css · medium confidence

Introduce structured authentication dispatch rules for login, session, and password management

The authentication module now uses a dedicated dispatch configuration file to define URL routing for key user flows. This includes dedicated endpoints for logging in, changing passwords, and resetting passwords, all configured to prevent search engine indexing (seo\_noindex) and tracking (notrack). A new session overview page is exposed at /logon/sessions, and an API endpoint at /zotonic-auth supports the authentication worker. Additionally, a redirect is added for the .well-known/change-password path to assist password managers.

_apps/zotonic\_mod\authentication/priv/dispatch · high confidence

Login page styling migrated to SCSS

The login page styles have been converted from LESS to SCSS, introducing a new build process via a Makefile that compiles logon.scss into logon.css. This change updates the styling for the authentication interface, including the logon box, error states, and social login options, ensuring consistent visual presentation for users on the login and 403 error pages.

_apps/zotonic\_mod\authentication/priv/lib-src · medium confidence

Manual backup initiation with read-only and permission checks

Users can now manually start a backup via a new action that checks for read-only mode and verifies the user has 'use' permission on mod\_backup. If a backup is already in progress, the system displays an error message. Additionally, if manual backups are disabled via configuration, users receive an error message indicating that manual backups are not allowed.

_apps/zotonic\_mod\backup/src/actions · medium confidence

The menu editor interface has been redesigned with new CSS styles for the tree list and menu items, providing a more modern grid-based layout for the admin menu editing tools. The update includes new JavaScript modules for menu editing, trash management, and nested sorting, alongside updated templates for menu rendering and hierarchy sorting, enhancing the user experience for managing site navigation structures.

_apps/zotonic\_mod\menu · high confidence

Migrate admin stylesheets from LESS to SCSS

The admin module's stylesheet build system and source files have been converted from LESS to SCSS. This includes new SCSS files for icon styling (z.icons, z.icons/core, z.icons/extend, z.icons/font-awesome, z.icons/material-design), button components (z.icons/icon-buttons), bridge status indicators (z.bridge), and modal dialogs (z.modal), along with a new Makefile to manage the compilation of these SCSS files.

_apps/zotonic\_mod\base/priv/lib-src/scss · high confidence

New JavaScript-based authentication workers for UI and background checks

The authentication module now uses dedicated JavaScript workers to manage the authentication state and UI. The new \zotonic.auth-ui.worker.js\ handles the login, password reset, and 2FA forms, while \zotonic.auth.worker.js\ manages the background polling for session status and token refresh. This shift introduces a more robust, client-side state management for authentication flows, including support for password expiration, OAuth2 login, and improved handling of race conditions during authentication checks.

_apps/zotonic\_mod\authentication/priv/lib/js · medium confidence

New and updated error messages for authentication failures

Added new template files to provide specific, user-friendly error messages for various authentication scenarios. These include templates for data breach warnings (referencing Have I Been Pwned), two-factor authentication passcode errors and reminders, password validation failures (too short, too simple, matching previous password, unequal confirmation), rate limiting, and account status issues (user not enabled, external login restrictions). Existing templates for login failures and password changes were also updated.

_apps/zotonic\_mod\_authentication/priv/templates/logon\error · medium confidence

New backup management and download endpoints

The backup module now exposes new administrative and user-facing routes. Administrators can access backup management and deletion screens via the admin interface, while users can download backup files through a dedicated download endpoint that serves files from the mod\_backup module as attachments.

_apps/zotonic\_mod\backup/priv/dispatch · high confidence

New development admin pages for templates, dispatch, and tracing

The development module now exposes several new admin pages under the /admin/development path, allowing users to inspect and debug their site's configuration and templates. These include a dispatch rules viewer, a template cross-reference checker, a template dependency graph, an observers list, and function tracing tools. Additionally, a basic test page is available at /test/hello\_world for development purposes.

