This release adds roles and permissions. Every account is now either the owner or has exactly one role, and you can edit the built-in User and Administrator roles or create your own under Settings → Roles, down to who can see or edit other people's flights. Existing accounts are migrated automatically: the owner stays the owner, admins become Administrator and everyone else becomes User. See Roles and Permissions.
AirTrail now has a versioned REST API at /api/v1 and a remote MCP server, so scripts and AI assistants can read and manage your flights. API keys and connected apps live under Settings → Security and carry scopes, so a key can be limited to less than your own role allows. Existing API keys keep full access, and the old /api/flight/* endpoints still work but are deprecated in favor of /api/v1. See Getting started with the API.
The basemap provider is now configurable under Settings → Appearance → Basemap Provider, with OpenFreeMap, CARTO, Protomaps or your own MapLibre style. OpenFreeMap is the new default and needs no key, so installs that never chose a provider will switch from the previous CARTO map to OpenFreeMap. CARTO now requires an API key. See Basemaps.
The flight list now shows at a glance which flights have a track, recorded times, other passengers or a note, the passenger picker suggests guests you've added before, and flight lookups can use AeroDataBox's direct API instead of RapidAPI. For NAS users, there are now PUID and PGID settings and Unraid templates. To make that work, the container now starts as root, hands the uploads folder to PUID/PGID (1000:1000 by default) and then drops to that user. Nothing changes for Docker Compose, but platforms that refuse to start containers as root, such as Kubernetes with runAsNonRoot, need an explicit user like runAsUser: 1000.
This release also fixes the flight reason dropdown not showing the selected reason, and updates AirTrail's dependencies, including MapLibre 6, which renders right-to-left map labels correctly.
This PR contains the following updates:
| Package | Update | Change |
|---|---|---|
| [johly/airtrail](https://github.com/johanohly/AirTrail) | minor | `v3.12.0` → `v3.13.0` |
---
### Release Notes
<details>
<summary>johanohly/AirTrail (johly/airtrail)</summary>
### [`v3.13.0`](https://github.com/johanohly/AirTrail/releases/tag/v3.13.0)
[Compare Source](https://github.com/johanohly/AirTrail/compare/v3.12.0...v3.13.0)
#### What's Changed
This release adds roles and permissions. Every account is now either the owner or has exactly one role, and you can edit the built-in **User** and **Administrator** roles or create your own under **Settings → Roles**, down to who can see or edit other people's flights. Existing accounts are migrated automatically: the owner stays the owner, admins become **Administrator** and everyone else becomes **User**. See [Roles and Permissions](https://airtrail.johan.ohly.dk/docs/administration/roles).
<img width="1200" alt="The Roles settings with the built-in roles and a custom role" src="https://github.com/user-attachments/assets/c07988bd-4212-4572-8664-e80b4e25dc27" />
AirTrail now has a versioned REST API at `/api/v1` and a remote [MCP server](https://airtrail.johan.ohly.dk/docs/api/model-context-protocol), so scripts and AI assistants can read and manage your flights. API keys and connected apps live under **Settings → Security** and carry scopes, so a key can be limited to less than your own role allows. Existing API keys keep full access, and the old `/api/flight/*` endpoints still work but are deprecated in favor of `/api/v1`. See [Getting started with the API](https://airtrail.johan.ohly.dk/docs/api/getting-started).
The basemap provider is now configurable under **Settings → Appearance → Basemap Provider**, with OpenFreeMap, CARTO, Protomaps or your own MapLibre style. OpenFreeMap is the new default and needs no key, so installs that never chose a provider will switch from the previous CARTO map to OpenFreeMap. CARTO now requires an API key. See [Basemaps](https://airtrail.johan.ohly.dk/docs/administration/basemaps).
The flight list now shows at a glance which flights have a track, recorded times, other passengers or a note, the passenger picker suggests guests you've added before, and flight lookups can use AeroDataBox's direct API instead of RapidAPI. For NAS users, there are now `PUID` and `PGID` settings and [Unraid templates](https://airtrail.johan.ohly.dk/docs/install/unraid). To make that work, the container now starts as root, hands the uploads folder to `PUID`/`PGID` (1000:1000 by default) and then drops to that user. Nothing changes for Docker Compose, but platforms that refuse to start containers as root, such as Kubernetes with `runAsNonRoot`, need an explicit user like `runAsUser: 1000`.
This release also fixes the flight reason dropdown not showing the selected reason, and updates AirTrail's dependencies, including MapLibre 6, which renders right-to-left map labels correctly.
