Wekan logo

Wekan

Open source kanban board application built with Meteor

Alternative to: trello


About Versions (307)

v12.08

2026-09-27

In short

Close the reported LDAP empty-password bypass and the directory group and SAML replay issues found during the authentication audit. Selected boards can also be duplicated with a choice of structure and data.

Security

Enforce assigned-only permissions in exporter authorization. Thanks to xet7.

ExportScopeBleed: board visibility alone allowed assigned-only members to export unassigned private board data. All nine exporter authorization methods now share an assignment check. Unfiltered exports refuse assigned-only members; the two Scrum report loaders retain access because they already filter cards and snapshots. Board Excel and card PDF/Excel refusals now return HTTP 403.

Three Node checks cover the policy, all exporter call sites and Hall of Fame coverage. Eleven HTTP scenarios pass across native JSON, ZIP, CSV, calendar, PDF, Excel and charts, including permitted scoped Scrum reports. Existing Upcoming regression evidence remains recorded. Firefox, WebKit, FerretDB and Sandstorm were not exercised. CWE-863, high severity; no CVE assigned.

Enforce current access on universal History reads and restores. Thanks to xet7.

HistoryScopeBleed: assigned-only members could read hidden-card history, and historical authorship could preserve private-board history access after membership was removed. Filter current access before search, paging, totals and contributor counts. Restore, undo and redo also enforce current scope and card edit permission; an old writable board cannot authorize editing a card moved elsewhere.

Ten focused Node runner entries and eight Chromium scenarios pass, including allowed restoration, denied hidden/moved-card writes, revoked board access, search/count isolation and existing rule undo/redo. Other browsers, FerretDB and Sandstorm were not tested. Existing Upcoming coverage remains recorded.

Normal filtering and stale restore attempts can follow legitimate permission changes, so they are not automatically labelled as account-blocking attacks. See the audit for detection limits and the verified scope. No CVE is assigned.

Reject empty LDAP user credentials in every login path. Thanks to kta1kri and xet7.

LdapBindBleed, reported in GHSA-m87f-f43w-hwmc: both LDAP user-authentication helpers and the DDP/REST login boundary reject empty or malformed credentials before binding or local fallback. Passwords are not trimmed; intentional anonymous service searches remain supported. Exploitation required a directory permitting unauthenticated binds and user searches. OpenLDAP documents unauthenticated binds as disabled by default. Blocked attempts appear as LdapBindBleed summaries in Admin Panel / Problems.

Enforce LDAP and CAS login-group restrictions. Thanks to xet7.

DirectoryGroupBleed: both LDAP modes enforce group membership and require a unique user entry. Missing membership values cannot broaden a query, and group denial cannot fall back to a cached local password. Service-search mode retains service credentials for its group lookup. LDAP filter and DN values are escaped in their respective contexts. CAS compares complete literal group CN values, rejecting prefix and regular-expression matches and malformed allowlists. Group denials appear as DirectoryGroupBleed summaries in Problems.

Require single-use SAML request correlation. Thanks to xet7.

SamlReplayBleed: require a live InResponseTo request ID through node-saml and consume verified response IDs before storing login credentials, including concurrent validation. Unsolicited IdP-initiated assertions are rejected. Process-local request state requires sticky routing in clustered deployments. Attributable concurrent replay denials appear as SamlReplayBleed summaries in Problems.

Verification for all three entries: 46 focused Node suites and five Chromium scenarios pass; the local Meteor application rebuilds. Tests cover allowed and refused logins, malformed credentials, group restrictions, safe query values, logging failure and signed SAML responses. The protocol fixture reproduces the old replay behavior and rejects replay, unsolicited, unsigned and tampered responses after the fix. Live directories, external providers, Sandstorm and the FerretDB authentication matrix were not tested. See the authentication audit for the reviewed providers and limits. Existing Upcoming entries retain their recorded positive, negative and UI regression coverage.

Also adds the following feature:

Map explicit Jira estimates into existing Scrum custom fields. Thanks to xet7.

