zotonic/zotonic
36.1
Weak · 6 August 2026
172.3k
lines of production code
Erlang
with JavaScript
3
measurements over time
What this system is
Zotonic is a modular Erlang/OTP web application framework that provides a comprehensive backend for content management, user authentication, and administrative control. It features a flexible access control system, a robust backup and migration infrastructure, and a modernized admin interface for managing resources, users, and system configuration. The system also includes specialized modules for handling media, file indexing, and real-time communication via MQTT and SMTP.
How it got here
2009–2017 — modularization and admin overhaul
209 changes.
The project underwent a major architectural shift, migrating from a monolithic structure to a modular OTP application layout with a Rebar3 build system. This period focused on replacing legacy components like Webmachine and ErlyDTL with modern alternatives such as Cowboy and Cotonic, while simultaneously rebuilding the administrative interface with granular access control and new management tools.
2018–2026 — Security, extensibility, and developer tooling
64 changes.
This period focused on hardening the platform's security posture by introducing two-factor authentication, rate limiting, file scanning, and robust password validation. It also significantly expanded the framework's extensibility through new behaviors and modules for OAuth2, Microsoft login, and server-side storage. Concurrently, developer experience was enhanced with live reload, template debugging, and a modernized admin interface using Bootstrap 3 and SCSS.
Features
Add 2FA model for TOTP provisioning and state management
Introduces the m\_auth2fa model, implementing the backend logic for two-factor authentication. This includes generating TOTP provisioning URLs and managing user secrets, checking if TOTP is enabled for a user, and enforcing site-wide 2FA modes (optional, ask, required, forced). The model also provides API endpoints to check clock skew for time-based codes and manage session states for the 2FA dialog.
_apps/zotonic\_mod\auth2fa/src/models · high confidence
Add ACL rules export controller
A new controller, controller\_admin\_acl\_rules\_export, has been added to the zotonic\_mod\_acl\_user\_groups application. This component enables administrators to export Access Control List (ACL) rules in a binary format (.dat file) that can be re-imported later. The controller handles authorization checks against the mod\_acl\_user\_groups module and sets appropriate headers for file download.
_apps/zotonic\_mod\_acl\_user\groups/src/controllers · high confidence
Add Apache 2.0 license and build configuration for mod\_authentication
The mod\_authentication module now includes an Apache 2.0 license file and a rebar3 build configuration. The build file defines dependencies on zotonic\_core and zotonic\_mod\_admin, and adds the termit library (version 2.0) as a dependency. This establishes the module's legal and build framework for distribution.
_apps/zotonic\_mod\authentication · high confidence
Add Apache 2.0 license and rebar3 build configuration for zotonic\_mod\_cron
The zotonic\_mod\_cron application now includes an Apache 2.0 license file and a rebar3 configuration file. The rebar3 config sets a minimum OTP version of 23, includes the erlcron dependency (version 1.2.3), and configures documentation generation using ex\_doc for Hex packages.
_apps/zotonic\_mod\cron · high confidence
Add Bootstrap integration module and application metadata
Introduced a new \mod\_bootstrap\ module and its corresponding \.app.src\ configuration, which integrates the Bootstrap CSS/JavaScript framework into the Zotonic platform. The module provides helper templates and assets for UI components, while the application metadata explicitly declares dependencies on \kernel\, \stdlib\, and \zotonic\_core\, and specifies the Apache-2.0 license.
_apps/zotonic\_mod\bootstrap/src · high confidence
Add CSS styles for the login and signup forms
A new stylesheet, logon.css, is introduced to define the visual presentation of the authentication interface. This includes styling for the login box, form elements, error messages, and external sign-up options, ensuring consistent formatting for user-facing authentication components.
_apps/zotonic\_mod\authentication/priv/lib/css · high confidence
Add CSV and XLSX file parsing and writing capabilities
The zotonic\_core application now includes new Erlang modules for handling spreadsheet data: z\_csv\_parser and z\_csv\_writer manage reading and writing CSV files, including automatic detection of separators and safe encoding of values to prevent CSV injection. Additionally, z\_xlsx\_parser is introduced to parse XLSX (Excel) files, with memory usage capped at 160MB by default to prevent excessive resource consumption. These modules provide the underlying functionality for importing and exporting data in these formats.
_apps/zotonic\core/src/csv · high confidence
Add CSV and XLSX import functionality to the admin interface
The zotonic\_mod\_import\_csv module now provides a new admin interface for importing data from CSV and XLSX files. Users can upload files via a new 'Import CSV or XLSX file' button in the admin menu, which opens a dialog to select and upload files. The module supports importing both resource data (pages) and edge definitions (relationships) from CSV files, as well as XLSX files. The import process runs in the background, and progress is reported in the admin log and via notifications. The module also watches the site's dropbox folder for incoming CSV/XLSX files and imports them automatically.
_apps/zotonic\_mod\_import\csv · high confidence
Add ClamAV support module and MS Office filtering
The ClamAV integration is now supported for scanning files and binary data, including specific filtering for MS Office documents that contain external links. This adds new capabilities for virus scanning and content filtering within the Zotonic mod\_clamav application.
_apps/zotonic\_mod\clamav/src/support · high confidence
Add ClamAV virus scanning for uploaded files
A new \mod\_clamav\ module has been added to scan all uploaded files for viruses and malware using ClamAV. The module checks files after mime type and access control are verified, returning an \infected\ error if a threat is detected. It also includes a periodic health check that logs warnings if the ClamAV daemon is unreachable. Configuration options are provided for the ClamAV server IP, port, maximum file size, and rejecting Microsoft Office files with external links.
_apps/zotonic\_mod\clamav/src · high confidence
Add EXIF metadata extraction and display for media uploads
The zotonic\_mod\_media\_exif module now extracts EXIF metadata from uploaded photos and stores it as resource properties, including GPS location, crop center, orientation, and date. A new template partial renders these EXIF values in the admin media details view, and a template filter formats raw EXIF data (such as GPS coordinates and exposure settings) into human-readable text for display.
_apps/zotonic\_mod\_media\exif · high confidence
Add Facebook authentication and login integration
Users can now log in to the site using their Facebook account. This change introduces a new \mod\_facebook\ module that integrates with the platform's authentication system, allowing administrators to configure Facebook App ID, Secret, and scopes in the admin panel. The module provides OAuth2-based login and account linking/disconnect features, rendering Facebook login buttons on the logon and user profile pages. It also includes a model for fetching Facebook profile data and search query handling.
_apps/zotonic\_mod\facebook · high confidence
Add GeoIP module for IP-to-location mapping
Introduces the zotonic\_mod\_geoip application, which maps IP addresses to geographical locations using the MaxMind database. The module provides filters to convert IP addresses into country codes, city, continent, and location data. It supports configuration of a MaxMind license key via the 'maxmind\_license\_key' config key or the 'locus' application environment.
_apps/zotonic\_mod\geoip · high confidence
Add LinkedIn authentication integration
The zotonic\_mod\_linkedin module is introduced to enable users to log in to the site using their LinkedIn account. Administrators can configure the LinkedIn App ID and Secret in the admin interface, and users will see a 'Log in with LinkedIn' button on the logon form. The module handles the OAuth 2.0 flow, fetching the user's profile data and email address from LinkedIn to authenticate the user.
_apps/zotonic\_mod\linkedin · high confidence
Add MQTT listener support
The application now includes a new MQTT listener, introducing the \zotonic\_listen\_mqtt\ module to start and manage TCP/SSL listeners for MQTT connections. The handler processes MQTT connect packets, manages session lifecycles, and forwards data to the \mqtt\_sessions\ application. Configuration options such as \mqtt\_listen\_ip\, \mqtt\_listen\_port\, and \mqtt\_listen\_ssl\_port\ control the listener behavior.
_apps/zotonic\_listen\mqtt/src · high confidence
Add MQTT messaging support with live update components and client storage models
The zotonic\_mod\_mqtt application is introduced, providing MQTT messaging capabilities that connect the server and browser. This includes a new \scomp\_mqtt\_live\ component for live-updating templates based on MQTT topic subscriptions, an \action\_mqtt\_publish\ action for publishing messages, and client-side storage models (\m\_client\_local\_storage\ and \m\_client\_session\_storage\) to interact with browser storage via MQTT topics. The module also includes JavaScript modules (\z.live.js\, \qlobber.js\) to handle client-side subscription and topic matching, enabling real-time updates and persistent client-side state management through the MQTT broker.
_apps/zotonic\_mod\mqtt · high confidence
Add Microsoft identity platform login support
The \zotonic\_mod\_microsoft\ application has been added to provide Microsoft/Azure authentication. Users can now log in using their Microsoft account by configuring an App registration in the Azure Portal. The module adds a new authentication service panel in the admin interface where administrators can set the Application ID, Client Secret, OAuth scope (defaulting to 'email profile'), and tenant (defaulting to 'common'). The login flow redirects users to Microsoft for authorization and handles the OAuth2 callback to create or link user accounts.
_apps/zotonic\_mod\microsoft · high confidence
Add SSL CA module with admin UI and documentation
The zotonic\_mod\_ssl\_ca application is introduced, providing support for SSL certificates from a Certificate Authority. This includes an admin UI panel (\_admin\_config\_ssl\_panel.mod\_ssl\_ca.tpl) that displays certificate information and guides users on adding certificates to the security directory. The module (mod\_ssl\_ca.erl) handles SSL options and certificate file scanning, while the app source (zotonic\_mod\_ssl\_ca.app.src) declares dependencies on kernel, stdlib, and zotonic\_core. Documentation is added via moduledoc and markdown files, and the project adopts the Apache 2.0 license.
_apps/zotonic\_mod\_ssl\ca · high confidence
Add TinyMCE-based rich text editor to the admin interface
The admin now includes a WYSIWYG editor powered by TinyMCE (version 5.10.2). Users can edit content using a rich text interface that supports media insertion (images, videos) and automatic link generation for Zotonic pages. The editor is initialized on textareas with the class \z\_editor-init\ and can be configured via the \tinyInit\ object or by providing a custom stylesheet at \priv/lib/css/tinymce-zotonic.css\. The module also exposes a \zmedia-props\ command to render a dialog for selecting media items.
_apps/zotonic\_mod\_editor\tinymce/src · high confidence
Add WordPress WXR import module
Users can now import WordPress content by uploading a .wxr (WordPress eXtended RSS) file. The new \zotonic\_mod\_import\_wordpress\ module parses the XML export, mapping posts, categories, tags, and authors into the Zotonic datamodel. The admin interface provides a dialog to select the file and an option to re-import previously deleted items. The module includes its own license file (Apache 2.0) and depends on \zotonic\_core\ and \zotonic\_mod\_wires\.
_apps/zotonic\_mod\_import\wordpress · high confidence
Add admin category management module
Introduces the new \mod\_admin\_category\ module, enabling administrators to edit and manage the category hierarchy through the admin interface. The module provides functionality to delete categories and their associated resources, as well as move resources between categories. It includes ACL checks to ensure users have the necessary permissions to view, edit, and delete categories, and handles the deletion of resources within a category by checking if the category is in use before allowing removal.
_apps/zotonic\_mod\_admin\category/src · high confidence
Add admin config editor controller
The admin config editor now displays a list of all configuration settings with string values. The new controller filters out non-string settings and metadata fields, presenting only the editable key/value pairs to the user.
_apps/zotonic\_mod\_admin\config/src/controllers · high confidence
Add admin config module for editing system configuration
A new module, mod\_admin\_config, has been introduced to allow administrators to edit and insert configuration keys with string values via the admin interface. This module provides a list of all configuration modules, keys, and textual values, enabling users to add, remove, and edit entries if they have the appropriate permissions. The module also supports SSL certificate configuration and email configuration, including the ability to send test emails. The module is registered in the application source file, specifying dependencies on kernel, stdlib, and zotonic\_core.
_apps/zotonic\_mod\_admin\config/src · high confidence
Add admin configuration routes for email and SSL settings
The dispatch file introduces three new routing rules for the admin interface: a general configuration overview, an email configuration page, and an SSL configuration page. Each route maps a specific admin path to a controller and template, enabling users to manage email and SSL settings through the admin panel.
_apps/zotonic\_mod\_admin\config/priv/dispatch · high confidence
Add admin interface for managing predicates and connections
A new dispatch configuration file introduces four URL routes for the admin module: an overview of all connections (edges), a graph view of those connections, a list of all predicates, and an edit page for individual predicates. These routes map to specific controllers and templates, enabling administrators to view and manage the site's predicate and connection structure through the admin interface.
_apps/zotonic\_mod\_admin\predicate/priv/dispatch · high confidence
Add admin interface for merging resources
The admin module now includes a new feature allowing administrators to merge two resources (e.g., pages) into a single page. Users can select a 'winner' and a 'loser'; all properties and connections from the loser are merged into the winner, after which the loser is deleted and its URL returns a 410 Gone status. The implementation includes a new \filter\_admin\_merge\_diff\ module for comparing resources and a \mod\_admin\_merge\ module that handles the UI, permission checks, and the background merge process.
_apps/zotonic\_mod\_admin\merge/src · high confidence
Add admin statistics module for viewing system metrics
Introduced a new admin module that allows administrators to view system statistics. The module registers an 'Admin Statistics' entry in the admin menu, providing access to dashboard metrics and related system data.
_apps/zotonic\_mod\_admin\statistics/src · high confidence
Add audio file support with metadata extraction and preview generation
A new 'mod\_audio' module has been introduced to handle audio media items. It intercepts audio file uploads to extract metadata (such as artist, album, and duration) using 'ffprobe' and generates a PNG preview image using 'ffmpeg'. The module extends the media viewer to render audio files and allows editing of extracted tags in the admin interface.
_apps/zotonic\_mod\audio/src · high confidence
Add cloud file store configuration and administration interface
The mod\_filestore module now provides a complete administrative interface for configuring and managing remote file storage. Administrators can configure S3-compatible cloud storage endpoints, FTP, and WebDAV services directly through the admin panel. The update introduces a new 'Cloud File Store' menu item in the system settings, allowing users to set credentials, enable/disable uploads, configure local file retention, and manage file deletion intervals. The system includes a credential testing feature to verify connectivity before saving settings. Additionally, the module now supports moving files between local and cloud storage, with statistics and queue management for uploaded and cached files.
_apps/zotonic\_mod\filestore · high confidence
Add comment module for user-generated content
The \zotonic\_mod\_comment\ application is introduced, providing a basic commenting system that allows users to add comments to any resource. The module includes an admin interface for reviewing and deleting comments, supports both authenticated and anonymous commenting, and integrates with the search and admin menu systems. It also handles the migration of old comment and rating tables to the new schema.
_apps/zotonic\_mod\comment/src · high confidence
Add contact form and email template for user submissions
Introduced a new contact form page and an accompanying email template. The form collects name, email, and message, while the email template formats the submitted data for notification. This adds a new user-facing capability to submit contact requests via the website.
_apps/zotonic\_mod\contact/priv · high confidence
Add contact form module for user-submitted email submissions
A new contact form module (mod\_contact) is introduced, allowing users to submit messages via a web form that are then emailed to a configured administrator address. The module handles form submission, validation, and delivery, with configurable email recipients and sender addresses. It also installs a default 'Contact' page at /contact.
_apps/zotonic\_mod\contact/src · high confidence
Add content group usage check model
A new model for content group memberships has been introduced, exposing an API path to check whether a specific content group (or any of its children) is currently in use by at least one resource. This allows users to query the system to determine if a content group is actively referenced in the database.
