Skip to content

Fledge v0.8.1.1 "Aerie" ​

A guided way to a first server, permissions you can give to one customer at a time, and Discord notifications that look the part: a complete guide and a new bundled plugin, Better Discord Notifications.

An aerie is a nest high up where a young bird is raised before its first flight. This release is about that first flight: the moment a new customer gets their first server.

Highlights ​

  • A guided first server. Customers who may create servers and have none see a welcome on the Servers page. New server opens a three-step guide: choose a kind of server (cards with description and size), set it up (name, location, and sliders for memory, CPU and disk bounded by what is left of their allowance) and review before creating. With a single released kind the first step is skipped.
  • "May create servers" now works per customer. Set it to Yes under Customers → Edit limits and that customer gets the button, in every self-service mode except Off. No always wins over a plan's Yes. Before, the switch had no effect in some modes, so customers it was set for saw no button.
  • Customers are told why they cannot create. The drawer explains whether it is the panel mode, a missing plan, an unconfirmed email address or a denial, and links to the store where it helps.
  • Better Discord Notifications, a fourth bundled plugin. Discord channels (administrators' and customers') can use a Rich embed (colour by severity, emoji, the server, the cause of a crash, a link to the right page in the panel, the last console lines, a footer) or a Compact embed. If the plugin is off or fails, the plain message is sent, so nothing is lost.
  • Discord, Slack and webhook notifications, documented end to end, with a new set-up guide, event suggestions, customer rules and troubleshooting.
  • Version 0.8.1.1.

Added ​

Better Discord Notifications (plugin discord-embeds 1.0.0) ​

  • A new plugin capability, notification styles: a manifest field notifications and a permission notifications. A style plugin is a formatter: it returns the body of the message and Fledge sends it, so it never sees the webhook address and needs no network permission. Contract: Notification styles.

  • Discord channels get a Message style (plain text by default) in the channel editor, with a small preview of each style, for administrators and customers alike. GET /api/notification-styles lists what is available; POST and PATCH /api/notification-channels accept style.

  • The plugin: severity colours you can change, an emoji per kind of event, the server, exit code and cause of a crash, simple facts from the event's data, console output in a code block (can be turned off), a title that links to the server or page in the panel, sender name and picture, time and event code, and an optional role ping on the administrators' channels only. See Better Discord Notifications.

  • Defence in depth. Whatever a formatter returns is rebuilt from an allow-list before it is sent: Discord's size limits, http(s) links only, no files or components, mention parsing always off, and role mentions only on the administrator's channel, only numeric ids, at most three. A formatter has three seconds; any failure means the plain message.

  • Tests: 9 unit tests that run the real plugin code (including hostile input), a 55-assertion integration test (npm run test:discord), and the bundled-plugin list test now expects four plugins.

  • Create-server guide and first-server welcome (web). Uses the active theme, standard radio groups and labelled sliders, and respects reduced motion.

  • Docs: Customer permissions (who may do what, mode by mode, with troubleshooting) and Discord and webhook notifications.

  • A Billing & customers menu in the documentation's top navigation and a link on the landing page, for quick access to sign-up, customers, permissions, limits, plans, the store, billing, the Stripe plugin and email templates.

  • Unit test for the self-service access rule and integration checks for customer-level grants (server-plan mode and account-plan mode).

Changed ​

  • Self-service access is decided by one function used by the feature list, the options endpoint and the create request, so the three can no longer disagree. A customer-level Yes works in Server plans and Account plans mode; the server options endpoint now offers the released templates to such customers (0.7.2.1 offered none in Server plans mode). Off still means off for everyone.
  • The options and feature responses now include a reason (why) when creation is not possible. The existing fields are unchanged.
  • The panel looks at what it should offer (store, billing, creating servers) again whenever the browser tab is shown and every five minutes, so a settings change reaches customers without signing in again.
  • The "templates customers may use" list in Settings is now shown in Server plans mode too, because a per-customer grant needs released templates.
  • The hint on May create servers explains the modes.

Security ​

  • Discord and generic webhook messages carry allowed_mentions: { parse: [] }. A server, customer or plan named @everyone or <@&role> could previously ping a whole Discord channel. Now it shows as plain text.

Fixed ​

  • Customers with May create servers set on their account could not create servers unless an account plan also granted it.
  • The Servers page could show a create action that then failed because the account was not yet allowed to create (for example an unconfirmed email address). The feature list now accounts for it.

Upgrade ​

  1. Back up PostgreSQL and follow the regular upgrade guide. There is no database migration and no node-agent change.
  2. Nothing changes for panels that do not use self-service. If you use Server plans mode and had set May create servers on single customers, those customers can now create fixed-size servers: check that the right templates are released and that their limits are what you want.
  3. If you use Discord notifications, mentions are simply no longer parsed. For colour-coded embeds, install Better Discord Notifications under Plugins and choose a message style on the Discord channel.

Verified ​

  • API and web TypeScript checks; web production build.
  • API unit tests (35, including the access rule and the Discord payload) and Rookery settings tests.
  • Billing integration suite against disposable PostgreSQL, including customer-level grants, plan grants, denials and the full purchase-to-creation path.
  • Rookery integration suite (sign-up, self-service, email) against disposable PostgreSQL.
  • The guide was exercised in Chrome against the seeded demo: no button before the grant, button and welcome after it, all three steps, creation and landing on the new server's page.
  • Better Discord Notifications: unit tests of the plugin and of the allow-list (9), and an integration test through the real plugin sandbox against a local receiver (55 assertions): styles list, install and consent, rich and compact messages, settings, customers, switching styles, fallback to plain when the plugin is off.
  • Documentation generation, link and screenshot checks, and the VitePress production build.

Not verified: Safari and Firefox, screen readers, and a real Discord server. The embeds are checked as data against Discord's documented limits and delivered to a local receiver, not rendered by Discord, so how they look in Discord (colours, spacing on mobile) is unconfirmed.

Known limits ​

  • The guide's colour per kind of server is derived from its id; there is no per-template icon yet.
  • Plain-text Discord messages are a single line. Rich styles exist only for Discord; Slack and generic webhooks stay as they were.
  • Discord webhooks cannot carry buttons, so links are in the title.
  • Notifications are best effort and not retried; see the notification guide.

Released under the AGPL-3.0-only license.