The Jira import page accepts an optional numeric estimate field ID and unit. Import validates the mapping and values before writes, creates a hidden numeric custom field and selects it for Scrum estimates without enabling Scrum. Jira export retains the source field ID and unit; native transfer and whole-board duplication preserve the mapping and remap the local field. Existing import and export selections require both Scrum and Custom Fields for this mapping.

Sixteen focused Node checks and six Chromium scenarios pass, covering zero, fractional and missing estimates, invalid inputs, section selection, UI import, Jira/native round trips, board duplication and existing Jira regressions. Document the mapping. Live Jira and other browsers were not exercised; existing Upcoming regression evidence remains recorded.

Retain Jira issue types and workflow categories in Scrum transfers. Thanks to xet7.

Jira import maps issue types and explicit status category keys into existing hidden Scrum card and list fields. Jira export retains these fields, and the Scrum selection controls both directions. Unknown categories remain unmapped; translated status titles never decide completion. Import leaves Scrum settings and visibility unchanged. Conflicting categories for the same named list and invalid issue types fail before board creation.

Fourteen focused Node checks and four Chromium scenarios pass, including Jira and native round trips, excluded fields, invalid inputs, existing completion policies and time-tracking regression coverage. Document mappings and remaining external sprint, release, epic and story-point work. Live Jira and other browsers were not exercised. Existing Upcoming regression evidence remains recorded; Blockly translation work remains paused.

Retain Scrum report context and original commitments in exports. Thanks to xet7.

Sprint Report and Velocity exports include snapshot estimate source, custom field and completion policy identifiers. Completed original commitments retain their start estimates and unknown counts separately from all completed work. Excel remains tabular; Scrum PDF prints wrapped labelled values for each sprint so the wide metric set does not disappear into clipped columns. Other chart PDFs keep their existing table layout.

Sixteen Node checks and one Chromium export scenario pass, covering changed estimates, added work, unknown context, complete row widths, wrapped PDF labels, unchanged non-Scrum tables, actual Excel cell values and PDF generation. Update the report guide. Existing Upcoming regression evidence remains recorded; other browsers were not exercised. Blockly translations remain paused.

Assign releases from Scrum planning card editors. Thanks to xet7.

Product Backlog and sprint card tables display release assignments and offer a selector to assign or clear a release from the current board. The controls reuse existing card write permissions, reference validation, revision checks and Scrum History. Card selections remain independent of the release-planning editor’s selected record. No new metadata fields or translation keys are needed.

Six Node checks and five Chromium scenarios pass. The new browser scenario covers saved selection, clearing, undo/redo and rejected foreign references; it caught and verified the fix for a selector helper-name collision. Existing Scrum planning, visibility, permission and export scenarios also pass. Update the Product Backlog guide. Existing Upcoming regression evidence remains recorded; other browsers were not exercised. Blockly translations remain paused.

Retain sprint calendars and report planned working days. Thanks to xet7.

Sprint snapshots retain the configured workweek. Sprint Report, Velocity and their Excel/PDF exports show inclusive planned working-day counts using the start snapshot’s calendar. Later board settings do not rewrite the result. Legacy snapshots without calendars and missing planned dates remain unknown; zero working days is a real value. Native transfer validates and preserves recorded calendars without inventing one for old data.

Twenty-three Node checks and five Chromium scenarios pass, including calendar isolation, leap dates, invalid/legacy transfers, unchanged counts after board calendar edits, Excel values, PDF output and existing full-board duplication. Update the report guide. This is planned duration, not measured daily progress; daily burndown history remains pending. Existing Upcoming regression evidence remains recorded; other browsers were not exercised. Blockly translations remain paused.

Configure Scrum team accountabilities and working days from settings. Thanks to xet7.

The shared Scrum settings form now exposes Product Owner, Scrum Master, Developers and working days using existing settings fields. Accountabilities select active board members without changing permissions. Administrators can clear assignments and select multiple developers and working days. Existing validation, revision checks and History undo/redo apply.

