Releases: deepakness/cogsend
Release list
v1.12.2
Quote posts on X keep every link you paste, and the quote card shows only the quoted post.
Fixes
- A second X link no longer replaces the quote. Pasting another link to an X post into a card that already quotes one used to swap the quote out and drop the first link. The new link now stays in your text as a plain link, which is how X shows it, and the note under the card offers Quote @handle's post instead to swap the two without losing either. To quote several posts, give each its own post with + Thread; the note says so.
- The quote card shows just the post. The price is gone from the card, and the links X adds at the end of a post for its link card or image (
t.co/…,pic.twitter.com/…) are no longer shown as text, matching how X displays the quote.
Documentation
- Writing and publishing describes how a second X link and the swap button work.
Upgrade
No migration. git pull && npm ci && npm run deploy:release.
Full changelog: v1.12.1...v1.12.2
v1.12.1
A fix for the quote button on phones.
Fixes
- The list of your X posts to quote stays on screen. The quote button's list opened upward from the card, so on the first card of a post it ran off the top of the page on a phone, where no scrolling reaches it. It now opens below the card and scrolls into view, clear of the bottom bar, including under the last card of a long thread.
Upgrade
No migration. git pull && npm ci && npm run deploy:release.
Full changelog: v1.12.0...v1.12.1
v1.12.0
Posts remembers where you were: the tab, account and search survive going to edit a post and coming back, and the tab bar on a phone no longer shows a scrollbar.
Features
- Posts keeps your place. The selected tab and account filter are now part of the address, such as
/posts?tab=scheduled, so reloading, sharing the link or coming back from editing a post lands on the same list. The search text comes back too, and with the right list on screen the browser returns you to the card you left. Switching tabs replaces the history entry, so Back still leaves Posts instead of stepping through every tab you clicked. - A cleaner tab bar on a phone. The status tabs still swipe sideways when they do not fit, but without the grey scrollbar. A fade marks the edge where more tabs are hidden and disappears once you reach the end. A link straight to a tab, such as the Failed link in the failure email, scrolls that tab into view instead of leaving it cut off.
Fixes
- Choosing Posts from the menu while on another tab now goes back to All Posts, instead of keeping the old tab with a plain
/postsaddress.
Documentation
- Posts and Insights says the tab, account and search are kept.
Upgrade
No migration. git pull && npm ci && npm run deploy:release.
Full changelog: v1.11.0...v1.12.0
v1.11.0
Quote posts on X: paste a link to an X post at the end of a card and the composer shows it as the quote X will publish, with the author and text of the quoted post.
Features
- X quote posts in the composer. X shows a post as a quote when its text ends with a link to another X post. With an X account selected, paste such a link at the end of a card and it becomes a quote card: the quoted post's author, date and text, the way X will show it. The link leaves the text box but stays saved at the end of the text, so publishing is unchanged. A link you type by hand moves into the card once you click away, and the × removes the quote.
- Help with links X will not quote. X quotes only a link at the very end of the text. A link to an X post anywhere else gets a note saying it will show as a plain link, with Make it the quote to move it to the end. Pasting a second link at the end replaces the quote, since X quotes one post.
- Quote one of your own posts. A quote button in each card lists your recent published X posts, and published X posts in Posts have Quote on X, which opens a new draft already quoting that post.
- Threads and images keep their quote. A
---split keeps the quote on the last piece, a long paste into a quote draft starts on the quoted card and leaves room for the link, and the card stays visible next to attached images, as X shows both. - Better previews for X links. The link preview for an X post now carries the post's author and text, read from X's oEmbed endpoint, instead of only "Name (@handle) on X". It needs no API key and spends no X credits.
Quote posts through X's API (quote_tweet_id) are Enterprise-only, so CogSend uses the link at the end of the text, which X turns into a quote. X bills a post that contains a link at $0.20 instead of $0.015, and a quote is such a post.
Fixes
- Dependencies updated to clear a high-severity
npm auditadvisory insource-map-js.
Documentation
- Writing and publishing has a new section, Quote posts on X.
- Posts and Insights lists Quote on X among a published post's actions.
Upgrade
No migration. git pull && npm ci && npm run deploy:release.
Full changelog: v1.10.0...v1.11.0
v1.10.0
CogSend on a phone: a Write button in the header, post cards that fit the screen, no zooming into fields on iPhone, and a composer that tells you when your draft is saved.
Features
- Write from any page on a phone. The header keeps a pencil button next to your avatar on small screens, where the Write button used to be hidden behind the menu.
- Post cards fit a phone. The time gets its own line and the actions sit underneath as equal-width buttons, instead of wrapping into each other. Desktop is unchanged.
