Tags give the ability to mark specific points in history as being important
-
v1.27.3
36d24661 · ·Tp-Note v1.27.3 -- Nested Projects, One Configuration Chain Project configuration files can now cascade. Until this release, every tpnote.toml found while searching upward from a note's directory lived in isolation -- each one either was the whole story or replaced whatever came before it. Now a project configuration file can opt in to inherit the one above it, chaining across as many nested directories as you like, while a separate setting decides independently where the document root itself sits. Picture a consultancy that keeps every client engagement under ~/clients/. A single tpnote.toml at the top defines the firm's house templates and note scheme once. Each client folder below it -- ~/clients/acme/, ~/clients/initech/ -- adds a one-line tpnote.toml that sets merge_parent_config = true to inherit those house defaults, while is_root_path_marker (true by default) still fixes its own document root, so the viewer never wanders out of one client's notes into another's. Change the house template once at the top and every client engagement picks it up automatically; override a single field inside one client's folder and only that client sees the difference. See the man page's CUSTOMIZATION section for the full mechanics, worked through with a similar nested-directory example. Breaking changes: - TPNOTE_CONFIG now overrides the user configuration file path instead of adding an extra merge layer between /etc and the user config. Previously an existing ~/.config/tpnote/tpnote.toml could silently win over an explicitly set TPNOTE_CONFIG; now only one of the two is ever read. - Removed the old behavior of renaming/disabling the configuration file after a load or version-mismatch error. An incompatible or invalid configuration file is now skipped (or, for the whole file, ignored) and Tp-Note continues with the rest of the merged configuration -- the file itself is left untouched on disk. - tpnote-lib: Context::from() and WorkflowBuilder::new() now require an explicit root_path: PathBuf argument; the library no longer discovers its own document root. Update call sites accordingly. Security: - A project configuration file (a tpnote.toml found by searching upward from the note's directory) can no longer set [app_args] -- the editor, editor console, and browser launch commands. Such a file can live in a directory you do not control (a cloned repository, an extracted archive, a synced folder), and those settings reach Command::new() with no sanitization, so merely opening a note below one could previously launch an attacker-chosen program. Tp-Note now always strips [app_args] from a project configuration file before merging it and logs a warning (exit status 5); every other setting in the file still applies normally. System and user configuration files, and a --config override, are unaffected. Features: - A project configuration file can now set the two root-level variables is_root_path_marker (default true) and merge_parent_config (default false), letting a project chain multiple configuration files across nested directories and/or move the document root independently of how far the configuration search extends. Being root-level variables, they must appear before the file's first [table] header. See the man page's CUSTOMIZATION section for worked examples. - A single bad configuration file no longer discards the whole merged configuration: only that file is skipped, with the rest of the chain (defaults, /etc, user config, other project configuration files) still applied. Exit status: - Exit status 5 is now returned whenever any sourced configuration file was invalid, unreadable, skipped, or below the minimum required version -- in addition to the existing case of `--config-defaults` failing to write. Tp-Note still runs to completion in this case (editor, viewer, export all still happen); exit status 1 (note processing failure) takes precedence over 5 if both occur. Fixes: - `--version`'s searched_config_file_paths now lists every directory actually walked while searching for a project configuration file, including ones where none was found, instead of silently omitting them and looking complete when it wasn't. sourced_config_files is unchanged (still only the files that actually got merged). - A typo inside a config table (e.g. `[arg_default] yscheme` instead of `scheme`, or `[viewer] xsame_user_policy` instead of `same_user_policy`) was silently ignored. Unknown fields nested inside a config table are now rejected the same way an unrecognized top-level key already was: skip-with-warning / exit status 5. Performance: - The upward project configuration file search now runs at most once per process instead of being repeated for the same directory. Docs: - Rewrote the man page's CUSTOMIZATION section with worked examples for the new project configuration file chain, and its Security note to describe the [app_args] restriction above. - Updated the README's "Upgrading" section and the manual's troubleshooting section to describe the current skip-and-continue behavior instead of the removed rename-and-disable behavior. - Added Weasyprint per-note page layout and page-break examples to the man page. Dependencies: - Update tpnote-lib to 0.47.0. - Routine dependency refresh: thiserror 2.0.20 -> 2.0.21, wl-clipboard-rs 0.9.3 -> 0.9.4, notify-rust 4.18.0 -> 4.18.1, yoke-derive 0.8.3 -> 0.8.4, and other transitive patch/minor bumps.