_apps/zotonic\_mod\_content\groups/src/models · high confidence
Add copyright management module with admin panel and template support
The new \mod\_copyright\ module provides an admin panel and templates to select and view copyrights attached to content items. It supports Creative Commons and RightsStatements.org licenses, with default values for rights, attribution, and year that can be overridden via configuration keys or by providing a custom \\_copyright.tpl\ template.
_apps/zotonic\_mod\copyright · high confidence
Add custom redirect module for domain and path redirection
Introduces the mod\_custom\_redirect module, enabling administrators to configure redirects for unknown hosts and paths. The module observes dispatch notifications to match incoming requests against a configurable list of domains and paths, supporting both permanent and temporary redirects. This adds a new capability to handle 404-style scenarios by redirecting users to specified locations.
_apps/zotonic\_mod\_custom\redirect/src · high confidence
Add detailed statistics panels for system, database, and dispatch metrics
The admin statistics interface now includes new panels for monitoring Erlang VM memory usage, system resource limits (atoms, ports, processes), database pool health, HTTP dispatch latency and throughput, and MQTT broker activity. These templates provide real-time visualizations and metrics for each subsystem, allowing administrators to monitor system health and performance directly from the admin dashboard.
_apps/zotonic\_mod\_admin\_statistics/priv/templates/stat\panel · high confidence
Add developer guide and license files for the TinyMCE editor module
The \apps/zotonic\_mod\_editor\_tinymce\ directory now includes a \DEVELOPER\ file that documents the step-by-step process for installing and configuring new versions of the TinyMCE editor, alongside \LICENSE\ (Apache 2.0) and \LICENSE-TINYMCE\ (LGPL 2.1) files that clarify the legal terms for the module and the embedded TinyMCE library.
_apps/zotonic\_mod\_editor\tinymce · high confidence
Add development tools: live reload, template graph, and variable debugging
The development module now supports live reloading of CSS, JavaScript, and template files, allowing developers to see changes instantly without a full page refresh. Additionally, a visual dependency graph of all templates is now available for navigation, and template variables can be live-debugged directly in the browser.
_apps/zotonic\_mod\development/priv/lib/js · high confidence
Add email receive module and restructure mailing list templates
Introduces a new \zotonic\_mod\_email\_receive\ module to handle inbound emails and route them to registered recipients, including a database model for managing email-to-user/resource mappings. Additionally, the mailing list module adds new admin templates for combining mailing list recipients, editing mailing list content and sidebar, viewing mailing status, and managing subscriptions, alongside updated routing for mailing list pages.
_apps/zotonic\_mod\mailinglist · high confidence
Add email relay capability for cross-server email handling
The \zotonic\_mod\_email\_relay\ application is introduced, enabling a Zotonic server to relay outbound emails to another Zotonic server, and conversely, to receive and process relayed emails and status reports from a remote server. Administrators can configure relay endpoints and shared secrets via the \mod\_admin\_config\ interface, and the module handles delivery status updates and recipient blocking synchronization between servers.
_apps/zotonic\_mod\_email\relay · high confidence
Add email status tracking and management for recipients
The zotonic\_mod\_email\_status module now tracks the delivery status of all outgoing emails, including successful sends, bounces, and errors. Administrators and users with appropriate permissions can view detailed status reports for any email address, including error counts, timestamps, and the most recent error message. The system allows users to manually clear error states or block/unblock email addresses to prevent sending to or receiving from specific addresses.
_apps/zotonic\_mod\_email\status · high confidence
Add export capabilities for CSV, JSON, XLSX, Atom, and iCalendar formats
The mod\_export module now provides a generic framework to export resources in multiple formats including CSV, JSON, XLSX, Atom, and iCalendar (ICS). Users can download data from the admin interface or via URL parameters, with support for customizing export fields and templates. The module registers content types for these formats and handles the streaming of export data, allowing users to export single resources, collections, or query results in various structured formats.
_apps/zotonic\_mod\export · high confidence
Add graph view for predicate management
The predicate administration interface now includes a visual graph view, allowing users to see and interact with the relationships between predicates and categories. This new feature includes a JavaScript implementation (admin-graph.js) and corresponding CSS styles (admin-graph.css) to render the graph, along with the inclusion of the Graphology library (graphology-0.26.0.umd.min.js) to support the graph visualization. Users can now explore connections, filter predicates within the graph, and manage hidden categories and predicates through this interactive view.
_apps/zotonic\_mod\_admin\predicate/priv/lib · high confidence
Add graph view for predicates with JS API and styling
The admin predicate module now includes a visual graph view that renders a directed resource graph using Sigma.js and Graphology. This adds a new interactive visualization where users can click resources to highlight incoming and outgoing edges, with incremental updates and pathfinding capabilities. The change introduces a public JavaScript API (exposed via the global \ResourceGraph\ object) for managing the graph, including methods to set, reset, add, and filter nodes and edges, as well as control path-only mode and hidden categories/predicates. Styling for the graph container and active resource panel is also added via new SCSS variables and layout rules.
_apps/zotonic\_mod\_admin\predicate · high confidence
Add license headers and build configuration to Zotonic modules
Each module in the \apps\ directory (including \zotonic\_mod\_acl\_mock\, \zotonic\_mod\_admin\, \zotonic\_mod\_admin\_category\, \zotonic\_mod\_admin\_config\, and \zotonic\_mod\_admin\_frontend\) now includes an Apache 2.0 LICENSE file and a \rebar.config\ file. The configuration enforces a minimum OTP version of 23, enables debug info, and sets up \ex\_doc\ for Hex documentation, preparing these applications for distribution as packages.
(repo-wide) · high confidence
Add localization and plugin logic for the TinyMCE zmedia editor plugin
The zmedia plugin for the TinyMCE editor now includes English, Dutch, and Russian translation files, enabling users to see the interface in their preferred language. The plugin's core JavaScript (plugin.min.js) has been added, implementing the logic for inserting and managing media items, including support for alignment, size, crop, link, and caption properties. This change provides the necessary infrastructure for the editor to handle Zotonic media items with full localization support.
_apps/zotonic\_mod\_editor\tinymce/priv/lib/js/tinymce-5.10.2/tinymce/plugins/zmedia · high confidence
Add m\_comment model for managing page comments
A new m\_comment model is introduced to handle comment operations, including listing comments by resource, counting them, retrieving individual comments, and inserting new ones. The model enforces access control by checking resource visibility and user permissions, and it caches comment listings and counts. It also provides an is\_deletable check to verify if a comment can be removed.
_apps/zotonic\_mod\comment/src/models · high confidence
Add media overlay for viewing larger media items
The mod\_wires module now includes a new media overlay feature that allows users to view larger versions of media items. This includes a new template (\_mediaoverlay.tpl) that renders media with navigation controls for previous/next items, a JavaScript module (mediaoverlay.js) to handle click events and notify the system, and corresponding CSS styles (mediaoverlay.scss/css) that define the overlay's appearance, including responsive adjustments for smaller screens. The media overlay is configured via a new mediaclass.config file.
_apps/zotonic\_mod\wires · high confidence
Add module management screen to the admin interface
A new module management screen has been added to the admin interface, allowing users to view, activate, and deactivate modules. The module list is sorted by status and priority, and modules with configuration options display a configuration button to open a dialog for setting required options.
_apps/zotonic\_mod\_admin\modules/src · high confidence
Add new JavaScript modules for HTTP ping, cryptography, hotkeys, and UI enhancements
The application now includes several new JavaScript modules in the \zotonic\_mod\_base\ library. These additions provide HTTP ping functionality for network latency and loss monitoring, cryptographic encoding/decoding (MD5, SHA1, Base64, XTEA), keyboard hotkey handling, loading masks for UI feedback, text shortening with HTML awareness, time picker support, scroll-based history management, UBF encoding, and enhanced autocomplete, clickable element, date picker, dialog, and feedback widgets. These modules expand the client-side capabilities for network monitoring, security, user interaction, and UI management.
_apps/zotonic\_mod\base/priv/lib/js/modules · high confidence
Add non-destructive image editing capabilities
The image edit module now provides a modal interface for non-destructive image adjustments including rotation, cropping, contrast, brightness, roll, tilt, and pan. These edits are stored as properties and applied when images are resized, leaving the original file untouched. The feature includes a new overlay-based UI, CSS styling, and backend logic to manage image edit settings.
_apps/zotonic\_mod\_image\edit · high confidence
Add page merge functionality to admin interface
The admin interface now includes a new page merge feature, allowing administrators to combine two pages into one. This includes a search and selection screen to find and choose the second page, a comparison view that displays differences between the two pages (including title, content, and now depiction/media), and a confirmation dialog where the user selects the 'winner' and 'loser' pages. The merge process also offers an option to add missing translations from the loser to the winner.
_apps/zotonic\_mod\_admin\merge/priv/templates · high confidence
Add password acceptability validator
A new \acceptable\_password\ validator is now available for validating password strength and length against site configuration. It checks minimum length, regex criteria, and optionally checks against known data breaches via the Have I Been Pwned service. The validator supports optional parameters like \allow\_empty\ and custom \failure\_message\.
_apps/zotonic\_mod\authentication/src/validators · high confidence
Add site update module for Git/Mercurial updates
A new module, mod\_site\_update, is introduced to allow administrators to update a site's code from a remote version control system (Git or Mercurial). This includes a new admin interface for configuring a webhook token, status buttons on the System -\> Status page to trigger updates, and a model API to check VCS status and handle webhook requests. The module also supports updating the Zotonic core itself via the status site.
_apps/zotonic\_mod\_site\update · high confidence
Add structured data (JSON-LD) and SEO admin interface
The mod\_seo module now generates Schema.org structured data in JSON-LD format for articles, events, videos, and other content types, enabling rich search results. An admin interface at /admin/seo allows configuring global SEO settings, including keywords, descriptions, and search engine verification codes for Google, Bing, Yandex, and Google Search Console. The module also supports Google Analytics, Google Tag Manager, and Plausible tracking scripts, with options to exclude pages or categories from search engine indexing.
_apps/zotonic\_mod\seo · high confidence
Add templates for rendering and editing page blocks
The admin interface now supports editing and displaying page blocks. For editing, new templates provide forms for header and text blocks, and a page block editor with connect/disconnect actions. For display, new templates render page blocks in various styles (header, text, quote, aside, inline, video, media) and handle the visual presentation of block content on the frontend.
_apps/zotonic\_mod\admin/priv/templates/blocks · high confidence
Add temporary resource filter for unowned resources
Introduced a new \filter\_temporary\_rsc\ module that creates temporary resources which are automatically deleted if unmodified after an hour. The filter supports both map and list-based property arguments, ensuring that only the session user who created the resource can edit it. This enables workflows where an intermediate title-dialog is skipped, with the system managing the resource's lifecycle via a background task.
_apps/zotonic\_mod\admin/src/filters · high confidence
Add test sandbox site for automated testing
A new test sandbox site is introduced, providing a dedicated environment for automated testing. This includes a configuration file (zotonic\_site.config) that defines the site's modules and database schema, along with a controller and templates for testing web interactions, postbacks, and UI effects. The setup also includes a basic test suite to verify the sandbox is active and its default modules are running.
_apps/zotonic\_site\testsandbox · high confidence
Add timezone and localization configuration to the admin interface
The admin interface now includes a dedicated configuration page for localization settings, allowing administrators to set a default timezone and choose whether to fix the timezone for all users. This is supported by new templates for the admin panel, a dispatch rule for the admin controller, and a JavaScript library (jstz) for client-side timezone detection. Additionally, translation files for date and time strings in multiple languages (Irish, Indonesian, Japanese, Dutch, Polish, Portuguese, Russian) have been added to support the localization features.
_apps/zotonic\_mod\l10n · high confidence
Add two-factor authentication (2FA) module
The new \zotonic\_mod\_auth2fa\ module introduces two-factor authentication using TOTP. This adds a configuration option to enforce 2FA on login or require it once after logon, and provides admin controls to manage user group settings and remove 2FA from accounts.
_apps/zotonic\_mod\auth2fa/src · high confidence
Add video embed support for YouTube, Vimeo, and other services
The zotonic\_mod\_video\_embed application is introduced to handle embedding videos as media pages. It allows users to paste YouTube, Vimeo, or other service URLs in the admin's create media/page dialog, which then generates the correct embed code. The module stores embed information in the medium table and provides templates to render the embedded video with responsive wrappers. Admin users can view and manage video embed details such as service, ID, author, and canonical URL.
_apps/zotonic\_mod\_video\embed · high confidence
Added Hello World controller for server health checks
A new Erlang controller, \controller\_hello\_world\, has been added to the Zotonic development module. This controller serves the string "Hello, World!" and is intended to be used as a dispatch rule to verify that the server is responding.
_apps/zotonic\_mod\development/src/controllers · high confidence
Added QR code generation and base32 encoding support
The 2FA module now includes a complete QR code generation implementation, adding new support files for QR encoding, matrix manipulation, masking, and Reed-Solomon error correction. Additionally, a new base32 encoding module and bit manipulation utilities have been introduced to support the QR functionality.
_apps/zotonic\_mod\auth2fa/src/support · high confidence
Added ability to disconnect authentication methods
Users can now disconnect specific authentication methods from their account. This new action allows for the removal of linked identities, providing greater control over account security and connected services.
_apps/zotonic\_mod\authentication/src/actions · high confidence
Added admin statistics controller for system statistics
A new Erlang controller, controller\_admin\_statistics, has been added to handle requests for the admin statistics page. This controller manages access control via the mod\_admin\_statistics ACL module and renders the admin\_statistics template to display system statistics in the admin interface.
_apps/zotonic\_mod\_admin\statistics/src/controllers · high confidence
Added base64url encoding and text diffing utilities
The application now includes a new Erlang module, base64url.erl, which provides functions for encoding and decoding data using the base64url alphabet (RFC 4648). Additionally, the backup module incorporates JavaScript libraries for generating text diffs: wdiff.js and jsdiff.js implement word-based and character-based diffing algorithms, which are utilized by the z.make\_diff.js module to render visual differences in text content.
_apps/zotonic\_core/src/base64url, apps/zotonic\_mod\backup/priv/lib · high confidence
Added build scripts and configuration to integrate Cotonic assets
The zotonic\_mod\_base app now includes shell scripts (cotonic-fetch.sh, cotonic-update.sh, cotonic-clean.sh) and a rebar.config file to manage the download and placement of Cotonic JavaScript files (cotonic.js, cotonic-worker.js, cotonic-service-worker.js) into the priv/lib/cotonic directory. This change establishes the build-time process for bundling these frontend assets, supported by an Apache 2.0 LICENSE file.
_apps/zotonic\_mod\base · high confidence
Added dispatch rules for ACL rule management and testing
The application now maps specific URL paths to controllers and templates for managing Access Control List (ACL) rules. This includes endpoints for viewing and editing rules for resources, collaboration, modules, uploads, and options, as well as a dedicated test interface for ACL rules. These routes enable administrators to configure and test ACL policies through the admin interface.
_apps/zotonic\_mod\_acl\_user\groups/priv/dispatch · high confidence
Added dispatch rules for the admin frontend edit page
The admin frontend module now includes a dispatch configuration that maps the 'edit' URL pattern to the 'page' controller. This setup renders the 'page\_admin\_frontend\_edit.tpl' template, enforces authentication, applies SEO noindex headers, disables caching, and handles both static and dynamic (by ID) edit routes.
