LiftTrace logo

LiftTrace

Self-hosted weightlifting tracker with programs, PR tracking, and an AI coach

Alternative to: strong, hevy

LiftTrace screenshot

About Versions (42)

v1.3.0-dev05

2026-09-13

Fifth dev pre-release toward v1.3.0. Three new features, two of them off by default.

Added

  • Progress photos. Attach dated photos to your body-stats history on a new /progress page, reached from Statistics and the Body Stats sheet. Browse them as a month-grouped timeline, wipe between any two with a draggable divider, or scrub the whole record on a date track and play it back as a time-lapse. The weight logged that day rides along, and can be filled in inline when it is missing. iPhone HEIC is converted in the browser. Photos sync, are included in full backups, and photo files are private rather than readable by URL the way avatars and exercise media are.
  • Public REST API for external integrations (#77, requested by @bursaar). Versioned JSON API at /api/v1 for scripts and automations that want plain HTTP rather than MCP. Off by default (PUBLIC_API_ENABLED=1). Eight read routes plus two additive write routes behind a second flag, using the same tokens and scopes MCP already introduced. See docs/public-api.md.
  • Outgoing webhooks (#79, requested by @bursaar). Signed HTTP POSTs the instant a workout is completed, a personal record is set, a program advances, or a body stat is logged. Off by default (WEBHOOKS_ENABLED=1). HMAC-SHA256 signed, retried up to 3 times, secrets encrypted at rest, SSRF-guarded targets. See docs/webhooks.md.
  • Trace can see your cardio, and log it. Cardio is stored separately from lifting, so Trace’s workout tools never reflected it. It can now read your cardio sessions and log new ones.

Changed

  • Muscle recovery body map, redrawn on correct proportions, with anatomical muscle regions instead of rectangles.

Fixed

  • The muscle recovery map looked empty if you had not trained recently. Untrained muscles were drawn in a colour all but identical to the body silhouette.

Security

  • Full-backup archives were downloadable without signing in. BACKUPS_PATH defaults to a directory inside UPLOADS_PATH, which is served ahead of the auth middleware, so a backup ZIP sitting there was fetchable by URL even though every /api/full-backup route is admin-only. That directory is now excluded. Scheduled backups are off by default, so an install that never enabled them and never created one by hand had nothing there to reach, and there is no directory listing, so a filename had to be known or guessed. If yours has been internet-facing with backups enabled, a look through your access log for /uploads/backups/ will settle it either way.
  • Bumped adm-zip to clear its open extraction advisory.

Full detail in the CHANGELOG.