Seven local Node checks and five Chromium scenarios pass, covering saved and cleared selections, invalid members/days, undo/redo, non-admin denial and the existing Scrum views, exports and visibility settings. One separately gated DDP Node suite skipped; the browser scenarios exercised the running server. Four new labels use English fallbacks in catalogs awaiting translations. Existing Upcoming regression evidence remains recorded; other browsers were not run. Blockly translations remain paused.

Select card creation and archival in the list Sync popup. Thanks to xet7.

Add Card and Move Card to Archive switches independently control new-source card creation and source-absence archival. Both default to enabled for existing configurations. Disabling either operation leaves matched-card updates and field selection available. Disabled archival skips child archive preflight; result counts include only enabled operations. Board write access is required.

Twenty-six focused Node checks and five Chromium scenarios pass. Coverage includes every operation combination, retained cards, defaults, saved settings, invalid inputs, nonmember denial and existing conflict messages. Update the Sync guide and Scrum design checkpoint. Existing Upcoming regression evidence remains recorded; other browsers and live providers were not exercised. Project-scoped source identities, atomic jobs and Scrum planning Sync remain pending. Blockly translation work remains paused.

Opt into Jira spent-time synchronization from the Sync popup. Thanks to xet7.

Jira Sync can include Spent time (hours), using the existing numeric seconds conversion. Existing configurations keep time synchronization disabled. Selected time values share the source baseline and conditional-write guards with text: local timer or manual edits are preserved or reported as conflicts. Zero hours remains a value; absent time is not replaced with zero.

Thirty-nine focused Node checks and four Chromium scenarios pass, including conversion, invalid values, opt-out, zero, conflict detection, popup persistence and unsupported-field rejection. Updated the Sync guide. Existing Upcoming regression evidence remains recorded. Other browsers and live Jira accounts were not exercised. Estimate and Scrum planning Sync remain pending; Blockly translation work remains paused.

Select title and description synchronization in the existing Sync popup. Thanks to xet7.

Title and Description switches default to enabled for existing configurations. Excluded fields are not compared, overwritten or advanced in the source-text baseline. Selecting no text fields is supported; new cards use the existing fallback title and an empty description. Creation and archive selection are unchanged. The existing write-access check applies to saving these options.

Twenty-nine focused Node checks and four Chromium scenarios pass, covering selection persistence, unsupported-field rejection, excluded text, new-card baselines and existing conflict messages. Updated the Sync guide. Existing Upcoming regression evidence remains recorded; other browsers and live provider accounts were not exercised. Scrum field mappings remain pending, and Blockly translations remain paused.

Round-trip Jira time tracking through external JSON export. Thanks to xet7.

Imported estimate fields carry stable markers, so renaming them does not break Jira export. Convert hours back to integer seconds; Dates controls spent time and Custom Fields controls estimates. Never infer semantics from field names or export ambiguous mappings and invalid values. Native export keeps markers.

Six focused Node checks and one Chromium scenario pass, including renamed fields, selection exclusions, zero values, native export and real Jira-format re-import. Existing Upcoming regression evidence remains recorded; other browsers were not run. Individual worklogs, sprint/release mappings and Sync remain pending. Blockly translation work remains paused.

Preserve Jira time tracking using existing WeKan fields. Thanks to xet7.

Jira JSON import converts numeric time-tracking seconds to hours. Spent time uses the existing card field; original and remaining estimates use numeric custom fields hidden from minicards by default. Explicit zeroes are preserved, and invalid durations fail before board creation. Existing Scrum settings can select the original estimate field. Native export retains the imported values. Localized duration text and incomplete worklog pages are not guessed.

Four focused Node checks and three Chromium scenarios pass, covering nested and flat source fields, fractional hours, zero/missing/invalid values, the import page, native export, Scrum estimate selection and existing Jira import compatibility. Existing Upcoming regression evidence remains recorded. Jira sprint/release mapping and external export/Sync integration remain pending; other browsers were not run. Blockly translation remains paused.

Visualize sprint reports and velocity with count and estimate bars. Thanks to xet7.

