Volver al índice

Evolución del proyecto

Registro de cambios

Historial público de funcionalidades, correcciones y actualizaciones de seguridad relevantes.

Las notas de versión conservan el inglés de la fuente canónica; la navegación, las fechas y los metadatos siguen el idioma seleccionado.

En desarrollo

Added

  • Media optimization now includes a fail-closed backfill command. Its default bounded dry-run uses stable allowlisted owner/field filters, reports only aggregate classifications and never mutates database, storage or queue. Explicit execution additionally requires confirmation and the feature/codec gate, while opaque recipe-bound checkpoints provide idempotent batch resume.

  • The inactive responsive-upload pipeline now has an idempotent database-queue job with generation-scoped locking, progressive retries, preflight checks, atomic variant publication and safe terminal-state cleanup. Superseded work becomes obsolete, while failures retain the current fallback and expose only minimized technical reason codes; HTTP dispatch remains disabled by default. Replaced public fallbacks are moved to a restorable quarantine only after commit and only when no database reference remains; rollbacks and shared files stay untouched, and permanent deletion is never triggered by the job.

  • Percorso's active ornamental twigs now end in one deterministic SVG leaf, using local green, orange and red tokens. Leaves share the branch reveal without adding drawable paths, filters or autonomous animation; they remain available in the rotated desktop view, stay out of vertical mobile and dense layouts, and are hidden in forced-colors mode.

  • On small screens, Percorso now offers an accessible opt-in switch that opens the existing desktop serpentine full-screen and rotates it by 90 degrees in portrait, while preserving the vertical mobile layout as the default and no-JavaScript fallback. The switch stays upright and keyboard reachable; Escape returns to the vertical view and restores focus.

Changed

  • Footer contact links now apply their accessible text color immediately, including after navigation history marks them as visited. The fake-login cache effect also releases completed per-letter animations and avoids unnecessary GPU filters, preserving the interaction while improving WebKit stability.

  • Responsive matrix tables now scroll consistently with Left/Right, Home and End when their named region has keyboard focus, including Firefox and WebKit, without overriding controls inside the table or the no-JavaScript fallback.

  • Collection cards now avoid a redundant action layout wrapper, keeping idle tab prefetch within its existing payload budget without changing action alignment. Percorso also clears obsolete animated branch state when its responsive layout changes.

  • New Project JPEG and PNG uploads can now enter the queued responsive-media lifecycle when its feature and runtime codec gates are explicitly enabled. Replacement and deletion keep complete media families consistent, while the default disabled state and a closed codec gate retain the existing atomic upload path without dispatching optimization jobs.

  • Compact administrative tables now show icon-only actions for opening a contact request, changing or deleting a user, and paying or deleting a work entry. The controls retain localized accessible names, pointer titles, confirmation dialogs and 44-pixel targets.

  • The contact page again uses the full responsive Bootstrap container for its desktop 5/7-column composition, while retaining the shared form-shell spacing and mobile reflow contracts.

  • Collection cards now present visit, detail, edit and delete as uniformly aligned icon actions. Each keeps a 44-pixel target, localized accessible name, hover title and the existing semantic color, focus and confirmation behavior; an explicit flex layout now optically centers different icon metrics. Detail pages retain their visible action labels, while the UI Kit separates text-only, text-and-icon and icon-only semantic examples.

