SleepyZoneBack to Watch
Change Log

Latest release

Version 1.2.1

SleepyZone 1.2.1

October 7, 2026

Settings Control Center and management QoL updates, plus the completed custom-domain cutover to sleepyzone.dev, canonical /schedule routing, branded Worker 404 handling, and multi-origin Direct R2 compatibility. Playback/video source remains protected by the existing SHA-256 gate.

Previous releases
Version 1.2.0SleepyZone 1.2.0October 4, 2026

Safety-focused viewer QoL, source-package integrity, and release validation update. Playback/streaming source remains frozen and protected by SHA-256 regression gates.

  • Fixed clean-source packaging so generated Windows Host test bin/obj output is excluded and rejected by release validation instead of being shipped in the source ZIP.
  • Added a protected playback/streaming SHA-256 gate covering the frozen player, Host streaming stack, delivery clients, host stream route, and playback-sensitive app-events source.
  • Fixed Live Chat viewer grammar so a single active viewer displays as 1 viewer while plural counts display viewers.
  • Fixed Viewer List cutoff and scrolling issues: long usernames now ellipsize before status text, Synced/Watching/Online stays readable, horizontal overflow is blocked, and vertical mouse/touch scrolling stays contained in the list without changing viewer presence or sync logic.
  • Added browser-local chat draft recovery that restores unsent text after reload/navigation and clears it after a confirmed send without adding D1 writes.
  • PopcornBot Bot Appearance now supports an editable solid color or static 2–3 color gradient, reusing the existing username-gradient rendering effect and updating live in chat without a D1 migration.
  • Renamed the built-in SleepyZone chat command !playing to !now across the website command flow and Windows Host PopcornBot UI/runtime; the separate Discord slash command /playing is unchanged.
  • Fixed the Windows Host PopcornBot gradient editor layout so Style, third-color toggle, color labels, picker buttons, Reset, and HEX fields remain aligned and readable instead of clipping inside the Bot Appearance card.
  • Added Copy Username to the existing chat message menu without changing Reply, Copy Message, moderation, or message transport.
  • GIF picker keeps Clear Search, removes the Recent/Searches history rows, and restores reliable mouse/touch scrolling through GIF results without changing GIF providers or chat delivery.
  • Full profile pages now remember the browser-local Recently Watched expanded/collapsed preference.
  • The Popcorn leaderboard highlights the logged-in viewer using the existing authenticated leaderboard response without changing ranking or Popcorn calculations.
  • The Watch page now shows a small browser-local NEW marker for Change Log releases the viewer has not opened yet.
  • The Windows Host Logs toolbar can wrap at narrower window sizes while preserving WordWrap and all existing log generation behavior.
  • No D1 migration is required for 1.2.0; migrations 0001 through 0009 and existing production data remain unchanged.
  • Playback, streaming, MediaMTX, FFmpeg, MovieStreamer, Direct R2, HLS recovery/synchronization, and PartyRoom lifecycle behavior were not intentionally changed.
  • Legacy portable-data recovery now recognizes both historical sibling data-folder names as read-only copy-missing sources while current Data always wins.
  • 7TV is now enforced as Owner/Moderator-only end to end: regular Members do not load or render 7TV sets and the Worker rejects Member access to the 7TV proxy routes; shared custom emotes remain unchanged.
  • Hardened GIF-provider credentials: GIPHY/KLIPY keys are no longer returned to browsers, provider search/share calls run through authenticated Worker routes, and KLIPY is declared as a required Cloudflare Worker secret instead of being committed in wrangler.jsonc.
Version 1.1.9SleepyZone 1.1.9October 3, 2026

Internal maintainability and source-structure release. The tested 1.1.8 behavior is preserved while large core files are separated into focused modules for safer future updates.

  • Split the Windows PopcornBot settings UI from one oversized MainForm partial into focused Status, Appearance, Points, Built-ins, Timers, Commands, and shared helper files without changing command or timer behavior.
  • Split the browser chat source into coordinator, rendering, realtime, and moderation modules while preserving the generated browser bundle behavior and existing GIF, emote, mention, reply, and reconnect flows.
  • Split the main Cloudflare Worker entrypoint into focused site, account, emote/invite, dashboard/media, and calendar/GIF helper modules while keeping existing API paths, authentication, status codes, and bindings unchanged.
  • Extracted PartyRoom command/game, PopcornBot queue, engagement/points, and message-storage helpers while keeping Durable Object construction, WebSocket lifecycle, presence, alarms, host sequencing, and reconnect fencing centralized.
  • Split the Windows HostController into core, Movie, Monitoring, and Lifecycle partials while preserving Start/Stop/Recover behavior, Direct R2, MediaMTX, Tailscale fallback, Discord lifecycle, telemetry, and stream-state behavior.
  • Split PopcornUi into focused card, button, status/control, and select-control files without changing the visual design or control behavior.
  • Added structural regression helpers/tests so future releases validate the split source as a single behavioral surface instead of assuming each subsystem lives in one file.
  • No new D1 migration is required for 1.1.9; production data and migrations 0001 through 0009 remain unchanged.
Version 1.1.8SleepyZone 1.1.8October 2, 2026

Semi-big reliability, recovery, storage, telemetry, structure, deployment, and accessibility update built on the stabilized 1.1.7 player.

  • Added manual Start From Time for Movie File Mode plus a portable crash-recovery checkpoint with explicit Resume, Start From Beginning, or dismiss behavior.
  • Crash-resumed movies retain a stable playback identity so Passport/watch tracking does not count the resumed half as a new movie.
  • Added measured OBS ingest and Direct R2 upload telemetry plus source resolution/FPS/audio/codec, reader counts, recovery counts, fallback counts, encoder speed, and free-disk reporting.
  • Added profile avatar removal and real 40/128/256/512 avatar variants with revision-safe replacement and account-delete cleanup.
  • Added shared-media storage statistics and reference-aware Calendar artwork cleanup with a 24-hour safety grace period.
  • Added bounded Calendar/moderation history retention with additive D1 migration 0009 while preserving active Undo records and enforcement data.
  • Completed KLIPY pasted/share-link recognition alongside the existing integrated GIF search.
  • Aligned Content Security Policy with the actual app by externalizing startup scripts while explicitly allowing the inline styles still used by the current UI runtime.
  • Added modal keyboard focus containment, Escape close where supported, and focus return without changing player/chat controls.
  • Centralized web release metadata in release.json, pinned Wrangler 4.129.0, declared Node 22, added npm test, and made generated web assets inherit the current release/build identity.
  • Removed the obsolete Discord Going Live banner resource and renamed the remaining branding flag to match its compact thumbnail behavior.
  • Added migration 0009, current-release validation cleanup, stronger packaging gates, and refreshed operational documentation.
  • Fixed iPad/WebKit GIF-picker crashes and black chat media by using static/lightweight touch previews, bounding mobile picker/chat DOM work, and removing mobile image src unloading without changing the HLS player.
Version 1.1.7SleepyZone 1.1.7October 1, 2026

Discord Movie Night presentation, iPad/WebKit long-session stability, viewer-presence accuracy, lightweight color themes, and Owner-controlled Supporter username gradients.

