Changelog β
All notable changes to Boltstore are documented here.
v1.0.3 - 2026-07-05 β
Fixed β
- Analytics charts now show accurate data β Fixed issues with volume endpoint and overview endpoint disagreeing on counts, corrected timezone offset handling near DST transitions, fixed 24h slot labels to include dates for clarity across midnight, and fixed 30d chart to properly aggregate all 7 days per weekly slot instead of only showing Sunday queries.
- Volume endpoint uses pre-aggregated tables β Queries now read from
_daily_statstable instead of scanning raw_query_log, and top queries now query the pre-aggregated_daily_queriestable for better performance. - Database delete properly cleans up analytics storage β When a database is deleted, its analytics snapshots (
_storage_snapshots,_daily_stats,_daily_queries,_query_log) are now properly removed, fixing inflated storage totals. - Analytics responses refresh automatically after import β Analytics snapshot is now properly awaited during database import, eliminating the need to restart or manually refresh the admin dashboard to see imported database analytics.
- Admin UI refreshes on mutations and navigation β The admin dashboard refreshes data immediately after any database operation (create, import, delete, rename) and loads fresh state when navigating between pages, eliminating unnecessary network traffic while keeping the UI in sync with the server.
- Response cache includes authentication information β Cache keys now incorporate authentication data, preventing one user from seeing another user's cached responses.
- Import clears stale cache data β After successfully importing a database, the response cache is now cleared to prevent stale analytics data from being served.
Changed β
- Universal refresh button in admin header β Added a refresh button to the admin header that invalidates all caches and reloads the current page's data on demand.
- Expanded 30d chart coverage β The 30-day chart now covers 7 days (6 weekly slots) instead of 5, including the current incomplete week for complete historical view.
- 7d chart label alignment β The 7-day chart now correctly anchors to current time and properly labels the rightmost slot with the start date.
Security β
- Rate limiting implemented on admin endpoints β Admin data endpoints now have rate limiting to prevent abuse.
- ATTACH DATABASE path validation hardened β Added stricter validation to prevent database path traversal attacks.
- Password complexity requirements enforced β Passwords must now meet minimum length and complexity requirements.
Performance β
- Analytics buffer size limits β Added configurable maximum buffer size to prevent unbounded memory growth.
- Analytics cache size limits β Added configurable maximum cache size with LRU eviction policy.
- Reduced overhead in analytics snapshot calculations β Optimized hot path operations and reduced unnecessary snapshot checks on overview and databases endpoints.
v1.0.2 β 2026-06-30 β
Changed β
- API keys now have full database access β API keys can execute any SQL via
/query(DDL, DML,SELECT,PRAGMA,ATTACH, etc.), manage config (/config), manage keys (/keys), export their database, view database details, view per-database analytics, and fetch batch schemas. Previously these operations required admin credentials. Import and database deletion remain admin-only. - Export accepts API keys β
/api/databases/:name/exportnow accepts a per-database API key alongside admin sessions. - UUID-based database identity (v3 migration) β Databases now have a stable UUID (
id) that survives renames. Child tables (_api_keys, analytics, activity) reference by UUID instead of name. On rename, only_databases.name,_databases.file_path,_api_keys.database_name, and analyticsdatabasecolumns are updated β all historical records carry over automatically.
Fixed β
- Admin UI: 16 pre-existing type errors fixed β Missing type re-exports in
client.ts,DataTable.vuetemplate ref callback, CSS module declaration inenv.d.ts, implicitanyparams inActivities.vue, missinggroupfield onDatabaseInfo, and removed unusedt.operationreference inDatabaseDetail.vue. - Admin UI: Error feedback for rename database/table β Renaming a database or table now shows validation errors inline in the UI instead of silently failing.
- Admin UI: Activities page showing
[object Object]in event column β Config/settings update events store the full config objects indetails.fromanddetails.to. TheformatDetailfunction coerced objects to[object Object]via template literals. Now showsChanged: cors, read_onlyfor config updates, and falls back to listing detail keys for other object shapes. - Rename database 500 error β After renaming, the old pool's SQLite connections still pointed at the deleted file. Now creates a new
DatabasePoolfor the renamed file instead of reusing the closed one. - Rename database: analytics cache stale for up to 60s β The analytics response cache was not invalidated on rename, so the dashboard showed the old name (or zeros) until the 60s TTL expired. Now invalidates all analytics caches immediately.
- Rename database: activity log not updated β
_activity_log.database_namewas not updated on rename, so the Activities page showed the old name for historical entries. Now updated alongside_api_keys.database_name. - Rename database: top queries showing old database name β Analytics tables (
_daily_stats,_daily_queries,_query_log,_storage_snapshots) were updated after the meta rename, allowing concurrent requests to flush new rows under the new name and violateUNIQUE(database, date, sql_text). Moved analytics UPDATE before the meta rename so no race is possible. - Search with multiple fields crashes with SQLite bind mismatch β The record listing endpoint (
GET /api/databases/:db/tables/:table/records) pushed 1 search bind value but generated N SQL placeholders (one per field). Now pushes one value per field, matching the placeholder count. - Analytics cache broken on first hit after startup β Cached
Responseobjects have single-use body streams, causing "Expected JSON but got : " errors on the second hit. Changed to cache raw data objects and reconstruct the response on each hit.
