# v1.2.0 — Comment on recipes, import them from a link (https://s-frei.github.io/rezepte/changelog/v1.2.0)



Rezepte 1.2.0 changes nothing you have to adapt: [back up your data directory](https://s-frei.github.io/rezepte/operations/data-and-backup), pull `ghcr.io/s-frei/rezepte:1.2.0` and start it, as [Updates](https://s-frei.github.io/rezepte/operations/updates) describes. Mail is off until you set it up.

## Talk about a recipe [#talk-about-a-recipe]

Every recipe has comments now, behind a tab beside "Method": the place for what the household learned cooking it - "Ours needed 10 more minutes in the oven." Everyone can read and write them on every recipe, locked ones included; you edit your own, and admins can delete any. When somebody else comments on a recipe you added or commented on, its card in the overview and its "Comments" tab get a small dot until you open the tab. Comments stay in the household: they are not on public links, shared images or in a zip export. See [Comments](https://s-frei.github.io/rezepte/guide/comments).

<Screenshot name="comments" caption="The comments, opened from their tab beside the method" />

## Import a recipe from a link or text [#import-a-recipe-from-a-link-or-text]

Paste a link to a recipe page, or the recipe copied out of a mail or a chat, and Rezepte fills in a new recipe for you to check before you save: title, servings, times, ingredients, steps, tags, the source and usually the photo. Ingredient lines it was unsure about are marked **Please check**, new tags are only suggested, and a recipe already imported from the same page is pointed out before you make a second one. Everyone can import: **Import** in the top bar, "Import recipe" in the command palette, or **+** and then **Import** on a phone. See [Importing a recipe](https://s-frei.github.io/rezepte/guide/importing).

<Screenshot name="import-dialog" caption="The import dialog with a link pasted" />

The page is fetched by the Rezepte server, which opens only addresses on the public internet - never your router or other machines in its own network.

## Steps show where they wait [#steps-show-where-they-wait]

Durations in a step - "25 to 30 minutes", "1 hour 30 minutes" - can be marked as times, and the recipe page and cook mode then show them underlined with a small clock. The editor suggests them as you type, in English and German; accept or dismiss each one, or select a duration it missed and choose "Mark as time". Recipes you saved earlier get times the next time you save them in the editor. See [Mark times in a step](https://s-frei.github.io/rezepte/guide/recipes#mark-times-in-a-step).

<Screenshot name="editor-times" caption="A duration suggested in a step" />

## Invitations and passwords by mail [#invitations-and-passwords-by-mail]

Connect Rezepte to the SMTP server of your mail provider - in the app under **Settings → Email**, a page only the owner has, or with the new `REZEPTE_SMTP_*` variables together with `REZEPTE_PUBLIC_URL` - and the owner can send a test mail to check it. A password entered in the app is stored unencrypted in `rezepte.db`, so keep your backups private. See [Mail](https://s-frei.github.io/rezepte/guide/mail) and [Configuration](https://s-frei.github.io/rezepte/getting-started/configuration#mail).

<Screenshot name="mail-card" caption="The Email card, with mail on" />

* **Invitations.** "Add account" gets an optional email field; fill it in and the setup link goes to that address, while the window shows where it went and keeps the link to pass on by hand if sending fails. The row's "Setup link" can mail a fresh link the same way.
* **Forgot password.** The login page shows **Forgot password?**. Enter a username or a confirmed email address and Rezepte mails a link for a new password, valid for one hour and good once; setting the password signs the account out everywhere else. The page answers the same whether or not an account exists, a second request within five minutes mails nothing, and the owner cannot be reset by mail. An account that signs in only through an identity provider gets a mail saying so instead. See [First login](https://s-frei.github.io/rezepte/getting-started/first-login#forgot-your-password).
* **Confirmed addresses.** Only a confirmed address receives a password link. An address entered in a profile, or set by an admin, is confirmed through a mailed link valid for 7 days; until then the profile says **Not confirmed yet** with **Send again**. An address opened from a mailed invitation, or vouched for by your identity provider, counts as confirmed, and Settings → People shows whose address is. See [Profile](https://s-frei.github.io/rezepte/guide/settings#profile).

