Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
63 commits
Select commit Hold shift + click to select a range
2cd8d0e
1.1.1 - Update `supportsTellraw` logic to support several possible ve…
WillTDA Jul 26, 2026
2d06db2
Bump better-sqlite3 from 13.0.1 to 13.0.2
dependabot[bot] Aug 1, 2026
b81b9d0
Bump express-rate-limit from 8.6.0 to 8.6.1
dependabot[bot] Aug 1, 2026
a2ba825
Bump sharp from 0.34.5 to 0.35.3
dependabot[bot] Aug 1, 2026
3bf07d7
Merge pull request #55 from diamonddigitaldev/dependabot/npm_and_yarn…
WillTDA Aug 3, 2026
573ab42
Merge pull request #54 from diamonddigitaldev/dependabot/npm_and_yarn…
WillTDA Aug 3, 2026
3457017
Merge pull request #53 from diamonddigitaldev/dependabot/npm_and_yarn…
WillTDA Aug 3, 2026
5b4e5fe
Document unlisted status page access as intentional (#58)
WillTDA Aug 3, 2026
6e78e53
Show absolute timestamp alongside relative age in the event log
WillTDA Aug 3, 2026
6f693e0
Lock upload modal inputs while a .mrpack or .cbx is uploading (#59)
WillTDA Aug 3, 2026
6d10bcf
Explain and recover from session expiry instead of an "unauthorized" …
WillTDA Aug 3, 2026
5fea21c
Block backups and management pages while a server is provisioning (#56)
WillTDA Aug 3, 2026
c25b30e
Fix Update Jar for imported and modpack-created servers (#60)
WillTDA Aug 3, 2026
005da39
Add API endpoints to read the mod/plugin list and environment map (#51)
WillTDA Aug 3, 2026
d2df3f9
Add file read/download endpoints and move export under /api/v1 (#57)
WillTDA Aug 3, 2026
dd1cd27
Release 1.1.1
WillTDA Aug 3, 2026
fba3921
Update `allowScripts`
WillTDA Aug 3, 2026
b42d709
Close the power-action race during a server restart
WillTDA Aug 3, 2026
58a2bcc
Track live server state in controls that require a stopped server
WillTDA Aug 3, 2026
588ecd6
Update the event log live over WebSocket
WillTDA Aug 3, 2026
f06faab
Add an API endpoint to read console output
WillTDA Aug 3, 2026
fc054e3
Promote release to 1.2.0-beta.1
WillTDA Aug 3, 2026
31b7942
Add file upload, rename and delete to the Files page
WillTDA Aug 4, 2026
68b7213
Stop a mod being listed twice when a disabled twin is left on disk
WillTDA Aug 4, 2026
3ba9ec8
Add a manual test checklist for the 1.2.0 betas
WillTDA Aug 4, 2026
ed786af
Promote release to 1.2.0-beta.2
WillTDA Aug 4, 2026
94e6858
Align action icons to right instead of center
WillTDA Aug 4, 2026
e38011e
Gate the new modals' confirm button on a valid name
WillTDA Aug 4, 2026
a2630ee
Fix the three issues found in the beta test pass
WillTDA Aug 4, 2026
a5f2daf
Promote release to 1.2.0-beta.3
WillTDA Aug 4, 2026
7d5c804
Stop a deferred backup still running after a Craftbox restart
WillTDA Aug 4, 2026
e81093b
Promote release to 1.2.0-beta.4
WillTDA Aug 4, 2026
5df7a7f
Add a New Text File button to the Files page
WillTDA Aug 6, 2026
3968cd5
Quote the destination folder in the create modals
WillTDA Aug 6, 2026
b8cb9b8
Send the server back button to its group page
WillTDA Aug 6, 2026
bac2b12
Centre the Assign Group field on the Settings page
WillTDA Aug 6, 2026
496e471
Rewrite the test checklist for 1.2.0-beta.5
WillTDA Aug 6, 2026
f628d3b
Promote release to 1.2.0-beta.5
WillTDA Aug 6, 2026
c7e2a58
Share the lone-row centring between the create and settings forms
WillTDA Aug 6, 2026
dcb6948
Add the create-page regression checks to the checklist
WillTDA Aug 6, 2026
3c82300
Run NPM audit fix
WillTDA Aug 16, 2026
09329d6
Decide text files by content instead of extension
WillTDA Aug 16, 2026
0484d36
Add the text file detection checks to the checklist
WillTDA Aug 16, 2026
27bc76c
Promote release to 1.2.0-beta.6
WillTDA Aug 16, 2026
e8fc292
Restore the cross-platform entries to the lockfile
WillTDA Aug 16, 2026
81f422d
Reject a typed name that is not a single path segment
WillTDA Aug 16, 2026
a337961
Record the beta.6 test pass in the checklist
WillTDA Aug 16, 2026
9ec22b7
Promote release to 1.2.0-beta.7
WillTDA Aug 16, 2026
d8405ec
Target the newest build for every loader
WillTDA Aug 26, 2026
b61a6c5
Give every download a real size and a reported outcome
WillTDA Aug 26, 2026
4032f1f
Update dependencies
WillTDA Aug 26, 2026
0b87c37
Say in the export panel that the archive is packed first
WillTDA Aug 26, 2026
7ef2a4c
Promote release to 1.2.0-beta.8
WillTDA Aug 26, 2026
81d467c
Drop the file toolbar's create buttons to a second row on narrow screens
WillTDA Aug 27, 2026
d4850e9
Give every download in flight its own frame
WillTDA Aug 27, 2026
889fd3f
Record the beta.8 test pass in the checklist
WillTDA Aug 27, 2026
ff1162c
Promote release to 1.2.0-beta.9
WillTDA Aug 27, 2026
357f217
docs: link AI Transparency & Quality Commitment statement
WillTDA Aug 27, 2026
909d158
Refuse a dropped folder instead of failing the upload
WillTDA Aug 28, 2026
9257b30
Promote release to 1.2.0-beta.10
WillTDA Aug 28, 2026
3ae7ede
Guard every page against a stray file drop
WillTDA Aug 28, 2026
a416314
Carry the advertised IP and group color through an export
WillTDA Aug 31, 2026
77119b6
Promote release to 1.2.0-beta.11
WillTDA Aug 31, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 2 additions & 20 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
<div align="center">