-
v1.27.2
1a8de1e9 · ·v1.27.2 Tp-Note v1.27.2 Breaking config change: - viewer.same_user_policy: the value "Reject" is renamed to "Enforce"; an existing tpnote.toml using "Reject" now fails to parse and must be updated. The field name, the "Off" value, and the feature itself are unchanged. Features: - Auto-generate heading ids (tmpl_html.auto_heading_ids) so a table of contents or cross-reference works without hand-written anchors, and the same note keeps navigating correctly when rendered by GitHub or GitLab instead of Tp-Note. Selectable slug algorithm: "Gfm" (default, matches GitHub/GitLab), "Pandoc" (matches Pandoc's auto_identifiers), or "Off". An explicit {#id} always wins. Fixes: - Same-document fragment links (#ch1) are now rebased onto the note's directory correctly, instead of being treated as a filename and concatenated onto the note's directory, which broke --export-link-rewriting=short|long and could 404 or silently swap documents in the viewer. Viewer: - Merge the two peer-rejection 403 pages (different OS user vs. undeterminable OS user) into one, naming both peer and local users and offering the two remedies (a non-sandboxed browser, or disabling same_user_policy) inline. - Log the 403 refusal reason before writing the response, not after, so it isn't lost when the peer already dropped the connection. - Relax the default viewer.displayed_tpnote_count_max from 20 to 1000, now that the viewer also binds to the first browser, checks the Host header, and checks the peer OS user. Config: - Drop Flatpak browsers from the default fallback-browser list (they are sandboxed and fail the same-user check by default); documented as a manual opt-in example instead. Dependencies: - Update tpnote-lib to 0.46.9. Docs: - Remove stale NetBSD/pkgsrc install instructions. - Separate Nix cross build instructions from the standard rustup/cargo build; mention the Windows MSI packaging script. -
v1.27.1
64cd61ec · ·Tp-Note v1.27.1 Fixes: - Percent-encode local links (viewer and --export) so '#', '?', and spaces in path segments survive; a directory or file name containing '#' no longer 404s in the viewer. - Strip Nix store RPATH and patch the ELF interpreter so the x86_64 .deb, GNU tar.gz, and ARM (aarch64/armv7l) cross-compiled binaries run on non-Nix systems. Dependencies: - Switch syntect to the pure-Rust fancy-regex backend. - Update tpnote-lib to 0.46.8 and tpnote-html2md to 0.3.10, including an html5ever/markup5ever 0.40 upgrade. - Routine dependency updates across the workspace. Tests: - tests/multi-user: add TPNOTE_TEST_BIN override to test an installed binary. Docs: - Manual, flake, and README updates.
-
v1.27.0
18f29f2a · ·Tp-Note's built-in viewer serves your note over a `localhost` HTTP server so your browser can live-preview it. On a shared machine that port is reachable by every logged-in user. This release adds two **on-by-default** protections, applied in the order a connection meets them — first *who* is connecting, then binding the session to *your* browser — plus routine dependency and toolchain updates. **New — OS-user isolation (`viewer.same_user_policy`, default `"Reject"`).** When a connection arrives while the viewer is establishing the session, it checks the OS user owning the connecting process and refuses one it cannot prove belongs to you — keeping other logged-in users out from the start. Trade-off: a client the viewer cannot attribute — some sandboxed Flatpak/Snap browsers — is also refused by default and shown a page telling it to set `same_user_policy = "Off"`. **New — session-cookie binding + `Host` check (`viewer.session_binding_cookie`, default `true`).** Once your browser is the first to load the note, the viewer binds the session to it with a random `HttpOnly; SameSite=Lax` cookie; from then on every request must present that cookie, and requests carrying a foreign `Host` header are refused (DNS-rebinding defense). This blocks a hostile web page open in your own browser from reading the note. A browser configured to refuse `localhost` cookies is refused and shown a page explaining the fix — or set `session_binding_cookie = false`. **New Cargo feature `same-user-policy`** (in the default set). Build `--no-default-features` without it to drop the peer-UID check and its `netstat2` / `sysinfo` dependencies. **On upgrade:** both options ship enabled. The config-file version is tied to the release version, so your existing config is backed up and regenerated with the new defaults on first run — the protections take effect automatically. If a sandboxed or cookie-averse browser is refused, the page it is shown names the option to relax. **Build requirement:** the minimum supported Rust version is now **1.95** (raised from 1.91.1), pulled in by updated dependencies (`sysinfo` 0.39, `netstat2` 0.11.2, `tera` 2.1, `clap` 4.6.4, …). Building from source or `cargo install` now needs rustc ≥ 1.95. Both controls concern only *local* users; Tp-Note never exposes anything to the network or the Internet. **Flatpak / Snap browser users — please note.** If your browser runs in a Flatpak or Snap sandbox and the viewer shows a "403 — access refused" page instead of your note, that is the OS-user check: the sandbox hides the browser's process from the viewer, so it cannot confirm the connection belongs to you and refuses it by default. Allow it by adding this to your configuration file and restarting Tp-Note: ```toml [viewer] same_user_policy = "Off" ``` Trade-off: with `"Off"` the viewer no longer verifies the connecting OS user. Session-cookie binding stays on, though, so another local user could read your note only by winning the race to claim the session **before your browser does**, in the brief start-up window — and even then you would notice, because your own browser would be locked out and shown an error page instead of the note. Once your browser has bound the session and the note is displayed, the cookie keeps other users out. This trade-off is a concern only if you set `same_user_policy = "Off"`; with the default (`"Reject"`) you are protected anyway.
