1.1.0
2026-10-04Seven-day link expiry, a Halloween theme, a tools page and a real 404
Changes
Added
- Every link now expires after seven days and is deleted: the slug, its destination and its click counter. Expiry is set on the stored record and re-checked on every read, so a link past its deadline is gone whether or not the underlying key has been swept yet
- expiry dates in the interface. The result panel shows the exact deadline, recent links show days left, and the reveal box says plainly when a slug expired rather than never existing
- expiry fields on the API. create, bulk, unshorten, links and export all report expiresAt and expiresInDays
- GET /api/sweep deletes anything past seven days and stamps links that predate timestamping, 4 requests a minute. DELETE /api/sweep?slug= removes a single link on request
- An expired slug becomes claimable again, so /api/check reports it as free and frees the name for the next person
- Halloween theme alongside dark and light. The button in the header cycles all three and the address bar colour follows
- New Tools page at /tools/ with a standalone QR generator, a slug inspector that explains which rule failed, a reveal box with local lookup history, and a QR photo reader where the browser supports one
- New API reference page at /api/ with a runnable example against the create and unshorten endpoints, plus collapsible detail per route
- New About page at /about/ covering how the service is built, what it costs and what it deliberately does not do
- Bulk shortening, up to ten links per request with optional per-row custom slugs, and a copy-results button
- POST /api/bulk for the same thing over HTTP, 5 requests a minute
- GET /api/unshorten to expand any shortn slug back to its destination with its click count, unlimited
- GET /api/export for a full dump as JSON or a downloadable CSV, 20 requests a minute
- Reveal and copy buttons on every recent link, and email alongside X, WhatsApp and Telegram in the share row
- QR codes download as PNG at four sizes or as scalable SVG
- Export buttons on the homepage for the whole store
- Keyboard shortcuts: slash focuses the URL field, Ctrl or Cmd plus Enter shortens
- Shared theme stylesheet and script so every page on both sites runs the same design system
- Visible version number in the footer and the API section, read live from /api/version
- Changelog auto-generation folds any commits made since the last release into an Unreleased block, grouped into Added, Fixed and Changed
Fixed
- Unknown paths return an honest 404 page instead of quietly rendering the homepage, which made broken links look like working ones
- The 404 page checks the store when the missing path looks like a slug and tells you where it actually pointed
- Header and footer text on the legal pages was corrupted by a bad character encoding during an earlier edit and has been rewritten
- Click counters no longer break on a non-numeric stored value, which previously threw inside the background write
- HEAD requests are handled without a body instead of running the full redirect path
- Nested paths no longer fall through to the homepage as if they were slugs
- Bulk creation matches the single-link path on reserved words, custom slug rules and scheme handling, so the two behave the same way
- Expired links are filtered out of /api/links, /api/stats and /api/export, so a public list or a CSV never shows something that would fail to redirect
- Links made before timestamping existed are given a real seven-day deadline on first read instead of living for ever, and /api/sweep does the same for the rest in bulk
Changed
- Homepage rebuilt as a two-column layout on desktop with tools and recent links in a sidebar, collapsing to a single column with a sticky action bar on phones
- Wider content column and larger touch targets, with tables and code blocks that scroll rather than overflow
- Slugs, docs, about and changelog joined the reserved list so a link can never shadow a real page
- Redirects send Referrer-Policy: unsafe-url so the destination receives the original referrer, and keep no-store so caches cannot swallow visits
- Every endpoint still sends Access-Control-Allow-Origin, and the new ones do too
- Documentation rewritten to match the current endpoints, with a troubleshooting table
- Terms, Privacy, Guidelines, About and the documentation now describe the seven-day lifetime instead of claiming links never expire. The guidelines gained a section on planning for the week a link has to last