  • Added automatic per-browser Connection Assist for unstable or long-distance routes. There are no viewer buttons or settings: healthy viewers keep normal playback, while only a browser that repeatedly enters genuine recovery gets temporary extra live-edge headroom without changing the stream for anyone else.
  • Fixed iPad chat/GIF keyboard interaction across Safari, Chrome, and Firefox: iPadOS is detected by touch capability, chat keeps its trusted-touch focus fallback, and the pre-keyboard watch viewport is frozen so typing or GIF search cannot resize/reposition the video stage and provoke a native-HLS reconnect cycle.
  • Mobile/tablet reconnect recovery now automatically resumes at the live position and restarts playback after a genuine recovery, so viewers no longer need to press Jump to Live after the stream reconnects; ordinary manual rewind/behind-live playback is still respected when no recovery is active.
  • Isolated GIF browsing/sending from video playback: touch devices load fewer results, preview stills are preferred and low-priority, hidden GIF previews are removed, GIF sends render the returned chat message directly instead of forcing an extra state refresh, and touch devices no longer auto-open the keyboard when the picker opens or after a GIF is sent.
  • Replaced native browser username color dialogs with a SleepyZone-built inline color editor: saturation/brightness field, hue rail, HEX entry, and vivid quick-pick colors all stay inside the site on desktop and mobile.
  • Supporter gradient usernames now render with stronger saturation/brightness, held endpoint colors, and a subtle readability glow so 2-color and 3-color names stand out more without changing the saved HEX values or adding animation.
  • Viewer List now actively reconciles presence through the existing PartyRoom WebSocket while the list is open. It refreshes the live Synced/Watching/Online snapshot every 12 seconds without a new recurring D1 viewer query, and stale lease cleanup is broadcast only when actually needed.
  • Added optional Movie Night flyer support to the Windows EXE Discord tab. PNG/JPG/JPEG flyers up to 8 MB are copied into portable Data\Discord and posted as a separate full-width image embed so flyer text remains clear and readable.
  • Going Live announcements automatically clean release-style filenames into readable movie titles, keep playlist order, and include the year when it can be detected.
  • Tonight's Lineup now displays each movie on its own clean line instead of joining the playlist with arrows, keeping every title uniform and easy to read in Discord.
  • When Start Host is pressed, SleepyZone reuses cached Media Library durations and measures any missing queued-movie durations with ffprobe so the Going Live announcement can show Total Playtime without requiring a full library scan.
  • If a queued movie still cannot be measured, SleepyZone shows the known playtime plus the remaining pending count instead of inventing a duration.
  • Added Discord link buttons for WATCH, SCHEDULE, CHANGE LOG, and LEADERBOARD while retaining the existing raw clickable URLs in the embed text.
  • Added an optional Event Name field in the Discord tab. When set, names such as DYSTOPIA, Resident Evil Marathon, or Spooktober become the Going Live embed heading; otherwise SleepyZone is Live remains the fallback.
  • Added Discord/Flyer preflight status before Host start, including bot/channel readiness, selected flyer validity, and missing playlist-duration warnings. Discord warnings remain non-blocking for video hosting.
  • Added optional Auto-clear flyer after Movie Night ends. When enabled, SleepyZone removes only its portable current flyer and clears the saved selection after normal Host shutdown so the previous event poster cannot be reused accidentally.
  • SEND TEST previews the event name, cleaned playlist lineup, currently known playtime, link buttons, packaged SleepyZone branding, and selected flyer while keeping the Discord gateway Offline.
  • Discord Going Live remains isolated from playback: flyer, REST, or Discord failures are logged and skipped without stopping Movie File, OBS/HLS, chat, Cloudflare, accounts, PopcornBot, rewards, or the viewer website.
  • iPad/iPadOS long-session stability: Direct R2 Movie File and OBS playback URLs now remain valid for 12 hours, preventing the old 75-minute authorization window from forcing native Safari/Chrome HLS source replacement during ordinary movies.
  • Native WebKit authorization renewal is now an emergency-only 90-second safety path instead of a 20-minute proactive video reload window; genuine stalled playback still uses the existing bounded recovery sequence.
  • Healthy Direct R2 viewers now use a two-hour control-plane safety reconciliation instead of a 30-minute refresh while WebSocket stream events continue to deliver real stream changes immediately.
  • Removed the redundant forced Watching/Synced WebSocket frame that used to accompany every 30-second ping. The ping already renews the watch lease, and a separate watching frame is now sent only when viewer state actually changes.
  • Throttled long-session engagement bookkeeping: Popcorn watch rewards are checked at most once per minute on routine pings and Movie Night Passport progress is checkpointed at most once every two minutes, while real watch start/stop state changes still process immediately.
  • Passport stop handling now banks the final bounded watch interval before clearing its anchor so lighter checkpointing does not discard legitimate watch time.
  • Profile-stat broadcasts still only invalidate the affected cached profile; profile data is re-fetched only when that viewer profile is actually open, so Profiles remain enabled without becoming a playback trigger.
  • iPad media hardening: Movie File Mode now outputs H.264 Main Level 4.1, yuv420p, constant-frame-rate video capped at 30 fps, with a 4.2 Mbps target and 4.5 Mbps VBV ceiling to prevent action-heavy scenes from producing large bitrate/decoder spikes.
  • Movie File HLS now uses a fixed four-second GOP aligned to the existing four-second MPEG-TS segments, preserving independent segment boundaries while keeping the existing 120-second live window.
  • Movie File audio is now AAC-LC 48 kHz stereo at 160 kbps for a conservative Apple-compatible media path without changing subtitle or playlist behavior.
  • iPad/mobile player recovery now uses slower escalating backoff instead of rapid retries. Native WebKit preserves the current decoder/session through the first three attempts and permits only bounded source rebuilds with a 45-second hard-reload cooldown.
  • Same-version iPad/WebKit reconnect fix: native HLS waiting/stalled events no longer show a Reconnecting overlay during ordinary short buffer refills; the existing frozen-playback watchdog now owns reconnect UI on iPad/iPhone.
  • Safari/WebKit playback progress is now authoritative recovery evidence. timeupdate/canplay/loadeddata can clear a stale reconnect overlay even when WebKit resumes without firing another playing event.
  • Prolonged native-HLS not-ready periods now receive a safe play() nudge before bounded recovery, without changing the video source or creating a reload loop.
  • When a genuine native-HLS stall finally requires a bounded source rebuild, SleepyZone now uses the freshest signed URL already returned by stream status for the same R2 object instead of reloading the older URL that had stalled.
  • Reduced hls.js mobile memory pressure by trimming forward/back buffer limits while retaining extra live-edge headroom for brief Wi-Fi or timer stalls.
  • Expanded privacy-safe Player Diagnostics with media error name/code, playback position, approximate movie segment, buffer-ahead time, video dimensions, network state, and dropped/decoded frame counters. The Player Error screen now includes the last media error and movie position when available.
  • Windows Host HLS delay/freeze logs now include movie title, playback position, source resolution/frame rate, encoder, and exact newest segment name so a failing movie timestamp can be correlated with the viewer report.
  • Hardware encoder selection now probes the exact iPad-safe profile, rate-control, frame-rate, and GOP options before Movie File startup; an incompatible NVENC/QSV/AMF path is skipped so SleepyZone can fall through to another working encoder instead of failing after selection.
  • Watching/Synced presence now reacts immediately to player buffering and recovery transitions: waiting/stalled playback drops Synced to Watching, playing/canplay restores Synced only when the viewer is actually near the live edge, and unchanged timeupdate checks do not send duplicate WebSocket frames.
  • Viewer list presence is now explicitly separated into Synced, Watching, and Online groups for regular viewers, so a viewer confirmed at the live edge no longer appears under the Watching section.
  • Added Owner-controlled Supporter Gradient access: solid username colors remain available to every account, while the Owner can selectively enable static 2-color or 3-color gradients for supporter accounts from Accounts & Moderation.
  • Supporter gradients remain synchronized to everyone in chat through the existing real-time user-style refresh path. The server authoritatively blocks gradient use unless that account has Gradient Access enabled.
  • Gradient rendering remains Safari/iPad compatible with standard and -webkit text clipping, has no animation loop, and immediately falls back to the normal solid username color when Supporter Gradient access is revoked.
  • Added additive D1 migration 0007 for username style mode and optional second/third gradient colors. Existing accounts, solid username colors, bans, chat, playback, Popcorn/rewards, profiles, schedules, HOST_KEY, and portable Data are preserved.
  • Added additive D1 migration 0008 for the per-account Supporter Gradient entitlement. Access is OFF by default; disabling access preserves saved gradient colors so they can return if the Owner enables access again later.
  • Promoted the release to SleepyZone 1.1.7 and updated Windows, Worker, browser, build/deploy, generated Change Log, diagnostics, and release-validation markers while retaining the iPad/player stability patch.
  • Simplified the three event themes into lightweight color themes only. Resident Evil, Fallout, and Horror Movie Month now change static site colors without loading event artwork, animated banner layers, or theme-specific header decorations.
  • Removed the website top event banner and its three packaged banner assets. The existing Resident Evil, Fallout, and Horror Movie Month viewer badges are retained and still update live for everyone.
  • Cleaned up Settings > Colors & Badges into one compact single-choice palette selector with an explicit SleepyZone Blue default, so switching colors no longer uses three independent on/off toggles.
  • 7TV configuration and shared-set management are visible to staff only: Owner and Moderators can view and load the shared 7TV set, while regular Members cannot see those settings. Shared/default emotes remain available to logged-in viewers through the normal emote picker.
  • Refined chat mentions: the visible MENTION label is removed, while @username and messages that tag you keep a clear non-glowing highlight so mentions remain easy to spot.
  • Reduced iPad/iPhone Safari memory pressure during long watch sessions by decoding animated chat GIFs/emotes only near the visible chat viewport, releasing off-screen media and picker previews when hidden, and bounding the shared GIF preview cache without changing desktop playback or adding viewer controls.
  • Changed account sessions to a rolling 30-day login: active viewers quietly renew in the background, temporary auth-status/D1/network failures show an automatic reconnect state instead of falsely sending viewers to Login, and long-lived PartyRoom WebSockets now refresh their authoritative session expiry from D1 instead of closing on a stale cached expiry.
  • Mini profiles, full profile pages, and the Popcorn leaderboard now render each viewer's authoritative solid username color or enabled 2–3 color Supporter gradient instead of falling back to plain white text.
  • The Popcorn Points label and leaderboard ranks #1, #2, and #3 now use SleepyZone blue instead of green.
  • Full profile Recently Watched history is now collapsed by default and can be reopened or hidden with an accessible toggle, reducing long-profile scrolling.
Version 1.1.6SleepyZone 1.1.6September 29, 2026

Viewer Engagement Update plus an optional host-controlled SleepyZone Discord bot with live/movie/end announcements and slash commands. Existing streaming and account/data systems remain unchanged.