![license](https://img.shields.io/badge/license-AGPL--3.0-blue?style=flat-square)
![version](https://img.shields.io/badge/version-1.1.0-brightgreen?style=flat-square)
![version](https://img.shields.io/badge/version-1.2.0--beta.11-orange?style=flat-square)
![docker](https://img.shields.io/badge/docker-supported-blue?style=flat-square)

[![discord](https://img.shields.io/discord/667479986214666272?logo=discord&logoColor=white&style=flat-square)](https://diamonddigital.dev/discord)
Expand Down Expand Up @@ -157,25 +157,7 @@ This project is licensed under the [GNU Affero General Public License v3.0](./LI

### AI Disclosure

This project uses AI tools to aid development.

AI is used to:
- Plan significant changes
- Implement initial passes of new features
- Perform security audits (alongside human review)
- Fix bugs and patch security vulnerabilities
- Review pull requests (alongside human review)

AI is NOT used to:
- Design UI/UX
- Design visual assets (such as bitmap and vector graphics)
- Triage issues
- Decide project direction
- Create release information

AI has a tendency to hallucinate/produce plausible but suboptimal, inaccurate or misleading solutions to delegated tasks.

Every commit is manually reviewed and approved by a member of Diamond Digital Development, and testing is carried out to ensure changes work as intended, do not introduce regressions, and meet reliability and security expectations before being merged into the `master` branch.
This project uses AI tools to aid development. Read our [AI Transparency & Quality Commitment](https://diamonddigital.dev/ai-transparency) statement for more information.


## Contact Us
Expand Down
103 changes: 86 additions & 17 deletions docs/API.md

Large diffs are not rendered by default.

355 changes: 197 additions & 158 deletions package-lock.json

Large diffs are not rendered by default.

16 changes: 8 additions & 8 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "craftbox",
"version": "1.1.0",
"version": "1.2.0-beta.11",
"description": "A modern self-hosted platform for managing Minecraft servers with built-in mod support.",
"main": "src/server.js",
"funding": {
Expand Down Expand Up @@ -31,27 +31,27 @@
"dependencies": {
"archiver": "^7.0.1",
"bcrypt": "^6.0.0",
"better-sqlite3": "^13.0.1",
"better-sqlite3": "^13.0.3",
"bootstrap": "^5.3.8",
"chart.js": "^4.5.1",
"content-disposition": "^1.0.1",
"ejs": "^6.0.1",
"express": "^5.2.1",
"express-rate-limit": "^8.6.0",
"express-rate-limit": "^8.6.2",
"express-session": "^1.19.0",
"material-icons": "^1.13.14",
"multer": "^2.1.1",
"node-stream-zip": "^1.16.0",
"passport": "^0.7.0",
"passport-local": "^1.0.0",
"quick.db": "^9.1.7",
"sharp": "^0.34.5",
"uuid": "^14.0.1",
"ws": "^8.21.1"
"sharp": "^0.35.4",
"uuid": "^14.0.2",
"ws": "^8.21.3"
},
"allowScripts": {
"bcrypt@6.0.0": true,
"better-sqlite3@13.0.1": true,
"sharp@0.34.5": true
"better-sqlite3@13.0.3": true,
"sharp@0.35.4": true
}
}
19 changes: 6 additions & 13 deletions public/js/account.js
Original file line number Diff line number Diff line change
@@ -1,6 +1,4 @@
document.addEventListener('DOMContentLoaded', function () {
var csrfToken = document.querySelector('input[name="_csrf"]').value;

// ═══════════════════════════════════════════
// Change Username / Password
// ═══════════════════════════════════════════
Expand Down Expand Up @@ -105,15 +103,11 @@ document.addEventListener('DOMContentLoaded', function () {
showOverlay('Generating key...', 'Please wait while the key is created.');

try {
var res = await fetch('/api/v1/account/apikeys', {
var res = await apiFetch('/api/v1/account/apikeys', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'X-CSRF-Token': csrfToken
},
body: JSON.stringify({ name: name })
body: { name: name }
});
var data = await res.json().catch(function () { return {}; });
var data = res.data || {};
if (!res.ok) {
hideOverlay();
confirmCreateBtn.disabled = false;
Expand Down Expand Up @@ -186,13 +180,12 @@ document.addEventListener('DOMContentLoaded', function () {
showOverlay('Deleting key...', 'Please wait while the key is removed.');

try {
var res = await fetch('/api/v1/account/apikeys/' + encodeURIComponent(pendingDeleteId), {
method: 'DELETE',
headers: { 'X-CSRF-Token': csrfToken }
var res = await apiFetch('/api/v1/account/apikeys/' + encodeURIComponent(pendingDeleteId), {
method: 'DELETE'
});

if (!res.ok && res.status !== 204) {
var data = await res.json().catch(function () { return {}; });
var data = res.data || {};
hideOverlay();
confirmDeleteBtn.disabled = false;
showToast(data.message || data.error || 'Failed to delete key.', 'danger');
Expand Down
Loading
Loading