_apps/zotonic\_mod\development/priv/dispatch · high confidence

Nix package management initialized with Nixpkgs 26.05

The project now manages system dependencies using Nix, introducing a new nix/nixpkgs.nix file that pins the Nixpkgs repository to the 26.05 release (26.05.tar.gz). This establishes the foundation for declarative, reproducible build environments via Nix.

nix · medium confidence

Redesign of ACL rule administration and user group management

The ACL administration interface has been completely restructured with new templates for managing access control rules, including dedicated dialogs for editing, importing, and testing rules. The user-add and user-edit dialogs now allow administrators to assign users to specific user groups. Additionally, the system now supports visibility levels in ACL rules, allowing administrators to control whether content is public, private, or restricted to specific user groups or collaboration groups.

_apps/zotonic\_mod\_acl\_user\groups/priv/templates · high confidence

Redesign of the Zotonic system status page

The Zotonic system status page has been completely redesigned with a new layout, updated CSS styles, and modernized templates. The previous 'less' based stylesheets have been replaced with SCSS, and the UI now features a Bootstrap-based navbar, a structured site overview table with status indicators, and improved templates for the home, logon, and status pages. The configuration file has also been updated to reflect the new OTP structure.

_apps/zotonic\_site\status · high confidence

Refactor admin identity actions into dedicated modules

The admin identity management actions have been reorganized into a dedicated \zotonic\_mod\_admin\_identity\ application. This includes new modules for managing usernames and passwords (\action\_admin\_identity\_dialog\_set\_username\_password.erl\, \action\_admin\_identity\_dialog\_user\_add.erl\), a new module for deleting usernames (\action\_admin\_identity\_delete\_username.erl\), and the migration of the username deletion dialog from the old \mod\_admin\ module. These changes consolidate user identity administration logic, enforcing stricter access controls (e.g., preventing the admin user from having a password) and providing specific UI dialogs for adding, editing, and deleting user credentials.

_apps/zotonic\_mod\_admin\identity/src/actions · high confidence

Relocate and reconfigure 2FA admin module dispatch

The dispatch rule for the two-factor authentication configuration has been moved from the generic admin modules area to the dedicated 2FA application directory. The route has changed from admin\_modules to admin\_auth2fa\_config, mapping the path admin/authentication-2fa to the admin controller using the admin\_auth2fa\_config template, with SSL enforced and access restricted to the mod\_admin\_config ACL module.

_apps/zotonic\_mod\auth2fa/priv/dispatch · medium confidence

Removal of artist event management features

The mod\_admin\_event module and its associated components have been removed. This eliminates the ability to add, view, and manage events for artists within the admin interface, including the 'Add event' dialog, sidebar widgets, and the underlying Erlang and template files that supported this functionality.

_modules/mod\_admin\event · high confidence

Removal of legacy Webmachine and Zotonic header files

The header files \include/resource\_html.hrl\, \include/webmachine\_resource.hrl\, and \include/zotonic.hrl\ have been removed. This eliminates the legacy Webmachine resource definitions and the central \\#context\ record structure, reflecting the migration away from Webmachine and the refactoring of the application's core data structures.

include · high confidence

Removed default site CSS and font files

The default site's stylesheet (zp-project.css) and a Cufon font file (cufon.anja.js) have been removed. This cleanup likely reflects a shift away from the previous visual styling and font rendering approach for the default site.

priv/sites/default · high confidence

Removed deprecated MochiWeb modules

The MochiWeb dependency has been updated to version r153, which includes the removal of several legacy modules: \mochifmt\ (string formatting), \mochihex\ (hexadecimal utilities), \mochijson\ and \mochijson2\ (JSON encoding/decoding), \mochinum\ (numeric algorithms), and various other utility modules like \mochiweb\_charref\, \mochiweb\_cookies\, \mochiweb\_echo\, \mochiweb\_headers\, and \mochiweb\. These files have been deleted from the \deps/mochiweb/src/\ directory, indicating a significant reduction in the bundled library's feature set.

deps/mochiweb · medium confidence

Removed erlang-oauth, mochiweb, and webmachine dependencies

The local dependencies for erlang-oauth, mochiweb, and webmachine have been removed from the project's deps directory. This change eliminates the bundled source code, build scripts, and templates for these libraries, indicating they are no longer managed as local submodules or vendored code.

deps · high confidence

Removed group management UI and actions from the admin module

The admin interface for managing groups and their members has been removed. This includes deleting the Erlang action modules (such as \action\_admin\_group\_dialog\_group\_delete\, \action\_admin\_group\_dialog\_group\_member\_add\, and others) that handled the backend logic for creating, editing, and deleting groups and members. Corresponding templates for the group list, member list, and confirmation dialogs have also been removed, along with the \mod\_admin\_group\ module and its associated resources and dispatch rules. This change eliminates the ability to perform group administration tasks through the web interface.