  • Compact viewer profiles + optional avatars
  • Movie Night Passport: Movies Watched + Popcorn
  • Owner/Mod polls: 1/2/5/10 min or manual (5 min default)
  • Additive D1 migration 0006; existing accounts, bans, chat, playback, Popcorn/rewards, schedule, themes, HOST_KEY and portable Data are preserved
  • Avatar stability isolation: avatar uploads remain in persistent R2, but runtime Cloudflare Images transformations are bypassed so the watch/chat Worker path has no Images dependency; uploaded avatars are already cropped/compressed to 512 px by the browser.
  • Avatars appear only in the viewer info card/popout, full profile page, and Popcorn leaderboard; chat and the viewer list remain avatar-free.
  • Added dedicated /profile/<username> pages with Movie Night Passport totals, Popcorn, member-since date, last watched title, and recent movie history.
  • Existing pre-1.1.6 D1 data-URL avatars remain readable, so the avatar storage upgrade does not require a destructive migration.
  • Cloudflare Stream is not used by SleepyZone 1.1.6, and this stability build also removes the IMAGES Worker binding while keeping authenticated R2 avatar delivery working.
  • Added a dedicated Discord tab to the Windows host for the SleepyZone Discord bot with matching rounded cards, token/server/channel/role setup, status, presence, announcements, and test controls.
  • The SleepyZone Discord bot remains installed in the server permanently, connects only when the SleepyZone Host starts, and returns to Offline when the Host stops or the EXE closes.
  • Discord Going Live announcements now post immediately when Start Host succeeds and include the SleepyZone watch link; optional Now Playing/movie-change and Movie Night Ended announcements remain isolated from playback.
  • Added Discord slash commands /playing, /next, /status, /watch, /schedule, and /leaderboard without enabling Message Content intent or reading normal Discord messages.
  • Compacted the Discord slash-command display, removed the Custom Discord Post composer, and made Start Host Going Live embeds automatically include the packaged SleepyZone moonlight banner beneath the message.
  • Discord server/channel/role discovery and Send Test use REST while the gateway is offline, so setup does not leave the bot Online outside a Host session.
  • Discord connection failures and reconnects are isolated from streaming, chat, Cloudflare, Popcorn/rewards, and the existing website PopcornBot; Discord errors are logged without exposing the bot token.
  • Recently Watched and Last Watched now convert release filenames into clean display titles, including TV episode labels such as Silo Season 1 Episode 7 and movie title/year labels such as Halloween 1978.
  • Removed the Movie Nights stat tile from the compact and full viewer profile Passport while keeping Movies Watched and Popcorn.
  • Expanded PopcornBot custom-command placeholders: {mention} now tags the person who used the command; @{randomuser} selects a random currently logged-in SleepyZone user (preferring someone other than the caller when possible); and {randommention}, {next}, {args}, {online}, {watching}, {time}, and {date} are now supported alongside {user} and {playing}.
  • Same-version mobile/iPad stability hotfix: coalesced Safari visibility, focus, pageshow and online resume signals into one recovery cycle so a single wake-up cannot trigger overlapping chat/socket and stream-status reconnect work.
  • Same-version theme stability hotfix: unchanged themes no longer reapply their body classes during routine state reconciliation, and animated event-banner effects are disabled on coarse-pointer touch devices to prevent WebKit repaint flashing after tab/app suspension.
  • Same-version iPad video hotfix: native Safari HLS now ignores brief readyState/buffering dips and foreground-resume jitter instead of immediately replacing the video source, preventing the visible reconnect/flash loop reported on iPad while leaving Android/desktop playback behavior unchanged.
  • Native-HLS recovery keeps the existing 18-second desktop grace while phones/tablets use a 45-second grace, retries playback in place before any source replacement, and rate-limits hard video-source reloads; signed Direct R2 source replacement is limited to a genuinely rotated URL near authorization expiry.
  • Same-version cache refresh: bumped the 1.1.6 browser build marker to sz116-20260930d so iPad Safari fetches the native-video recovery fix immediately after deployment.
  • Mobile/tablet reconnect stabilization: healthy browser focus/resume events no longer refresh or restart the live player; Direct R2 renewal now follows the URL actually loaded by the player and renews inside a 20-minute safety window before the 75-minute authorization expires; same-stream signature rotation stays buffered until renewal is needed; realtime liveness tolerates mobile timer throttling; browser build marker is sz116-20260930g.
  • Same-version Images isolation diagnostic: comparison with the stable 1.1.5(6) build showed the first 1.1.6 engagement release added the IMAGES binding while core video-player logic was unchanged; build sz116-20260930g removes that runtime dependency to isolate the reconnect regression without removing avatars, profiles, polls, Passport data, or the paid Cloudflare subscription itself.
  • Mobile/tablet smooth-playback hardening: Movie File and OBS HLS now retain a 120-second live history instead of ~24 seconds; mobile/tablet hls.js keeps extra live-edge/buffer headroom and retries transient failures without rebuilding the source until the final bounded recovery attempt; native mobile HLS receives a 45-second stall grace; and a temporary stream-status request failure can no longer disturb already-buffered playback. Desktop playback timing remains on the existing profile.
Version 1.1.5SleepyZone 1.1.5September 29, 2026

One GIF button now uses one search box and one mixed KLIPY + GIPHY result grid, with the KLIPY browser-network fix and the full September 30 stable-audit hardening carried into 1.1.5. The existing 1.1.4 connection-stability fixes remain intact. Same-version viewer engagement update adds compact viewer profiles with optional avatars, Movie Night Passport counts, timed Owner/Moderator polls without changing the streaming pipeline.

  • Added KLIPY as a second GIF source inside the existing single GIF button and picker.
  • Removed the provider tabs: Search and Trending now query enabled KLIPY and GIPHY sources together from one search box and interleave both libraries in one result grid.
  • Fixed the KLIPY NetworkError by adding https://api.klipy.com to the site Content Security Policy connect-src allowlist in both Worker-served HTML and static headers.
  • A failure or rate limit from one GIF provider no longer blocks the other provider: successful results remain visible in the combined grid and the status line reports the failed source.
  • KLIPY share tracking still fires after a KLIPY GIF is posted, and result cards retain their provider identity so chat keeps provider-specific validation.
  • KLIPY is configured in the private Cloudflare build through Worker configuration, while the existing Owner-managed GIPHY D1 settings continue to work unchanged.
  • Stable-audit fix: MediaMTX stale PID ownership markers are retained when cleanup cannot be confirmed, and shutdown verifies process exit before claiming success.
  • Stable-audit fix: Movie File FFmpeg now persists exact PID plus process start time, safely recovers an owned stale process after a crash/relaunch, and refuses to kill a reused unrelated PID.
  • Stable-audit fix: FFmpeg stop failures keep ownership state for retry instead of allowing a duplicate publisher to start.
  • Stable-audit fix: Tailscale Funnel can re-adopt the existing Popcorn local-gateway mapping after an unclean exit, protects unrelated 443 mappings, and retains ownership when Funnel shutdown fails.
  • Stable-audit fix: Local Gateway and partial host-start cleanup failures now produce subsystem-specific log entries instead of being silently swallowed.
  • Updated Windows host, Worker, helper User-Agent, build markers, release builder, deploy scripts, validation gates, and generated website assets to 1.1.5.
  • Preserved the 1.1.4 mobile Wake Lock, WebSocket heartbeat, Direct R2 recovery, bounded player recovery, failover grace-window, permanent-ban, themes, schedule, rewards, PopcornBot, and portable Data protections.
  • Same-version deploy hotfix: GIF provider regression tests now use Windows-safe file URL path conversion, preventing drive-letter duplication and encoded-space ENOENT failures during DEPLOY_CLOUDFLARE.bat validation.
  • Same-version branding hotfix: added a standard /favicon.ico plus explicit 16x16/32x32 favicon links using the SleepyZone raccoon mark so browser tabs and newly created bookmarks no longer fall back to the generic globe icon.
  • Same-version bookmark icon hotfix: favicon assets now use standard root URLs and cacheable icon-specific responses so Chromium-based browsers can persist the SleepyZone raccoon icon in bookmarks instead of falling back to the globe.
  • Same-version cleanup: removed the unused Default/Main Theme Header customization from Settings → Themes, including custom header text, text sizing, custom font uploads, the live header title lane, and its realtime/API code. Existing event themes and backend data remain untouched.
  • Same-version branding hotfix: corrected the login-page wordmark to SleepyZone, with Sleepy in white and Zone in the cyan-to-blue treatment used by the new raccoon logo.
  • Same-version visual refresh: changed the default watch-room palette from green to the redesigned SleepyZone EXE colors, using dark navy/charcoal surfaces with #31A9FF blue accents while leaving Resident Evil, Fallout, and Horror Movie Month event themes unchanged.
  • Same-version branding cleanup: newly generated invite codes now use the SZ- prefix and the signup placeholder matches it; existing legacy invite codes remain valid because invite verification is hash-based rather than prefix-based.
  • Same-version host branding cleanup: current host-version metadata now reports SleepyZone 1.1.5 while compatibility namespaces, storage paths, D1 filenames and other internal legacy identifiers remain unchanged.
  • Same-version release hardening: bumped the browser asset build marker to sz115-20260929l and added regression checks for SleepyZone-visible branding, SZ invite generation, PWA icons and D1 migration mirror consistency.
  • Improved in-chat @mentions so messages that tag you now show a visible MENTION badge, a stronger row highlight, and more readable mention pills inside the chat body.
  • Fixed viewer profile stat refresh so Movie Nights, Movies Watched, Last Watched, and Popcorn use fresh authoritative data when the card opens and update live when Passport or Popcorn balances change.
  • Same-version deploy hotfix: normalized Windows batch files to CRLF and added a release gate for the Cloudflare auth-repair subroutine so cmd.exe can reliably resolve :repaircloudflareauth after a stale Wrangler OAuth/D1 authorization check.
  • Same-version viewer profiles: clicking an active viewer or chat username can open a compact profile showing Movie Nights, Movies Watched, Popcorn, and a simple Passport tab.
  • Same-version avatar support: each logged-in viewer can upload a square profile avatar from their own device; the browser crops/compresses it to 256×256 and the account can display it in the profile and top account box while initials remain the fallback.
  • Same-version Movie Night Passport: active Movie File viewing now records one movie after 10 minutes of watch time and counts distinct Vancouver-local movie nights; the Passport intentionally contains only Movie Nights and Movies Watched.
  • Same-version Owner/Moderator polls: one poll can be active above chat with 1, 2, 5, or 10 minute durations or manual end, one vote per viewer, live totals, and a 5-minute default.
  • Same-version profile cleanup: removed the duplicate Overview / Passport tabs and combined viewer stats into one compact profile, adding Member Since and Last Watched from existing account/passport data without adding another D1 migration.
Version 1.1.4SleepyZone 1.1.4September 28, 2026

Connection-stability hotfix for viewer chat and live video. Short Cloudflare/D1/Direct R2 hiccups are absorbed without unnecessarily rebuilding healthy sockets or players, while existing bounded recovery and Tailscale failover remain in place.