_apps/zotonic\_mod\_admin\frontend/priv/dispatch · high confidence
Added email and username uniqueness validators
New validators have been introduced for the admin identity module to check if an entered email address or username is unique within the system. The email validator (\validator\_admin\_identity\_email\_unique\) verifies uniqueness by querying the \m\_identity\ table, supporting an optional \id\ parameter to exclude the current user's record during editing. The username validator (\validator\_admin\_identity\_username\_unique\) similarly checks for uniqueness, including a check against reserved names, and provides a user-friendly error message when a username is already in use. Both validators support an \id\ argument to allow editing without triggering a conflict for the current user.
_apps/zotonic\_mod\_admin\identity/src/validators · high confidence
Added email normalization filter for identity management
A new filter, \filter\_normalize\_email\, has been introduced to the admin identity module. This component is responsible for normalizing email addresses used as keys in the identity table. It processes the input by lowercasing and trimming the email address, ensuring consistent formatting for identity lookups.
_apps/zotonic\_mod\_admin\identity/src/filters · medium confidence
Added hasedge validator for checking resource edges
A new 'hasedge' validator is now available to verify that a resource has a specific number of edges with a given predicate. This allows forms to enforce minimum or maximum edge counts (e.g., requiring at least one author or keyword) during form submission, with success or error messages displayed based on the validation result.
_apps/zotonic\_mod\admin/src/validators · high confidence
Added internal link insertion to the TinyMCE editor
The TinyMCE editor now supports inserting internal links to Zotonic pages directly within the body text. This change introduces a new 'zlink' plugin for TinyMCE 5.10.2, adding a 'Zotonic Link' button and menu item that trigger a dialog for selecting internal links. The plugin includes localization files for English, Dutch, and Russian to support the 'Insert internal link' and 'Insert an internal link' labels.
_apps/zotonic\_mod\_editor\_tinymce/priv/lib/js/tinymce-4.9.3/tinymce/plugins/zlink, apps/zotonic\_mod\_editor\tinymce/priv/lib/js/tinymce-5.10.2/tinymce/plugins/zlink · high confidence
Added language profile data for automatic language detection
The translation module now includes n-gram profile data for multiple languages (including Afrikaans, Arabic, Belarusian, etc.) to support automatic language detection. This data is used by the system to guess the language of a resource when no language is explicitly set, enabling better automatic translation and URL handling for multilingual sites.
_apps/zotonic\_mod\translation · high confidence
Added loadmore model for dynamic content loading
A new 'loadmore' model has been introduced to handle loading additional content via button presses. This model supports silent URL replacement and flexible argument handling, allowing users to dynamically load and replace content templates based on message payloads.
_apps/zotonic\_mod\base/priv/lib/js/models · high confidence
Added localization files and core plugin logic for the Zotonic media plugin
The zmedia plugin for the TinyMCE editor now includes English, Dutch, and Russian translation files that map 'Insert a media item' and 'Insert media item' to their respective languages. The plugin's main JavaScript file (plugin.min.js) was added, implementing the logic to insert, display, and manage media items within the editor, including handling properties dialogs and click events for media elements.
_apps/zotonic\_mod\_editor\tinymce/priv/lib/js/tinymce-4.9.3/tinymce/plugins/zmedia · high confidence
Added manifest.json template and robots.txt for site configuration
A new manifest.json template is introduced to define the web application's metadata, including title, scope, display mode, and icon sizes (144, 192, 512). Additionally, a robots.txt file is added to restrict search engine access to admin and language selection URLs, while allowing all other URLs.
_apps/zotonic\_mod\base/priv/lib/misc · high confidence
Added mock ACL module for testing
A new mock ACL module (mod\_acl\_mock) has been added to the Zotonic framework to provide minimal dependencies for running the testsandbox. This module is explicitly marked as a mock for testing purposes and should not be used in production environments.
_apps/zotonic\_mod\_acl\mock/src · high confidence
Added module management actions for activation, deactivation, and rescanning
The admin module now includes new actions to manage module states. Administrators can now activate or deactivate modules via the admin interface, with checks for cyclic dependencies and missing prerequisites. Additionally, a new 'module rescan' action allows administrators to force a rescan of all modules, actions, and templates, ensuring the dispatcher reloads all dispatch rules after changes.
_apps/zotonic\_mod\_admin\modules/src/actions · high confidence
Added new icon set for UI elements and social media links
The \z.icons\ module now includes a new icon font and associated CSS/JS resources, providing a set of 25 glyphs for common UI actions (edit, ok, minus, plus, help, info, user, cross, grab/drag, logo) and social media platforms (Google Plus, LinkedIn, Instagram, Twitter, Facebook, GitHub). This adds visual assets for navigation, status indicators, and social sharing links within the Zotonic application.
_apps/zotonic\_mod\base/priv/lib/css/z.icons · high confidence
Added source SVGs for the application favicon
New SVG source files (favicon.svg and z.svg) were added to the images directory, providing the original vector assets for the site's favicon.
_apps/zotonic\_mod\base/priv/lib/images · high confidence
Admin backup management and revision control
The admin interface now provides a dedicated backup management screen where administrators can download nightly backups, configure backup settings, and restore resources. Additionally, a new revision control feature allows users to view differences between resource versions and revert to previous states, with access controlled by the mod\_backup and mod\_admin permissions.
_apps/zotonic\_mod\backup/src/controllers · high confidence
Admin config model exposes SSL, security dir, and module settings via new API
A new model \m\_admin\_config\ is introduced to expose admin configuration data through a structured API. Admin users can now retrieve SSL certificate metadata, the resolved security directory path, and a list of available module configurations with their default values. Non-admin users receive empty or undefined responses for these endpoints, ensuring that sensitive configuration details remain restricted to administrators.
_apps/zotonic\_mod\_admin\config/src/models · high confidence
Admin identity model exposes configuration endpoints for password and user defaults
A new Erlang model, m\_admin\_identity, has been added to expose configuration values for admin identity settings. This model provides read-only access to the password validation regex, as well as the default category and content group for newly created users, allowing these settings to be retrieved via specific API paths.
_apps/zotonic\_mod\_admin\identity/src/models · high confidence
Admin interface for managing OAuth2 apps and consumers
The OAuth2 module now provides a complete admin interface for managing OAuth2 applications and consumers. Administrators can create, edit, and delete OAuth2 apps (for authentication and API access control) and consumers (for importing content and authenticating users from external sites). The new dialogs allow configuring app details, redirect URLs, client credentials, and token permissions. This enables easier management of OAuth2 integrations directly from the admin panel.
_apps/zotonic\_mod\oauth2 · high confidence
Admin interface for managing custom redirects
The ZMod custom\_redirect module now provides a dedicated admin interface for managing domain and path-based redirects. Administrators can view, add, and delete redirect rules via a new template (admin\_custom\_redirect.tpl) and a corresponding dispatch route at /admin/custom-redirect. The interface allows configuration of host, path, and redirect destination, with support for permanent (301) redirects.
_apps/zotonic\_mod\_custom\redirect/priv · high confidence
Admin interface for managing edge predicates
A new admin module has been added to allow users to edit, delete, and move edge predicates directly from the admin interface. This includes a dedicated page for listing all defined predicates, with support for bulk deletion and moving edges to a new predicate. The module hooks into the resource update process to save predicate-specific fields (subject/object lists) and ensures caches are properly flushed when predicate metadata changes.
_apps/zotonic\_mod\_admin\predicate/src · high confidence
Admin interface module and app definition added
The mod\_admin module and its application source file are introduced, establishing the core administrative backend for content editing and site administration. The module provides documentation on extending the admin menu, customizing the edit page with sidebar and content widgets, overriding TinyMCE options, and customizing the admin overview page with category-specific information and sorting.
_apps/zotonic\_mod\admin/src · high confidence
Admin module routing rules added
The admin module now includes a dispatch configuration that maps URL paths to specific controllers and templates. This enables navigation to the admin overview, media, edit, referrers, and status pages within the admin interface.
_apps/zotonic\_mod\admin/priv/dispatch · high confidence
Admin widgets now support collapsible panels with persistent state
The admin interface now allows users to collapse and expand widget panels. Each panel's expanded/collapsed state is saved in the browser's session storage, so the last used state is remembered across page loads. The widget header includes a toggle icon that lets users minimize or maximize the content area, improving the admin UI by reducing visual clutter.
_apps/zotonic\_mod\admin/priv/lib/js/modules · high confidence
Automated Hex package publishing and release preparation
The release process now includes automated scripts to prepare and publish all Zotonic applications to the Hex package manager. The new \release/prepare-release.sh\ script updates version numbers across the codebase, while \release/hex-publish.sh\ handles the build and publication of core dependencies, file handlers, and other modules in a specific order to ensure correct dependency resolution and index updates.
release · high confidence
Backup module introduces encryption, replication, and granular retention controls
The mod\_backup module has been significantly enhanced with new capabilities for data protection and recovery. Users can now encrypt backups via a new configuration option, securing stored data. The module also supports data replication and failover by allowing a server in 'backup' mode to download and import the latest backup from a filestore, automatically restoring the database, configuration, and files. Additionally, the module now tracks per-resource revision logs, enabling individual resource rollback and recovery, with configurable retention periods for general resources (18 months), user resources (90 days), and deleted user data (30 days).
_apps/zotonic\_mod\backup/src · high confidence
Content group management in the admin interface
The admin interface now supports assigning and filtering by content groups. A new sidebar widget allows editors to select a content group when creating or editing a page. A filter panel on the content overview lets users filter the list by content group. A bulk update dialog includes a content group selector. The delete confirmation dialog now offers the option to move pages to another content group or delete them entirely.
_apps/zotonic\_mod\_content\groups/priv · medium confidence
Default ACL rules and support modules for user groups
The mod\_acl\_user\_groups application now includes a new set of support modules in the src/support directory, introducing default access control rules and management utilities. This includes acl\_default\_rules.erl, which defines standard permissions for anonymous, member, editor, and manager groups across default and system content groups; acl\_user\_group\_rebuilder.erl, which handles the expansion and caching of ACL rules in ETS tables; acl\_user\_group\_checks.erl, which provides the core logic for verifying permissions such as insert, update, and move actions; and admin\_acl\_rules.erl, which exposes the administrative interface for managing these rules. These changes establish the foundational structure for user-group-based access control within the application.
_apps/zotonic\_mod\_acl\_user\groups/src/support · high confidence
Extract HTTP listener into a dedicated zotonic\_listen\_http application
The HTTP listener functionality has been extracted from the core into a new, standalone application named zotonic\_listen\_http. This new module manages the lifecycle of HTTP and HTTPS listeners using the cowmachine library, providing explicit start and stop controls for IPv4 and IPv6 connections. Additionally, a dedicated metrics callback module (zotonic\_listen\_http\_metrics) has been introduced to capture and record HTTP request performance data, including duration, status codes, and payload sizes, into the z\_stats system.
_apps/zotonic\_listen\http/src · high confidence
Filehandler and filewatcher apps now include Apache 2.0 license and build configs
The zotonic\_filehandler and zotonic\_filewatcher applications now include Apache License 2.0 files and rebar3 configuration files. The filehandler's build configuration specifies dependencies on zotonic\_filewatcher, zotonic\_fileindexer, zotonic\_stdlib (\~\> 1.20), erlexec (\~\> 2.0), jobs (0.10.0), and buffalo (\~\> 2.0). The filewatcher's build configuration specifies dependencies on zotonic\_notifier and erlexec (\~\> 2.0).
_apps/zotonic\filehandler · high confidence
Introduce DKIM email signing for outgoing messages
The mod\_email\_dkim module now automatically signs outgoing emails with DomainKeys Identified Mail (DKIM) signatures, improving email authentication and deliverability. The module generates an RSA keypair on first install and provides an admin panel at /admin/email/dkim to display the required DNS TXT record for configuration. It signs standard headers (From, To, Subject, etc.) and includes List-Unsubscribe headers as required by RFC 8058.
_apps/zotonic\_mod\_email\dkim · high confidence
Introduce a new search view with autocomplete and faceted search UI
The search module now includes a new search view that provides an autocomplete interface for text search and supports faceted search with alternative counts per facet. This change adds the necessary CSS styles for the search results list, JavaScript for handling input and navigation, and templates for rendering search results and list items. Additionally, a status endpoint is added to check the health of the search facet table, and a button is provided in the admin status to rebuild search facets.
_apps/zotonic\_mod\search · high confidence
Introduce content group management module
Added the \mod\_content\_groups\ module, which enables hierarchical content grouping and access-control rules on resources. This new feature allows administrators to categorize content into a hierarchical structure, with built-in ACL checks to prevent deletion of content groups that still contain resources. The module handles admin menu integration, resource updates, and provides callbacks for managing content group data and schema.
_apps/zotonic\_mod\_content\groups/src · high confidence
Introduce cookie consent management for embedded content
The Zotonic platform now includes a new \mod\_cookie\_consent\ module that manages user consent for cookies, specifically targeting embedded content like media, iframes, JavaScript, and CSS. This feature allows the platform to hide or show elements based on user preferences for functional, statistics, or all cookies. The module provides templates and attributes (e.g., \data-cookie-consent\) to wrap external content so it is only loaded if the user has consented. It also includes a data model for cookie consent preferences and handles the \observe\_media\_viewer\_consent\ event to render consent placeholders.
_apps/zotonic\_mod\_cookie\consent/src · high confidence
Introduce cookie consent management for external content
The \zotonic\_mod\_cookie\_consent\ module is added, providing a system to manage user consent for cookies before loading external content. This includes a JavaScript library (\z.cookie\_consent.js\) that handles the consent dialog, CSS styles for the consent banner and preview states, and templates (\\_cookie\_consent.tpl\, \\_media\_cookie\_consent.tpl\) that wrap external media and scripts in a way that delays their execution until consent is given. The module also adds an admin widget for editing cookie consent text and configuration.
_apps/zotonic\_mod\_cookie\consent/priv · high confidence
Introduce m\_acl\_rule and m\_acl\_user\_group models for ACL rule and user-group management
Adds the m\_acl\_rule and m\_acl\_user\_group model files, exposing a structured API for inspecting and managing ACL rules and user-group memberships. Users can now query ACL rule states, check insertion and movement permissions, retrieve upload size and MIME type defaults, and verify collaboration group usage through dedicated model endpoints.
_apps/zotonic\_mod\_acl\_user\groups/src/models · medium confidence
Introduce mod\_admin\_frontend for simplified content editing
Added a new 'mod\_admin\_frontend' module that provides a streamlined, Bootstrap-based interface for editing pages, menu trees, and collections. This module is designed for non-admin users, offering a subset of the full admin capabilities to reduce complexity. The implementation includes the main Erlang module (mod\_admin\_frontend.erl) handling postback events and template rendering, along with the application source file (zotonic\_mod\_admin\_frontend.app.src) which declares dependencies on kernel, stdlib, and zotonic\_core.
_apps/zotonic\_mod\_admin\frontend/src · high confidence
Introduce mod\_authentication module for user authentication
The mod\_authentication module is introduced to handle user authentication and identification. It provides controllers for logon and logoff, implements various hooks for access control, and supports configuration options such as password length, one-step logon, and remember-me functionality. The module also includes event handling for admin menu, client logon/switch user, and hourly maintenance tasks.
_apps/zotonic\_mod\authentication/src · high confidence
Introduce mod\_base as the new base module for Zotonic
The mod\_base module is introduced as the central container for basic Zotonic components, including dispatch rules, actions, and template components. This new module provides foundational configuration options for site titles, pagination, session management, and email handling, while also managing core events like content type dispatching and edge hierarchy updates.