_modules/mod\_admin\group · high confidence

Removed legacy ISO 639 language mapping and z\_trans module

The src/i18n/iso639.erl and src/i18n/z\_trans.erl files have been deleted. This removes the internal mapping of two-letter language codes to English names and the legacy z\_trans translation lookup mechanism, likely as part of a broader i18n refactoring.

src/i18n · high confidence

Removed legacy esmtp email sending implementation

The module replaced its internal esmtp-based email sending logic with a new gen\_smtp based SMTP implementation. This change removes the old esmtp\_fsm, esmtp\_mime, and rfc2047 modules, along with the email\_base template, streamlining how the system sends emails.

_modules/mod\emailer · high confidence

Removed obsolete test module and its associated resources

The \mod\_test\ module, which previously served as a test harness for the module system, has been removed. This includes the deletion of the \gen\_server\ implementation, the \testing\ dispatch file, the \resource\_test\_helloworld\ resource, and all associated templates (including \test\_helloworld.tpl\ and \test\_included.tpl\). These components are no longer needed for internal testing.

_modules/mod\test · high confidence

Removed standalone Google SEO module in favor of unified SEO module

The standalone \mod\_seo\_google\ module and its associated templates have been removed. Google Analytics and Webmaster Tools configuration is now handled within the unified \mod\_seo\ module, which also adds support for Bing webmaster tools.

_modules/mod\_seo\google · high confidence

Replace bash launcher scripts with Erlang-based zotonic launcher

The \bin/zotonic\ shell script and \bin/zotonic.escript\ have been replaced by a new Erlang-based launcher. This change introduces a \completion\ command to install bash autocompletion for the \zotonic\ CLI, adds support for FreeBSD and DragonFly BSD operating systems, and restricts the Erlang Port Mapper Daemon (epmd) to listen only on the loopback interface (127.0.0.1) for improved security. The launcher now dynamically loads command modules from \apps/zotonic\_launcher/src/command\.

_apps/zotonic\launcher/bin · high confidence

Restructured and expanded authentication templates

The authentication module's templates have been reorganized into a modular structure, introducing dedicated templates for password changes, session management, and external service errors. Users can now change their passwords directly from the login interface, manage active sessions via a new session overview, and see clearer error messages when connecting external accounts. The login form now supports a two-step process where the username is verified before the password is requested, improving the user experience for password managers and reducing information leakage about registered email addresses.

_apps/zotonic\_mod\authentication/priv/templates · high confidence

Restructured database installation and upgrade logic

The database installation and upgrade process has been refactored into dedicated modules: \z\_install\ handles the SQL data model, \z\_install\_data\ seeds initial categories, predicates, and the admin user, \z\_install\_reinstall\ provides a schema drop-and-recreate workflow, and \z\_install\_update\ manages startup checks and upgrades. This separation clarifies the distinct phases of database initialization, data seeding, and versioned upgrades.

_apps/zotonic\core/src/install · high confidence

Simplified Zotonic application structure and supervisor

The Zotonic application entry point and supervisor have been refactored to support an umbrella application structure. The \zotonic.app\ and \zotonic.app.src\ files have been updated to declare dependencies on \cowboy\, \cowmachine\, and \zotonic\_launcher\, replacing the previous \webmachine\ and \zotonic\_deps\ dependencies. The \zotonic\ and \zotonic\_deps\ modules have been removed, and the \zotonic\_sup\ supervisor has been simplified to an empty structure, delegating supervision to the new \zotonic\_launcher\ application.

src · high confidence

TinyMCE editor updated to version 5.10.2

The TinyMCE rich text editor library has been upgraded from version 4.5.5 to 5.10.2. This update replaces the older 4.x series plugins with the 5.10.2 versions for all standard plugins (including advlist, anchor, autolink, autoresize, autosave, bbcode, charmap, code, and codesample), bringing the editor to a more recent release with updated plugin implementations.