  • Media integrity audits now reconcile the complete optimization family across public and private disks, including active staging prefixes and residual technical files left without database records. Files under the opaque media/ namespace are reported but excluded from generic quarantine, and historical purge stops when a path becomes a registered generation fallback or variant. A read-only family resolver now rejects active, non-canonical or incomplete generations before any future whole-family maintenance action; its versioned multi-disk plan records checksums before the internal executor moves or restores a complete obsolete family with rollback on partial failure and database locks acquired before filesystem mutation. Concurrent maintenance of the same family now serializes without partial artefacts; a disabled-by-default purge preflight verifies retention and integrity without deleting files, while the internal resumable purge retains its manifest across partial failures and completion. A read-only archive snapshot now records opaque family identity, active state, recipe, canonical destinations, bounded file metadata and verified SHA-256 checksums; its deterministic manifest adds aggregate limits, totals and a global checksum. A strict input validator reconstructs all archive and storage paths and rejects unknown fields, states, disks, duplicates and inconsistent nested checksums. Private user and settings media are excluded in favor of stable editorial owner identities; an internal writer serializes only declared files after a final byte and checksum read. A private preview stager rejects unsafe or undeclared ZIP entries, rechecks MIME, bytes and checksums, removes partial copies on failure and reports active-generation conflicts. The family archive is now available as a separate audited admin export, preview and confirmation flow while the existing editorial v1 routes and reader remain unchanged. A transactionally locked confirmation preflight repeats staging verification and rejects missing owners, storage-key collisions, prior generations or active pointers before any mutation. The internal promoter keeps those locks through publication, commits records and active owner pointers together, and rolls back only files created by the failed attempt; staging is discarded only after a successful commit.

  • Project and Hobby detail images can now use verified runtime responsive variants through <picture>, srcset, explicit sizes and intrinsic dimensions. Pending or failed processing remains invisible and keeps the same valid fallback image, while legacy content retains its previous query budget and rendering path.

  • Every main UI Kit panel is now a keyboard-accessible native disclosure, so long demonstrations can be collapsed independently without JavaScript. The responsive table examples now load the same dark table stylesheet used by real consumers, restoring readable text and mobile card behavior.

  • The public and administrative UI Kit now groups each Font Awesome icon once by its canonical family, exposes localized group descriptions and optional semantic tags, and filters by group, family, name or tag. The generated subset is now the single taxonomy source, preventing stale manifest entries while keeping source paths restricted to administrators.

  • Visual regression baselines now have a deterministic private manifest with opaque IDs, explicit synthetic-data and review-status classification, intrinsic dimensions and checksums. Cards distinguish approved, regression and missing states with text and symbols as well as color. Frontend quality gates reject undeclared or unsafe assets without publishing their repository paths. Admin-only index and asset routes enforce an explicit policy, verify integrity at read time and use private, non-cacheable responses with opaque filenames.

  • Administrators can now browse visual baselines in a localized, paginated gallery with allowlisted server-side filters, lazy intrinsic-size previews and direct navigation from the Tools menu and dashboard. Each card identifies the approved state in text and keeps filesystem paths out of the response.

  • Visual baseline cards now flow in a responsive vertical gallery with top-aligned 3:4 cropped previews, while pagination still limits each page to twelve lazy-loaded images. Selecting a preview opens the complete image in a modal with focus management, keyboard dismissal and previous/next navigation. The modal preserves the intrinsic image ratio and scrolls tall captures vertically. Tablet and desktop users can expand it to the full viewport with an accessible stateful control, while retaining the protected direct-image link as the no-JavaScript fallback.

  • Page shells now use explicit narrative, form, administration, data, detail and documentation density modifiers with bounded responsive gutters. The representative tranche covers Privacy, shared forms, the admin dashboard, users, public entity details and public documentation without reducing touch targets or introducing global overflow. Authentication and demo forms, Contacts, Profile and shared CRUD forms now use the same form-shell rhythm. Administrative content, media, portability, debug and documentation pages now share their semantic shell too; the public and admin UI Kit select the appropriate density from the same view, and dismissible alerts retain a 44×44 px close target on narrow screens.

  • UI catalogue generation now refreshes the component manifest before deriving Font Awesome references from it, so a single canonical command produces immediately verifiable artefacts after Blade changes.

  • Administrative analytics, performance, contact-request and private-work panels now use the full responsive data shell with consistent gutters, while table overflow remains confined to its named local region.