  • Mobile screen-awake hotfix: while an active stream is open, Screen Wake Lock now survives player buffering/playlist transitions and is re-requested directly from real tap/keyboard gestures for Safari/WebKit, so a 30-second phone Auto-Lock timer does not black out playback just because chat is idle.
  • Viewer chat heartbeat replies now return before the periodic D1 session re-check, preventing a slow database response from making an otherwise healthy WebSocket miss its browser liveness probe and reconnect.
  • Direct R2 non-fatal HLS network errors are left to hls.js built-in retry logic instead of immediately escalating into a full player recovery sequence; fatal errors and the frozen-playback watchdog still trigger bounded recovery.
  • Player recovery now refreshes Cloud stream state only at the beginning and midpoint of a recovery sequence instead of on every retry, reducing request pressure and signed-URL churn during unstable connections.
  • The Direct R2 relay no longer flips viewer readiness off after only a few rapid sync failures once playback is already live; it waits for the upload pump to be genuinely stale.
  • The Windows host keeps an already-live Direct R2 stream advertised online for a short grace window while the one-way Tailscale emergency failover comes up, preventing online/offline heartbeat flapping from tearing down viewer playback.
  • Preserved the six-attempt bounded player recovery limit, manual Try Again, stream revision protection, PopcornBot reconnect behavior, watch leases, permanent-ban protections, themes, schedules, accounts, rewards and portable Data.
Version 1.1.3SleepyZone 1.1.3September 25, 2026

Permanent-ban hardening and theme-rendering stability. Invite-only account lineage is preserved for moderation, banned accounts remain reserved until explicitly unbanned, and desktop/mobile theme first-paint flashes are suppressed.

  • Permanent bans now retain the banned account as a protected record until the Owner explicitly unbans it; banned accounts cannot be renamed or deleted while the ban is active.
  • Ban enforcement now removes every active login session, sends force-logout before severing live sockets, tears down active browser playback, closes matching WebSockets, and blocks the banned account from obtaining fresh playback state.
  • Invite-only ban-evasion protection: the invite that originally created an account is preserved as persistent account lineage and is automatically revoked when that account is banned.
  • Accounts & Moderation now shows the registration invite hint and invite-use time when available, making it easier to trace which invite created an account.
  • New additive D1 migration 0005 preserves account-to-invite origin records and safely backfills existing invite-created accounts without deleting current users, sessions, chat, balances, schedules, or settings.
  • Theme first-paint fix: add an inline dark browser canvas/background before external CSS loads so reloads, tab restores, and slower mobile/desktop paints cannot briefly fall back to the browser default white page.
  • Theme rendering hardening: keep explicit dark background-color fallbacks on html/body/app surfaces and replace filter-based banner pulse animation with compositor-safer opacity/shadow animation to reduce browser repaint flashes.
  • Preserved existing Resident Evil, Fallout and Spooktober artwork, Owner theme controls, Movie/OBS playback, Direct R2 delivery, Tailscale fallback, chat, PopcornBot, rewards, schedule, accounts and portable Data.
Version 1.1.2SleepyZone 1.1.2September 18, 2026

Player stability update: bounded HLS recovery, signed R2 authorization renewal, less subtitle work, and private browser diagnostics. Existing playback controls, chat, streaming delivery and portable Data are preserved. Same-version hotfix: viewer presence/sync reconciliation and PopcornBot transport diagnostics.

  • Player recovery: only one automatic recovery sequence runs at a time. Stop all automatic HLS retries after six attempts, then offer Try Again without freezing the page in a restart loop.
  • Recovery success: reloading a manifest alone no longer clears the retry counter. Require playable buffered fragments or real playback progress; stalled playback requires the movie clock to advance.
  • Direct R2: refresh stream status before a signed URL expires, recognize renewed credentials for the same media object, and retain the existing player and Worker request-budget protection.
  • Error diagnostics: record a bounded local history of player failures, HTTP response codes, connection method, recovery attempts and outcome. Player Settings now has Copy diagnostics; keys, signed URLs, chat and account data are excluded.
  • Subtitles: skip unnecessary full-track retiming when subtitle offset and timeline are unchanged, and only alter individual cues whose times actually changed.
  • Preserved Movie File Mode and OBS/HLS, Direct R2 primary delivery, Tailscale emergency fallback, manual Jump to Live, native/mobile playback, accounts, roles, chat, PopcornBot, rewards, themes, schedule and portable Data.
  • Validation: add player regression coverage for repeated errors, retry exhaustion, manifest-only recovery, signed URL expiry, diagnostics redaction and subtitle no-op performance.
  • 1.1.2 hotfix: Twitch iframe viewers report Watching while their embedded stream is open; Twitch cannot claim Movie/OBS sync without access to iframe playback state.
  • 1.1.2 hotfix: refresh stream status after recovered chat connections, reassert current player status when opening the viewer list, and reconcile stale presence without adding periodic HTTP polling.
  • 1.1.2 hotfix: ignore closing sockets and prevent an older HTTP viewer-list result from overwriting fresh WebSocket presence. Broadcast sync resets when stream revisions change.
  • 1.1.2 hotfix: stop sending unused presence/stream broadcast events to PopcornBot, correlate Durable Object WebSocket errors, and avoid duplicate cleanup error reporting. External abnormal closures may still occur; automatic reconnect remains in place.
Version 1.1.1SleepyZone 1.1.1September 17, 2026

1.1.1 reliability hotfix: scoped R2 cleanup, complete chat history catch-up, connection diagnostics, atomic message receipts and bounded broadcast logging. Existing media and Data preserved.

  • PopcornBot: establish a PartyRoom hello handshake before reporting Connected; add bounded connect/handshake timeouts and log socket close codes and reasons.
  • PopcornBot: separate the timer supervisor and independent heartbeat task so failed timers do not take down a healthy chat connection.
  • PopcornBot: diagnose interruptions with reconnect counts and durations, preserve reconnect backoff across unstable short sessions, and restart an unexpectedly completed reconnect loop without restarting the stream.
  • PopcornBot timers: retain a pending message ID until the PartyRoom acknowledges delivery, then reset its interval and line count; unconfirmed sends retry with the same ID.
  • PartyRoom: add additive Durable Object schema v4 with receipt tables for chat requests and bot timer messages; duplicate retries do not repost or repeat Popcorn awards or commands.
  • Viewer chat: use a handshake timeout, longer stale-socket probe, jittered reconnect backoff and browser close diagnostics for network/device suspension recovery.
  • Viewer chat: distinguish expired or revoked sessions from ordinary network failures; keep composer text and reply state intact while reconnecting and restore missed chat through the existing state poll.
  • Viewer chat: create and reuse an idempotency ID for uncertain chat sends, allowing manual retry without double-posting.
  • Performance: skip no-op bot-style updates and avoid additional HTTP polling; existing 30-second viewer presence heartbeat and 150-second watch lease are unchanged.
  • Host EXE: surface PopcornBot reconnect count and last interruption in the existing bot status panel and diagnostics; retain familiar connection warning and recovery messages.
  • Expanded release tests for additive v4 migration, duplicate chat requests, command retries, timer receipts and ping/pong; preserved Movie/OBS playback, manual Catch Up, Direct R2, Tailscale, saved portable Data, themes, and Popcorn payouts.
  • 1.1.1 hotfix: disable dangerous bucket-wide R2 startup cleanup; reject legacy cleanup requests and require a validated relay session for deletion.
  • 1.1.1 hotfix: paginate chat recovery without skipping retained messages, including older pinned history.
  • 1.1.1 hotfix: correlate bot/viewer connections by ID and ignore messages from replaced bot sockets; preserve existing reconnect warnings.
  • 1.1.1 hotfix: atomically persist accepted chat messages, send receipts and popcorn rewards; commit bot replies with durable command/timer receipts before broadcasting.
  • 1.1.1 hotfix: record rate-limited aggregate chat broadcast failures without chat text or user data.
Version 1.1.0SleepyZone 1.1.0September 13, 2026

Major reliability hardening plus peer-to-peer Popcorn transfers, real Popcorn duels, Magic 8-Ball, and a dedicated Popcorn leaderboard, built additively on the existing 1.0.9 streaming, chat, account, reward, Direct R2, and Tailscale systems.

