This changelog records changes that affect how people create, protect, retrieve, manage, or understand a paste. Small visual adjustments are omitted unless they change accessibility, security, or the meaning of a control.
August 2026: Safer pre-share workflow
Added local secret-pattern detection with categorized findings, redacted preview, manual application, and a standalone browser tool. Added local language suggestions that preserve manual control.
Added unique-view limits, first-party QR codes for eligible links, line and line-range links, in-paste search, and keyboard shortcuts. Updated the API contract and owner editing workflow.
August 2026: Search and authority architecture
Added factual comparison, redaction, environment-file, HTTP transcript, container-configuration, moderation, transparency, status, and security-contact resources. Added contextual links and sitemap entries.
Rewrote the homepage title, H1, semantic H2s, proof section, and product schema around the free online pastebin use case without indexing uncontrolled paste pages.
Practical next step: Pastebin.ai features - Review current capabilities.
August 2026: Security and reliability
Added CSRF enforcement, trusted-host validation, security headers, rate limits, database indexes, cleanup maintenance, and a process restart script. Query-string homepage requests redirect before session loading to prevent noindex cache poisoning.
Added Google OAuth with PKCE, nonce and state verification, signed-in ownership, folders, revisions, account deletion, and revocable API tokens.
How changes are documented
Behavior is tested before a changelog entry is published. The OpenAPI version changes when a documented request or response contract changes materially.
Security-sensitive implementation details may be summarized rather than disclosed when full detail would make abuse easier. Corrections update the visible reviewed date and structured data.
