This release includes 1 breaking change for platform teams planning a safe upgrade.
Published 18d
Media Servers
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
calibre
ebook
ebook-manager
epub
Affected surfaces
auth
Summary
AI summaryUpdates Highlights, Breaking API changes, and Internal across a mixed release.
Full changelog
Highlights
- Web login now works over plain HTTP (e.g.
http://<nas-ip>:8080). Auth cookies were always markedSecure, which browsers reject on non-HTTPS origins — typical LAN deployments couldn't log in at all. TheSecureflag now follows the request scheme, and bundled nginx preservesX-Forwarded-Protofrom any TLS-terminating proxy, so HTTPS deployments keep the hardened cookies exactly as before. - Move books between libraries (admin): new "Move to library" action in the book detail menu, backed by an explicit
PUT /api/books/{id}/library. Books that are part of a Work or managed by a Calibre sync cannot move. - App version on the profile page — no longer buried in admin settings.
Fixes
- Files that are not valid EPUBs are rejected with a 400 instead of being accepted as broken, title-less books.
- Demo mode: the shared demo account can no longer change its username (password was already blocked), and the profile page hides both controls for it.
- Unknown book ids on library membership endpoints return 404 instead of a 500.
Breaking API changes
POST /api/libraries/{id}/booksandDELETE /api/libraries/{id}/books/{book_id}are removed. Under the one-library-per-book model they dead-ended each other and no sequence of calls could move a book. UsePUT /api/books/{book_id}/libraryinstead.
Internal
- New real-service integration test layer (FastAPI against real Postgres + Redis, EPUB factory fixtures) and Playwright e2e suite (full docker stack, including a vertical-rl rendering regression test) — both run in CI.
Breaking Changes
- Removed `POST /api/libraries/{id}/books` and `DELETE /api/libraries/{id}/books/{book_id}` endpoints; use `PUT /api/books/{book_id}/library` instead.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About BeePub
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]