  • Reliability fix: ignore delayed same-session host-offline events with an older host or stream revision so a newer heartbeat cannot be incorrectly undone.
  • Reliability fix: full calendar backup restores now support up to 250 events in one transactional operation; an import failure rolls back instead of leaving a partially restored calendar.
  • Reliability fix: Cloud heartbeat, host-offline and stale-host expiry updates now use an additive D1 generation guard, preventing concurrent updates from committing stale Cloud state. Migration 0004 is applied before the updated Worker deploys.
  • Reliability fix: Direct R2 signed URL renewal is recognized as the same media object and refreshes the existing player source instead of destroying and rebuilding the player; manual Catch Up is unchanged.
  • Finishing patch: fixed cross-device Popcorn watch-reward timer resets. An idle/closing phone no longer clears watch progress while another device is actively watching; movie stop and final-device disconnect still reset the timer.
  • Finishing patch: enforced the existing 2,000,000,000 Popcorn balance ceiling for chat and watch rewards. Slots check the maximum 20x payout before taking the bet or starting cooldown; unsafe spins are rejected without changing odds, payouts, or current balances.
  • Finishing patch: added owner-side PopcornBot queue lifecycle diagnostics and cumulative counters for received, completed, rejected and expired commands. Logs include command identifiers but never command arguments or private chat text; diagnostic failures cannot block commands.
  • Finishing patch: added behavioural regression tests for multi-device watch leases, capped rewards and full slot payouts, transfers, duels, queued-command ACK/retries and expiry. Tests are required by both the Windows build and Cloudflare release validation gates.
  • Hot fix: added the built-in !givepopcorn @username <amount> command. Any signed-in viewer can transfer Popcorn from their own authoritative balance to another active registered account; self-transfers, invalid/negative amounts, insufficient funds, unavailable accounts, and transfers that would exceed the 2,000,000,000 balance ceiling are rejected server-side. The PopcornBot built-in command panel was also rebuilt as a smaller 3×3 grid so all built-ins fit cleanly, and the reclaimed height is given to the Custom Commands editor/list.
  • Hot fix: added Default/Main theme header customization under Settings → Themes. The Owner can type live header text, size it from 12–38 px, upload WOFF2/WOFF/TTF/OTF fonts up to 4 MB, or remove the font/text. Custom fonts are stored in the existing R2 storage and served to every viewer; the title is hard-clipped to the existing header safe area so it cannot render above or below the bar, and Resident Evil, Fallout, and Spooktober remain unchanged.
  • Hot fix: repaired subtitles after background-tab/app suspension. Returning to the watch tab now refreshes stream state first, re-times the existing Movie File Mode cues, restores the viewer's saved subtitle On/Off state, forces the browser caption renderer to repaint when needed, and reloads only a failed subtitle track with the newest authorized URL without seeking or auto-catching-up the video.
  • Hot fix: removed viewer-list opening lag. The viewer list now opens immediately from the existing realtime presence state instead of waiting on an HTTP/D1 round trip; stale/reconnect fallback refreshes happen in the background, and the fallback D1 query reads only currently present user IDs instead of scanning the full users table.
  • Hot fix: reduced 7TV Load Set UI stalls. Loading a set no longer builds up to 600 hidden emote-picker cells/images while the picker is closed, older reply previews refresh in small low-priority batches, picker images use async/low-priority loading, and duplicate Load Set clicks are blocked while the request is in flight.
  • Hot fix: repaired Movie File Mode and OBS/HLS viewer-list synchronization without automatic playback catch-up. Stream revisions now force each viewer browser to re-report its real Watching/Synced state, the existing 30-second realtime cadence re-confirms that state as a safety net, and manual Catch Up remains the only action that seeks a viewer forward.
  • Hot fix: improved iPad/iPadOS Safari connection recovery. Returning from fullscreen, app switching, a suspended tab, or a network change now immediately revalidates the realtime WebSocket and live stream; stale-open sockets are rebuilt instead of waiting through reconnect backoff, and viewer leases tolerate Safari timer throttling without changing Popcorn reward timing or amounts.
  • Hot fix: duel responses are now the simple !accept and !decline commands. GIF posts now stack directly under the sender username instead of leaving a large horizontal gap, including GIPHY picker posts and shared/direct GIF links; the Powered By GIPHY credit is reduced to a much smaller unobtrusive label.
  • Added versioned Durable Object schema management so PartyRoom upgrades are additive, preserve existing chat/Popcorn data, and record a known schema version without rebuilding populated storage.
  • Added Host Session ID + revision protection. New hosting sessions identify themselves uniquely, older/out-of-order host updates cannot overwrite a newer session, and legacy traffic remains compatible until a 1.1.0 session establishes ownership.
  • Added Cloud/PartyRoom heartbeat ACK + reconciliation reporting. Cloud state can succeed even if PartyRoom temporarily misses an update; the host reports reconciliation pending and the next normal heartbeat retries automatically without stopping streaming.
  • Added a background-task supervisor around existing host jobs. It observes failures and consumes task exceptions without replacing the existing heartbeat, relay, subtitle, telemetry, failover, recovery, or PopcornBot scheduling logic.
  • Added short-lived viewer/watch leases using the existing WebSocket heartbeat and the existing PartyRoom alarm. Sleeping/disconnected viewers expire automatically without adding a competing timer system or changing Popcorn reward amounts/timing.
  • Added a durable bounded PopcornBot command queue for Windows-forwarded commands, including unique command IDs, reconnect delivery, acknowledgements, expiry, and duplicate-response protection while keeping normal connected commands immediate.
  • Added the real server-side !duel command. Use !duel @username <25-1000>, then the challenged viewer can !accept or !decline; challengers can !duel cancel and unanswered challenges expire after 60 seconds.
  • Duel wagers use the authoritative Popcorn balances. Both balances are rechecked at acceptance, the winner is chosen with server-side cryptographic randomness, the winner gains the wager, the loser loses it, and duplicate settlement/negative-balance cases are blocked.
  • Added the built-in !8ball command with randomized server-side Magic 8-Ball responses. Commands do not award chat Popcorn and !8ball never changes a balance.
  • Added the built-in !top command. Using !top posts the full Popcorn leaderboard link in chat instead of automatically navigating the viewer, and no new button or item was added to the existing top header.
  • Added a dedicated Popcorn leaderboard page that lists every registered account from highest balance to lowest using the same authoritative balances as !popcorn, !slots, !duel, and host balance tools. Zero-balance accounts are included and ties are deterministic.
  • Added Back to Watching on the leaderboard. The leaderboard is a true separate page, so the Watch player is unloaded rather than leaving movie audio/video running invisibly behind it.
  • Expanded PopcornBot built-in command presentation and auditing for !duel, !accept, !decline, !8ball, and !top while preventing those built-ins from being replaced by custom commands.
  • Preserved Movie File Mode, OBS, FFmpeg, MediaMTX, Direct R2, Tailscale emergency failover, HLS/player controls, subtitle synchronization, accounts, roles, calendar data, chat history, !popcorn, !slots, existing balances, and existing reward amounts/timing during the 1.1.0 hardening work.
Version 1.0.9SleepyZone 1.0.9September 12, 2026

Quality, visibility, navigation, release-safety, and 1.0.9 hot-fix update that keeps the working Cloudflare/D1/Direct R2/Tailscale architecture intact while polishing pinned-message author alignment and the Users moderation panel.

  • Hot fix: pinned messages now keep the role icon, active event/theme badge, username, and colon in one compact aligned author cluster, so the name stays directly beside its badge and still lines up cleanly when no theme badge is active.
  • Hot fix: Accounts & Moderation in the User settings tab is now a collapsible dropdown matching Role Permissions, while all existing account search, filters, moderation actions, refresh behavior, permissions, and APIs remain unchanged.
  • Changed Schedule into a true top-level page experience. Opening /schedule now unloads the Watch page instead of hiding it in-place, so movie audio and video playback stop immediately and no HLS, Direct R2, Tailscale, subtitle timing, Wake Lock, or player-recovery work continues in the background.
  • Kept Schedule authentication and Owner/Moderator editing intact while preventing login/signup on /schedule from starting Watch-page realtime, chat, integration, or stream-player systems. Returning to Watch performs a clean normal live reconnect.
  • Added local subtitle On/Off preference persistence. A viewer's browser now remembers the subtitle choice across stream reloads/reconnects, and Reset My UI Preferences clears subtitle, volume, mute, quality, chat-layout, and other local display preferences.
  • Improved Auto quality display so hls.js playback shows the currently selected rendition, such as Auto · 1080p or Auto · 720p, without changing adaptive-bitrate selection logic.
  • Added a brief Live feed restored notice after the existing bounded browser recovery system successfully restores playback, without creating a second reconnect engine.
  • Made chat send state visible: Send is temporarily disabled and shows Sending… while the existing duplicate-send guard is active, then returns to normal immediately afterward.
  • Expanded Windows-host session telemetry with peak readers, successful automatic movie recoveries, emergency fallback activations, and HLS health-state change counts. These counters reset at each new host session.
  • Improved host stream-health presentation by showing the current HLS health state together with segment age and keeping Healthy, Delayed, Frozen, Recovering, and emergency-delivery information easier to identify.
  • Added Copy Session Summary beside Copy Diagnostics. The summary includes version, uptime, current/peak readers, source/delivery mode, HLS health, recovery/fallback counts, and excludes credentials, tokens, invite codes, and signed playback URLs.
  • Hardened deployment-contract validation for the existing Worker name, DB/LIVE/EMOTES/ROOM bindings, assets binding, request-budget media-relay setting, and the existing D1 database name.
  • Added explicit D1 migration protection for 1.0.9: the tracked migration set remains exactly 0001, 0002, and 0003, with no new schema migration introduced by this release.
  • Added release fingerprint manifests containing the 1.0.9 version/build marker and SHA-256 hashes for important packaged files, making private release packages easier to verify.
  • Expanded post-deployment verification to check the Schedule route, manifest, generated app/calendar assets, and existing Change Log/live build markers in addition to the previous deployment checks.
  • Preserved the existing D1 schema, authentication model, PartyRoom/WebSocket architecture, Direct R2 primary delivery, Tailscale emergency fallback, Worker media-relay blocking, Movie File Mode recovery engine, subtitle media-clock synchronization, Popcorn economy, bot commands, and current mobile watch/chat architecture.
Version 1.0.8SleepyZone 1.0.8September 11, 2026

Reliability and release-safety update focused on protecting working systems, detecting real playback stalls, recovering Movie File Mode safely, improving host diagnostics, and making future SleepyZone updates easier to validate.