(repo-wide) · high confidence

TinyMCE version resolution now defaults to newest when configured version is unsupported

The TinyMCE editor model now automatically falls back to the newest available version if the configured version is not supported. Previously, an unsupported version might have caused issues or required manual intervention; now, the system logs a warning and resolves to the latest bundled version, ensuring the editor remains functional without breaking changes for users who have configured older, potentially deprecated, TinyMCE versions.

_apps/zotonic\_mod\_editor\tinymce/src/models · high confidence

Updated Bootstrap JavaScript library to v3.4.1

The admin interface's bundled JavaScript library, Bootstrap, has been upgraded from version 3.3.5 to 3.4.1. This update replaces the \bootstrap.js\ and \bootstrap.min.js\ files in the admin module's public resources, bringing the latest bug fixes and improvements from the Bootstrap 3.4.1 release to the admin UI components.

_apps/zotonic\_mod\admin/priv/lib/js/bootstrap3 · high confidence

Updated Bootstrap theme CSS to v3.4.1

The Bootstrap theme CSS files (bootstrap-theme.css, bootstrap-theme.min.css, and the associated .map file) have been updated to version 3.4.1. This update refreshes the default button, alert, progress bar, and panel heading styles to match the latest Bootstrap release, ensuring consistent visual styling across the application's UI components.

_apps/zotonic\_mod\bootstrap/priv · high confidence

Updated Font Awesome 4.2.0 assets

The \zotonic\_mod\_artwork\ module now includes the full, unminified CSS and SVG font files for Font Awesome 4.2.0, replacing the previous minified CSS version. This change ensures that the application uses the complete, readable CSS definitions and SVG font data for rendering icons, which may affect how styles are applied or how the font loads in the browser.

_apps/zotonic\_mod\artwork/priv · medium confidence

Updated TinyMCE editor to version 5.10.2

The embedded TinyMCE editor has been upgraded from version 4.5.5 to 5.10.2. This update brings a modernized user interface, improved accessibility features, and various bug fixes for table handling, link detection, and content editing. The configuration file (\tiny-init.js\) has been updated to reflect the new default plugins, toolbar layout, and style formats available in version 5.10.2.

_apps/zotonic\_mod\_editor\tinymce/priv/lib/js/tinymce-5.10.2 · high confidence

Updated TinyMCE editor with new configuration, assets, and translations

The TinyMCE 4.9.3 editor integration was updated to include a new \tiny-init.js\ configuration file that defines the editor's default settings, including the 'modern' theme, specific plugins (such as 'zlink' and 'zmedia'), and a customised list of valid HTML elements. The update also adds the \jquery.tinymce.min.js\ plugin file, which provides the jQuery integration for the editor. Additionally, new language files for English (GB), Dutch, and Russian were added to support multilingual user interfaces, and the 'lightgray' skin assets (CSS and SVG fonts) were updated to style the editor's content and interface.

_apps/zotonic\_mod\_editor\tinymce/priv/lib/js/tinymce-4.9.3 · high confidence

Updated TinyMCE editor with version selection and enhanced media editing options

The TinyMCE editor module now supports selecting between TinyMCE versions 4.9.3 and 5.10.2 via the admin configuration, with 5.10.2 set as the default. The media insertion dialog has been expanded to include alignment, crop, size, and link options, and now features a 'Remove from text' button and an 'Edit' link to manage media properties directly.

_apps/zotonic\_mod\_editor\tinymce/priv/templates · high confidence

Updated translations for multiple languages

The translation files in apps/zotonic\_core/priv/translations have been updated with new and revised text for various languages, including Arabic, German, English, and Spanish. This includes updates to country and language name translations, as well as general application strings. These changes ensure that the user interface is fully localized and up-to-date with the latest source strings.

_apps/zotonic\core/priv/translations · high confidence

Video handling and conversion logic moved to dedicated module

The video processing logic, including conversion to MP4, preview generation, and metadata extraction, has been consolidated into the new \zotonic\_mod\_video\ application. This change introduces a dedicated module for video support, replacing the previous inline handling within the core. Users will now see video-specific templates and CSS for the admin interface, and video uploads are processed through a dedicated queue and conversion pipeline, improving separation of concerns and maintainability.