Sprint Report and Velocity now show responsive horizontal bars above their existing tables. Switch between card counts and known estimates. Exact values, unknown-estimate counts and partial-snapshot warnings remain visible. Separate scales prevent comparisons across incompatible units, estimate sources, custom fields and completion policies. Native HTML/CSS adds no dependency.

Twelve focused Node checks and four Chromium scenarios pass, covering metric switching, both chart views, mobile width, zero and unknown estimates, separate scales, partial warnings, existing permissions and Excel/PDF export. The expanded report-view scenario was rerun successfully. Existing Upcoming regression evidence remains recorded; other browsers were not run. Daily burndown history and the remaining transfer integrations are still pending. Blockly translation work remains paused.

Preserve Scrum data when duplicating boards. Thanks to xet7.

The existing duplication selector includes Scrum, selected by default with its custom-field dependency. Planning records receive new IDs; copied card, list, swimlane and snapshot references point to the destination. Clearing Scrum omits its settings and metadata. Copies without cards retain planning records with reduced snapshots visibly marked partial in reports and Excel/PDF rows. Source History is not copied, and source board data remains unchanged.

Seventeen Node checks and seven Chromium scenarios pass, covering all copy selection modes, attachment inclusion/exclusion, reference remapping, omitted Scrum data, structure-only copies and partial-report labels. Existing Upcoming regression evidence remains recorded; other browsers were not exercised. Standalone card/list/swimlane copy and move, scoped import, History transport and Sync remain separate pending work. Blockly translation remains paused.

Restore Scrum data when importing a native board export. Thanks to xet7.

Native new-board import validates the versioned Scrum section before creating users or boards, then remaps planning, card, list, swimlane, user and estimate field references. Snapshots retain their outcomes, source provenance is kept, and imported accountabilities grant no permissions. Deselecting Scrum omits its payload and metadata. Board administrators can inspect import losses.

Nineteen focused Node checks and three native import/export Chromium scenarios pass. The import-page round trip covers release links, exact event timestamps, numeric estimate remapping, zero values, provenance and loss reporting. Invalid sprint and estimate-field references create no board. Existing Upcoming regression evidence remains recorded; other browsers were not run.

Universal History transfer, existing-board scoped import, duplication and Sync remain pending. Imports are not multi-document transactions, so database failure after validation can still leave a partially created board.

Include versioned Scrum data in native board exports. Thanks to xet7.

The export selector includes Scrum settings, planning records, optional item metadata and lifecycle snapshots. Scoped exports retain referenced planning records, reduce snapshots and follow-up links, mark partial snapshots and report omitted dependencies. Operational checkpoints and revision counters are excluded. Existing anonymization covers the added prose fields.

Eleven focused Node checks and three Chromium-driven HTTP scenarios pass, covering complete/scoped exports, omitted sections and estimate fields, assigned-only denial and enabled/disabled anonymization. Existing Upcoming regression evidence remains recorded. History transfer, board duplication and Sync integration remain pending; this does not yet establish a complete Scrum backup/restore round trip including History. Other browsers were not exercised. Native new-board import is covered by its separate entry.

Edit Scrum releases and events from Sprints. Thanks to xet7.

Board administrators select existing releases and events to edit them using the existing revision-checked methods. Release forms expose goals, planned dates, status, release timestamps and notes. Event forms include local time, timebox, notes and visible follow-up cards; summaries link those cards. Unchanged event and release timestamps keep their original precision.

Four Chromium scenarios and twelve focused Node checks pass. Coverage includes updating rather than duplicating records, exact event timestamps, follow-up retention, History undo, administrator checks and hidden-by-default metadata. Three new source keys are registered in every catalog; this does not resume the paused Blockly translation work. Other browsers were not exercised. Existing Upcoming regression evidence remains recorded.

Integrate Scrum changes with reversible board History. Thanks to xet7.

Each Scrum view opens the existing board History filtered to Scrum changes. Settings, planning records and optional metadata record before/after values; a sprint close and its card moves undo and redo as one operation. Restoration checks current board and card permissions, preserves unrelated card content, and rejects newer conflicting edits or deletion of referenced planning data.