_apps/zotonic\_mod\base/src · high confidence
Introduce model API for backup configuration and revision management
The backup module now exposes a structured model API for managing backup settings and revision data. Administrators can query backup configuration (e.g., encryption status, daily dump settings, directory paths) and manage resource revisions (e.g., listing, title retrieval, retention periods) through specific model paths. Access to most backup model endpoints is restricted to users with the 'use' permission on mod\_backup, ensuring that sensitive backup metadata and revision history are only accessible to authorized users.
_apps/zotonic\_mod\backup/src/models · high confidence
Introduce modular access control for user groups and content groups
The zotonic\_mod\_acl\_user\_groups module is introduced to provide rule-based access control, allowing administrators to define permissions for user groups (anonymous, members, editors, managers) and content groups (default, system, collaboration). This enables granular control over resource visibility, insertion, updates, and deletions, as well as file upload restrictions (size and MIME types) and property-level privacy settings for sensitive fields like email and address. The module also supports module-level access rules and manages ACL state via a new schema version.
_apps/zotonic\_mod\_acl\_user\groups/src · high confidence
Introduce periodic task scheduling and tick notifications
The mod\_cron module now provides a built-in mechanism for scheduling regular jobs and emitting periodic tick notifications. It registers scheduled jobs using the erlcron library and emits tick events (tick\_1s, tick\_1m, tick\_5m, tick\_10m, tick\_15m, tick\_30m, tick\_1h, tick\_2h, tick\_3h, tick\_4h, tick\_6h, tick\_12h, and tick\_24h) via the notifier. Modules can define periodic jobs using the -mod\_cron\_jobs attribute, which are then managed by mod\_cron, allowing for automated background tasks and time-based event observation.
_apps/zotonic\_mod\cron/src · high confidence
Introduce server-side session storage for client and server data
Adds a new server-side storage mechanism tied to the client's session ID, allowing applications to store and retrieve data on the server. The feature includes a public API for standard key-value storage and a separate secure API for sensitive data like OAuth secrets, which is not accessible from the client. Storage is managed by background processes that expire after 900 seconds of inactivity and are limited to 100 KB of data. Configuration keys \mod\_server\_storage.storage\_expire\ and \mod\_server\_storage.storage\_maxsize\ allow tuning the timeout and size limits.
_apps/zotonic\_mod\_server\storage · high confidence
Introduce the zotonic\_notifier application for event-driven notifications
Adds the zotonic\_notifier application, providing a notification system that allows components to register observers for specific events. The system supports synchronous and asynchronous notifications, priority-based execution order, and operations to map, fold, or retrieve observers. It includes a supervisor for managing notifier instances and workers that handle the actual event dispatching, enabling decoupled communication between different parts of the application.
_apps/zotonic\notifier · high confidence
Introduce token management module for authentication
A new module, z\_authentication\_tokens, has been added to handle the creation, decoding, and caching of authentication tokens and cookies. This introduces a centralized mechanism for managing auth cookies, autologon cookies, and onetime tokens, including specific expiration times (e.g., 30 seconds for onetime tokens) and caching strategies for request handling.
_apps/zotonic\_mod\authentication/src/support · high confidence
Introduce web worker-based file uploader with drag-and-drop support
The file uploader has been refactored to use a dedicated web worker (zotonic.fileuploader.worker.js) that uploads files in parallel 128KB blocks for improved performance and responsiveness. This change adds drag-and-drop upload support in the admin interface (z.fileuploader-admin.js), allowing users to drop files directly onto the page. The backend (controller\_fileuploader.erl, m\_fileuploader.erl, z\_fileuploader.erl) now handles block-based uploads via MQTT topics, supporting features like upload cancellation, progress tracking, and error handling. The module also includes a new license file (Apache 2.0) and associated header/template files to wire the new client-side and server-side components together.
_apps/zotonic\_mod\fileuploader · high confidence
Introduce zotonic\_apps package for simplified dependency management
A new 'zotonic\_apps' package has been added to the 'apps/zotonic\_apps' directory, providing a single dependency that includes all core Zotonic applications. This allows users to easily fetch and manage all core applications from Zotonic by adding 'zotonic\_apps' to their 'rebar.config' dependencies, simplifying the setup process for new projects.
_apps/zotonic\apps · high confidence
Introduce zotonic\_fileindexer application
Added the zotonic\_fileindexer application, which provides a fileindex record for directory indices. The new module includes an Apache 2.0 license, a header file defining the fileindex record structure, and a rebar3 configuration that declares a dependency on zotonic\_notifier.
_apps/zotonic\fileindexer · high confidence
Introduce zotonic\_fileindexer for recursive file indexing
A new zotonic\_fileindexer application has been added to index files within application directories. It provides a caching layer (zotonic\_fileindexer\_cache) and a recursive scanner (zotonic\_fileindexer\_scan) to find files matching specific patterns, with support for flushing the cache to force a rescan.
_apps/zotonic\fileindexer/src · high confidence
Introduce zotonic\_launcher application for server lifecycle management
The zotonic\_launcher application is introduced to manage the startup, shutdown, and configuration loading for the Zotonic server. It provides functions to start and stop the server, handle configuration files, and coordinate the lifecycle of dependent applications. The launcher also includes a supervisor to manage child processes like HTTP, SMTP, and MQTT listeners, ensuring proper initialization and cleanup.
_apps/zotonic\launcher/src · high confidence
Introduces shared admin JavaScript utilities
A new \admin-common.js\ file is added to the admin interface, providing shared JavaScript utilities for the admin panel. This includes an \adminLinkedTable\ widget that makes table rows and cells clickable, an \autofocus\ widget for form fields, a scroll listener that adds a 'scrolled' class to the body, a keyboard shortcut (Ctrl+S) to submit forms, and helper functions for managing block names and media selection.
_apps/zotonic\_mod\admin/priv/lib/js/apps · high confidence
Introduction of a typed key/value store module
A new typed key/value store module (mod\_tkvstore) is introduced, providing a high-performance, low-latency interface for storing and retrieving structured data. The module implements a gen\_server that serializes get/put/delete operations and persists them to a PostgreSQL table. It includes a corresponding model (m\_tkvstore) that exposes API paths for reading and writing values, along with initialization logic to ensure the required database table exists. The implementation uses the standard Erlang logger for structured logging and depends on zotonic\_core.
_apps/zotonic\_mod\tkvstore · high confidence
Introduction of new CLI launcher and documentation generation scripts
The 'bin' directory now includes three new executable scripts: 'zotonic', a shell-based launcher that sets up the ZOTONIC environment variable and delegates to the Erlang-based 'zotonic\_launcher'; 'generate\_edoc.escript', an escript that generates EDoc documentation for core and module apps; and 'mergepot', a disabled shell script for translation file merging. These scripts provide new entry points for documentation generation and command-line interaction.
bin · high confidence
Introduction of the zotonic\_mod\_artwork module for icons and images
A new module, zotonic\_mod\_artwork, has been added to provide a collection of icons and images for sites and modules. This includes Font Awesome 4 and 3, Material Design Iconic Font, and various image assets such as emoticons, country flags, and social media icons. The module is configured with an Apache-2.0 license and depends on the standard kernel and stdlib applications.
_apps/zotonic\_mod\artwork/src · high confidence
New CLI commands for site management, backups, and debugging
The zotonic\_launcher command-line interface gains a suite of new commands to improve site lifecycle management and operational visibility. Administrators can now create new sites with the \addsite\ command, which supports options for skeletons, database configuration, and umbrella structures. Backup management is enhanced with \backup\ commands to list, start, restore, and download backups, alongside a \decrypt\ command for encrypted backup files. Operational tasks are expanded with \compile\ and \compilefile\ for recompilation, \config\ and \configtest\ for inspecting and validating configuration, and \connectdb\ to verify database connectivity. Additionally, \debug\ starts the node in the foreground, \etop\ provides process monitoring, \flush\ clears caches, \load\ reloads modules, and \logtail\ follows log files. These commands collectively provide deeper control over the running system.
_apps/zotonic\launcher/src/command · high confidence
New Docker development environment for Zotonic
A new Docker-based development environment has been introduced, providing a containerized setup for running Zotonic alongside PostgreSQL. The change includes a new Dockerfile.dev based on Erlang 27.3.4, a docker-entrypoint.sh script that handles user/group ID mapping (fixing macOS permission issues), and configuration files (erlang.config, zotonic-docker.config) that configure logging and database connections. This allows developers to run the application in a consistent, isolated environment with proper file ownership and logging.
docker · high confidence
New LESS styles for icons, modals, and bridge status
Added new LESS source files to compile CSS for icon integration (supporting Zotonic, Font Awesome, and Material Design icons), modal dialog styling (including multi-level overlay support), and a visual warning for bridge connection status.
_apps/zotonic\_mod\base/priv/lib-src/less · high confidence
New SEO sitemap module with manual rebuild and per-page priority/frequency settings
The \zotonic\_mod\_seo\_sitemap\ app is introduced to generate and manage site sitemaps for search engine indexing. Administrators can now manually trigger a sitemap rebuild via a new button in the SEO settings and status pages. Additionally, content editors can set the sitemap priority and change frequency for individual pages and categories through the admin interface, allowing fine-grained control over how search engines index the site.
_apps/zotonic\_mod\_seo\sitemap · high confidence
New admin configuration and email management interface
The admin interface now features a dedicated System Configuration page that lists all available configuration keys, their default values, and descriptions. Administrators can create, edit, and delete configuration entries directly from this list. Additionally, the Email configuration section has been expanded to include a test email form, allowing admins to send test messages and view their status. The SSL certificates page has also been updated to display certificate details and expiration information for all active modules.
_apps/zotonic\_mod\_admin\config/priv/templates · high confidence
New admin controllers and Gravatar filter for comment moderation
Added new Erlang controllers for the comment module: \controller\_admin\_comments\ provides an admin interface to moderate, delete, and toggle the visibility of comments, while \controller\_admin\_comments\_settings\ allows authorized users to save comment form settings. Additionally, a new \filter\_gravatar\_code\ filter was introduced to generate MD5 hashes for email addresses, enabling Gravatar image display.
_apps/zotonic\_mod\comment/src/controllers · high confidence
New admin identity module for user management
A new \mod\_admin\_identity\ module has been added to the admin interface, providing a user interface to create new users, manage passwords, and handle identity verification. The module supports configuring password complexity rules via a \password\_regex\ configuration key, assigns new users to a configurable category and content group, and includes documentation on migrating legacy password hashes.
_apps/zotonic\_mod\_admin\identity/src · high confidence
New admin interface and templates for comment moderation
The comment module now provides a dedicated admin section for managing user-submitted comments. Administrators can view recent comments in a table, view the original page, toggle comment visibility (publish/unpublish), and delete comments. A settings page allows administrators to enable or disable comment moderation. The public comment form includes fields for name, email, and message, with optional moderation notices. Avatar images are now loaded over HTTPS.
_apps/zotonic\_mod\comment/priv · high confidence
New admin interface for managing and sorting categories
A new controller has been added to provide an editable overview of all categories, allowing users to rearrange the category tree, add new categories, or remove existing ones through the admin interface.
_apps/zotonic\_mod\_admin\category/src/controllers · high confidence
New admin interface for managing user identities and credentials
The admin interface for managing user identities has been significantly restructured and expanded. A new dedicated 'Users' overview page allows administrators to list, search, and filter users by email or name. Administrators can now set, change, or delete usernames and passwords directly from the user edit sidebar and overview, with a confirmation dialog for deletions. The user creation flow has been updated to include fields for name, email, category, and username/password. Email verification is managed via a new table in the user edit page, allowing admins to verify, delete, or view the status of email addresses. Additionally, the admin can log in as a specific user, and the system now supports sending welcome emails to new users.
_apps/zotonic\_mod\_admin\identity/priv/templates · high confidence
New admin interface for requesting Let's Encrypt SSL certificates
Administrators can now request and manage Let's Encrypt SSL certificates directly from the Zonotic admin panel. This change introduces a dedicated configuration panel that displays the current certificate status, including validity, expiration, and alternative names (SANs). The interface includes a form to request new certificates, validates hostnames and reachability before submission, and provides clear error messages if port 80 or 443 are not correctly configured. The status template also links to external debugging tools like letsdebug.net to assist with certificate issuance issues.
_apps/zotonic\_mod\_ssl\letsencrypt · high confidence
New admin log views for UI errors, email status, and CSP reports
The logging module now provides dedicated admin UI pages for viewing browser-side UI errors, email delivery status, and Content-Security-Policy violations. A new JavaScript client-side error handler posts errors to the server, which are stored in a ring buffer to prevent overload. The email log displays the status of sent and received emails, including sending, sent, relayed, bounce, failed, retry, blocked, and received states. The CSP log shows the latest 100 unique Content-Security-Policy violation reports, including directives, blocked URLs, and source locations. All logs are accessible via the admin interface under the 'Log' section.
_apps/zotonic\_mod\logging · high confidence
New admin menu item and separator record definitions
A new header file, admin\_menu.hrl, was added to the admin module, introducing Erlang records for menu\_item and menu\_separator. These records define the structure for admin menu entries, including fields for id, parent, label, url, icon, visiblecheck, and sort order, as well as a separator record with parent, visiblecheck, and sort fields.
_apps/zotonic\_mod\admin/include · high confidence
New admin routes for user management, identity verification, and resource merging
Administrators can now access new endpoints for managing users and verifying identities, as well as merging and comparing resources. Specifically, the identity module adds routes for listing users and verifying identity keys, while the merge module adds routes for editing and comparing merged resources.
_apps/zotonic\_mod\_admin\_identity/priv/dispatch, apps/zotonic\_mod\_admin\merge/priv/dispatch · high confidence
New admin statistics page with real-time system metrics
The admin statistics page has been introduced to display real-time system metrics, including memory usage, IO, database status, and filezcache stats. The new template structure includes reusable components for stat rows and panels, along with JavaScript logic to update values via MQTT subscriptions to 'bridge/origin/$SYS/statistics' and 'bridge/origin/$SYS/erlang' topics.
_apps/zotonic\_mod\_admin\statistics/priv/templates · high confidence
New admin status and configuration model endpoints
The admin module now exposes a comprehensive set of read-only model endpoints for system diagnostics and configuration paths. The status model provides access to the running Zotonic and Erlang/OTP versions, database server version, and various directory paths (config, security, log, data, cache, work, and files). It also exposes OS memory statistics, disk space information, TCP connection counts, and SSL application configuration status. Additionally, the admin model introduces endpoints for the pivot queue count, new-resource dialog defaults (published, dependent, hide\_dependent), edge list length, auto-connect settings, and referer tracking. The admin menu model now serves the full hierarchical menu tree, and the admin note model allows viewing and editing editorial notes attached to resources.
_apps/zotonic\_mod\admin/src/models · high confidence
New admin support modules for resource diffing, media import, and reference tracking
The admin module now includes new support files: \admin\_rsc\_diff.erl\ to format resource records for browser-side diffing, \z\_admin\_media\_discover.erl\ to handle embedding and importing media from URLs, \z\_admin\_refers.erl\ to automatically track resource references via 'refers' edges, and \z\_admin\_rsc\_import.erl\ to support re-importing non-authoritative resources. These changes enhance the admin interface's ability to display resource differences, import external media, maintain data integrity through reference tracking, and manage remote resource imports.