##### 🚀 Features
- feat: configurable basemap providers by [@​johanohly](https://github.com/johanohly) in [#​725](https://github.com/johanohly/AirTrail/pull/725)
- feat: RBAC by [@​johanohly](https://github.com/johanohly) in [#​726](https://github.com/johanohly/AirTrail/pull/726)
- feat: add versioned REST API and MCP server by [@​johanohly](https://github.com/johanohly) in [#​737](https://github.com/johanohly/AirTrail/pull/737)
##### 🌟 Enhancements
- feat: show track, time, passenger and note indicators in the flight list by [@​Gaudv](https://github.com/Gaudv) in [#​714](https://github.com/johanohly/AirTrail/pull/714)
- feat: support the direct AeroDataBox API alongside RapidAPI by [@​mhlas7](https://github.com/mhlas7) in [#​732](https://github.com/johanohly/AirTrail/pull/732)
- feat: suggest previously added guests in the passenger picker by [@​Gaudv](https://github.com/Gaudv) in [#​711](https://github.com/johanohly/AirTrail/pull/711)
##### 🐛 Bug fixes
- fix: stabilize mobile drawers and dismissal behavior by [@​johanohly](https://github.com/johanohly) in [#​723](https://github.com/johanohly/AirTrail/pull/723)
- fix: stop preference changes resetting other preferences by [@​johanohly](https://github.com/johanohly) in [#​738](https://github.com/johanohly/AirTrail/pull/738)
- fix: allow selecting GPX and KML track files on iOS by [@​johanohly](https://github.com/johanohly) in [#​739](https://github.com/johanohly/AirTrail/pull/739)
- fix: allow typing any day before the month in date fields by [@​johanohly](https://github.com/johanohly) in [#​740](https://github.com/johanohly/AirTrail/pull/740)
##### 📚 Documentation
- fix: restore the broken star history chart by [@​FaintFlower](https://github.com/FaintFlower) in [#​718](https://github.com/johanohly/AirTrail/pull/718)
#### New Contributors
- [@​FaintFlower](https://github.com/FaintFlower) made their first contribution in [#​718](https://github.com/johanohly/AirTrail/pull/718)
**Full Changelog**: <https://github.com/johanohly/AirTrail/compare/v3.12.0...v3.13.0>
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTUuMTAiLCJ1cGRhdGVkSW5WZXIiOiI0NC4xMTUuMTAiLCJ0YXJnZXRCcmFuY2giOiJtYXN0ZXIiLCJsYWJlbHMiOltdfQ==-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
v3.12.0→v3.13.0Release Notes
johanohly/AirTrail (johly/airtrail)
v3.13.0Compare Source
What's Changed
This release adds roles and permissions. Every account is now either the owner or has exactly one role, and you can edit the built-in User and Administrator roles or create your own under Settings → Roles, down to who can see or edit other people's flights. Existing accounts are migrated automatically: the owner stays the owner, admins become Administrator and everyone else becomes User. See Roles and Permissions.
AirTrail now has a versioned REST API at
/api/v1and a remote MCP server, so scripts and AI assistants can read and manage your flights. API keys and connected apps live under Settings → Security and carry scopes, so a key can be limited to less than your own role allows. Existing API keys keep full access, and the old/api/flight/*endpoints still work but are deprecated in favor of/api/v1. See Getting started with the API.The basemap provider is now configurable under Settings → Appearance → Basemap Provider, with OpenFreeMap, CARTO, Protomaps or your own MapLibre style. OpenFreeMap is the new default and needs no key, so installs that never chose a provider will switch from the previous CARTO map to OpenFreeMap. CARTO now requires an API key. See Basemaps.
The flight list now shows at a glance which flights have a track, recorded times, other passengers or a note, the passenger picker suggests guests you've added before, and flight lookups can use AeroDataBox's direct API instead of RapidAPI. For NAS users, there are now
PUIDandPGIDsettings and Unraid templates. To make that work, the container now starts as root, hands the uploads folder toPUID/PGID(1000:1000 by default) and then drops to that user. Nothing changes for Docker Compose, but platforms that refuse to start containers as root, such as Kubernetes withrunAsNonRoot, need an explicit user likerunAsUser: 1000.This release also fixes the flight reason dropdown not showing the selected reason, and updates AirTrail's dependencies, including MapLibre 6, which renders right-to-left map labels correctly.
🚀 Features
🌟 Enhancements
🐛 Bug fixes
📚 Documentation
New Contributors
Full Changelog: https://github.com/johanohly/AirTrail/compare/v3.12.0...v3.13.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.