Interrupted restores retain a private checkpoint until data, timeline and undo status are saved. Retrying resumes completed writes without duplicating the timeline or accidentally undoing an older change. This is not a transaction; original-edit/History atomicity and large-board limits remain documented work.

Eighteen focused Node checks, one real Meteor/Mongo lifecycle test and fifteen Chromium scenarios pass. Coverage includes the History menu and restore, compound undo/redo, access denial, conflicts, planning record recreation, reference protection and interrupted recovery. Existing Upcoming regression evidence remains recorded. Firefox, WebKit and FerretDB were not exercised.

Add Scrum planning, optional metadata and sprint snapshot reports. Thanks to xet7.

Board View adds Product Backlog, Sprints, Sprint Report and Velocity. Reuse existing estimates and card permissions with board-local sprint plans, revision checks, start/close snapshots and recoverable unfinished-work rollover. Board Settings controls independent hidden-by-default metadata on cards, minicards, lists and swimlanes. Release and event creation is included.

Report tables keep unknown estimates distinct from zero and export through the existing Excel/PDF workflow. Assigned-only members receive explicitly labelled partial reports. Native checkbox controls remain visible in settings, and the public-board view selector recognizes the new views.

Twelve focused Node checks, one real Meteor/Mongo lifecycle regression and three Chromium scenarios pass. Coverage includes stale/foreign writes, permission denial, lifecycle snapshots, rollover retries, actual Excel/PDF files and independent Card/Minicard visibility. Other browsers and FerretDB were not exercised. Existing Upcoming regression evidence remains recorded.

The menu-aligned Scrum guides distinguish the implemented planning feature from pending complete import/export/sync mappings, interactive charts. These remain active implementation work; this entry does not claim complete Scrum support.

Save rule configuration changes in reversible board history. Thanks to xet7.

Rule creation, edits, enabled state and deletion record snapshots containing the rule, trigger and action. Compound edits produce one history entry. Existing History can undo, redo and restore these changes; restoration checks current board-admin access and action destination permissions. Stale undo requests cannot overwrite another administrator’s newer configuration.

Three Chromium scenarios cover lifecycle undo/redo, ordinary-member rejection and conflicting edits. Existing history, rule and undo suites also pass. This reuses board history rather than adding an independent audit store.

Edit IFTTT rules with locally loaded Blockly blocks. Thanks to xet7.

Board administrators can drag, edit and save rule blocks using the existing rule engine. List, Workflow, Blocks and History have direct sidebar choices. Workflow writes use server methods. Blockly 13.3.0 and its local media load only when the editor is opened; no generated code or remote scripts execute. Unknown rule fields survive edits, and changed drafts retain conflict checks.

All 696 Blockly messages map to WeKan translation keys. Existing upstream and local translations are preserved, with additional direct translations in completed language batches. Other locales still contain English fallbacks; translation of every language is not finished. Cornish, Manx, Gaelic, Breton, Kashubian, Upper Sorbian, Silesian and several regional Romance languages need native review of specialist terminology. No translation service is used.

Five Blockly/catalog Node checks and four Chromium scenarios pass, including round trips, invalid workspaces, preserved parameters, permission rejection, Finnish and Arabic editing, drag operations and rule execution. Catalog checks verify key order and placeholders across all 246 locale files. The Blocks guide documents usage, supported editing and remaining translation work.

Choose which structure and data to duplicate from selected boards. Thanks to xet7.

All Boards / Multi-selection now has one Duplicate Board action. It opens a checkbox popup with all choices selected, Select All, Select None and Cancel. Choose swimlanes, lists, labels, custom fields, rules, outgoing webhooks, cards, checklists with their items, comments and attachments. Selecting child data selects its required containers; clearing a container clears its children. The separate Duplicate Board — Without cards action is removed; clear Cards in the popup instead. Select None copies only the board itself and its settings and access roles, without source structure or content.