_apps/zotonic\_mod\admin/src/support · high confidence
New and updated base components for charts, debugging, and UI
The \scomps\ directory now includes several new components: \scomp\_base\_chart\_pie\ and \scomp\_base\_chart\_pie3d\ provide simplified interfaces for generating Google pie charts; \scomp\_base\_debug\ allows developers to inspect template variables; \scomp\_base\_inplace\_textbox\ renders editable text fields; \scomp\_base\_lazy\ handles lazy loading of content; \scomp\_base\_loremipsum\ generates placeholder text; \scomp\_base\_spinner\ adds an AJAX activity indicator; \scomp\_base\_tabs\ enables jQuery UI tabbed interfaces; and \scomp\_base\_worker\ initializes web workers. Additionally, \scomp\_base\_google\_chart\ and \scomp\_base\_pager\ have been updated to support these new capabilities and improve existing functionality.
_apps/zotonic\_mod\base/src/scomps · high confidence
New authentication controllers for login, logout, and post-login redirection
The authentication module now exposes three new HTTP controllers to handle user sessions: \controller\_authentication.erl\ manages the primary login flow (including password expiration handling), \controller\_logoff.erl\ handles session termination and cookie cleanup, and \controller\_logon\_done.erl\ manages post-login redirection. These controllers provide the backend endpoints for the browser's \auth\ module to perform authentication, logoff, and redirect users to the correct page after a successful login.
_apps/zotonic\_mod\authentication/src/controllers · high confidence
New authentication model API for password and identity management
The m\_authentication model now exposes a structured HTTP API for managing authentication state and password workflows. Users can now validate passwords against site policies (minimum length, leak checks), check authentication status, and trigger password reset reminders or identity verification emails via dedicated endpoints. The model also supports remember-me functionality and one-step logon configuration checks, providing a centralized backend for identity-related operations.
_apps/zotonic\_mod\authentication/src/models · high confidence
New base templates and UI components for the web and email clients
The base application now provides a comprehensive set of reusable templates and components, including a new \base\_noscript.tpl\ and \base.tpl\ structure that initializes the Cotonic JavaScript framework and manages script loading with Content-Security-Policy nonces. The update introduces dedicated templates for action dialogs, search results, and pagination, while also adding an email template (\email\_base.tpl\) with improved styling and preheader support. Additionally, the \base\_simple.tpl\ and \directory\_index.tpl\ templates are added to support headless or simplified page rendering and file browsing, and a \security.txt\ template is introduced to expose security contact information.
_apps/zotonic\_mod\base/priv/templates · high confidence
New base templates for email rendering
A new set of base email templates has been introduced to standardize the structure and styling of outgoing emails. The update includes a reusable button component for call-to-action links, a media handler for displaying images and videos within email bodies, and layout blocks for headers, text, and page content. These templates provide a consistent visual foundation for email communications, ensuring proper spacing, typography, and media handling across all email templates.
_apps/zotonic\_mod\base/priv/templates/email · high confidence
New blog site template with full content and styling
The 'blog' site skeleton has been significantly expanded with a complete set of templates, stylesheets, and sample content. Users creating a new blog site will now receive a fully styled home page, article listing, and individual article pages, along with a contact form template and sidebar components. The template also includes CSS for the default blog layout and sample HTML data for articles, keywords, and media, providing a more robust starting point for new sites.
_apps/zotonic\_mod\_zotonic\_site\management · high confidence
New controllers for API, file serving, and error handling
The controllers/controller\_api.erl, controller\_csp\_report.erl, controller\_file.erl, controller\_file\_id.erl, controller\_http\_error.erl, controller\_id.erl, controller\_keyserver\_key.erl, controller\_mqtt\_transport.erl, controller\_nocontent.erl, and controller\_page.erl have been added to the codebase. These new controllers provide endpoints for handling REST API requests, processing Content Security Policy reports, serving and redirecting files, managing HTTP errors, handling resource IDs, retrieving public keys, managing MQTT transport, returning no-content responses, and displaying HTML pages with SEO headers.
_apps/zotonic\_mod\base/src/controllers · high confidence
New date and list manipulation template filters
The template language gains several new filters for date manipulation and list processing. Date filters include add\_day, add\_hour, add\_month, add\_week, and add\_year to adjust dates by specific time units, as well as date\_range to format date ranges and datediff to calculate differences between dates. List manipulation includes after and before to find adjacent elements, and element to extract items from tuples or lists. These additions expand the built-in capabilities for formatting and transforming data in templates.
_apps/zotonic\_mod\base/src/filters · high confidence
New development model API for diagnostics and tracing
A new model file, m\_development.erl, has been added to provide a structured API for development and diagnostics. This includes endpoints to check and enable database query tracing, function tracing, and template trace relations (parents, children, and filename menus). It also exposes configuration flags for cache flushing, recompilation, and reindexing, alongside inspection of registered observers and dispatch rules. Access to most of these features requires admin or development permissions, ensuring that sensitive diagnostic data is protected.
_apps/zotonic\_mod\development/src/models · high confidence
New development module for template, function, and database tracing
A new 'Development' module has been added to provide comprehensive debugging tools for site development. It introduces function call tracing (sending output via MQTT), database query tracing, and template compilation/selection debugging. The module also supports live reloading of CSS, JS, and template files in the browser, and includes a floating trace button to debug the current page. Configuration options allow enabling/disabling these features, and the module handles file watcher events to automatically recompile and load changed files.
_apps/zotonic\_mod\development/src · high confidence
New development tools for debugging templates, dispatching, and database queries
Added four new support modules to the development module: z\_development\_dbtrace for toggling database query tracing, z\_development\_dispatch for explaining request dispatching, z\_development\_template for template selection debugging, and z\_development\_template\_xref for checking template cross-references and missing includes. These tools provide developers with detailed insights into template dependencies, request routing, and database interactions, with the template graph module also generating DOT format graphs of template relationships.
_apps/zotonic\_mod\development/src/support · medium confidence
New development tools for tracing, debugging, and inspecting templates
The development module now provides a suite of new tools for debugging and inspecting templates. Administrators can view a live dependency graph of all templates, perform cross-reference checks to find missing includes or syntax errors, and trace template rendering in real-time. Additionally, a floating button allows quick access to template traces, and the debug pane is now resizable. These features are accessible via the new 'Site Development' admin page.
_apps/zotonic\_mod\development/priv/templates · high confidence
New dialog for creating predicates in the admin interface
The admin interface now includes a dedicated dialog for creating new predicates. This feature allows users to define a new predicate via a form, with the system handling the creation, redirecting to the edit page upon success, and displaying appropriate error messages for duplicate names or permission issues.
_apps/zotonic\_mod\_admin\predicate/src/actions · high confidence
New dispatch rules for static assets, API endpoints, and Cotonic integration
The application now serves several new static resources and API routes. Standard library files (CSS, JS, images) are accessible via /lib, /lib-min, and /lib-nocache paths. New endpoints include /api/\* for API access, /manifest.json for site information, /.zotonic/ping for health checks, and /.zotonic/csp\_report for Content-Security-Policy violation logs. Additionally, a /test/connection page is exposed for connection testing, and Cotonic-specific routes are added for the service worker, key server, and MQTT transport.
_apps/zotonic\_mod\base/priv/dispatch · high confidence
New filters for formatting dispatch rules and path elements
Two new filter modules have been added to the development module to improve the display of dispatch rules in the admin interface. The \filter\_format\_dispatch\_controller\_option\ module formats controller options (such as id, acl, and template) into styled HTML labels, while \filter\_format\_dispatch\_path\_element\ formats path elements, distinguishing between variables and exact matches with appropriate HTML markup. These changes enhance the readability of the site's dispatch configuration in the admin UI.
_apps/zotonic\_mod\development/src/filters · high confidence
New form validation types: acceptance, confirmation, custom, date, email, email\_unique, format, json, length, name\_unique, numericality, page\_path\_unique, postback, and presence
The \zotonic\_mod\_base\ application now includes a comprehensive set of form validators, each implemented as a dedicated module in the \src/validators\ directory. These new validators allow users to enforce specific input constraints directly in their templates. The additions include \acceptance\ for boolean checks, \confirmation\ for matching fields, \custom\ for JavaScript-based validation, \date\ for format validation, \email\ and \email\_unique\ for address validation and uniqueness, \format\ for regular expression matching, \json\ for valid JSON strings, \length\ for string length limits, \name\_unique\ and \page\_path\_unique\ for resource uniqueness checks, \numericality\ for integer/float ranges, \postback\ for server-side callbacks, and \presence\ to ensure fields are not empty. Each validator provides both client-side (JavaScript) and server-side (Erlang) validation logic.
_apps/zotonic\_mod\base/src/validators · high confidence
New frontend edit templates for the admin interface
The admin frontend now uses a dedicated set of templates (\_admin\_frontend\_edit.tpl, \_admin\_frontend\_editor.tpl, etc.) that provide a lighter, more modern UI for editing resources. This includes a redesigned edit form with tabbed navigation for content, language, and access control, alongside a custom TinyMCE initialization script that configures the editor with specific plugins (lists, searchreplace, etc.) and a custom valid elements list. The layout also integrates a sidebar menu and a fixed-top navbar with save/cancel buttons, ensuring the edit experience is consistent with the new admin frontend architecture.
_apps/zotonic\_mod\_admin\frontend/priv/templates · high confidence
New header and record definitions for core, logging, and wired events
The \zotonic\_core\ application introduces a new set of header files (\zotonic.hrl\, \zotonic\_deprecated.hrl\, \zotonic\_file.hrl\, \zotonic\_log.hrl\, \zotonic\_notifications.hrl\, \zotonic\_release.hrl\, and \zotonic\_wired.hrl\) that define the internal data structures and macros for the framework. These include the main \\#context\ record, logging macros, filestore request records, and notification records for HTTP, modules, and user identity. Additionally, a \zotonic\_deprecated.hrl\ is added to mark the \\#z\_msg\_v1\ record as deprecated, signaling that the legacy transport system is being phased out in favor of the new MQTT-based architecture.
_apps/zotonic\core/include · high confidence
New i18n infrastructure for translations and language management
The i18n subsystem has been refactored with new modules to handle translations and language configuration. A new \z\_trans\ module provides functions for looking up and merging translations, backed by a \z\_trans\_server\ that manages an ETS table of all translations. Language handling is now managed by \z\_language\ and \z\_language\_data\, which provide APIs for fetching language info, checking validity, and managing the list of enabled/editable languages. Additionally, \z\_gettext\ and \z\_gettext\_compile\ handle parsing and generating .po/.pot files for the translation workflow.
_apps/zotonic\core/src/i18n · high confidence
New interface for managing page connections and predicates
The admin interface now includes a dedicated 'Page connections' section that allows administrators to view, filter, and manage relationships between pages. This update introduces a new list view for all page connections, enabling filtering by subject, object, and predicate, as well as a new graph-based visualization for exploring connections from a specific page. Additionally, administrators can now create new predicates, delete them (with options to handle existing connections), and configure detailed settings for each predicate, such as valid categories, connection direction, and search indexing behavior.
_apps/zotonic\_mod\_admin\predicate/priv/templates · high confidence
New model API endpoints for core data access
The zotonic\_core models (m\_acl, m\_category, m\_config, m\_dispatch, m\_edge, m\_hierarchy, m\_identity, m\_media, m\_rsc, m\_search, m\_site, m\_trans, m\_predicate, m\_post, m\_delete) now expose structured API paths for programmatic access. This allows templates and external clients to query user identity, access control status, category trees, configuration values, resource edges, and search results via predictable URL patterns, replacing the need for direct function calls or less structured data access.
_apps/zotonic\core/src/models · high confidence
New model, observer, and scomp behaviours for extensibility
Three new behaviours are introduced to standardize extension points in the framework. The \zotonic\_model\ behaviour defines callbacks for handling GET, POST, and DELETE operations via templates, MQTT, and the API, allowing modules to implement custom data models. The \zotonic\_observer\ behaviour provides a typed interface for handling various system notifications, including dispatch routing, content security header modification, and CSP report handling. Additionally, the \zotonic\_scomp\ behaviour defines the interface for screen components, specifying how they render content and manage caching via the \render\ and \vary\ callbacks.
_apps/zotonic\core/src/behaviours · high confidence
New multi-step email-based signup flow with code verification
The \zotonic\_mod\_signup\ module now implements a new, structured signup process that requires email verification. Users enter their email address, receive a one-time code via email, and must enter that code to proceed to the final registration form. The flow includes steps for email entry, code verification, and final account creation with name, username, and password fields. The module also provides a separate confirmation flow for publishing and verifying accounts via email links.
_apps/zotonic\_mod\signup · high confidence
New pivot templates for search indexing
Added new template files in the pivot directory to define how resources are indexed for search. The main pivot template now includes separate blocks for title text, main body text, block text, and related text, allowing for more granular control over what content is indexed. Additionally, specific templates for titles, addresses, names, dates, and related IDs have been introduced to support the search indexing process.
_apps/zotonic\_mod\base/priv/templates/pivot · high confidence
New rate-limiting module for authentication attempts
A new \zotonic\_mod\_ratelimit\ module has been added to enforce rate limits on authentication and password reset flows. It tracks failed attempts per username or email, blocking the account for an hour after five failures. To prevent false positives from different devices, it uses a signed device-ID cookie, allowing each known browser its own set of five attempts. Administrators can reset these counters via a new button in the admin status template.
_apps/zotonic\_mod\ratelimit · high confidence
New record types for file handler notifications
Three new record types are introduced to structure file handler events: zotonic\_filehandler\_categorize for mapping files to categories, zotonic\_filehandler\_map for defining file actions, and zotonic\_filehandler\_filechange for tracking file modifications. These records define the data structures used by the file handler to process and react to file system changes.
_apps/zotonic\filehandler/include · high confidence
New ticket-based authentication for out-of-band MQTT posts via HTTP
A new model \m\_mqtt\_ticket\ has been added to provide a ticketing system for handling out-of-band MQTT actions via HTTP. This allows users to create one-time use tickets that store the current MQTT client context (including client ID, topic, ACL user ID, and other settings) for up to 30 seconds. These tickets can then be used in subsequent HTTP requests to authenticate and route MQTT messages, with the system automatically transferring the stored context to the new request. The model exposes API endpoints to create (\/new\) and delete/invalidate (\/+ticket\) these tickets.
_apps/zotonic\_mod\base/src/models · high confidence
New zotonic\_listen\_smtp app for SMTP handling
The SMTP listener functionality has been split into a dedicated \zotonic\_listen\_smtp\ application, containing the server logic, email reception, spam checking, and auto-reply/bounce detection modules. This new app depends on \gen\_smtp\ and \zotonic\_core\, and includes configuration for listening on an IP and port, TLS options, and size limits for received emails.
_apps/zotonic\_listen\smtp/src · high confidence
OEmbed support for embedding external media
The oembed module now enables embedding media from external URLs (such as YouTube, Vimeo, Spotify, and others) using the OEmbed protocol. Administrators can paste URLs in the admin interface to automatically fetch and display embedded content, including thumbnails, titles, and provider information. The module includes templates for rendering embedded content with responsive wrappers and provides an admin tool to fix previously failed embeds.
_apps/zotonic\_mod\oembed · high confidence
Redesigned connect and media upload dialogs in the admin interface
The admin interface now features a redesigned, tabbed dialog for connecting and creating resources, as well as uploading media. The new \\_action\_dialog\_connect.tpl\ provides a unified interface with tabs for finding, creating, and uploading content, while \\_action\_dialog\_media\_upload.tpl\ handles file uploads and URL embedding. These changes replace the previous single-purpose dialogs with a more flexible, multi-tabbed approach that supports various content types and improves the user experience for linking and managing resources.
