{
  "version": "1.1.0",
  "unreleased": null,
  "releases": [
    {
      "version": "1.1.0",
      "date": "2026-10-04",
      "title": "Seven-day link expiry, a Halloween theme, a tools page and a real 404",
      "changes": {
        "added": [
          "Every link now expires after seven days and is deleted: the slug, its destination and its click counter. Expiry is set on the stored record and re-checked on every read, so a link past its deadline is gone whether or not the underlying key has been swept yet",
          "expiry dates in the interface. The result panel shows the exact deadline, recent links show days left, and the reveal box says plainly when a slug expired rather than never existing",
          "expiry fields on the API. create, bulk, unshorten, links and export all report expiresAt and expiresInDays",
          "GET /api/sweep deletes anything past seven days and stamps links that predate timestamping, 4 requests a minute. DELETE /api/sweep?slug= removes a single link on request",
          "An expired slug becomes claimable again, so /api/check reports it as free and frees the name for the next person",
          "Halloween theme alongside dark and light. The button in the header cycles all three and the address bar colour follows",
          "New Tools page at /tools/ with a standalone QR generator, a slug inspector that explains which rule failed, a reveal box with local lookup history, and a QR photo reader where the browser supports one",
          "New API reference page at /api/ with a runnable example against the create and unshorten endpoints, plus collapsible detail per route",
          "New About page at /about/ covering how the service is built, what it costs and what it deliberately does not do",
          "Bulk shortening, up to ten links per request with optional per-row custom slugs, and a copy-results button",
          "POST /api/bulk for the same thing over HTTP, 5 requests a minute",
          "GET /api/unshorten to expand any shortn slug back to its destination with its click count, unlimited",
          "GET /api/export for a full dump as JSON or a downloadable CSV, 20 requests a minute",
          "Reveal and copy buttons on every recent link, and email alongside X, WhatsApp and Telegram in the share row",
          "QR codes download as PNG at four sizes or as scalable SVG",
          "Export buttons on the homepage for the whole store",
          "Keyboard shortcuts: slash focuses the URL field, Ctrl or Cmd plus Enter shortens",
          "Shared theme stylesheet and script so every page on both sites runs the same design system",
          "Visible version number in the footer and the API section, read live from /api/version",
          "Changelog auto-generation folds any commits made since the last release into an Unreleased block, grouped into Added, Fixed and Changed"
        ],
        "fixed": [
          "Unknown paths return an honest 404 page instead of quietly rendering the homepage, which made broken links look like working ones",
          "The 404 page checks the store when the missing path looks like a slug and tells you where it actually pointed",
          "Header and footer text on the legal pages was corrupted by a bad character encoding during an earlier edit and has been rewritten",
          "Click counters no longer break on a non-numeric stored value, which previously threw inside the background write",
          "HEAD requests are handled without a body instead of running the full redirect path",
          "Nested paths no longer fall through to the homepage as if they were slugs",
          "Bulk creation matches the single-link path on reserved words, custom slug rules and scheme handling, so the two behave the same way",
          "Expired links are filtered out of /api/links, /api/stats and /api/export, so a public list or a CSV never shows something that would fail to redirect",
          "Links made before timestamping existed are given a real seven-day deadline on first read instead of living for ever, and /api/sweep does the same for the rest in bulk"
        ],
        "changed": [
          "Homepage rebuilt as a two-column layout on desktop with tools and recent links in a sidebar, collapsing to a single column with a sticky action bar on phones",
          "Wider content column and larger touch targets, with tables and code blocks that scroll rather than overflow",
          "Slugs, docs, about and changelog joined the reserved list so a link can never shadow a real page",
          "Redirects send Referrer-Policy: unsafe-url so the destination receives the original referrer, and keep no-store so caches cannot swallow visits",
          "Every endpoint still sends Access-Control-Allow-Origin, and the new ones do too",
          "Documentation rewritten to match the current endpoints, with a troubleshooting table",
          "Terms, Privacy, Guidelines, About and the documentation now describe the seven-day lifetime instead of claiming links never expire. The guidelines gained a section on planning for the week a link has to last"
        ]
      }
    },
    {
      "version": "1.0.0",
      "date": "2026-10-04",
      "title": "First release",
      "changes": {
        "added": [
          "Shorten any http or https link to a short slug",
          "Custom slugs, 3 to 32 characters, checked for availability as you type",
          "302 redirects served from the edge with background click counting",
          "QR code generation, generated in your browser",
          "Recent links with click counts and relative timestamps",
          "Local history of your last 8 links, stored only in your browser",
          "Developer API: POST /api/create, GET /api/links, /api/stats, /api/check",
          "Rate limiting per IP on every endpoint",
          "/docs/, /changelog/, Terms, Privacy and Guidelines",
          "sitemap.xml and robots.txt",
          "Dark and light themes with a mobile action bar"
        ],
        "fixed": [
          "Redirects resolve for every generated slug. The lookup only checked lowercase while slugs were stored mixed-case, so auto-generated links fell through to the homepage instead of redirecting",
          "Legal pages, sitemap and robots.txt are served. The catch-all route was swallowing those paths",
          "Public /api/links no longer leaks internal rate-limit counters",
          "/api/check reports reserved slugs correctly instead of claiming they are free",
          "Duplicate slugs return 409 slug taken"
        ],
        "changed": [
          "Random slugs use an unambiguous lowercase alphabet, so G and 6 are never confused",
          "Custom slugs are normalised to lowercase, so Go and go are the same link"
        ],
        "removed": [
          "Third-party ad scripts. Rotating house banners remain, with no keys and no tracking"
        ]
      }
    }
  ]
}