-
v1.26.7
c3a23561 · ·Tp-Note v1.26.7 A feature release adding inline Mermaid diagrams and LaTeX math to the HTML rendition, governed by a new embedded-content error policy, plus routine dependency upgrades. - Mermaid code blocks are now rendered to inline SVG in both the viewer and the exporter (new `mermaid` build feature, listed in `tpnote --version`). - LaTeX math formulas are rendered to MathML behind a new `latex` build feature. - New embedded-content error policy (`Inline` / `HardError`) controls how a failed Mermaid diagram or LaTeX formula is handled: rendered inline as an error box (viewer default), or aborting the export in batch mode (`tpnote -x . -b`, which always uses `HardError`), so a broken embed can never slip silently into an exported HTML or PDF. - Worked around a label auto-wrapping defect in the Mermaid renderer so multi-line node labels are sized and their edges routed correctly. - Added vertical spacing to rendered content tables for readability. - Upgraded compatible dependencies. - Published crates: tpnote-lib 0.46.6, tpnote 1.26.7 (tpnote-html2md unchanged at 0.3.9). Installers and standalone binaries for Windows, macOS, Linux and Debian/Ubuntu are attached below.
-
v1.26.6
ff3de1ea · ·Tp-Note v1.26.6 A bugfix release centred on the file-annotation templates, plus routine dependency upgrades. - Piped front matter now passes through when annotating a file: a YAML header supplied on stdin or the clipboard can override title, subtitle/keywords, author, date and sort_tag, and any extra fields are preserved in the new note's header (default and zettel schemes). - Fixed a crash ("value must be a string") when annotating files whose stem contains no '--' subtitle separator: out-of-bounds nth() returns None, which default() now substitutes (boolean=true). - Removed fragile trunc calls from pipelines whose values are not guaranteed to be strings. - Fixed a whitespace-trim bug in the zettel scheme that glued the closing '---' header marker to the last field when no front matter was piped, leaving the YAML header unterminated. - Upgraded compatible dependencies. - Published crates: tpnote-html2md 0.3.9, tpnote-lib 0.46.5, tpnote 1.26.6. Installers and standalone binaries for Windows, macOS, Linux and Debian/Ubuntu are attached below. -
v1.26.5
ed3008e7 · ·Tp-Note v1.26.5 This is a maintenance and infrastructure release focused on improving the build system and distribution process. - Added unified complete-build CI pipeline with flat, standard-named release assets - Hardened build scripts with robust artifact copy and documentation cleanup - Updated MSI download URL in winget package script to point to GitHub releases - Refactored distribution section and consolidated documentation - Moved winget distribution guide into script preamble for better maintainability Available as installers and standalone binaries for Windows, macOS, Linux, and Debian/Ubuntu at https://github.com/getreu/tp-note/releases/tag/v1.26.5
-
v1.26.4
2c7ef3bc · ·Clipboard front matter carries over when annotating files - New: input YAML header overrides the note header in file-annotation mode — when annotating a non-Tp-Note file (e.g. `tpnote report.pdf`), a YAML header supplied through the clipboard or stdin now populates the new note's `title:`, `author:` and `date:` fields (and `keywords:` under the `zettel` scheme) instead of always deriving them from the filename, the username and the current date. Missing fields fall back to those previous defaults, so behaviour is unchanged when no header is supplied. Because the title is taken from the header, the new note's filename follows it as well. - Maintenance: upgraded compatible dependencies (clipboard-rs 0.3.5, time 0.3.53, html-escape 0.2.14); bumped tpnote-lib to v0.46.3.