- Shorter, clearer times on cards. Cards read "in 59m · Today, 6:40 PM" — how far away first, then Today, Tomorrow or Yesterday where that applies. The time zone is named once under the list instead of on every card; hovering a time still shows the full timestamp.
- The composer shows whether your draft is saved. The top right reads Saving…, Saved, or Not saved with a Retry button, on desktop as well as on a phone. A failed save stays reported until a save actually goes through.
Fixes
- iPhone no longer zooms into a field when you tap it. Every text field, select and the composer itself uses 16px text on touch screens, the size below which iOS Safari zooms the page and leaves it zoomed. The schedule picker stacks its date and time on touch screens so both still fit.
- A draft is saved as soon as you switch away. Switching to another tab or app saves at once instead of waiting for the autosave, so a phone that closes the browser in the background does not cost you what you last typed, and the reopened tab comes back to the same draft.
- Draft cards list Remove last (Edit Post, Duplicate, Remove), so the destructive action is never in the middle.
- Dependencies updated to clear high-severity
npm auditadvisories.
Documentation
- Writing and publishing describes the save status and saving when you switch away.
Upgrade
No migration. git pull && npm ci && npm run deploy:release.
Full changelog: v1.9.0...v1.10.0
v1.9.0
Fixes from a full audit: scheduled posts that fell out of Posts, text lost when splitting a card, X character counts, Insights time zones, and duplicate posts after a platform timeout — plus privacy and security hardening and a lighter footprint on the Workers Free plan.
Fixes
- Upcoming posts no longer drop out of Posts. Once more than 100 posts had been scheduled and published, the list filled with old history and hid what was still waiting. It now shows everything waiting first, soonest first, then history, newest first.
- Typing
---keeps all your text. A card with several markers splits into that many cards; the text after a second marker used to be lost. Images on later cards stay with their posts. - X character counts match X. Every link counts as 23 and CJK characters and emoji as 2, so a long link no longer blocks a post X accepts, and an over-long CJK post is caught before it is scheduled.
- Insights counts days in your time zone, not UTC. The app records your browser's zone when you open it.
- No duplicate posts after a timeout on X, LinkedIn or Threads. When one of them does not answer a post request, CogSend no longer retries on its own — the post may already be live — and the error says it "may have been published", so you can check before pressing Retry. A post the platform accepted without returning its id is recorded as published instead of being sent again, and a LinkedIn publish whose result could not be saved resumes instead of posting twice.
Security and privacy
/api/healthno longer tells anyone whether 2FA is set up.npm run doctorreads it from D1 when you are signed in to Cloudflare.- Signing in no longer reveals the account's email. A wrong email takes as long as a wrong password, and it now counts toward the per-address lockout like a wrong password does.
- Checking a Mastodon account follows redirects through the same guard as publishing, with a timeout, so a stored instance cannot hand the account's token to another host.
- Post links from platforms are kept only when they are http(s).
- The default avatar is drawn from your initials instead of loaded from Dicebear, which received your display name on every page.
Performance
- Threads and Zernio publishes no longer read image bytes they never send, and media downloads and video seeks stream from R2 instead of loading whole files into the Worker.
- Scheduler cleanup runs hourly instead of every minute, and the heartbeat is one statement, leaving more of each tick's Workers Free budget for publishing.
- Link previews scan only the page head when its tags are there.
Documentation
- Writing and publishing explains how X counts characters and that several
---markers make several cards. - Posts and Insights says which time zone Insights uses.
- API and Troubleshooting cover the "may have been published" error.
- Deploying notes where
npm run doctorgets the 2FA status.
Upgrade
No migration. git pull && npm ci && npm run deploy:release. Update your checkout before running npm run doctor against the new version: an older doctor reads the new health response as "2FA not set up".
Full changelog: v1.8.0...v1.9.0
v1.8.0
The Insights chart now answers the moment you point at it: any day's numbers, the previous period alongside, and where posts failed.
Features
- Read any day from the chart instantly. Hovering anywhere in a day's column shows a tooltip right away, with a guide line and markers on both lines. It gives the running total, that day's count, the previous period's value with its own date, and any failures. The tooltip sits on the far side of the pointer so it never covers what you are reading. On touch, tap or drag; with a keyboard, Tab into the chart and use the arrow keys, Home, End and Esc, with each day announced to screen readers.
- The legend shows live values. It reads the period totals by default and follows the day you are reading.
- Days with failures are marked with a red dot under the chart, and a Failed entry appears in the legend when there are any.
Fixes
- The previous period is easy to tell apart. It is now a light dotted line, or light bars, instead of a dark grey close to this period's colour.
