9.8 KiB
BZOD v0.6.0 — Legacy Restore Compatibility & Version Reporting
Release Date: 2026-08-09
Highlights
-
Legacy Backup Restore Compatibility: Backups created with the web admin "Download Backup" feature (
legacy_flat_backupformat) can now be correctly restored into the current multi-tenant database architecture. Previously, these restores failed with "no such table: users" because the restore validator ran against the empty legacyusers.dbbefore layout normalization. -
CLI Version Reporting:
bzod --versionandbzod -Vnow report the application version derived from Cargo.toml package metadata, ensuring the reported version cannot diverge from the build. -
Deploy Script Modernization: Removed the obsolete
init-dbcommand from the deployment script. Database creation and schema migration are now handled automatically bybzod serve. The deploy script now verifies the installed binary version using--version.
Breaking Changes
None.
BZOD v0.5.3 — Architecture Refinement & Redirect Hardening
BZOD v0.5.3 is an internal quality and maintainability release focused on architectural refinement, redirect handler hardening, and comprehensive verification.
No new user-facing features are introduced. Existing API contracts, route behavior, authentication, and tenant isolation are fully preserved.
Highlights
Modular Admin Architecture
The former monolithic admin handler file was eliminated and replaced with a focused module directory at src/web/admin/.
Feature modules:
auth.rs— authentication and session handlingdashboard.rs— dashboard renderingurls.rs— URL management handlerspages.rs— landing page management handlersanalytics.rs— analytics and export handlerssettings.rs— settings and configuration handlersusers.rs— user management handlerssessions.rs— session administrationquotas.rs— quota managementhealth.rs— health diagnosticsbackups.rs— backup and restore handlersapi_keys.rs— API key managementaudit.rs— audit log handlersmoderation.rs— content moderation handlers
Benefits:
- Improved code organization and navigability
- Reduced coupling between feature areas
- Improved database lock scoping
- Reduced duplicated handler logic
- Better error handling consistency and observability
- Simplified future extension
Redirect Handler Hardening
The public redirect path (GET /:code) was hardened against invalid HTTP Location header values.
Changes:
- Removed the panic-prone
HeaderValue::from_str(...).unwrap()pattern - Added destination URL validation (scheme enforcement, control character rejection)
- Added safe Location header construction that handles malformed values gracefully
- Improved database error logging with structured fields
- Reduced unnecessary database mutex lock acquisitions
- Removed synchronous expiration writes from the redirect hot path
Existing redirect security and tenant isolation behavior was preserved.
Root Landing Page Verification
- Confirmed
GET /as an intentional application route servingwww/index.html - Resolved a runtime path-resolution issue affecting static landing-page resolution
- Verified
GET /returns HTTP 200 - Verified
GET /loginreturns HTTP 200 - Verified
GET /admin/loginreturns HTTP 200
Testing & Validation
BZOD v0.5.3 passed:
- Release build (
cargo build --release) - Comprehensive automated test suite, including:
- Authentication and migration tests
- Redirect security tests
- Root landing page test
- Backup and restore tests
- Business workflow tests
- Security tests
- Slug namespace, registry, and transfer tests
- User management and isolation tests
- WAL recovery tests
- HTTP end-to-end tests
- Runtime smoke tests against the release binary
- SQLite WAL mode and foreign-key enforcement initialization
- Database migration verification (all migrations up to date)
Compatibility
- No breaking changes
- No API changes
- No route changes
- No database schema changes
- No configuration changes
- Direct upgrade from v0.5.1 with no migration required
Repository
- Clean source tree established
- Build artifacts, temporary reports, and IDE metadata removed
- Existing BZOD Git history preserved
- Refactoring baseline merged with existing history
BZOD v0.5.1 — Namespace Integrity & Platform Hardening
Release Date: 2026-06-20
BZOD v0.5.1 focuses on platform integrity, multi-tenant safety, dashboard parity, QR reliability, and upgrade validation.
While v0.5.0 introduced the multi-user architecture, v0.5.1 strengthens the foundations required for safe operation at scale.
Highlights
Runtime Efficiency (v0.5.1)
| Metric | Value |
|---|---|
| Binary Size | 11 MB |
| RSS Memory | 11.8 MB |
| Peak RSS | 11.8 MB |
| CPU Idle | 0.02% |
| Swap Usage | 0 KB |
| PIDs | 7 |
On a typical 32 GB server:
- Memory usage: ~0.04%
- No swapping
- Plenty of headroom
BZOD runs closer to a lightweight infrastructure service than a typical web application.