  • About, CV, Master Control and the application 403/404 pages now share the narrative shell rhythm. Visual column and catalogue layouts retain their wider measure, while reading-focused error pages remain compact.

  • Selected checkboxes now retain their selected surface on fine-pointer hover; focus, validation and disabled states keep precedence while hover still adds a non-conflicting visual cue.

  • Responsive table coverage now includes the real Performance matrices, long localized content in all five languages and 200% equivalent zoom. Long Performance audit commands wrap within the viewport instead of creating document-level horizontal scrolling on small screens.

  • The mobile About expansion now settles rapid repeated toggles in the latest requested state, emits a single final event, keeps its label and ARIA state synchronized, and skips animation when reduced motion is requested. Its interaction contract now also covers compact viewports, 200% equivalent zoom, forced colors, all five languages, CLS and unwanted scrolling.

  • The mobile administrator account menu now groups tools, demos and error pages into compact keyboard-accessible submenus, while profile and logout remain immediately available.

  • Mobile card tables now use the full available width without a blank strip on the right, while matrix tables keep horizontal scrolling without reserving an unrelated vertical scrollbar gutter.

  • Percorso now uses an efficient animation profile on small or touch devices: electric pulses launch every two seconds instead of every second, expensive SVG painting is capped near 30 fps, and small touch screens omit continuous halo filters. The flow pauses when the timeline leaves the viewport while preserving the same pulse speed, route geometry and accessible static path.

  • Percorso now adapts its desktop serpent to the available width: two projects per row from 1200 px, three from 1440 px, and four from 1800 px. Turns and branch direction are recalculated at each breakpoint, while the rotated small-screen desktop view uses one project per row and the actual rotated viewport width.

  • La timeline Portfolio è stata rinominata Percorso (/percorso) e resa nuovamente pubblica e indicizzabile; il vecchio URL /portfolio resta temporaneamente un alias pubblico.

  • A dedicated, localized Percorso page that orders projects chronologically, gives every project its own segment and places only its directly related skills on that branch. Its server-rendered timeline reserves its final layout and, when JavaScript and motion are available, remains visually empty while the drawing module initializes and before the intentional first growth beat, then reveals branches and trunk, each year and project, and finally the skill fruits in chronological order. Nothing complete remains rendered beneath the reveal, completed segments are not retraced, and the layout stays stable throughout. Projects form knots along a full-width, responsive two-to-four-project horizontal serpent, while gapless junctions connect every segment and turn. Skill branches grow from their project knot, route around pill-shaped project labels and end in one of three deterministic, outline-only fruit shapes containing the accessible skill link. Each fruit keeps its peduncle attached to the corresponding branch without introducing extra announced content. Fruits now use a broad central body around the label, reserve a 144 × 96 px minimum readable area, adapt through 9, 12 and 15 rem width profiles according to the localized skill-title length, and use red, green and lilac outlines for apple, pear and plum respectively. Narrow viewports cap those profiles to the available branch width without overflow. Pears now grow to 144 px high and apply a lower optical label alignment inside the wider body, while their branch connector follows the taller silhouette without gaps. Hover and keyboard focus now light each fruit with a variant-specific neon outline, glow and matching title while reduced-motion, reduced-transparency and forced-colors preferences retain safe fallbacks. Roughly three out of four desktop skill branches now sprout varied deterministic asymmetric side twigs that stay joined to the stem and join the segment-by-segment growth; trunks, dense tracks and mobile fallbacks remain undecorated, with no client-side randomness. Explicitly unfilled turns no longer create a dark panel at the diagram edge, and the progressive drawing mask is removed once growth finishes so no partial gaps remain. Without JavaScript or with reduced motion the complete timeline is immediately visible; a module error or safety fallback restores the same readable final state. On mobile the path becomes a continuous left-hand vertical trunk: each year aligns with its project pill, every segment reaches the next marker and the final project keeps its own branch. Long labels and fruits remain inside the viewport, while dense content uses the same readable fallback. The path remains complete with reduced transparency or forced colors, while showing only each project's release year without entity icons, redundant type labels or skill periods, and shows each skill only on the first chronological project that uses it. It ships with a continuous electric stream driven by one global clock: a pulse starts at the oldest base every second on desktop and every two seconds on the efficient small-screen or touch profile, travels at a uniform rendered speed across SVG boundaries and forks only when it reaches a skill branch. Multiple pulses can circulate during the initial reveal without pre-populating the first frame. The first growth steps now remain visible longer, then the reveal accelerates progressively to a stable minimum cadence so the opening is easier to follow without delaying every later project. The electric vein may briefly lead an unrevealed chronological body to preserve a seamless handoff, while content remains hidden. Frame stalls resume smoothly without pulse bursts, and responsive geometry is rebuilt for the vertical mobile route. Dense fallbacks now use a curved SVG spine that grows out of the project trunk and carries the same pulse into every lateral skill branch. Variant-specific vertical and lateral fruit connectors now use short, shape-specific S curves with server-rendered root-body and root-current layers. They slightly overlap the branch and fruit and are painted before the outline, producing an organic, gapless graft across desktop, rotated, dense and mobile layouts without new JavaScript animation. Reduced-motion, reduced-transparency and forced-colors modes keep the roots static and fully readable. The timeline also ships with editable provisional seed years without replacing periods already corrected in admin. An opt-in, production-blocked demo seeder adds eight localized projects for testing four complete rows without changing normal seeding. Hobbies and unlinked skills remain available in Collections but are intentionally omitted from this timeline.