<Screenshot name="forgot-password" caption="Asking for a link for a new password" />

## API [#api]

* Comments: `GET /api/v1/comments?recipeId=…` lists a recipe's comments, each with `new`, `canEdit` and `canDelete`; `POST /api/v1/recipes/{id}/comments` writes one (1 to 2000 characters of plain text), `PATCH` and `DELETE /api/v1/comments/{commentId}` change and remove one, and `PUT /api/v1/recipes/{id}/comments/seen` with `{"upTo": …}` clears the dot. Reading and marking seen take `recipes:read`, writing `recipes:write`. Recipe cards carry `newComments`.
* Import: `POST /api/v1/recipe-drafts` with `{"url": "…"}` or `{"text": "…"}` returns an unsaved draft - `recipe`, `review`, `suggestedTags`, `photo`, `duplicate` and `truncated` - for `POST /api/v1/recipes` to save; `GET /api/v1/recipe-drafts/photo` serves the draft's photo for two minutes. Both take `recipes:write`.
* Step times: a step carries an optional `times` list of `{phrase, seconds, maxSeconds}` beside `references`, in recipes, zip exports and public shares. `phrase` must stand in the step's text and hold a number; `seconds` runs from 1 to 604800 (a week), and `maxSeconds` is there only for a range. A client that saves a recipe without `times` drops its step times, as it already did with `references`.
* MCP: two new tools, `list_comments` and `add_comment`. The tools that write recipes now ask for `times` on every step, as they do for `references`.
* Mail: `GET`, `PUT` and `DELETE /api/v1/settings/mail` and `POST /api/v1/settings/mail/test` read, save, clear and try the mail server, for the owner with a session only; the password is never returned, only `passwordSet`. `GET /api/v1/settings` carries `mailEnabled`.
* Invitations: `POST /api/v1/users` accepts an optional `email`; `POST /api/v1/users/{id}/setup-link` accepts `{"mail": false}` to skip sending. The setup link in either answer carries `mailedTo` and, when sending failed, `mailError`. `PATCH /api/v1/users/{id}` accepts `email` from a signed-in session, and `GET /api/v1/users` carries `email` and `emailVerified`.
* Passwords and addresses: `POST /api/v1/auth/password/forgot` always answers `204`, and `GET /api/v1/auth/password` says whether the login page offers it; `/api/v1/auth/setup/inspect` names a link's `purpose`, `setup` or `reset`. `POST /api/v1/auth/email/confirm` answers with the confirmed `address`, and `POST /api/v1/auth/me/email/confirmation` sends the confirmation again, at most once a minute (`429` with `Retry-After`). `/api/v1/auth/me` and `PATCH /api/v1/auth/me/profile` carry `emailConfirmationPending`.
* API tokens carry `ownerDisplayName` and `ownerColor`.

The [API reference](https://s-frei.github.io/rezepte/api/reference) lists every endpoint.

## Also in this release [#also-in-this-release]

* **New:** Settings → API reads like two recipes, one for AI assistants and one for your own scripts, each with what it needs and its steps. See [API](https://s-frei.github.io/rezepte/guide/settings#api).
* **New:** API tokens and shared links hang in their lists like key tags, with a bar for how much of their lifetime has passed; admins can switch the token list to "Everyone in the household". See [API tokens](https://s-frei.github.io/rezepte/api/tokens).
* **New:** Admins can set a member's email address in their edit dialog (the pencil in their row), and the owner anyone's.
* **Improved:** The recipe page sets ingredients and method side by side only where both fit, and on a tablet splits a long ingredient list into two columns.
* **Improved:** A few icons answer what you did: the heart beats when you mark a recipe tasty, the star turns for a favorite, a check appears once something is copied, and the send icon flies off with a test mail.
* **Improved:** "Add account" fits a phone and, on a computer, sets its fields in two columns instead of scrolling.
* **Improved:** On a phone, a person card opens as a sheet from the bottom of the screen.
* **Improved:** Every scrolling area has the same thin scrollbar in the app's colors.
* **Improved:** After a dialog in Settings → People closes, keyboard focus returns to the person's row.
* **Fixed:** A step in cook mode no longer runs off both sides of a narrow phone.
* **Fixed:** The `@` ingredient picker in the editor closes when you press outside it.
* **Fixed:** The command palette and the phone's "You" sheet no longer close by themselves when opened while the overview is still loading.
* **Fixed:** The export list under Import & export no longer breaks when a recipe is saved while it loads.