  • Added a permanent regression-validation framework for release-critical SleepyZone behavior, including version consistency, Direct R2/Tailscale delivery invariants, Worker media-relay protection, authentication hardening, chat/economy constants, player recovery hooks, and website structure checks.
  • Added a release safety gate so BUILD_RELEASE.bat runs the 1.0.8 validation suite before compiling and packaging; a failed required check stops the release build instead of producing a release ZIP that looks successful.
  • Hardened the 1.0.8 regression validator for Windows PowerShell 5.1 by using ASCII-safe source markers, and failed validations now repeat the exact failed check at the bottom of the report for easier troubleshooting.
  • Hardened the local MediaMTX readiness probe so host stop/start cycles do not reuse HTTP/1.1 sockets from a previous MediaMTX process instance. Transient localhost connection resets and readiness timeouts now resolve as a normal not-ready/retry result instead of surfacing later as an unobserved task error, while real cancellation still propagates normally.
  • Added version-consistency validation across the Windows host, Cloud Worker/package metadata, build/deploy scripts, website build marker, and Change Log so future releases are less likely to ship mixed version labels.
  • Expanded Movie File Mode HLS health monitoring from segment age alone to actual segment progression. The host now distinguishes Healthy, Delayed, and Frozen movie HLS states and records meaningful state changes.
  • Added bounded automatic Movie File Mode recovery for genuine FFmpeg crashes or frozen local HLS. Recovery is limited to two attempts, preserves the active movie, selected audio stream, approximate playback position, subtitle track/settings, and logical movie start time, and never loops forever.
  • Hardened intentional-stop handling so Stop Movie, normal movie completion, playlist transitions, source switching, and host shutdown do not get mistaken for failures that should restart the movie.
  • Added a viewer-side frozen-playback watchdog that detects when the browser video clock stops advancing while playback should be live and routes recovery through the existing bounded player-recovery system instead of adding a competing reconnect engine.
  • Added a Host Reliability section with a safe Run Preflight check for configuration, portable Data write access, disk space, installed media tools, Cloud/HOST_KEY/Direct R2 connectivity, and Tailscale fallback readiness. Missing first-run FFmpeg/MediaMTX tools are warnings because normal startup already installs verified copies.
  • Enhanced the existing Copy Diagnostics feature instead of duplicating it. Diagnostics now include stream mode, operation state, HLS health/segment age, encoder, delivery path, Direct R2/Tailscale state, Worker health, disk space, recent readers, uptime, and recent stream-health events while excluding private keys, credentials, tokens, invite codes, and signed playback URLs.
  • Added a rolling 20-event stream-health history for host start/stop, source state, HLS delay/freeze/recovery, automatic movie recovery, emergency Tailscale failover, disk-space warnings, and preflight results.
  • Added low-disk-space monitoring for the portable SleepyZone drive. The host warns below 5 GB and the preflight treats critically low free space below 2 GB as a blocking issue; no personal files are automatically deleted.
  • Strengthened password hashing for new and successfully authenticated accounts from PBKDF2-SHA256 30,000 iterations to a 50,000-iteration target. Existing hashes remain readable and are transparently upgraded after a successful login with no password reset or D1 schema change.
  • Added visible Screen Wake Lock status inside Player Settings so mobile viewers can see whether Keep Screen Awake is Active, Idle, Unavailable, or unsupported by their browser.
  • Added local viewer volume/mute persistence so each browser remembers its last volume and mute setting without adding Cloudflare storage or requests.
  • Fixed mobile audio recovery when a remembered volume was 0: tapping the sound button now restores an audible volume and clears mute instead of leaving phone viewers permanently stuck on the crossed-out speaker icon.
  • Improved subtitle syncing for Movie File Mode: the owner Sync offset control now adjusts in finer 100 ms steps, and subtitle setting changes can be applied during playback without waiting for a full movie restart.
  • Improved viewer subtitle timing stability by strengthening subtitle re-sync after seeks, reconnect/recovery, jumping back to Live, metadata/playback resume, and tab return, while smoothing tiny HLS timing fluctuations so subtitles stay aligned more consistently over longer playback.
  • Fixed cross-device Movie File Mode subtitle alignment for native/mobile HLS: viewers now use the stream's PROGRAM-DATE-TIME media clock through HTMLMediaElement.getStartDate() when hls.js timing is unavailable, instead of depending on the viewer device clock; loaded-data re-sync was also added so the timing anchor is applied as soon as native HLS exposes it.
  • Fixed a mobile keyboard routing issue where tapping into chat could expose the Schedule/Calendar page behind the composer. Mobile chat focus now locks the Watch view to the visual viewport, blocks same-tap Schedule ghost clicks, and intentional Schedule navigation blurs the chat field first so iPhone browsers cannot leave the keyboard/composer over the calendar.
  • Added standalone web-app metadata for iPhone/iPad Home Screen launches. Normal Safari still owns its browser address/domain UI, but a Home Screen launch can run SleepyZone without the Safari address bar.
  • Bumped the 1.0.8 web build/cache marker so Safari and other browsers fetch the newest mobile CSS/JavaScript instead of reusing an older 1.0.8 asset bundle after deployment.
  • Hardened iPhone/iPad keyboard handling so the Watch layout follows Safari's visual viewport offset as well as its height. This prevents keyboard focus from panning the video/player out of view or leaving a mostly blank watch area in portrait or landscape.
  • Added a landscape-phone chat toggle for the Watch page: on short mobile landscape layouts, viewers can hide chat for more video space and bring it back from the player controls, while unread chat badges continue working when chat is hidden.
  • Audited PopcornBot and moderation action timing. !popcorn and !slots still execute immediately inside PartyRoom, custom commands still use the live PopcornBot WebSocket, and no additional command polling delay was introduced; existing command/slot cooldowns remain intentional safeguards.
  • Reduced active-host moderation audit latency: while hosting, the Windows app now checks website moderation audit entries every 10 seconds instead of every 60 seconds, while idle polling remains every five minutes for request-budget protection.
  • Tightened the pinned-message layout so the live event/theme badge sits closer to the username while preserving the existing pin/unpin behavior.
  • Changed Cloudflare release deployment dependency installation from npm install to npm ci so production deploys use the exact package-lock dependency tree.
  • Kept the existing D1 schema, WebSocket/PartyRoom architecture, Direct R2 primary delivery, Tailscale emergency fallback, Worker media-relay blocking, GIPHY flow, PopcornBot/economy behavior, mobile watch/chat layout, themes, calendar, schedule, pinned-message behavior, and existing moderation/account role structure unchanged.
  • Fixed release-package build marker synchronization so DEPLOY_CLOUDFLARE.bat and the Windows regression validator now target the same current web cache build as the generated 1.0.8 site; validation now protects against stale deploy markers.
Version 1.0.7SleepyZone 1.0.7September 11, 2026

Mobile watch-and-chat polish plus Cloudflare request-budget protection and a private preconfigured Direct R2 bootstrap. 1.0.7 now gives phones a permanent video-over-chat layout while keeping viewer media off the Worker and preserving the portable private host setup.