Server validation and board-admin permission checks remain enforced. Scoped copies remap parent/subtask and dependency links, preserve custom-field values without sharing source definitions, and omit deselected labels and covers. Attachment copying now imports its dependencies explicitly, waits for flushed bytes and the installed Meteor-Files promise API, and propagates stream errors.

Verification: ten focused Node suites (14 runner entries) and nine Chromium scenarios pass. Coverage includes full, cards-only, swimlane-only and empty copies, real attachment bytes and covers, unchanged source data, multi-board selection, cancellation, invalid options and non-admin rejection. Other browser engines, cloud attachment stores and live FerretDB backends were not tested. Existing Upcoming entries retain their recorded positive, negative and UI coverage. Updated the All Boards documentation.

Show a single comment in the minicard badge tooltip. Thanks to lonix1 and xet7.

Hovering the minicard comment-count badge shows the comment text when exactly one visible, nonempty comment exists. Multiple or empty comments retain the localized count message. Reuses existing published data and renders the title as plain text; no new dependencies, subscriptions or permissions are needed. Fixes #1933.

Three focused Node suites and two Chromium scenarios pass, covering single, multiple, empty and malformed comment data, HTML-looking text, admin/read-only access and private-board comment isolation. Other browser engines and live FerretDB backends were not tested. Existing Upcoming changes retain their recorded positive, negative and UI regression coverage. Updated the comment feature documentation and open-issue audit.

Filter subtasks by their parent card. Thanks to robinvd and xet7.

Card actions now offer Filter: Subtasks. The Filter sidebar also offers parent cards from the current board. Both use the existing parentId relationship and filter engine, showing direct children without changing any cards. Multiple parents can be selected, and changing boards clears this selection. Read-only members can filter; private parent titles are not fetched or disclosed. Fixes #1871.

Verification: nine focused Node checks and three Chromium scenarios pass, covering parent selection, combined filters, reset, admin/read-only access, private-parent publication boundaries and unchanged card data. The Chromium run also rechecks the private-source linked-card regression from #1942, already closed by the private-source fix. Other browser engines and a live FerretDB backend were not tested.

Removed the completed parent-filter and private-linked-card entries from TODO Later. Corrected the reminder entry: scheduled due/overdue rule triggers exist; assignee email recipients and start-date reminders remain pending under #4278. Updated the filter, subtask and open-issue audit documentation.

Preserve valid MongoDB updates when editing rule documents. Thanks to xet7.

Trigger and action timestamp hooks now distinguish replacement documents from update modifiers. Replacement edits preserve creation timestamps without mixing top-level fields with $set, which MongoDB rejects. Modifier updates continue to set their modification timestamp.

Two focused tests exercise both forms and ensure replacement documents never receive update operators. Browser rule-editing scenarios also pass.

Keep rules-page text and controls visible across layouts. Thanks to xet7.

Long titles, trigger descriptions and buttons wrap within their rows. Controls participate in layout instead of overlapping through absolute positioning. Small screens stack the trigger menu and form, while workflow cards and primary-button icons remain readable with the current theme.

Four Chromium scenarios pass at desktop and mobile widths with English and Arabic, including blue, dark and light themes. They check every trigger and action category, long content and control boundaries.

Apply import and export anonymization to Scrum prose. Thanks to xet7.

Known username mentions in Scrum goals, definitions, acceptance criteria, swimlane purpose and planning text use the existing anonymization map. Native streaming export now applies the same pass to board and swimlane fields. Identity references, estimate units, source provenance and snapshots retain their meaning. This rewrites mentions, not arbitrary personal information.

Six focused Node checks and one Chromium-driven native export scenario pass. The export test covers enabled/disabled anonymization and unchanged stored data. Canonical transfer text is covered by unit tests; native Scrum planning record transfer remains pending. Existing Upcoming evidence remains recorded.

Keep read-only Scrum viewing out of write-denial logging. Thanks to xet7.

Rendering card capabilities no longer records an attempted write for ordinary read-only members. This prevents false account blocking while keeping the same permission decisions and denial logging for actual mutations.