  • A private, owner-scoped administrative work log with exact hourly totals, payment cycles, optional encrypted notes for each work entry and localized server-rendered controls. Open cycles now summarize only the hours and amount still awaiting payment, while the paid archive retains the complete totals.

  • Admin-only, checksum-verified JSON portability for the current asset, Lighthouse, Sass and per-page CSS coverage snapshots, promoting the prior production state to the comparison baseline after preview and explicit import confirmation.

  • Versioned, privacy-first analytics CSV portability with an admin-only preview, explicit transactional import, canonical route allowlist, and minimized audit records.

  • A standalone Nginx 503 fallback that remains readable when Laravel or PHP-FPM is unavailable during an incident or maintenance operation.

  • A public, localized UI Kit with a server-side allowlist and a separate administrative catalogue.

  • A public changelog with release anchors, search integration, and sanitized Markdown rendering.

  • An opt-in encrypted contact inbox with delivery status, validated workflow, administrative management, and deterministic retention.

  • A dedicated production queue worker with database-backed jobs, automatic restart, healthcheck, and monitored runtime heartbeat.

  • German as a fifth localized experience across public content, navigation, metadata, and documentation.

  • An opt-in Firefox and WebKit browser matrix for responsive, touch, reduced-motion, and keyboard compatibility checks.

Changed

  • Administrative list tables now become labelled cards below 768 px, keep contextual action names and 44 px touch targets, and wrap long values without hiding their semantic headers. Comparative tables now use named, keyboard-focusable local scroll regions with a mobile hint and contained overscroll. The UI Kit documents both strategies and authenticated browser coverage exercises representative card and matrix surfaces at 320/390 px.

  • Administrative data tables now expose explicit column and row header scopes to assistive technology. Row identities retain their previous visual weight on list-style tables.

  • Administrative data tables now derive an accessible name from their visible page, section or disclosure heading. The table contract test rejects unnamed web tables while keeping presentational email and PDF tables excluded.

  • Administrative tables now declare a verified mobile strategy (cards or matrix) in their markup. Email and PDF layout tables remain explicitly excluded; this classification does not yet change the rendered layout.