-
v1.26.3
1b5c14e5 · ·Graceful clipboard handling and timezone-correct dates - Fix: invalid YAML header in clipboard/stdin treated as body — when the clipboard or stdin stream contains syntactically invalid YAML between --- delimiters, Tp-Note no longer aborts with an error. Instead a warning is logged and the entire input is treated as plain body text, so note creation continues normally. - Fix: note filenames use local date instead of UTC — the date filter previously computed dates from the Unix epoch in UTC, causing wrong dates in filenames for users in timezones east of UTC (e.g. a note created at 02:00 EEST was dated the previous day). Dates now reflect the local timezone. This regression was introduced with v1.26.2.
-
v1.26.2
821b5646 · ·New feature: Plain Markdown Viewer and Editor Tp-Note is now a versatile viewer and editor for **any Markdown file**, not just Tp-Note-formatted files with YAML headers. This makes Tp-Note a practical tool for working with standard Markdown documents across your file system. **Key capability:** By default, when you open a plain Markdown file without a YAML front matter header, Tp-Note opens it directly for viewing and editing **without modifying the file**. No automatic header injection, no filename changes—just clean viewing and editing. **Usage:** - **View only:** `tpnote --view myfile.md` - **Edit and view:** `tpnote myfile.md` - **Convert to Tp-Note file:** `tpnote --add-header myfile.md` (prepends YAML header, enables filename synchronization) The `--add-header` flag now defaults to **disabled** (`arg_default.add_header = false`). This means: - Plain Markdown files are opened as-is without automatic header prepending - To convert a plain Markdown file into a full Tp-Note note with YAML metadata, explicitly pass `--add-header` - Existing Tp-Note files (with YAML headers) continue to work unchanged—header synchronization and filename updates happen automatically
-
v1.26.0
d33c5c01 · ·This release ships a fix for a "too many headers" regression The regression appeared when notes were viewed with some recent versions of Firefox/LibreWolf. The SSE view updating code failed because the browser sent too many HTTP headers for Tp-Note's internal buffer. This buffer has been increased in this release. The HTML to Markdown filter now parses language tags for programming languages in code listings in some circumstances.
-
v1.25.19
90c03908 · ·Enable more languages for language detection The `lingua` crate v1.8.0 detects language much faster than before, but requires 3 times as much disk space in the Tp-Note binary. Therefor, this release: * Ships approximately the language detection data for only half of the 77 available languages (see `features` for the `lingua` crate in `Cargo.toml`). * Enables by default all available languages as search candidates. (Can be configured with `filter.get_lang.language_candidates`, e.g. `filter.get_lang.language_candidates = [ "en", "fr", "de" ]`).
-
v1.25.17
ebc1818f · ·Reduce false positives in natural language detection. This release filters URLs in texts with markup before passing it to the Lingua crate. Before, URLs were often recognized as one of the configure natural languages. There are no changes in the configuration or the templates. Just the `get_lang()` filter got a little smarter. Now, it can even launch multiple threads from a thread pool with the help of the Rayon crate. This reduces Tp-Note's startup time when creating new, very large notes.
-
v1.25.15
8ccd5bbd · ·Publish a Tp-Note installer package for Windows 11 This release upgrades the Windows installer tool chain. The published Windows installer package (`tpnote-1.25.15-x86_64.msi`) is tested with Windows 11 and is probably the first working Tp-Note installer package for this Windows version. The new installer also sets sub-entries to the context menu that appears when you right-click on a file, a directory, the desktop or on the file explorer's background. First, click on "Show more options" and then on one of the following: "New Tp-Note", "Open", "View Tp-Note" or "Export Tp-Note".
-
v1.25.13
88839719 · ·Improve interchangeability between operating systems This release filters the Windows `\r` (carriage return) of all input streams for internal processing. Under Windows, new notes are still written with `\r\n` as newline characters. The Git configuration of Tp-Note's repository is adjusted to use exclusively `\n` for all platforms. This fixes a minor bug introduced with v1.25.12 (commit 3b5564e, upgrade of the `toml` crate). This bug only concerned Windows builds.