_apps/zotonic\_mod\admin/priv/templates · high confidence
Standardize build system with Rebar3 and modernize project configuration
The project now uses Rebar3 as the primary build system, replacing the previous Makefile-based approach. This change introduces a standardized \rebar.config\ and \rebar.lock\ file to manage dependencies, ensuring consistent builds across different environments. Additionally, the repository now includes a \.dockerignore\ file to optimize Docker builds, an \.editorconfig\ for consistent coding styles, and a \crowdin.yml\ to streamline translation workflows. The \zotonic.tmproj\ (TextMate project file) has been removed as it is no longer needed.
(repo-wide) · high confidence
Survey module restructured with new admin UI and feedback features
The survey module has been restructured to provide a modernized admin interface for creating and editing surveys. A new tabbed layout organizes survey editing into Description, Settings, Questions, and Results. The question editor now supports drag-and-drop reordering of pages and questions, allowing administrators to easily rearrange the survey flow. Additionally, the module now supports test/quiz functionality, enabling administrators to define correct/incorrect feedback for questions and track user scores and pass/fail status in the results view.
_apps/zotonic\_mod\survey · high confidence
Two-factor authentication (2FA) configuration and management templates
The 2FA module now provides dedicated templates for configuring and managing two-factor authentication. Administrators can set a global 2FA policy (optional, ask on login, nag on every page, or force) and override it per user group. Users see their 2FA status in the admin sidebar and user info, and can enable, disable, or remove 2FA via new dialog and action templates that handle QR codes, passcode entry, and confirmation prompts.
_apps/zotonic\_mod\auth2fa/priv/templates · high confidence
Unsaved changes warning for edit pages
The admin frontend now intercepts navigation away from edit pages to warn users about unsaved changes. This is implemented in the new \admin-frontend.js\ module, which registers handlers for link clicks and internal menu events to trigger a confirmation dialog before discarding changes.
_apps/zotonic\_mod\_admin\frontend/priv/lib/js · high confidence
Updated TinyMCE editor to version 4.9.3 with new plugins and styles
The TinyMCE editor has been updated to version 4.9.3, introducing several new plugins: advlist, anchor, autolink, autoresize, autosave, bbcode, charmap, code, codesample, colorpicker, and compat3x. Additionally, the codesample plugin now includes Prism.js CSS for syntax highlighting. These changes enhance the editor's capabilities by adding features like automatic link detection, code sample insertion with syntax highlighting, and backward compatibility with older TinyMCE APIs.
(repo-wide) · high confidence
Zotonic launcher app initialized with updated dependencies
The zotonic\_launcher application has been introduced, establishing the build configuration and licensing for the HTTP and SMTP listener components. The project now requires OTP 23 or higher and includes dependencies on yamerl (version 0.8.1) and cowmachine (version 1.8), alongside internal Zotonic libraries.
_apps/zotonic\launcher · high confidence
Removals
Removal of TinyMCE table and Safari compatibility plugins
The TinyMCE editor's table management capabilities and Safari-specific compatibility patches have been removed. This includes the deletion of the table plugin's JavaScript and source files, the associated CSS stylesheets, and the HTML templates for the cell and row editing dialogs. Additionally, the 'safari' plugin, which provided workarounds for WebKit rendering issues in TinyMCE, has been removed along with its associated JavaScript files. Users will no longer have access to table insertion, editing, and formatting features within the editor, nor will the editor apply specific styling fixes for Safari/WebKit browsers.
(repo-wide) · high confidence
Removal of Webmachine demo application and core library files
The Webmachine demo application files (including \webmachine\_demo\, \webmachine\_demo\_app\, \webmachine\_demo\_resource\, \webmachine\_demo\_sup\, and \demo\_fs\_resource\) have been removed from the \deps/webmachine/demo\ directory. Additionally, the core Webmachine library files (including \webmachine.app\, \webmachine.erl\, \webmachine\_app.erl\, \webmachine\_decision\_core.erl\, \webmachine\_deps.erl\, \webmachine\_dispatcher.erl\, \webmachine\_error\_handler.erl\, \webmachine\_host.erl\, \webmachine\_logger.erl\, \webmachine\_mochiweb.erl\, \webmachine\_multipart.erl\, and \webmachine\_perf\_logger.erl\) have been deleted from the \deps/webmachine/src\ directory. This removes the example resources and the main Webmachine framework code from the dependency tree.
deps/webmachine · high confidence
Removal of legacy admin modules and templates
The legacy admin module (mod\_admin) and its associated resources, actions, and templates have been removed from the codebase. This includes the deletion of Erlang modules for handling admin pages (such as resource\_admin, resource\_admin\_edit, and resource\_admin\_logon), action handlers for dialogs (like action\_admin\_dialog\_link and action\_admin\_dialog\_new\_rsc), and related CSS/JS assets. This change eliminates the old admin interface implementation, likely as part of a broader refactoring or migration to a new admin architecture.
_modules/mod\admin · high confidence
Removal of legacy search module and helper
The \mod\_search\ module and the \search\_all\_bytitle\ helper have been removed from the codebase. This change eliminates the legacy search implementation that previously handled basic content searches, including features like featured resource listing, latest/upcoming item retrieval, and title-based sorting. Users relying on these specific search capabilities will need to use the updated search infrastructure.
_modules/mod\search · high confidence
Removal of legacy sitemap module
The 'SEO Sitemap' module has been removed from the system. This eliminates the previous implementation that generated a static XML sitemap for search engines, which previously relied on a gen\_server process and a specific template for crawling. Users relying on this specific module will need to use alternative methods for sitemap generation.
_modules/mod\_seo\sitemap · high confidence
Removal of video embed module
The mod\_video\_embed module and its associated templates have been removed from the system. This eliminates the ability to embed videos from services like YouTube and Vimeo as media pages, as well as the associated admin forms and UI components for creating and editing embedded video content.
_modules/mod\_atom\_feed, modules/mod\_video\embed · high confidence
Removed ErlyDTL template engine
The ErlyDTL template engine and its associated modules (including the compiler, parser, scanner, and filters) have been removed from the codebase. This eliminates the legacy template rendering system, requiring the use of the current template engine for all template processing.
src/erlydtl · high confidence
Removed admin config module
The admin config module, which allowed administrators to edit system configuration keys with string values, has been removed. This includes the associated action handlers, resource files, and templates for creating, editing, and deleting configuration entries. Administrators can no longer manage configuration settings through this specific interface.
_modules/mod\_admin\config · high confidence
Removed default site and Emacs mode test fixtures
The default site implementation (including templates, dispatch rules, and the default gen\_server module) has been removed from the repository. Additionally, the Emacs mode test fixtures (zotonic-tpl-mode.el, zotonic-tpl-mode-tests.tpl, and zotonic-tpl-mode-highlight.tpl) have been deleted, indicating a cleanup of the development and default site assets.
priv · high confidence
Removed deprecated Erlang OAuth dependency
The \erlang-oauth\ dependency has been removed from the project. This eliminates the \oauth\ application and all associated Erlang modules (including \oauth\, \oauth\_client\, \oauth\_hmac\_sha1\, \oauth\_http\, \oauth\_plaintext\, \oauth\_rsa\_sha1\, \oauth\_unix\, and \oauth\_uri\) from the \deps\ directory, reducing the codebase by deleting these files and the application definition.
deps/erlang-oauth · high confidence
Removed deprecated base action modules
The \mod\_base\ module has removed a large number of deprecated action modules, including \action\_base\_add\_class\, \action\_base\_alert\, \action\_base\_animate\, \action\_base\_buttonize\, \action\_base\_confirm\, \action\_base\_dialog\, \action\_base\_dialog\_close\, \action\_base\_dialog\_open\, \action\_base\_disable\, \action\_base\_effect\, \action\_base\_enable\, \action\_base\_event\, \action\_base\_fade\_in\, \action\_base\_fade\_out\, \action\_base\_growl\, \action\_base\_hide\, \action\_base\_insert\_bottom\, \action\_base\_insert\_top\, \action\_base\_jquery\_effect\, \action\_base\_logoff\, \action\_base\_postback\, \action\_base\_redirect\, and \action\_base\_reload\. These removals streamline the codebase by eliminating legacy implementations that are no longer supported.
_modules/mod\base · high confidence
Removed deprecated database installation modules
The legacy database installation modules (z\_install, z\_install\_data, z\_installer) have been removed from the src/install directory. This cleanup eliminates outdated code responsible for initial database schema creation and default data seeding, reflecting a shift toward modern, modular installation processes.
src/install · high confidence
Removed deprecated module management actions and templates
The \mod\_admin\_modules\ module's legacy implementation has been removed, specifically deleting the \action\_admin\_modules\_module\_rescan\ and \action\_admin\_modules\_module\_toggle\ actions, along with the \mod\_admin\_modules\ gen\_server, the \resource\_admin\_module\_manager\ resource, and the associated templates (\admin\_modules.tpl\, \\_admin\_menu\_module.tpl\). This removes the old-style module activation/deactivation and manual rescan interface from the admin panel.
_modules/mod\_admin\modules · high confidence
Removed development module and its associated services
The mod\_development module, the z\_development\_server, and the service\_development\_recompile service have been removed from the codebase. This eliminates the automatic recompilation and hot-reloading of Erlang modules during development, meaning developers will no longer have their code changes automatically compiled and loaded into the running system.
_modules/mod\development · high confidence
Removed legacy PostgreSQL driver and connection pool
The custom \pgsql\ and \epgsql\_pool\ modules, along with their associated test suites, schema definitions, and documentation, have been removed from the \src/dbdrivers/postgresql\ directory. This change eliminates the previous PostgreSQL database driver implementation, indicating a shift to a different database driver or connection management strategy.
src/dbdrivers · high confidence
Removed legacy SEO module and admin interface
The mod\_seo module, its gen\_server, dispatch rules, and admin UI templates have been removed. This eliminates the previous centralized SEO configuration interface and associated backend logic, reflecting a shift away from the legacy SEO management approach.
_modules/mod\seo · high confidence
Removed legacy TinyMCE 3.3.2a theme files
The 'advanced' theme files for TinyMCE (version 3.3.2a) have been removed from the application. This includes the main theme JavaScript (\editor\_template.js\), the source file (\editor\_template\_src.js\), and all associated HTML templates and JavaScript logic for dialogs such as the about, anchor, charmap, color picker, and image insertion windows. This cleanup removes the deprecated theme implementation, likely to prevent browser caching issues or to prepare for a newer editor version.
_modules/mod\base/lib/js/modules/tinymce · high confidence
Removed legacy category management actions and templates
The legacy category management actions (add, delete, sorter) and their associated templates have been removed from the admin interface. This cleanup eliminates the old gen\_server-based module and associated dispatch rules, streamlining the admin category editing workflow.
_modules/mod\_admin\category · high confidence
Removed legacy menu editor and associated components
The legacy menu editor interface and its supporting components have been removed from mod\_menu. This includes the dispatch route for the admin menu, the gen\_server implementation, the resource handler for the admin menu, the scomp for rendering menus, and all associated templates (including the menu view, module header, typeahead results, and the main admin page). This cleanup removes the old drag-and-drop menu management system in favor of newer approaches.
_modules/mod\menu · high confidence
Removed legacy model modules from the codebase
The legacy model modules (m\_acl, m\_category, m\_config, m\_edge, m\_group, m\_identity, m\_media, m\_predicate, and m\_rsc) have been removed. This change eliminates the old data access layer, requiring the system to use the updated resource and edge handling logic.
src/models · high confidence
Removed legacy user management actions and templates
The 'mod\_admin\_identity' module's legacy user management actions and templates have been removed. This includes the deletion of Erlang action modules (e.g., \action\_admin\_identity\_delete\_username\, \action\_admin\_identity\_dialog\_set\_username\_password\), the \mod\_admin\_identity\ gen\_server, and associated templates (e.g., \\_action\_dialog\_user\_add.tpl\, \admin\_users.tpl\). This change eliminates the old dialog-based interface for managing usernames and passwords, likely as part of a broader refactoring of the admin interface.
_modules/mod\_admin\identity · high confidence
Removed obsolete TinyMCE zmedia plugin
The TinyMCE editor plugin for Zotonic media items (zmedia) has been removed. This plugin previously handled the insertion and editing of media items within the editor, including opening property dialogs and managing image alignment. Its removal indicates that this specific integration is no longer supported or has been replaced by a different mechanism.
_modules/mod\base/lib/js/modules/tinymce/plugins/zmedia · high confidence
Removed obsolete gen\_model behaviour
The gen\_model behaviour module has been removed from the codebase. This cleanup eliminates an obsolete abstraction layer that was no longer required for the application's data model implementation.
src/support · high confidence
Removed predicate management from the admin interface
The \mod\_admin\_predicate\ module and all its associated files have been removed from the codebase. This includes the main module, dispatch rules, resource handlers, action controllers, and templates that previously allowed administrators to create, edit, and delete predicates directly through the admin panel.
_modules/mod\_admin\predicate · high confidence
Removed the legacy mod\_oauth module
The legacy OAuth module (mod\_oauth) and all its associated files have been removed. This includes the dispatch rules, the main gen\_server, model files for application and permission management, Webmachine resource handlers, and all related templates. This change eliminates the older OAuth implementation in favor of a newer authentication system.
_modules/mod\oauth · high confidence
Architecture
Core support modules reorganized into the support directory
The Zotonic core support modules (z, z\_acl, z\_auth, z\_config, z\_config\_files, z\_context, z\_controller\_helper) have been moved to the apps/zotonic\_core/src/support directory. This change restructures the application's internal codebase, grouping these foundational utilities together for better organization and maintainability.
_apps/zotonic\core/src/support · high confidence
Behavioural changes
Add default CSS styles for the TinyMCE editor iframe
A new stylesheet, tinymce-zotonic.css, has been added to define the visual appearance of the TinyMCE editor's editable area. This includes styling for body text, paragraphs, and specifically images (with classes for alignment and size) and aside elements, ensuring consistent formatting within the editor.
_apps/zotonic\_mod\_editor\tinymce/priv/lib/css · high confidence
Add module reinstallation capability to the admin module manager
The admin module manager now includes a button to re-install a module's data model. When a user triggers this action, the system attempts to re-run the module's schema management, providing feedback via a growl notification indicating whether the reinstallation was successful or if the module lacks the necessary schema management function.
_apps/zotonic\_mod\_admin\modules/src/controllers · medium confidence
Added Zotonic launcher configuration and placeholder
Introduced a new header file, zotonic\_command.hrl, which defines default node names for the Zotonic application and test sandbox, along with a wait-time constant. Additionally, an empty placeholder file was added to the apps\_user directory.
_apps/zotonic\_launcher/include, apps\user · low confidence
Added admin modules dispatch rule
A new dispatch rule has been added to map the 'admin\_modules' module to the '/admin/modules' path, utilizing the 'controller\_admin\_module\_manager' controller with 'seo\_noindex' configuration.
_apps/zotonic\_mod\_admin\modules/priv/dispatch · high confidence
Added category management and deletion UI
The admin interface now includes a dedicated page for managing the category hierarchy, allowing administrators to drag and drop categories to reorder them. A new confirmation dialog has been added for deleting categories, which offers the option to move associated pages to another category or delete all pages within the categories being removed. Additionally, a dispatcher has been added to route requests to the category sorter controller.
_apps/zotonic\_mod\_admin\category/priv · medium confidence
Added release notes and documentation assets
Added release notes for versions 0.01.0 through 0.08.0, documenting new features, modules, and bug fixes for each release. Also added the BrowserStack logo as an SVG image in the documentation assets.
doc · high confidence
Adds new CSS styles for UI components and updates asset paths
The mod\_base module now includes several new CSS files to support various UI features: a loading mask overlay, a time picker, syntax highlighting for code blocks (PrismJS), bridge connection status warnings, toast notifications, a comprehensive icon font system (Zotonic, FontAwesome, Material Design), and multi-level modal dialogs. Additionally, the existing datepicker stylesheet was moved and its internal image URLs were updated to use the new /lib/images/ path structure.