  • Returned Windows host runtime/user storage to the portable Data folder beside SleepyZone.exe. This build no longer creates or uses a new legacy sibling Data folder for normal runtime storage.
  • Added a read-only transition import for anyone who already has a legacy sibling Data folder from the short-lived 1.0.7 persistence experiment: missing files are copied back into portable Data, but the sibling folder is never created, modified, or deleted by this build.
  • Added the owner's working cloud/Direct R2 configuration as a private Bootstrap\cloud-host.json seed. On a fresh build, SleepyZone automatically creates Data\cloud-host.json from that seed only when the runtime config is missing, so normal fresh builds no longer require re-entering the R2 Account ID, Access Key, Secret, bucket, or HOST_KEY.
  • Removed Configure Direct R2.bat from the normal Windows package and source workflow because Direct R2 is preconfigured in this private master. Settings can still edit/save the active portable Data\cloud-host.json if the credentials ever need to change.
  • The private source ZIP and Windows release now intentionally contain live host/R2 credentials in Bootstrap. They must remain private and should never be published or redistributed.
  • Preserved the low-request delivery order: Direct R2 remains primary, Tailscale remains the emergency fallback, and Worker-served HLS remains disabled by default.
  • Cloudflare deployment continues to reapply the popcornparties-live browser CORS policy before deploying the Worker/site so Direct R2 remains browser-reachable.
  • Added Cloudflare request-budget protection without changing the 1.0.7 version: automatic Worker-served HLS media is disabled by default so normal movie manifests and segments cannot silently consume the daily Worker request allowance.
  • Changed host media fallback order to Direct R2 -> bounded recovery -> Tailscale emergency delivery. Initial Direct R2 verification failures and sustained mid-stream Direct R2 failures no longer promote video to the Worker relay.
  • Removed the browser player's automatic /api/stream/fallback path. Direct R2 browser/preflight/network problems now use bounded recovery while the host can switch delivery to Tailscale, rather than moving every HLS request onto the Worker.
  • Added a Worker-side circuit breaker: /live media serving, Worker relay session start/object upload routes, and /api/stream/fallback are disabled by default through ALLOW_WORKER_MEDIA_RELAY=false.
  • Reduced Windows moderation-log polling from every 4 seconds to once per minute while the Host is running and once every 5 minutes while the EXE is idle, while retaining a 1-second catch-up cadence only when a real 100-entry backlog exists.
  • Stopped recurring offline /api/stream/status checks while a viewer has a healthy WebSocket. Stream start/stop changes continue to arrive immediately through the existing realtime stream event; the 5-minute HTTP check remains only as a disconnected-WebSocket safety fallback.
  • Reduced healthy Direct R2 status safety refreshes from every 5 minutes to every 30 minutes, which remains safely inside the existing 75-minute signed-link lifetime. Tailscale keeps the shorter safety cadence needed for its playback authorization.
  • Reduced Owner Settings background traffic: Dashboard telemetry now refreshes once per minute only while the Overview page is actually visible, and Access no longer has a recurring 15-second poll because it already updates from actions and WebSocket refresh events.
  • Added visible Windows-host messaging showing that Worker media relay is blocked and viewer video is using Direct R2 or Tailscale, making request-budget-safe delivery easier to confirm during a stream.
  • Expanded the 30-viewer / 12-movie request-budget validation to count host heartbeat, Direct R2 safety status, heavy chat, WebSocket upgrades, movie transitions, moderation audit polling, maintenance Cron, cleanup, and optional always-open Owner Dashboard traffic; validation also fails if normal frontend/host code can automatically engage Worker media relay.
  • Synthetic 24-hour / 12-movie request-budget projections now land at about 50,898 Worker requests for 30 viewers on Direct R2 (52,338 with Owner Overview left open all day), and about 59,538 if Tailscale carries video all day (60,978 with Owner Overview open), while keeping Worker media relay requests at 0. These are conservative source-based projections, not a Cloudflare billing guarantee.
  • Redesigned pinned chat messages into a cleaner streaming-style card with a compact PINNED MESSAGE header, dedicated pin icon, subtle Popcorn-gold accent, clearer username/message hierarchy, and a smaller rounded Unpin control.
  • Preserved pinned-message behavior while changing the presentation: clicking the card still jumps to the original message, Owner/Moderator permissions are unchanged, and role icons, theme badges, username colors, and emotes continue to render normally.
  • Fixed occasional duplicate typed chat posts by allowing only one chat send request to be in flight at a time, preventing rapid Enter presses or double-clicks from submitting the same message twice while the first request is still completing.
  • Applied the same one-send protection to GIPHY posts so repeated clicks cannot publish the same GIF twice during a pending request.
  • Normalized message IDs before client-side render de-duplication so a single server message cannot be drawn twice when the HTTP send response and WebSocket broadcast arrive through slightly different ID representations.
  • Improved slow-send behavior so the chat input/reply state is only cleared when it still matches the message that was submitted; newer text typed while a request finishes is left intact.
  • Replaced the prior mobile chat drawer/split trigger with a permanent phone watch layout: the full-width 16:9 player stays at the top, chat lives directly underneath it, and the composer remains anchored at the bottom.
  • Mobile player controls now auto-hide while a movie is playing. Tapping the video reveals Play/Pause, sound, LIVE status, player settings, and fullscreen controls, then fades them away again after about 2.5 seconds of inactivity; paused video keeps the controls visible.
  • Removed the mobile Live Chat header row from watch mode, including the movie/viewer-style information area, so there is no extra information strip between the video and chat.
  • Removed the mobile show/hide-chat player button and close-chat behavior from normal phone watch mode because chat is now always present underneath the video instead of opening as a drawer.
  • Kept the mobile composer focused on chat essentials: message input, Emote, GIF when GIPHY is enabled, and Send. Existing chat permissions, replies, autocomplete, emotes, and GIF posting remain intact.
  • Added Visual Viewport sizing so opening the on-screen keyboard reduces the chat region instead of pushing chat over the player; the 16:9 video remains a separate visible layout region while typing whenever the remaining viewport can contain it.
  • Kept short landscape phones in a no-overlap side-by-side arrangement with video on the left and chat on the right, while portrait phones use the video-above-chat stack.
  • Increased eligible chat rewards from 10 to 25 Popcorn while preserving the existing 60-second earning cooldown and command exclusions.
  • Increased active Movie File Mode watch rewards from 10 to 25 Popcorn every 10 minutes; the existing watch-time interval and activity tracking remain unchanged.
  • Raised the !slots minimum bet from 10 to 25 Popcorn while preserving the 50 default bet, 1000 maximum, 15-second cooldown, and existing payout table.
  • Hardened the website shell by adding explicit type=button behavior to previously implicit buttons, preventing accidental form submissions if those controls are later placed inside or moved near forms.
  • Added missing accessible labels to icon-only chat, emote, upload, and Settings close controls without changing their appearance or layout.
  • Promoted 1.0.7 to the active Change Log release and kept 1.0.6 directly below it in the existing collapsed Previous releases section so the latest changes are immediately visible without losing older release history.
  • Synchronized the Windows host, Cloudflare Worker/package metadata, User-Agent strings, deploy/build scripts, website footer, /__pp_build response, cache/build markers, generated app.js, Change Log HTML, embedded site pages, documentation, and source package to version 1.0.7.
  • Preserved existing D1 data/migrations, authentication/sessions, WebSockets, mobile watch-and-chat no-overlap behavior, chat de-duplication, themes, Popcorn economy, and PopcornBot. Normal viewer media delivery is now Direct R2 or Tailscale only; no database reset or broad streaming rewrite was introduced.
Version 1.0.6SleepyZone 1.0.6September 10, 2026

Build-audit repair release focused on stability, deployment reliability, security hardening, conservative cleanup, and the new production login/create-account experience. This finalized 1.0.6 package explicitly includes requested audit repair items 2–7 while keeping the version at 1.0.6.

  • Preserved Direct R2 as the primary media path so normal HLS segments still bypass the Cloudflare Worker and the existing low-request streaming architecture remains intact.
  • Reduced Direct R2 signed-link exposure to a 75-minute window and now rotate the signing window every 45 minutes through the existing host heartbeat/status flow; no new viewer polling loop or per-segment Worker proxy was added.
  • Prevented signature-only Direct R2 URL refreshes from unnecessarily increasing the stream revision or broadcasting a fake stream change.
  • Made Member/Moderator role changes update already-connected WebSocket user attachments immediately so live presence no longer waits for reconnect.
  • Removed duplicate stale-host disconnect chat notices while preserving both immediate Durable Object expiry and scheduled D1 cleanup.
  • Allowed a real zero-watcher count instead of forcing viewerCount to at least 1, without changing the existing viewers popover behavior.
  • Stopped returning raw server exception details to clients and hardened GIPHY/Tenor share-link redirects by validating every redirect before following it.
  • Added SHA-256 integrity verification before newly downloaded FFmpeg or MediaMTX archives are extracted and executed.
  • Added tracked additive D1 migrations for fresh Cloudflare setup and a one-time BOOTSTRAP_SECRET setup helper/documentation without resetting existing D1 data.
  • Cleaned deleted-user Popcorn balance storage after successful account deletion and added explicit Library scan/watch resource disposal during app shutdown.
  • Aligned website OBS setup with the Windows host: Server rtmp://127.0.0.1:19350 and Stream Key popcorn.
  • Updated the Windows host, Worker/package, deploy/build scripts, generated website assets, documentation, Change Log, and source package to 1.0.6.
  • Verified the requested audit repair set 2–7 is present in this finalized 1.0.6 source without duplicating handlers or changing the established architecture.
  • Refined the chat message context menu into a shorter grouped layout with compact action rows, quick-recognition icons, section dividers, hover states, amber Timeout styling, stronger Ban styling, and ellipsis cues for actions that open another step; existing Reply, Mention, Copy, Pin/Unpin, Delete, Timeout, and Ban behavior is preserved.
  • Replaced the old public authentication modal presentation with the new full-screen SleepyZone login/create-account design while preserving the existing 1.0.6 authentication backend, D1 accounts, sessions, roles, password hashing, and API routes.
  • Kept production access behavior in the redesigned page: Invite Only shows the real invite-code field, Closed hides account creation, Party Lock explains that new Member logins/account creation are paused, and first-time Owner setup remains available on fresh databases.
  • Added unobtrusive Caps Lock warnings on authentication password fields, a no-email password-recovery reminder for new accounts, and clearer offline/network errors without changing server-side credential validation.
  • Kept the logged-in Account window separate from the new full-screen entry page, reused the packaged SleepyZone logo instead of embedding a duplicate image, and retained responsive short-screen/mobile behavior.
  • Fixed Movie File Mode media inspection so FFprobe JSON is parsed only from standard output; separate diagnostics can no longer be appended after valid JSON and trigger the “invalid after a single JSON value” popup.
  • Redesigned pinned chat messages into a cleaner streaming-style card with a dedicated pin icon, compact PINNED MESSAGE label, clearer message hierarchy, subtle Popcorn-gold accent, and a smaller rounded Unpin control; jump-to-message, permissions, role/theme badges, emotes, and pin/unpin behavior are unchanged.
Version 1.0.5SleepyZone 1.0.5September 10, 2026

Moderation logging consolidation: website moderation activity now feeds the Windows EXE color-coded Logs, while the web Users page stays focused on account management.

