Skip to content

dawarich

v1.9.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Privacy & Ad-blocking
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

google-maps gpslogger self-hosted maps memory owntracks
+1 more
timeline

Summary

AI summary

Trip photos now appear on Map v2 trip/replay views with privacy masking, duplicate visit suggestions are prevented, notes migration fixes content errors, and reverse geocoding always uses HTTPS.

Full changelog

Added

  • Trip photos now appear on the Map v2 trip and replay views: thumbnails pop in one at a time as the replay playhead reaches each photo's timestamp, and the same photos are available on public shared-trip links. Photos that fall inside one of your privacy zones are masked from both the map and shared links.

Fixed

  • Re-running visit detection no longer creates duplicate suggestions for a visit you already confirmed, even after correcting its address moved the place marker away from the underlying points (#2952)
  • Adding a per-day trip note no longer fails with "Content missing" on instances upgraded from a pre-release build; a migration backfills the notes table columns that an earlier if_not_exists table creation could have skipped (#2987)
  • Reverse geocoding against the hosted photon.dawarich.app (and photon.komoot.io) now always uses HTTPS, even when PHOTON_API_USE_HTTPS is unset or not exactly true, fixing the Geocoder::ResponseParseError caused by Cloudflare's HTTP→HTTPS redirect (#2982)

💙 This release is supported by Steven B., James Manolios, chenrik, aldumil, derpderpington, Chippie, dint, jhalpern, Lex Fradski, Schlufo, cyberswan.at, craftyklaus, Andre, hogenf, naraxius, Embrace, martin4861, Alex, evetters, GregF, Jon Coffee, Lukas, Robbie G, Kilian, Hans G, Chris, tabaha, Andre, Michael C, Chris, Jonah B., Dante, daallex, Tanner A., Milien M., Mathias, Travis S., Matthew F., Johnathan D., bleibdirtroy, no1etal, dixet, Bailey J., Alex D., Benjamin M., Daniel A., Florian, BeeHappy, ChemistryDachshund, OrangeWindies, Michelangelo V., Edward, Erazem Z., Denis Abt, Tony G., Andrew D., Lomky, Osamu Y., Linus T., Christian C., Sebastian, Jan K., Nathan T., Max G., Lars N., Karol B., Konstantin, Johannes H., t3hero, g3lin, Tim, Philipp M., Brand K., Pablo F. M., Jon H., fkB, Mikael, Dániel A., Hai_Tsung, ShooTex, GreenTentacle, PinkahPandah, David, Ken, Denna G., Andre, Hendl91, Jon H., MrRed, Arkadiusz Z., Jake, Bator T., Alex J. H., eps-dev, twiggu, Dragan V., Jerome G., Sheya B., ArnyminerZ, Gustav B., higgs01, Frank F., F. J. Kruz, Jon D., Alexander J. H., Daniel D., Gonzalo M., Ricardo T., Christof Z., Narrator, JohnSmith21, smartbert, A.M., Matthew Z., Dror T., Jonathan K., Henrik H., Kyle C., Mario B., Albin H., Phillip S., Bernd, Tom, Brett J., Nick O., greeting7416, Dick, Brian R., Henning, Markus, TheSlimShady, Andrew M., Peter D., Mkpenguin, Mason B., Chance, GoogilyBoogily, Dragon, Oliver, HexitNiels, Michael G., Pablo A., on Patreon and KoFi 💙


What's Changed

  • 1.9.1 by @Freika in https://github.com/Freika/dawarich/pull/3001

Full Changelog: https://github.com/Freika/dawarich/compare/1.9.0...1.9.1

Security Fixes

  • Reverse geocoding against photon.dawarich.app and photon.komoot.io now always uses HTTPS, preventing ResponseParseError caused by Cloudflare HTTP→HTTPS redirect

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track dawarich

Get notified when new releases ship.

Sign up free

About dawarich

Your favorite self-hostable alternative to Google Timeline (Google Location History)

All releases →

Related context

Earlier breaking changes

  • v1.10.1 Drops legacy `latitude`/`longitude` columns on `points`; migrates to single `lonlat` column.
  • v1.8.0 Changes declining a visit to delete the visit entirely; removes "Declined" filter and Restore action.
  • v1.7.9 Place deletion no longer deletes visits; sets dependent: :nullify.
  • v1.7.9 Visit detection creates one Place per visit, not 25 candidates.
  • v1.7.8 Places without linked visits are permanently deleted during ownership migration.

Beta — feedback welcome: [email protected]