_apps/zotonic\_mod\base/priv/lib/css · high confidence
Admin UI styling overhaul and form control updates
The admin interface receives a comprehensive visual update, including a lighter UI theme, improved button visibility, and better hover states for muted text. Form controls now feature floating labels that display on focus or when content is present, with specific styling for invalid/valid states and error highlighting. The layout for media details, menu editing, and dialog boxes has been refined, including fixes for Safari 17.4.1 word-break issues and margin adjustments for buttons and tabs.
_apps/zotonic\_mod\admin/priv/lib/css · high confidence
Admin UI updated to use Bootstrap 3 with custom styling
The admin interface now uses Bootstrap 3 (via the bootstrap-sass 3.4.1 library) to generate the admin CSS. This includes a new Makefile to compile the SCSS sources, a main SCSS file that imports Bootstrap components and applies custom color variables (such as $brand-primary: \#0fa2db) and font families, and the necessary font and license files for the icon set.
_apps/zotonic\_mod\admin/priv/lib-src/admin-bootstrap3 · high confidence
Admin config actions migrated to OTP app structure with updated ACL checks
The configuration management actions in the admin interface have been reorganized into the new OTP app structure (apps/zotonic\_mod\_admin\_config/src/actions). This includes the addition of new actions for toggling config values and creating new config entries, alongside refactored actions for editing and deleting configurations. A key behavioral change is the replacement of the strict \z\_acl:has\_role(admin, Context)\ check with the more granular \z\_acl:is\_admin\_editable(Context)\ check, allowing a broader set of users to modify configurations. Additionally, the edit dialog now dynamically titles the dialog with the module and key being edited, and the edit action now supports renaming the module and key of a configuration entry.
_apps/zotonic\_mod\_admin\config/src/actions · medium confidence
Admin controllers restructured into dedicated modules
The admin interface's backend logic has been reorganized into separate controller modules for specific functions: the main admin dashboard, resource editing, media previewing, and referrer listing. This separation clarifies the responsibilities of each controller and improves maintainability of the admin panel's core features.
_apps/zotonic\_mod\admin/src/controllers · high confidence
Admin interface styles migrated from LESS to SCSS
The admin interface's styling has been refactored from LESS to SCSS. This migration updates the visual presentation of the admin panel, including the navbar, buttons, forms, and various widgets, ensuring consistent styling across the application.
_apps/zotonic\_mod\admin/priv/lib-src/zotonic-admin/scss · high confidence
Admin module actions restructured and modernized
The \mod\_admin\ actions have been migrated from \modules/mod\_admin/actions\ to \apps/zotonic\_mod\admin/src/actions\, modernized with Erlang 20+ syntax (e.g., \\#postback\ records instead of tuples), and enriched with \moduledoc\ documentation. This change also standardizes error and success messages to use the internationalization function \?\\_()\ for translation support, and updates copyright headers to 2026.
_apps/zotonic\_mod\admin/src/actions · high confidence
Admin statistics route reconfigured
The dispatch rule for the admin interface has been moved from the configuration module to the statistics module. The route previously mapped to 'admin/config' and 'resource\_admin\_config' now maps to 'admin/statistics' and 'controller\_admin\_statistics', effectively changing the URL path and the controller handling the request.
_apps/zotonic\_mod\_admin\statistics/priv/dispatch · high confidence
Audio media editing and display enhancements
The audio module now provides a dedicated admin interface for editing audio metadata, including fields for album, artist, composer, genre, track, copyright, and compilation status. Additionally, the media metadata view displays the audio bit rate in kbps for rates above 1024 bps, and lists all audio tags. A new audio viewer template enables playback of audio files with optional autoplay and preload controls.
_apps/zotonic\_mod\audio/priv · high confidence
Backup module refactored with new support files for config, creation, encryption, and restore
The backup module's support logic has been reorganized into dedicated Erlang modules: backup\_config.erl centralizes all configuration retrieval (including encryption, retention, and admin panel settings); backup\_create.erl handles the backup creation process, including database dumps, file archiving, and optional encryption; backup\_file\_crypto.erl provides the encryption/decryption utilities for backup files; backup\_restore.erl manages the restoration of backups, including database, file, security, and config restoration; and backup\_rsc\_upload.erl handles resource uploads during backup operations. This refactoring improves modularity and maintainability of the backup feature.
_apps/zotonic\_mod\backup/src/support · high confidence
Centralized configuration for logging, SSL, and application settings
The zotonic\_launcher app now provides centralized configuration templates for Erlang and Zotonic runtime settings. The new erlang.config.in file configures the Erlang logger with handlers for console, file, and Logstash output, alongside SSL session caching and disk usage monitoring. The zotonic.config.in template introduces global settings for HTTP/HTTPS/MQTT listeners, security headers, database defaults, and SMTP relay options, allowing administrators to customize the server's behavior and security posture.
_apps/zotonic\launcher/priv · high confidence
Complete refactoring of the email sending subsystem
The email sending functionality has been completely refactored into a new modular structure. The core logic for sending emails is now in \z\_email.erl\, which handles recipient formatting, admin email retrieval, and the main send interface. A new \rfc2047.erl\ module provides RFC 2047 encoding for email headers. Image embedding is handled by a dedicated \z\_email\_embed.erl\ module, which respects a 1MB size limit for embedded images. The \z\_email\_server.erl\ module manages the email queue, connection pooling, and delivery logic, introducing configurable limits on simultaneous senders and domain connections. This change improves code organization, robustness, and maintainability of the email system.
_apps/zotonic\core/src/smtp · high confidence
Core application structure and startup logic reorganized
The Zotonic core application has been restructured to follow OTP conventions, moving the main application module and supervisor into the standard \src\ directory. This change introduces a new \zotonic\_core.app.src\ file that explicitly lists all core dependencies, including \mnesia\, \ranch\, \cowboy\, and various internal modules. The \zotonic\_core\ module now handles initial setup tasks such as loading applications, configuring environment variables, and ensuring the Mnesia schema is created in a node-specific directory. The \zotonic\_core\_sup\ supervisor manages key background processes like job queues, side jobs, and file watchers. This reorganization improves the reliability of the startup sequence and ensures consistent directory structures for data and logs.
_apps/zotonic\core/src · high confidence
Custom redirect model exposes API and enforces path validation
The \m\_custom\_redirect\ model now exposes a structured API for managing custom redirects, including \list\, \get\, \insert\, \update\, and \delete\ operations. The model enforces that the \path\ field must be a valid UTF-8 string before querying the database, preventing errors on production sites. Additionally, the model explicitly prevents redirects for paths starting with \.zotonic\ or \.well-known\ to ensure these system paths are not redirected.
_apps/zotonic\_mod\_custom\redirect/src/models · medium confidence
Customized error pages and updated build configuration
The default HTTP error pages for 400, 500, and 503 status codes have been replaced with custom, user-friendly HTML templates. Additionally, the project's build configuration (rebar.config) has been updated to specify a minimum Erlang/OTP version of 23 and includes an updated list of dependencies.
_apps/zotonic\core · high confidence
Database layer refactored with new z\_db modules and codec
The database abstraction has been restructured into dedicated modules: z\_db (core interface), z\_db\_pgsql (PostgreSQL pool worker), z\_db\_pgsql\_codec (binary/JSONB/datetime encoding), z\_db\_pool (connection pooling), z\_db\_table (DDL operations), and z\_db\_worker (worker behavior). This introduces support for binary keys, JSONB decoding, and structured logging, while fixing issues with connection timeouts, stale connections, and error handling for SQL failures.
_apps/zotonic\core/src/db · high confidence
Enhanced backup management with encryption, filestore support, and revision controls
The backup module's admin interface has been significantly updated. The backup list now displays encryption status and filestore upload status, with download links for encrypted or standard archives. A new template renders a side-by-side diff view for comparing page revisions, and the main backup page now shows the backup directory path. Configuration options allow administrators to enable daily database-only backups, toggle backup encryption, and control the retention period for revisions. The sidebar and edit pages now feature a 'Revert to earlier version' link, and deleted pages can be recovered directly from the admin panel.
_apps/zotonic\_mod\backup/priv/templates · high confidence
Enhanced debug pane with resizable layout and template variable inspection
The development module's debug pane now supports a resizable layout, allowing users to drag a splitter to adjust the width of the template code and data viewer. This change introduces CSS styles for a new template debugging overlay, including a grid-based layout with a source code panel, a resizable splitter, and a data viewer that displays template variables with collapsible nodes and syntax highlighting. Additionally, styles for trace status indicators and graph visualization are added to support the floating trace button feature.
_apps/zotonic\_mod\_development/priv/lib-src, apps/zotonic\_mod\development/priv/lib/css · medium confidence
Enhanced module management in the admin interface
The admin modules overview now displays each module's version number alongside its title and description, and includes a 'Reinstall' button to restore a module's datamodel. Additionally, the interface now warns about uninstalled or missing modules and provides confirmation dialogs when activating or deactivating modules that have dependencies, ensuring users are aware of the impact on other modules.
_apps/zotonic\_mod\_admin\modules/priv/templates · high confidence
Filehandler app structure and compilation logic
The zotonic\_filehandler application is restructured with a new app.src manifest declaring dependencies on kernel, stdlib, erlexec, jobs, buffalo, zotonic\_notifier, and zotonic\_filewatcher. The module zotonic\_filehandler now exposes functions to compile all files, reload modules, and send terminal notifications. The handler serializes file change events, maps them to actions (compile, load, etc.), and triggers recompilation or reloading as needed.
_apps/zotonic\filehandler/src · high confidence
Filewatcher refactored into a standalone application
The filewatcher functionality has been refactored into its own dedicated application, \zotonic\_filewatcher\. This change introduces a new application structure with its own supervision tree, including workers for the file handler, beam reloader, and monitor. The implementation now supports multiple file system monitoring backends (inotify, fswatch, and a polling-based fallback) with automatic fallback and backoff on errors. The application also includes a new \zotonic\_filewatcher\_monitor\ module for polling-based file status changes, and the \zotonic\_filewatcher\_sup\ supervisor manages the lifecycle of these components. This separation improves modularity and allows for more robust error handling and configuration of file watching behavior.
_apps/zotonic\filewatcher/src · high confidence
Fix TinyMCE editor overlay obscuring save buttons
The admin frontend CSS has been updated to correct the layout of the editor interface. Specifically, the TinyMCE editor's auxiliary container is now hidden (height: 0) to prevent it from overlapping with the save buttons. Additional styling adjustments were made to the navbar checkboxes, buttons, and meta-data sections to improve visual consistency and spacing.
_apps/zotonic\_mod\_admin\frontend/priv/lib/css · medium confidence
Introduce structured authentication dispatch rules for login, session, and password management
The authentication module now uses a dedicated dispatch configuration file to define URL routing for key user flows. This includes dedicated endpoints for logging in, changing passwords, and resetting passwords, all configured to prevent search engine indexing (seo\_noindex) and tracking (notrack). A new session overview page is exposed at /logon/sessions, and an API endpoint at /zotonic-auth supports the authentication worker. Additionally, a redirect is added for the .well-known/change-password path to assist password managers.
_apps/zotonic\_mod\authentication/priv/dispatch · high confidence
Login page styling migrated to SCSS
The login page styles have been converted from LESS to SCSS, introducing a new build process via a Makefile that compiles logon.scss into logon.css. This change updates the styling for the authentication interface, including the logon box, error states, and social login options, ensuring consistent visual presentation for users on the login and 403 error pages.
_apps/zotonic\_mod\authentication/priv/lib-src · medium confidence
Manual backup initiation with read-only and permission checks
Users can now manually start a backup via a new action that checks for read-only mode and verifies the user has 'use' permission on mod\_backup. If a backup is already in progress, the system displays an error message. Additionally, if manual backups are disabled via configuration, users receive an error message indicating that manual backups are not allowed.
_apps/zotonic\_mod\backup/src/actions · medium confidence
Menu editor UI and styling overhaul
The menu editor interface has been redesigned with new CSS styles for the tree list and menu items, providing a more modern grid-based layout for the admin menu editing tools. The update includes new JavaScript modules for menu editing, trash management, and nested sorting, alongside updated templates for menu rendering and hierarchy sorting, enhancing the user experience for managing site navigation structures.
_apps/zotonic\_mod\menu · high confidence
Migrate admin stylesheets from LESS to SCSS
The admin module's stylesheet build system and source files have been converted from LESS to SCSS. This includes new SCSS files for icon styling (z.icons, z.icons/core, z.icons/extend, z.icons/font-awesome, z.icons/material-design), button components (z.icons/icon-buttons), bridge status indicators (z.bridge), and modal dialogs (z.modal), along with a new Makefile to manage the compilation of these SCSS files.
_apps/zotonic\_mod\base/priv/lib-src/scss · high confidence
New JavaScript-based authentication workers for UI and background checks
The authentication module now uses dedicated JavaScript workers to manage the authentication state and UI. The new \zotonic.auth-ui.worker.js\ handles the login, password reset, and 2FA forms, while \zotonic.auth.worker.js\ manages the background polling for session status and token refresh. This shift introduces a more robust, client-side state management for authentication flows, including support for password expiration, OAuth2 login, and improved handling of race conditions during authentication checks.
_apps/zotonic\_mod\authentication/priv/lib/js · medium confidence
New and updated error messages for authentication failures
Added new template files to provide specific, user-friendly error messages for various authentication scenarios. These include templates for data breach warnings (referencing Have I Been Pwned), two-factor authentication passcode errors and reminders, password validation failures (too short, too simple, matching previous password, unequal confirmation), rate limiting, and account status issues (user not enabled, external login restrictions). Existing templates for login failures and password changes were also updated.
_apps/zotonic\_mod\_authentication/priv/templates/logon\error · medium confidence
New backup management and download endpoints
The backup module now exposes new administrative and user-facing routes. Administrators can access backup management and deletion screens via the admin interface, while users can download backup files through a dedicated download endpoint that serves files from the mod\_backup module as attachments.
_apps/zotonic\_mod\backup/priv/dispatch · high confidence
New development admin pages for templates, dispatch, and tracing
The development module now exposes several new admin pages under the /admin/development path, allowing users to inspect and debug their site's configuration and templates. These include a dispatch rules viewer, a template cross-reference checker, a template dependency graph, an observers list, and function tracing tools. Additionally, a basic test page is available at /test/hello\_world for development purposes.
_apps/zotonic\_mod\development/priv/dispatch · high confidence
Nix package management initialized with Nixpkgs 26.05
The project now manages system dependencies using Nix, introducing a new nix/nixpkgs.nix file that pins the Nixpkgs repository to the 26.05 release (26.05.tar.gz). This establishes the foundation for declarative, reproducible build environments via Nix.
nix · medium confidence
Redesign of ACL rule administration and user group management
The ACL administration interface has been completely restructured with new templates for managing access control rules, including dedicated dialogs for editing, importing, and testing rules. The user-add and user-edit dialogs now allow administrators to assign users to specific user groups. Additionally, the system now supports visibility levels in ACL rules, allowing administrators to control whether content is public, private, or restricted to specific user groups or collaboration groups.