- The change against the previous period is red when you published less, not always green.
- The newest day is always labelled on the chart, and the edge labels are no longer clipped.
Documentation
- Posts and Insights explains how to read a day from the chart and what the red dots mean.
Upgrade
No migration. git pull && npm ci && npm run deploy:release.
Full changelog: v1.7.2...v1.8.0
v1.7.2
Two install fixes for new users: a clear Node version requirement, and a new Cloudflare account's workers.dev subdomain handled by setup instead of failing at the last step.
Fixes
- Setup registers a new account's workers.dev subdomain before creating anything. A brand-new Cloudflare account has no workers.dev subdomain, and
wrangler deployonly offers to register one at a terminal, sonpm run setupused to fail at the deploy step after the database, bucket and account were already created. Setup now checks right after the account check: it names the subdomain when one exists, asks for one when it does not, and stops early with the dashboard link when it cannot ask.--subdomain <name>answers without a prompt. If the deploy still hits this error, the message is now three clear lines instead of wrangler's full output. npm run doctorreports a missing workers.dev subdomain, with the link that fixes it.- The Node range matches what the dependencies support. CogSend now declares
^22.13.0 || ^24.0.0 || >=26.0.0. Odd-numbered releases such as Node 25 were never supported by the toolchain, andnpm installfailed with a confusing error about vitest; it now names CogSend's own range..nvmrcpins 24 fornvm use.
Documentation
- Install and deploy and Troubleshooting cover the workers.dev subdomain and the new
--subdomainflag. The README and deploy docs state the supported Node versions.
Upgrade
No migration. git pull && npm ci && npm run deploy:release.
Full changelog: v1.7.1...v1.7.2
v1.7.1
One fix to what the new Cloudflare account check tells you to do, and clearer docs on picking the login and the account.
Fixes
- The account refusal suggests a fix that works. When a command would reach a different Cloudflare account than your last deploy, it suggested adding
account_idtowrangler.personal.jsonc. With the wrong login that only turns the refusal into an authentication error. It now tells you to use a login that reaches the deployed account, either withWRANGLER_PROFILEor by binding the checkout to the profile once withnpx wrangler auth activate <profile>.npm run doctorgives the same advice.
Documentation
- Configuration → More than one Cloudflare account now separates the login from the account. Bind your Wrangler profile to the checkout once with
npx wrangler auth activate <profile>, so no command needsWRANGLER_PROFILE. Pinaccount_idto choose the account when a login reaches several, and so that the wrong login fails instead of writing elsewhere. Troubleshooting and Install and deploy say the same.
Upgrade
No migration. git pull && npm ci && npm run deploy:release.
If you type WRANGLER_PROFILE on every command, run npx wrangler auth activate <profile> once from your checkout instead.
Full changelog: v1.7.0...v1.7.1
v1.7.0
Commands can no longer write to a different Cloudflare account than the one your instance lives on, and doctor and setup work with WRANGLER_PROFILE again.
Features
- Commands check which Cloudflare account they reach before writing. Deploys,
secrets:put, remote migrations,setupandadmin:resetprint the account they are about to use, and each deploy records it for the checkout. A later command that would reach a different account now stops and says how to fix it, instead of quietly setting secrets or deploying to another account's Worker of the same name. This used to happen whenWRANGLER_PROFILEwas left off one command, or when a checkout moved out of a folder bound to a Wrangler profile. To move an instance on purpose, deploy once withCOGSEND_ALLOW_ACCOUNT_CHANGE=1 npm run deploy. npm run doctorshows the account your commands reach. It fails when that is not the account the checkout deployed to, and warns when you use a profile or have several accounts but have not pinned one withaccount_id.- The header shows the bare cog glyph instead of the tile.
Fixes
doctorandsetupwork withWRANGLER_PROFILE. Wrangler refuses--profileonwhoami, so with a profile set,doctorreported "Not signed in to Cloudflare" and skipped its remote checks, andsetupstopped at step 1. Both now read the account through the profile, and when the profile is not signed in they suggestnpx wrangler auth create <profile>.
Documentation
- Configuration has a new "More than one Cloudflare account" section that recommends
account_idinwrangler.personal.jsonc, withWRANGLER_PROFILEas the fallback. Troubleshooting explains the new refusal.
Upgrade
No migration. git pull && npm ci && npm run deploy:release.
The first deploy after upgrading records the account it goes to, so if you use a profile, include it on that run (WRANGLER_PROFILE=<profile> npm run deploy:release). If your login reaches more than one account, add "account_id" to wrangler.personal.jsonc. npm run doctor prints the id.
Full changelog: v1.6.1...v1.7.0