  • Percorso now requests only the localized title and timeline fields needed to render its diagram. Its SVG engine also reuses measured geometry for the three visual layers of every branch and carries the initial measurements into the lightning setup. Its animation loop reuses pulse bookkeeping and avoids redundant per-frame sorting, reducing response payload, startup work and garbage collection while preserving the progressive reveal and lightning flow. The performance audit now measures its canonical /percorso URL while keeping previously saved /portfolio measurements readable.

  • The UI Kit now documents Percorso's Atomic anatomy, responsive states, accessibility fallbacks and page-only assets. The admin performance dashboard also highlights its latest real Lighthouse snapshot, transfer inventory, active runtime optimizations and targeted audit command without inventing missing measurements.

  • Le anteprime social usano ora il logo del portfolio come immagine canonica Open Graph e Twitter quando una pagina non dichiara un'immagine propria; l'avatar resta disponibile per i contenuti personali e i dati strutturati.

  • The provisional Percorso project periods now reflect the confirmed 2025–2026 project sequence for Napoli Liberazione, Gestionale E-Commerce Teatro, Gestionale Piattaforma Radio, E-commerce Tour in Barca, Gestionale Minimarket, Gestionale Tavola Calda, Portfolio, and ERP Associazione Culturale. Month-level dates remain outside the current year-only timeline contract.

  • The Percorso timeline now follows the shared Atomic Design hierarchy, with dedicated path/year/turn atoms, project/skill molecules and timeline organisms while preserving its server-rendered markup and behavior.

  • The Percorso page now opens directly on its timeline after a compact title, removing the redundant breadcrumb, introduction, collections call to action, and secondary timeline heading.

  • On mobile, Collections now lives in the Content dropdown while the public Percorso keeps the released direct slot with a route-shaped icon. Collections reuses the former code icon, and the Content dropdown keeps its address-card trigger. Localized current states and 44-pixel touch targets remain available across the compact one- and two-row layouts; public desktop navigation keeps Collections direct.

  • Enabled checkboxes now expose a fine-pointer-only hover state without masking keyboard focus, selection, validation errors, disabled controls, or touch behavior; the localized UI Kit documents every checkbox state.

  • The private work log now supports deleting entries from open cycles, shows period, total hours and localized payment time, and confirms payments with the authoritative cycle total. Database failures now roll back cleanly and return localized generic feedback without logging private work values. Employers and recipients are now reusable private entities with filters, dedicated management pages, last-used defaults and an optional default hourly rate per employer; the work-log index only exposes their selectors. Payment cycles are now scoped to one employer, can include entries for different recipients, and allow an individual entry to be marked paid; the cycle closes automatically when its final unpaid entry is paid. Paid cycles now have a separate read-only, filterable history page.

  • Audited pages now share explicit CLS budgets, and the footer reserves the brand image dimensions before loading so fake authentication pages no longer shift vertically on narrow viewports.

  • Global navigation dropdowns now use a smaller first-party accessible controller while preserving keyboard, touch, focus and audio behavior.

  • Performance comparisons now use consistent semantic color coding for passing, warning, failing, improved, regressed and unchanged values across summary cards and detailed audit tables.

  • Frontend performance reports now retain the current and immediately preceding asset, Lighthouse, Sass and per-page CSS coverage audits, with localized deltas and trend indicators in the admin performance dashboard.

  • Breadcrumb styles now load through one shared component entrypoint only on the five pages that render them, reducing CSS transferred globally without changing their appearance or keyboard behavior.

  • Pagination styles now load through one shared component entrypoint only on the seven pages that render paginated results, preserving the existing responsive, hover and keyboard states while reducing global CSS.

  • File-picker styles now load through one shared atomic entrypoint only on the ten pages that expose a visible file input, preserving native hover, focus, invalid and disabled states while reducing global CSS.

  • Bootstrap table styles now load through one shared entrypoint only on the eight administrative pages that render tabular data, preserving responsive tables while removing the module from the global CSS bundle.

  • Bootstrap modal styles and confirmation markup are now delivered only to authenticated sessions, keeping destructive-action dialogs available while removing unused modal code from anonymous pages.