Global Slug Registry
Introduced a hardened global slug registry to guarantee namespace integrity across the entire platform.
The following resources can no longer share the same slug:
- Administrator URLs
- Administrator Landing Pages
- User URLs
- User Landing Pages
Duplicate namespace conflicts are automatically detected and blocked.
Namespace Integrity Validation
New validation routines now verify:
- Duplicate slug detection
- Missing ownership records
- Invalid registry entries
- Invalid target types
- Orphaned slug references
Namespace conflicts now abort upgrades and restores before corruption can occur.
Reservation-Based Slug Allocation
BZOD now reserves slugs before content creation.
Creation workflow:
Quota Check
↓
Reserve Global Slug
↓
Create Content
↓
Activate Slug
↓
Increment Quota
↓
Audit Log
Benefits:
- Prevents race conditions
- Prevents duplicate creation under concurrency
- Enables safer rollback handling
Stale Reservation Recovery
Added automatic cleanup of abandoned slug reservations.
Scenarios covered:
- Server crash during creation
- Interrupted writes
- Failed transactions
BZOD now automatically recovers stale reservations during startup.
Dashboard Parity
Administrator and Standard User dashboards now provide equivalent functionality where appropriate.
Added parity validation for:
- URL management
- Landing page management
- Analytics
- QR code previews
- Export functionality
Differences remain only for administrator-specific operations.
Unified Analytics Templates
Removed duplicated analytics templates.
Benefits:
- Consistent rendering
- Reduced maintenance burden
- Improved reliability
Administrator and user analytics now share the same rendering logic.
QR Code Improvements
QR functionality was substantially improved.
Added
- Inline QR previews
- PNG downloads
- SVG downloads
- Shared QR rendering component
Fixed
- Landing page QR generation
- Multi-user QR ownership handling
- QR routing consistency
- Content-type validation
Canonical Landing Page Routing
Landing page slugs now redirect permanently to canonical page URLs.
Example:
/landing-page
redirects to:
/p/landing-page
using:
301 Moved Permanently
This improves consistency and SEO behavior.
Ownership Isolation Hardening
Additional protections ensure:
- Users cannot access another user's analytics
- Users cannot export another user's data
- Users cannot manage another user's resources
New ownership validation tests were added.
Backup & Restore Improvements
Restore operations now validate namespace integrity before importing data.
Benefits:
- No silent slug collisions
- No partial restores
- No hidden ownership conflicts
Restore operations fail safely when conflicts are detected.
Upgrade Validation Enhancements
Upgrade workflows now verify:
- Global namespace consistency
- Duplicate slug conflicts
- Registry integrity
- Tenant ownership correctness
Unsafe upgrades are blocked automatically.
Health & Diagnostics
The system health subsystem now validates:
- Global slug registry integrity
- Namespace conflicts
- Ownership consistency
- Stale reservations
This improves operational visibility and troubleshooting.
Testing & Validation
BZOD v0.5.1 passed:
- Formatting validation (
cargo fmt --check) - Static analysis (
cargo clippy --all-targets -- -D warnings) - Full automated test suite
- Namespace integrity tests
- Ownership isolation tests
- QR endpoint tests
- Dashboard parity tests
- Upgrade validation tests
- Backup & restore tests
- Disaster recovery tests
- Security tests
- Concurrency tests
All automated tests pass successfully.
Upgrade Notes
Administrators upgrading from v0.5.0 should review:
- UPGRADE.md
- MULTI_USER.md
- BACKUP_RESTORE.md
- DATABASES.md
- TESTING.md
BZOD will automatically validate namespace integrity before completing upgrades.
Duplicate slugs that previously existed across users or resource types must be resolved before migration can proceed.
Breaking Changes
Global Namespace Enforcement
Slugs are now globally unique across the entire platform.
Configurations that previously relied on duplicate slugs across users or resource types will be rejected during upgrade.
This behavior is intentional and protects routing integrity.
Summary
BZOD v0.5.1 is an integrity-focused release that significantly strengthens:
- Namespace safety
- Multi-tenant isolation
- Dashboard consistency
- QR reliability
- Restore safety
- Upgrade safety
- Operational diagnostics
The result is a more predictable, recoverable, and production-ready platform.