Performance β
- Admin dashboard: 5 analytics endpoints now run in parallel β The analytics page fetched overview, database stats, volume, top queries, and errors sequentially (5 sequential
awaitcalls). All 5 now fire simultaneously viaPromise.allSettled(), reducing page load time by ~2-3x. - Server-side response caching β Analytics overview, databases, and volume endpoints now cache responses in memory for 60 seconds (configurable TTL). Subsequent requests within the TTL window return cached
Responseobjects directly, reducing SQLite query load to near zero. - Session token caching β SHA-256 session lookups are cached for 60 seconds, reducing repeated
_sessionstable queries on every admin request. - Batch schema endpoint β The database detail page now fetches all table schemas in a single
GET /api/databases/:db/tables/schemacall instead of N+1 sequential requests. Returns allCREATE TABLEstatements in one response. - Pre-aggregated daily summary tables β Analytics queries now read from
_daily_statsand_daily_queriestables instead of scanning the raw_query_logon every dashboard load. Daily summaries are upserted during the existing 5-second flush cycle (no new timers or cron) and stay within ~5 seconds of real-time. Dashboard panel queries are drastically faster for large datasets, and pruning is handled in a single pass.
v1.0.1 β 2026-06-28 β
Fixed β
- Dashboard not found in Docker/npm (admin build missing) β The Vue admin dashboard (
admin/dist/) was not included in the Docker image or the npm package. Fixed by building the admin in the Dockerfile and addingadmin/disttopackage.jsonfiles. - Analytics storage showing 0 B on fresh databases β Storage was only computed by the 5-minute snapshot timer. Newly imported/created databases showed
0 Buntil the timer fired. Added on-demandensureSnapshot()that computesPRAGMA page_count Γ page_sizeat query time if no snapshot exists yet. - Executable binary: missing admin dashboard β The standalone binary (
bun build --compile) bundles only the server code. The admin dashboard now ships asadmin-dist.tar.gzalongside the binary, extracted by the install script todirname(process.execPath)/admin/dist/. - Analytics > Top Queries column widths β Database column was taking too much space; query column was cramped. Pinned Database column to
120pxand numeric columns to10%each. Query text now truncates with ellipsis when it exceeds the cell width instead of wrapping. - Analytics > Errors showing all entries β The errors table displayed all 20 entries inline. Now shows only the top 5 with a "View All" button that opens a modal with the full list.
- Database detail tabs broken on small screens β Tabs overflowed the viewport on narrow screens. Made the tab bar horizontally scrollable and hid the SQLite info badge on small screens (
<sm). - Dashboard overview refetching static data on range change β Switching the time range (24h/7d/30d) re-fetched health, databases, and activity data unnecessarily. Split loading into static data (fetched once) and range-dependent data (refetched only on range change).
- Volume chart x-axis not anchored to current time β The 24h chart always showed static hours 00β23 regardless of the current time. The rightmost slot now aligns to the next time boundary (next hour for 24h, next midnight for 7d, next Sunday for 30d) using the browser's detected timezone (
Intl.DateTimeFormat). DST and timezone offset changes are handled correctly. - Volume chart 30d only counting Sunday queries β Weekly aggregation looked up only the start Sunday's daily bucket, missing queries from MondayβSaturday. Now iterates across all 7 days of each weekly slot and sums the daily counts.
- Analytics > Errors not showing entries older than 24h β The errors endpoint defaulted to
range=24hwhen no range was passed, and the frontend never sent one. Switching to 7d/30d on the analytics page now passes the active range to the errors endpoint. - Database > Queries table truncating SQL β The query column shared the same truncation CSS (ellipsis) as the Analytics overview, preventing users from reading full SQL on the database detail page. Split into two styles:
.top-queries-table(overview, still truncates) and.detail-queries-table(database detail, wraps text).
Changed β
- Docker: data persistence β Switched from a Docker named volume (
boltstore-data) to a bind mount (./data:/app/data) indocker-compose.yml. Data survives container/image deletion and is directly accessible on the host (macOS, Linux, Windows). package.jsonprepublish β Now builds the admin dashboard before publishing.- Volume chart: bar β line β Small values (e.g., 10 next to 250) were nearly impossible to hover on a bar chart. Switched to a filled line chart with visible data points and
nearest+intersect: falseinteraction so the tooltip triggers anywhere along the line. - Compact number formatting β Large numbers (queries, writes, rows, error counts) across the dashboard now display as
1.5K,1.2Minstead of raw1,500,1,234,007. AddedformatCompact()utility used in metric cards, database lists, top queries, and activity totals.
v1.0.0 β 2026-06-25 β
Initial release.
Features β
- HTTP REST API for SQLite databases (CRUD, DDL, raw SQL)
- Multi-database isolation β each database gets its own SQLite file
- Admin dashboard (Vue 3 SPA) at
/dashboard - API key authentication (per-database) + admin sessions
- Database import/export (
.dbfiles viaVACUUM INTO) - Built-in analytics β query log and storage snapshots
- Per-database config (CORS, read-only mode, group)
- Audit logging for admin actions
- Deployment via standalone binary,
npm install -g, or Docker