  • Removed the Moderation Log tab and log list from website Settings > Users.
  • Removed Recent Moderation History from individual website account details so Users is focused on account and moderation controls.
  • Kept the Cloudflare D1 moderation audit records intact for accountability and compatibility; only the duplicate website presentation was removed.
  • Added a private HOST_KEY-protected incremental moderation-audit feed for the Windows host.
  • Windows Logs now receives website moderation/access actions through the existing AppLog system under the [Moderation] component label.
  • Moderation entries use the existing log colors: routine changes are [INFO], successful invite creation is [SUCCESS], destructive or disciplinary actions are [WARN], and genuine transport/runtime failures remain handled as errors by the normal logging system.
  • Added a portable moderation-audit cursor under Data so actions made while the EXE is closed are caught up when it returns.
  • The first 1.0.5 run baselines at the current D1 audit position instead of replaying the entire historical moderation table into the EXE log.
  • Temporary moderation-feed connection problems warn once, back off, and report recovery instead of flooding the log.
  • Changed the Change Log page so the current release stays fully visible while older releases are collapsed into expandable dropdown entries.
  • The Change Log footer now lists only the current updated version under Recent release notes include.
  • Updated Windows host, Cloudflare Worker/package, deploy/build scripts, generated web assets, build marker, documentation, and source package to 1.0.5.
Version 1.0.4SleepyZone 1.0.4September 10, 2026

Settings cleanup: less duplicated information, clearer account management, and removal of website-only controls that could never run from the cloud UI.

  • Simplified Overview into a status-first dashboard focused on OBS, source, viewers, bandwidth, transcoder/audio health, service health, and active warnings.
  • Removed the duplicated Overview public-link controls and hid Windows-host-only backup, restore, restart, relay, and public-access controls from the website Settings UI.
  • Moved Owner announcements from Overview into Emotes & Chat so chat-related controls have one home.
  • Simplified Access by removing the redundant manual Refresh button and duplicate Currently Online account list while keeping automatic refresh, registration, party lock, invites, and global logout.
  • Replaced each active invite's multiple expiry buttons with one compact Expiry menu plus Revoke; revoked invites keep Delete.
  • Simplified Streaming so the OBS server and required source are prominent, setup-only values are tucked into expandable OBS Setup Instructions, and the Public Link remains the single public URL control.
  • Collapsed Roles & Privileges into expandable Role Permissions and replaced duplicate user-filter chips with a compact account summary plus moderation counters only when non-zero.
  • Consolidated Emotes & Chat into clearer Emotes, GIPHY, and Chat groups; moved Delete All Custom Emotes beside custom-emote storage and kept Clear Chat in a dedicated danger area.
  • Default 7TV now shows Retry only when loading fails instead of a permanent Reload button.
  • Corrected GIPHY status wording so it consistently says the saved API key is stored in Cloudflare D1.
  • Simplified Themes by keeping the single active-theme badge and switches while removing duplicate Active/Off labels and redundant explanatory text.
  • Preserved the existing IDs/API hooks and regenerated browser assets so streaming, accounts, moderation, invites, themes, chat, emotes, PopcornBot, and Cloudflare behavior continue using the existing backend paths.
Version 1.0.3SleepyZone 1.0.3September 10, 2026

Logging overhaul: a branded color-coded host console, cleaner stream diagnostics, and PopcornBot/Popcorn audit logging. Version 1.0.2 notes are included below because these releases shipped back-to-back.

  • Added a readable SleepyZone ASCII banner as the first content shown in the Windows app Logs tab for each app launch.
  • Upgraded the Logs tab to color-coded output: [INFO] is light gray, [SUCCESS] is green, [WARN] is amber/yellow, and [ERROR] is red. Timestamps and component labels are muted while normal message text stays white.
  • Added a dedicated [SUCCESS] level for completed milestones such as host startup, MediaMTX readiness, FFmpeg readiness, HLS live state, delivery readiness, and normal shutdown.
  • Early startup entries are retained in memory and replayed underneath the ASCII banner when the Logs page is created, so the banner stays first without losing startup diagnostics.
  • Follow Logs now stops following when you manually scroll upward and resumes automatically when you return to the bottom. New entries preserve your scroll position while you are reading older log lines.
  • Clear now resets the log view back to the SleepyZone ASCII header instead of leaving the console completely blank.
  • Exception entries stay as clean one-line red errors in the app while the full exception detail remains available in the log file for troubleshooting.
  • Cleaned MediaMTX output by removing its duplicate native timestamp/severity prefix and presenting it under a single [MediaMTX] component label. Intentional shutdown no longer creates a false unexpected-stop error.
  • Cleaned FFmpeg movie logging with filename-only loaded messages, compact video/audio details, clear HLS-live state, normal playback-finished/publishing-stopped messages, and a red error only for an unexpected non-zero process exit.
  • Recoverable Direct R2 verification/playback problems and automatic switching to Worker relay fallback now use [WARN] instead of [ERROR]; genuine fallback failures remain errors.
  • Added PopcornBot command auditing for !playing, !next, and custom commands, including successful responses, cooldowns, and ignored or unauthorized command attempts.
  • Added a private PartyRoom-to-Windows-host audit event for server-side !popcorn and !slots activity without logging ordinary chat message text.
  • Added log entries for !popcorn balance checks, !slots bets, wins/losses, rejected spins, cooldowns, invalid bets, disabled slots, and insufficient Popcorn.
  • Added log entries when viewers earn Popcorn from eligible chat activity or active Movie File Mode watch time, including the resulting balance.
  • Added Owner-side Popcorn balance audit entries for Load User, Add Popcorn, Remove Popcorn, Set Balance, and !slots enable/disable changes.
  • PopcornBot timer posts now use [SUCCESS], while connection recovery keeps the established [WARN] interruption and [INFO] connected messages.
  • Hardened DEPLOY_CLOUDFLARE.bat live verification so it waits and retries while Cloudflare workers.dev edges finish propagating a newly deployed Worker/assets instead of immediately reporting a false deployment failure when the previous build is briefly returned.
Version 1.0.2SleepyZone 1.0.2September 10, 2026

Player fitting, PopcornBot reliability, !next, Popcorn rewards/slots, compact PopcornBot controls, and stable Owner balance editing.

  • Updated the movie player to always fit the complete video frame inside the available player area, preserving aspect ratio and using black bars when necessary instead of cropping.
  • Improved PopcornBot recovery so an interrupted party-chat connection automatically reconnects without requiring a host restart.
  • PopcornBot now logs [WARN] PopcornBot connection interrupted. Reconnecting... on a dropped connection and [INFO] PopcornBot connected to party chat. after recovery.
  • Added the built-in !next command so PopcornBot reports the next movie in the current local playlist, including playlist loop behavior.
  • Added persistent server-side Popcorn balances. Viewers earn 10 Popcorn every 10 minutes while actively watching Movie File Mode and 10 Popcorn for an eligible chat message, with a 60-second chat reward cooldown.
  • Added the built-in !popcorn command to show a viewer's saved Popcorn balance.
  • Added the server-side !slots mini-game with a 50 Popcorn default bet, 10-1000 bet range, 15-second cooldown, emoji reels, 1.5x two-match wins, and 2x/3x/5x/8x/20x triple-symbol payouts.
  • Added an independent Enable !slots toggle in the PopcornBot page. Turning slots off does not stop watch/chat Popcorn earning and !popcorn continues to work.
  • Popcorn rewards reuse existing chat and WebSocket/heartbeat activity instead of adding a polling loop or a new recurring client request.
  • Changed Manage User Popcorn to a matching dark registered-user dropdown populated from existing site accounts, with a shorter username field, nearby Amount field, LOAD USER, Add/Remove/Set Balance actions, current balance, and status feedback.
  • Reduced the Popcorn Points and Built-In Commands tiles to compact two-line cards so they no longer waste vertical space and leave more room for future built-in commands.
  • Removed the Popcorn management scroll-restore workaround and changed Add Popcorn, Remove Popcorn, Set Balance, and Load User to use a non-focus-shifting async busy guard so clicking those actions does not scroll or jerk the PopcornBot page.
  • Popcorn balance edits are protected by the private host key and applied server-side to the same persistent account balance used by !popcorn and !slots.
Version 1.0.1SleepyZone 1.0.1September 9, 2026

Theme banner refresh for Fallout and Spooktober, with packaged local panoramic artwork and the standardized private source ZIP layout.

  • Fallout now uses the packaged local Fallout TV Show Night panoramic banner.
  • Spooktober now uses the packaged local Spooktober Horror Movie Month panoramic banner.
  • Both banner assets were normalized to the same 947 x 68 source-art dimensions as the Resident Evil banner and render inside the existing 615 x 46 header slot.
  • Removed the old remote Fallout/Spooktober character-image layers from the active banner implementation while leaving Resident Evil artwork and behavior unchanged.
  • Fallout and Spooktober username badges continue using the existing live-theme badge system.
  • Private source ZIPs now package everything under a single top-level SleepyZone-Source 1.0.1 folder.

Recent release notes include 1.2.1.