_apps/zotonic\_mod\_acl\_user\groups/priv/templates · high confidence
Redesign of the Zotonic system status page
The Zotonic system status page has been completely redesigned with a new layout, updated CSS styles, and modernized templates. The previous 'less' based stylesheets have been replaced with SCSS, and the UI now features a Bootstrap-based navbar, a structured site overview table with status indicators, and improved templates for the home, logon, and status pages. The configuration file has also been updated to reflect the new OTP structure.
_apps/zotonic\_site\status · high confidence
Refactor admin identity actions into dedicated modules
The admin identity management actions have been reorganized into a dedicated \zotonic\_mod\_admin\_identity\ application. This includes new modules for managing usernames and passwords (\action\_admin\_identity\_dialog\_set\_username\_password.erl\, \action\_admin\_identity\_dialog\_user\_add.erl\), a new module for deleting usernames (\action\_admin\_identity\_delete\_username.erl\), and the migration of the username deletion dialog from the old \mod\_admin\ module. These changes consolidate user identity administration logic, enforcing stricter access controls (e.g., preventing the admin user from having a password) and providing specific UI dialogs for adding, editing, and deleting user credentials.
_apps/zotonic\_mod\_admin\identity/src/actions · high confidence
Relocate and reconfigure 2FA admin module dispatch
The dispatch rule for the two-factor authentication configuration has been moved from the generic admin modules area to the dedicated 2FA application directory. The route has changed from admin\_modules to admin\_auth2fa\_config, mapping the path admin/authentication-2fa to the admin controller using the admin\_auth2fa\_config template, with SSL enforced and access restricted to the mod\_admin\_config ACL module.
_apps/zotonic\_mod\auth2fa/priv/dispatch · medium confidence
Removal of artist event management features
The mod\_admin\_event module and its associated components have been removed. This eliminates the ability to add, view, and manage events for artists within the admin interface, including the 'Add event' dialog, sidebar widgets, and the underlying Erlang and template files that supported this functionality.
_modules/mod\_admin\event · high confidence
Removal of legacy Webmachine and Zotonic header files
The header files \include/resource\_html.hrl\, \include/webmachine\_resource.hrl\, and \include/zotonic.hrl\ have been removed. This eliminates the legacy Webmachine resource definitions and the central \\#context\ record structure, reflecting the migration away from Webmachine and the refactoring of the application's core data structures.
include · high confidence
Removed default site CSS and font files
The default site's stylesheet (zp-project.css) and a Cufon font file (cufon.anja.js) have been removed. This cleanup likely reflects a shift away from the previous visual styling and font rendering approach for the default site.
priv/sites/default · high confidence
Removed deprecated MochiWeb modules
The MochiWeb dependency has been updated to version r153, which includes the removal of several legacy modules: \mochifmt\ (string formatting), \mochihex\ (hexadecimal utilities), \mochijson\ and \mochijson2\ (JSON encoding/decoding), \mochinum\ (numeric algorithms), and various other utility modules like \mochiweb\_charref\, \mochiweb\_cookies\, \mochiweb\_echo\, \mochiweb\_headers\, and \mochiweb\. These files have been deleted from the \deps/mochiweb/src/\ directory, indicating a significant reduction in the bundled library's feature set.
deps/mochiweb · medium confidence
Removed erlang-oauth, mochiweb, and webmachine dependencies
The local dependencies for erlang-oauth, mochiweb, and webmachine have been removed from the project's deps directory. This change eliminates the bundled source code, build scripts, and templates for these libraries, indicating they are no longer managed as local submodules or vendored code.
deps · high confidence
Removed group management UI and actions from the admin module
The admin interface for managing groups and their members has been removed. This includes deleting the Erlang action modules (such as \action\_admin\_group\_dialog\_group\_delete\, \action\_admin\_group\_dialog\_group\_member\_add\, and others) that handled the backend logic for creating, editing, and deleting groups and members. Corresponding templates for the group list, member list, and confirmation dialogs have also been removed, along with the \mod\_admin\_group\ module and its associated resources and dispatch rules. This change eliminates the ability to perform group administration tasks through the web interface.
_modules/mod\_admin\group · high confidence
Removed legacy ISO 639 language mapping and z\_trans module
The src/i18n/iso639.erl and src/i18n/z\_trans.erl files have been deleted. This removes the internal mapping of two-letter language codes to English names and the legacy z\_trans translation lookup mechanism, likely as part of a broader i18n refactoring.
src/i18n · high confidence
Removed legacy esmtp email sending implementation
The module replaced its internal esmtp-based email sending logic with a new gen\_smtp based SMTP implementation. This change removes the old esmtp\_fsm, esmtp\_mime, and rfc2047 modules, along with the email\_base template, streamlining how the system sends emails.
_modules/mod\emailer · high confidence
Removed obsolete test module and its associated resources
The \mod\_test\ module, which previously served as a test harness for the module system, has been removed. This includes the deletion of the \gen\_server\ implementation, the \testing\ dispatch file, the \resource\_test\_helloworld\ resource, and all associated templates (including \test\_helloworld.tpl\ and \test\_included.tpl\). These components are no longer needed for internal testing.
_modules/mod\test · high confidence
Removed standalone Google SEO module in favor of unified SEO module
The standalone \mod\_seo\_google\ module and its associated templates have been removed. Google Analytics and Webmaster Tools configuration is now handled within the unified \mod\_seo\ module, which also adds support for Bing webmaster tools.
_modules/mod\_seo\google · high confidence
Replace bash launcher scripts with Erlang-based zotonic launcher
The \bin/zotonic\ shell script and \bin/zotonic.escript\ have been replaced by a new Erlang-based launcher. This change introduces a \completion\ command to install bash autocompletion for the \zotonic\ CLI, adds support for FreeBSD and DragonFly BSD operating systems, and restricts the Erlang Port Mapper Daemon (epmd) to listen only on the loopback interface (127.0.0.1) for improved security. The launcher now dynamically loads command modules from \apps/zotonic\_launcher/src/command\.
_apps/zotonic\launcher/bin · high confidence
Restructured and expanded authentication templates
The authentication module's templates have been reorganized into a modular structure, introducing dedicated templates for password changes, session management, and external service errors. Users can now change their passwords directly from the login interface, manage active sessions via a new session overview, and see clearer error messages when connecting external accounts. The login form now supports a two-step process where the username is verified before the password is requested, improving the user experience for password managers and reducing information leakage about registered email addresses.
_apps/zotonic\_mod\authentication/priv/templates · high confidence
Restructured database installation and upgrade logic
The database installation and upgrade process has been refactored into dedicated modules: \z\_install\ handles the SQL data model, \z\_install\_data\ seeds initial categories, predicates, and the admin user, \z\_install\_reinstall\ provides a schema drop-and-recreate workflow, and \z\_install\_update\ manages startup checks and upgrades. This separation clarifies the distinct phases of database initialization, data seeding, and versioned upgrades.
_apps/zotonic\core/src/install · high confidence
Simplified Zotonic application structure and supervisor
The Zotonic application entry point and supervisor have been refactored to support an umbrella application structure. The \zotonic.app\ and \zotonic.app.src\ files have been updated to declare dependencies on \cowboy\, \cowmachine\, and \zotonic\_launcher\, replacing the previous \webmachine\ and \zotonic\_deps\ dependencies. The \zotonic\ and \zotonic\_deps\ modules have been removed, and the \zotonic\_sup\ supervisor has been simplified to an empty structure, delegating supervision to the new \zotonic\_launcher\ application.
src · high confidence
TinyMCE editor updated to version 5.10.2
The TinyMCE rich text editor library has been upgraded from version 4.5.5 to 5.10.2. This update replaces the older 4.x series plugins with the 5.10.2 versions for all standard plugins (including advlist, anchor, autolink, autoresize, autosave, bbcode, charmap, code, and codesample), bringing the editor to a more recent release with updated plugin implementations.
(repo-wide) · high confidence
TinyMCE version resolution now defaults to newest when configured version is unsupported
The TinyMCE editor model now automatically falls back to the newest available version if the configured version is not supported. Previously, an unsupported version might have caused issues or required manual intervention; now, the system logs a warning and resolves to the latest bundled version, ensuring the editor remains functional without breaking changes for users who have configured older, potentially deprecated, TinyMCE versions.
_apps/zotonic\_mod\_editor\tinymce/src/models · high confidence
Updated Bootstrap JavaScript library to v3.4.1
The admin interface's bundled JavaScript library, Bootstrap, has been upgraded from version 3.3.5 to 3.4.1. This update replaces the \bootstrap.js\ and \bootstrap.min.js\ files in the admin module's public resources, bringing the latest bug fixes and improvements from the Bootstrap 3.4.1 release to the admin UI components.
_apps/zotonic\_mod\admin/priv/lib/js/bootstrap3 · high confidence
Updated Bootstrap theme CSS to v3.4.1
The Bootstrap theme CSS files (bootstrap-theme.css, bootstrap-theme.min.css, and the associated .map file) have been updated to version 3.4.1. This update refreshes the default button, alert, progress bar, and panel heading styles to match the latest Bootstrap release, ensuring consistent visual styling across the application's UI components.
_apps/zotonic\_mod\bootstrap/priv · high confidence
Updated Font Awesome 4.2.0 assets
The \zotonic\_mod\_artwork\ module now includes the full, unminified CSS and SVG font files for Font Awesome 4.2.0, replacing the previous minified CSS version. This change ensures that the application uses the complete, readable CSS definitions and SVG font data for rendering icons, which may affect how styles are applied or how the font loads in the browser.
_apps/zotonic\_mod\artwork/priv · medium confidence
Updated TinyMCE editor to version 5.10.2
The embedded TinyMCE editor has been upgraded from version 4.5.5 to 5.10.2. This update brings a modernized user interface, improved accessibility features, and various bug fixes for table handling, link detection, and content editing. The configuration file (\tiny-init.js\) has been updated to reflect the new default plugins, toolbar layout, and style formats available in version 5.10.2.
_apps/zotonic\_mod\_editor\tinymce/priv/lib/js/tinymce-5.10.2 · high confidence
Updated TinyMCE editor with new configuration, assets, and translations
The TinyMCE 4.9.3 editor integration was updated to include a new \tiny-init.js\ configuration file that defines the editor's default settings, including the 'modern' theme, specific plugins (such as 'zlink' and 'zmedia'), and a customised list of valid HTML elements. The update also adds the \jquery.tinymce.min.js\ plugin file, which provides the jQuery integration for the editor. Additionally, new language files for English (GB), Dutch, and Russian were added to support multilingual user interfaces, and the 'lightgray' skin assets (CSS and SVG fonts) were updated to style the editor's content and interface.
_apps/zotonic\_mod\_editor\tinymce/priv/lib/js/tinymce-4.9.3 · high confidence
Updated TinyMCE editor with version selection and enhanced media editing options
The TinyMCE editor module now supports selecting between TinyMCE versions 4.9.3 and 5.10.2 via the admin configuration, with 5.10.2 set as the default. The media insertion dialog has been expanded to include alignment, crop, size, and link options, and now features a 'Remove from text' button and an 'Edit' link to manage media properties directly.
_apps/zotonic\_mod\_editor\tinymce/priv/templates · high confidence
Updated translations for multiple languages
The translation files in apps/zotonic\_core/priv/translations have been updated with new and revised text for various languages, including Arabic, German, English, and Spanish. This includes updates to country and language name translations, as well as general application strings. These changes ensure that the user interface is fully localized and up-to-date with the latest source strings.
_apps/zotonic\core/priv/translations · high confidence
Video handling and conversion logic moved to dedicated module
The video processing logic, including conversion to MP4, preview generation, and metadata extraction, has been consolidated into the new \zotonic\_mod\_video\ application. This change introduces a dedicated module for video support, replacing the previous inline handling within the core. Users will now see video-specific templates and CSS for the admin interface, and video uploads are processed through a dedicated queue and conversion pipeline, improving separation of concerns and maintainability.
_apps/zotonic\_mod\video · high confidence
Fixes
Fix spec for z\_list\_of\_ids\_filter:filter functions
Corrected the type specifications for the filter functions in the z\_list\_of\_ids\_filter module, ensuring that the function signatures accurately reflect the expected input and output types for resource filtering operations.
_apps/zotonic\_mod\base/src/support · medium confidence
Improved Markdown and HTML-to-Markdown conversion
The markdown conversion logic has been updated to fix several issues with HTML-to-Markdown and Markdown-to-HTML conversion. Specific fixes address crashes and formatting errors when converting certain HTML tables, list indentations, code blocks, and inline markup. The changes also improve handling of Unicode strings and ensure that spaces after code tags are preserved during conversion.
_apps/zotonic\core/src/markdown · medium confidence
Test coverage
Added EUnit tests for ACL user-group authorization logic; Added EUnit tests for base filters and admin module; Added comprehensive test coverage for core modules; Added connection and postback test pages for diagnosing browser and server connectivity; Added test data fixtures for config, CSV, and email parsing; Removed ErlyDTL test suite and templates.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 36.
Lenses
- Code Health 24
- Architecture 100
- Maturity 65
- Readiness 50
- Security 48
- Event-Driven 80
- Event Sourcing 100
- Accessibility 34
Changes since last survey
- 300 commits — 251 feature/other, 49 fixes
By area
- apps/zotonic_core — 125 commits
- apps/zotonic_mod_survey — 36 commits
- (root) — 33 commits
- (repo) — 12 commits
- apps/zotonic_mod_admin — 12 commits
- apps/zotonic_mod_development — 10 commits
- apps/zotonic_mod_admin_predicate — 7 commits
- apps/zotonic_mod_base — 6 commits
- apps/zotonic_mod_filestore — 6 commits
- apps/zotonic_mod_wires — 6 commits
- apps/zotonic_mod_signup — 4 commits
- .agents/skills — 3 commits
- apps/zotonic_mod_media_exif — 3 commits
- apps/zotonic_mod_search — 3 commits
- doc/release-notes — 3 commits
- apps/zotonic_mod_email_status — 2 commits
- apps/zotonic_mod_export — 2 commits
- apps/zotonic_mod_import_csv — 2 commits
- apps/zotonic_mod_logging — 2 commits
- apps/zotonic_mod_seo — 2 commits
Notable commits
- fix: Add log audit key, for now for auth. Also fix issue with copyright edit form (#4276)
- fix: Connect dialog: Fix option Any category (#4352)
- fix: Fix a problem where a button click can be lost if the focused input is invalid (#4459)
- fix: Fix an issue with parallel edge insert and unknown ACL actions (#4259)
- fix: Fix an issue with searching for dashed words, like 'e-learning'
- fix: Fix edocs and old '@type' specs. (#4377)
- fix: Fix hex publish zotonic_apps (#4384)
- fix: Fix ids facet search integer input (#4448)
- fix: Fix small edoc and spec issue (#4330)
- fix: Fix template compiler callbacks
- fix: Fix variable from the confirmation dialog (#4416)
- fix: Fixes for hex package release (#4382)
- fix: Misc fixes Jan 26 (batch 1) (#4270)
- fix: Revert "Wiring normal signups together."
- fix: core: fix an issue in markdown where inline markup was applied after a non space character (#4323)
- fix: core: fix an issue in search with passing non-list category terms (#4434)
- fix: core: fix an issue where qargs url expansion left 'qargs' in the arg list (#4474)
- fix: core: fix an issue where the dispatcher could crash on an empty path (#4263)
- fix: core: fix an issue where the language config could be overwritten (#4367)
- fix: core: fix an issue where the memo cache was not flushed correctly (#4329)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
zotonic/zotonic was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0d5de7630a8be1b70133adf38f04cc9ca4019ad2 — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.