Ten focused Node checks and one Chromium scenario pass. Coverage verifies role permissions, default mutation logging and repeated read-only Scrum views without losing the session. Existing Upcoming regression evidence remains recorded; other browser engines were not run for this fix.

Resume interrupted sprint closes from the Sprints view. Thanks to xet7.

Board administrators can resume a closed sprint whose card rollover was interrupted, using its saved revision and destination. A pending History recovery blocks this action until it finishes. The recovery button disappears when all pending cards have been handled.

Seven focused Node checks and the Chromium recovery scenario pass, including read-only denial, pending History exclusion and successful card rollover. The related Scrum and History browser suites also passed. Register the new source message in every catalog; Blockly translation work remains paused. Existing Upcoming coverage remains recorded. Other browsers were not run.

Separate partial Scrum reports from complete chart scales. Thanks to xet7.

Partial snapshots from scoped imports or restricted views no longer share a chart scale with complete sprint snapshots. Keep the existing visible warnings and exact totals. Assigned-only reports continue to exclude hidden cards and their estimates from both chart data and exported workbooks.

Nine focused Node checks and one Chromium scenario pass. The browser scenario checks rendered counts, metric selection, partial warnings, server snapshot filtering and Excel values for an assigned-only member. Existing Upcoming regression evidence remains recorded; other browsers were not run.

Avoid repeated full-snapshot scans in Scrum reports. Thanks to xet7.

Completed-commitment totals now use an index of completed card IDs instead of scanning the closing snapshot for each original card. This keeps matching work linear at the supported 10,000-card snapshot limit while retaining original commitment estimates and separate added/removed scope totals.

The deterministic work-bound regression fails before the fix and passes after it. Fourteen focused Node checks and two Chromium scenarios pass, including report metric selection, assigned-only filtering and Excel/PDF output. Existing Upcoming regression evidence remains recorded; other browsers were not run. This does not resolve the remaining large-board History storage limits.

Preserve Jira estimate mappings through the custom-field editor. Thanks to xet7.

Saving the existing custom-field popup no longer erases valid Jira time markers from numeric fields when rebuilding their settings. Renaming an imported estimate through the UI retains its meaning for Jira export. Invalid markers and markers on non-numeric fields are not retained by the editor.

Seven focused Node checks and one Chromium scenario pass. Tests execute the production save handler, cover valid/invalid markers, and rename through the actual popup before exporting and re-importing Jira time values. Existing Upcoming regression evidence remains recorded; other browsers were not run.

Honor import selections for Jira estimates and spent time. Thanks to xet7.

The existing import selector now removes Jira’s nested time fields and their flat fallbacks before creation. Custom Fields controls original/remaining estimates; Dates controls spent time. Excluded estimates do not create numeric custom fields, and fallback values cannot silently restore excluded data.

Seven focused Node checks and two Chromium scenarios pass. The browser tests exercise Dates-only and Custom-Fields-only imports and retain full native, Jira and board-copy round-trip coverage. Updated the Jira guide. Existing Upcoming regression evidence remains recorded; other browsers were not run.

Reject malformed Sync responses before changing cards. Thanks to xet7.

List Sync reuses the existing import source-shape validator before parsing and reconciliation. Malformed responses and parser failures set the existing error without creating, changing or archiving cards. A valid empty source retains existing archive behavior; an invalid response no longer masquerades as one.

Five focused Node checks and one Chromium scenario pass. Server tests execute the sync function with malformed, valid-empty and parser-failing responses; the browser verifies error display separately without contacting a provider. Existing Upcoming regression evidence remains recorded. Complete pagination and local-edit conflict handling remain pending. Other browsers were not run.

Fetch all advertised issue pages before synchronizing lists. Thanks to xet7.

Sync now follows Jira REST v2 search offsets and GitHub, Gitea/Forgejo and GitLab next-page headers before reconciling cards. Validate advertised totals; abort failed, incomplete, changing or looping pagination instead of returning partial results that could archive later-page cards. Limit runs to 1,000 pages or 100,000 items. Pagination stays on the configured origin; redirects fail.

