Release notes
What has changed in CC Editor, newest first.
1.2.0
11 August 2026Choose how you appear to others, and page tabs in the editor.
- Added A settings page. You can set an optional moniker — the only thing other people can see about you — and turn on anonymity, which credits your cards to "Anonymous" while keeping the moniker for later. Your email address is never shown to other users, whatever you choose.
- Added Page tabs above the card in the editor, alongside the existing side list. Both select the same page, so you can use whichever is nearer.
- Changed Cards are now credited using your moniker rather than your account name. Anyone who has not set one is shown as "Anonymous", so nobody is identified by accident.
1.1.0
11 August 2026Proper privacy and terms documents, and a tidier footer.
- Changed Replaced the placeholder privacy and terms text with full documents: fifteen numbered sections each, covering UK GDPR legal bases, data retention, your rights, complaints to the ICO, and governing law. Both make clear that convention cards are public and that your email address is never shown to other users.
- Changed Reorganised the footer: copyright and the legal links on the left, Home, Help, About and Feedback as buttons on the right.
- Fixed Sign-in emails now always include a contact address. Previously the address was omitted unless configured, which is exactly what somebody who did not request a code needs to see.
1.0.0
11 August 2026Ready for real use. Adds the pages around the editor, a storage allowance, tools to run the site, and a way to tell us what is broken.
- Added About, Help, Privacy and Terms pages, reachable from a new site footer. The terms and privacy notice are linked from the sign-in page, where the account is actually created.
- Added A feedback page for reporting bugs and suggesting improvements. You do not need to be signed in, and leaving an email address is optional.
- Added These release notes, at /releases.
- Added A 5 MB storage allowance per user, covering all your cards and their system notes. Usage appears on the My Cards page once you pass halfway. Saves that would exceed it are refused with an explanation, and shrinking or deleting a card always works even when you are over.
- Fixed A card too large to send now says so. Previously an oversized save reported "expected a JSON body" — as though the card were corrupt — and an oversized PDF request quietly printed the last saved version instead of what was on screen. Both now explain the real problem.
- Fixed A failed save no longer disappears after three seconds. When a save cannot succeed on its own, the warning stays on screen until you act, instead of flickering past while you keep typing.
- Security Rate-limited the sign-in endpoints. Requesting a code is capped at 3 per minute per IP, closing an unbounded outbound-email path that could have been used to spend the mail quota or bombard an address.
- Security Rate-limited PDF rendering to 10 per minute per IP and capped a single card at 1 MB. Rendering is the most expensive thing the server does and is open to everyone, so it was the cheapest way to burn CPU anonymously.
- Security Set the trusted origin explicitly rather than relying on a default, so a misconfigured site address cannot silently trust the wrong one.
- Added Admin area with site statistics, a searchable user list, and the ability to ban and unban accounts. Admins are named in an environment variable, never in the database, so admin rights cannot be granted by a database write.
- Added Admin system settings that take effect without a redeploy: the default storage allowance, the maximum size of one card, whether new sign-ups are open, and a site-wide notice banner. Individual users can be given their own storage allowance.
- Changed Deployment now builds a Docker image and ships it to the server automatically on a tagged release, with its own database.
0.1.0
10 August 2026First working editor, and the pipeline to ship it.
- Added Convention card editor for the EBU 20B and WBF card variants, with click-to-edit fields on the real artwork.
- Added System notes in Markdown, with bridge notation and KaTeX support.
- Added Server-side PDF export, rendered fresh on every request.
- Added Public card browsing and forking.
- Added Passwordless sign-in by six-digit emailed code.
- Added Installable on a phone home screen: web manifest, icon set and theme colour.
- Added CI on every push (lint, type check, tests, secret scan) and a Docker build and deploy pipeline.
- Fixed Missing favicon, manifest and app icons that were referenced but had never been created.