  • Runtime notices now share the project feedback surface, removing Bootstrap alert styles from the global bundle while preserving semantic live regions and fake-auth feedback variants.

  • Bootstrap now generates only utility families used by the first-party interface, with a contract test preventing removed responsive classes from being introduced silently.

  • Bootstrap grid, containers and navbar remain available where structurally required, while the unused button-group module and nine unconsumed helper families no longer inflate the global stylesheet.

  • Shared performance-panel declarations are consolidated without introducing presentational utilities or changing selector specificity, restoring the blocking Sass architecture budget.

  • Bootstrap's selective Sass adapter is now resolved through the vendor dependency boundary, removing build-time deprecation noise without hiding first-party warnings or increasing the compiled CSS bundle.

  • Frontend budgets and saved Lighthouse measurements now live in a dedicated admin performance page, with complete asset and per-page resource inventories; Analytics and Performance are reached from the admin dashboard instead of the global navigation.

  • Production frontend builders now share the repository Prettier exclusions, use npm 12.0.2 consistently, and distinguish advisory Sass reduction targets from fail-closed structural budgets.

  • Shared joke demonstrations now avoid stealing input focus or scrolling the viewport on touch devices, and cancel simulated typing during navigation.

  • Fake authentication jokes now keep dialogs, cues, dodge controls and side effects inside 320px viewports, with non-blocking inline feedback.

  • The cache-letter joke now animates an aria-hidden visual copy, remains dispersed after the animation and restores the original markup only through its explicit regeneration control.

  • Setup locale, primo deploy e aggiornamenti production now have separate command-by-command runbooks, while environment templates document supported values and constraints inline.

  • Static portfolio imagery now uses deduplicated responsive WebP/AVIF variants generated reproducibly during the production build, without retaining byte-identical legacy aliases in the public tree.

  • Production startup diagnostics now identify the invalid environment variable without exposing its secret value.

  • Production deploys now detect persisted MySQL credential drift before migrations without changing or deleting database volumes.

  • Production deploy scripts now initialize a missing private release-state directory while continuing to reject unsafe existing paths and permissions.

  • TLS preflight now validates root-owned Certbot material through constrained non-interactive privilege escalation instead of weakening private-key access.

  • Existing healthy production containers can now initialize missing atomic release state through an explicit OCI- and asset-verified bootstrap action.

  • Collection tabs, project skill filters, pagination, URL history, and connection-aware prefetch now share a progressive server-rendered contract.

  • The UI Kit inventory and technical documentation now reflect the layered SVG avatar, current component catalogue, and reproducible quality budgets.

Fixed

  • Production images now include the private Markdown archive required by the authenticated documentation browser, and build validation rejects missing documentation or incomplete translation schemas across all five locales.

  • The maintenance page language controls now switch the static 503 response even while Laravel is serving its pre-rendered deploy maintenance page or PHP-FPM is temporarily unavailable.

Security

  • Public component previews exclude administrative actions, operational state, mutation routes, and private configuration.
  • Contact request personal fields are encrypted, omitted from list queries and audit logs, and removed by a scheduled retention command.

2026.07.28

Added

  • A code-based interactive homepage avatar with keyboard-safe animations and an administrative comparison workspace.
  • Public technical documentation covering architecture, project overview, and case studies.

Changed

  • Collection filters now update asynchronously while preserving URL history, focus, and a stable card layout.
  • Project, hobby, skill, CV, and navigation interfaces now share reusable components and consistent interaction states.

Fixed

  • Production images now normalize immutable application and public-file modes, preventing restrictive host checkout umasks from blocking PHP-FPM or Nginx.
  • Improved mobile navigation, pagination, dropdown focus handling, form controls, and audio feedback across mouse and keyboard interactions.

Security

  • Administrative routes, content editing, media tools, and analytics remain protected by server-side authorization and audit middleware.