Eleven focused Node checks and the Chromium Sync error-display scenario pass. Mocked provider responses exercise multi-page success, short pages, failures, missing links, bounds and invalid origins. No live provider account was used. Existing Upcoming regression evidence remains recorded. Jira Cloud’s newer search endpoint and local-edit conflict handling remain pending; other browsers were not run. Updated the Sync guide with provider references.

Use enhanced Jira Cloud search for list synchronization. Thanks to xet7.

Standard .atlassian.net tenant URLs now use REST v3 enhanced JQL search with explicit parser fields and token pagination. Missing termination metadata or repeated tokens abort before reconciliation. Self-hosted Jira retains the existing offset-based search path. Shared page/item limits still apply.

Thirteen focused Node checks pass using mocked provider responses, including opaque-token encoding, required fields, empty results, malformed responses and retained self-hosted pagination. Existing Sync popup browser coverage and Upcoming regression evidence remain recorded. No live Jira account was used. Custom Cloud domains and government-cloud endpoint selection remain pending; no new UI was added. Updated the Sync guide with the API reference.

Reject ambiguous source identities before list synchronization. Thanks to xet7.

Normalized Sync tasks must have unique valid external IDs and string text fields. Missing IDs no longer disappear silently from reconciliation, and a duplicate ID cannot silently replace an earlier source record. Invalid task collections use the existing error path before any card mutation. Valid empty sources and unchanged records retain their existing behavior.

Fifteen focused Node checks and the Chromium Sync error-display scenario pass. Tests execute the sync function with malformed normalized tasks and confirm zero card writes. Existing pagination, parser and reconciliation checks pass. Updated the Sync guide. Existing Upcoming regression evidence remains recorded; other browsers and live provider accounts were not exercised.

Preserve local title and description edits during Sync. Thanks to xet7.

Store the last accepted source text on synced cards. Upstream-only changes merge, local-only changes remain, and differing edits on both sides stop the run before card writes. Legacy cards adopt a baseline only when local and source text agree. The existing Sync popup identifies conflicting source IDs and fields; aligning both texts permits a retry.

Conditional updates reject intervening text, archive-state or location changes. Sync now displays structured failures as errors rather than success. Twenty-two focused Node checks and two Chromium scenarios pass, including merge decisions, legacy baselines, concurrent-write rejection and popup error handling. Provider responses are mocked; no live tracker account was used. Earlier successful writes can remain after a later race: this is not a transaction. Dedicated resolution controls, Scrum mappings and fully atomic Sync remain pending. Existing Upcoming regression evidence remains recorded; other browsers were not run. Blockly translations remain paused.

Keep copied cards independent from external Sync identities. Thanks to xet7.

Card and subtask copies no longer inherit external Sync IDs, source types or last-source text. The original mapping remains intact. Sync refuses existing duplicate local mappings before updates or archives, instead of selecting an arbitrary matching card. The existing popup reports the duplicate identity.

Seventeen focused Node checks and one Chromium board-copy scenario pass. Coverage exercises real copy bodies, source preservation, subtask fields and zero card writes when local identities are duplicated. The browser confirms Scrum references still remap while copied Sync identities are absent. Updated the Sync guide. Existing Upcoming regression evidence remains recorded; other browsers and live provider accounts were not exercised.

Guard Sync archives against moved cards and independent subtasks. Thanks to xet7.

Source-absence archives now verify the original card text, baseline, archive state and board/list location before writing. Concurrent changes stop the remaining run. Sync no longer recursively archives subtasks; an active subtask outside the source archive plan stops the run before card writes.

Nineteen focused Node checks and three Chromium error-display scenarios pass. Server tests cover valid removal, concurrent change rejection and independent subtask protection. Browser tests check structured archive errors alongside text conflicts and malformed-source errors. Updated the Sync guide. This is not a transaction, and concurrent child creation remains outside the guard. Existing Upcoming regression evidence remains recorded; other browsers and live provider accounts were not exercised.

Thanks to above GitHub users for their contributions.

More details at ChangeLog