_apps/zotonic\_mod\video · high confidence

Fixes

Fix spec for z\_list\_of\_ids\_filter:filter functions

Corrected the type specifications for the filter functions in the z\_list\_of\_ids\_filter module, ensuring that the function signatures accurately reflect the expected input and output types for resource filtering operations.

_apps/zotonic\_mod\base/src/support · medium confidence

Improved Markdown and HTML-to-Markdown conversion

The markdown conversion logic has been updated to fix several issues with HTML-to-Markdown and Markdown-to-HTML conversion. Specific fixes address crashes and formatting errors when converting certain HTML tables, list indentations, code blocks, and inline markup. The changes also improve handling of Unicode strings and ensure that spaces after code tags are preserved during conversion.

_apps/zotonic\core/src/markdown · medium confidence

Test coverage

Added EUnit tests for ACL user-group authorization logic; Added EUnit tests for base filters and admin module; Added comprehensive test coverage for core modules; Added connection and postback test pages for diagnosing browser and server connectivity; Added test data fixtures for config, CSV, and email parsing; Removed ErlyDTL test suite and templates.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 36.

Lenses

  • Code Health 24
  • Architecture 100
  • Maturity 65
  • Readiness 50
  • Security 48
  • Event-Driven 80
  • Event Sourcing 100
  • Accessibility 34

Changes since last survey

  • 300 commits — 251 feature/other, 49 fixes

By area

  • apps/zotonic_core — 125 commits
  • apps/zotonic_mod_survey — 36 commits
  • (root) — 33 commits
  • (repo) — 12 commits
  • apps/zotonic_mod_admin — 12 commits
  • apps/zotonic_mod_development — 10 commits
  • apps/zotonic_mod_admin_predicate — 7 commits
  • apps/zotonic_mod_base — 6 commits
  • apps/zotonic_mod_filestore — 6 commits
  • apps/zotonic_mod_wires — 6 commits
  • apps/zotonic_mod_signup — 4 commits
  • .agents/skills — 3 commits
  • apps/zotonic_mod_media_exif — 3 commits
  • apps/zotonic_mod_search — 3 commits
  • doc/release-notes — 3 commits
  • apps/zotonic_mod_email_status — 2 commits
  • apps/zotonic_mod_export — 2 commits
  • apps/zotonic_mod_import_csv — 2 commits
  • apps/zotonic_mod_logging — 2 commits
  • apps/zotonic_mod_seo — 2 commits

Notable commits

  • fix: Add log audit key, for now for auth. Also fix issue with copyright edit form (#4276)
  • fix: Connect dialog: Fix option Any category (#4352)
  • fix: Fix a problem where a button click can be lost if the focused input is invalid (#4459)
  • fix: Fix an issue with parallel edge insert and unknown ACL actions (#4259)
  • fix: Fix an issue with searching for dashed words, like 'e-learning'
  • fix: Fix edocs and old '@type' specs. (#4377)
  • fix: Fix hex publish zotonic_apps (#4384)
  • fix: Fix ids facet search integer input (#4448)
  • fix: Fix small edoc and spec issue (#4330)
  • fix: Fix template compiler callbacks
  • fix: Fix variable from the confirmation dialog (#4416)
  • fix: Fixes for hex package release (#4382)
  • fix: Misc fixes Jan 26 (batch 1) (#4270)
  • fix: Revert "Wiring normal signups together."
  • fix: core: fix an issue in markdown where inline markup was applied after a non space character (#4323)
  • fix: core: fix an issue in search with passing non-list category terms (#4434)
  • fix: core: fix an issue where qargs url expansion left 'qargs' in the arg list (#4474)
  • fix: core: fix an issue where the dispatcher could crash on an empty path (#4263)
  • fix: core: fix an issue where the language config could be overwritten (#4367)
  • fix: core: fix an issue where the memo cache was not flushed correctly (#4329)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

zotonic/zotonic was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0d5de7630a8be1b70133adf38f04cc9ca4019ad2 — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.