Changelog
All notable changes to Content Repurpose (nr_) are documented here.
The format follows Keep a Changelog and the project adheres to Semantic Versioning. This page lists the main points of each release; the full entries, with the reasoning behind each change, are in the repository's CHANGELOG.md.
Version 0.9.0 (2026-09-30)
Security
- A source URL can no longer reach the host or the internal network: only
httpandhttpsare fetched, and a host that resolves to a loopback, private, link-local or reserved address is refused. - A remote source is limited to 5 MiB and 30 seconds (a PDF to 50 MiB and
120 seconds), and redirects are not followed. The time limit covers the
whole transfer only with the PHP extension
curl; without it, it applies to each read. See A URL job fails with "Source is larger than …" or "Source did not arrive within …". - Job and artifact errors no longer show the text model's messages, server paths, SQL, process output or webhook URLs; those go to the TYPO3 log. A source URL in an error, a label or a prompt is shown without user name, password, query and fragment.
- HTML renders run without JavaScript and without network access.
- Vision OCR of a PDF needs the
nrrepurpose:permission.generate_ vision
Added
- A developer chapter, a troubleshooting page and a usage chapter with screenshots of the backend module.
LICENSEwith the GPL-2.0 text, and README instructions for verifying a release.
Changed
- Requires nr-vault 1.1 (
^1., was1 ^0.) and therefore nr-llm 0.38.2 or later. nr-vault 1.x refuses a provider host that DNS does not resolve: a host reached through16 /etc/or a container runtime's resolver needs an entry inhosts $GLOBALS.['TYPO3_ CONF_ VARS'] ['HTTP'] ['allowed_ hosts'] - The Netresearch-theme Schaubild, story slides, slide deck and handout carry the [n] logo and a linked company footer; the extension icon is the [n] symbol.
- Record forms, permission options and extension settings are translated (English and German).
composer.carries the extension version andjson provides;Packages typo3/moves tocms- install require-.dev - The renderer passes the Chromium path to
render.itself; the worker no longer needs to exportcjs CHROMIUM_. See Renderer environment.PATH - Breaking for custom PHP code: the pipeline passes a typed
Jobinstead of the raw job row (Snapshot Source,Ingestion Service Interface:: ingest () Document,Analyzer Interface:: analyze () Pdf,File Resolver:: resolve () Generation), andContext Processtakes an optionalRunner Interface:: run () $envargument. Code that implements or calls these has to follow.
Fixed
- A failed job names how many formats failed, instead of showing an empty error, and its artifact count matches its artifacts.
- A
pdf_job reads the PDF attached to it, not the file whose uid equals the number of attachments.fal - Story headlines no longer run off the slide, and the footer and copy stay legible over a KI background.
- A podcast no longer fails on a numeric persona name or a nested value in the dialogue script.
- Slide renders and most temp files of a run are removed.
- The job list is paged, draws its progress bar and fits the module; error text on cards and table rows is readable in the dark scheme.
- Source downloads work under Guzzle 8.
ext_states the same dependency ranges asemconf. php composer..json
Version 0.8.2 (2026-09-27)
Fixed
- The Create & queue button gives its feedback again: its script is now an ES module instead of an inline script the backend Content Security Policy refused, so a double click can no longer queue a job twice.
- An alt-text generator listening to FAL events no longer fails every PNG
artifact: files are written with their bytes in place before FAL indexes
them. The podcast subtitles (
vtt) are added totextfile_.ext
Version 0.8.1 (2026-09-27)
Changed
- Accepts nr-llm 0.38 (
^0.).35 | | ^0. 36 | | ^0. 37 | | ^0. 38
Version 0.8.0 (2026-09-27)
Added
- Story video: the finished story slides can also become one silent 1080×1920 MP4 (option Also as video).
- Approval step for every artifact, gated by the custom permission
nrrepurpose:. See ADR-007: Approval Step and Publishing Through a Webhook.approve_ artifacts - Social planning: approved social posts are scheduled and sent to a
webhook by the command
nr_. See Publishing social posts.repurpose: publish- due - Two documents as PDF: a 16:9 slide deck and an A4 handout, printed by the headless Chromium. See ADR-006: Document Formats as HTML Printed to PDF.
- The PDF carries the AI label in its document information and XMP metadata.
New database columns: run the database analyzer after the update.
Version 0.7.0 (2026-09-26)
Added
- Every artifact is labelled as AI-generated, machine-readable in each
stored file and in the artifact metadata; the visible labels are
controlled by
aiandLabel Images ai. See AI labelling and ADR-005: AI Label on Every Artifact, Embedded at Storage.Label Texts
Version 0.6.0 (2026-09-25)
Security
- Source text can no longer pose as an instruction in the text completions (document analysis, podcast, Schaubild, story, text formats): the source material reaches the model only as one block marked as untrusted data (CWE-1427). Image-generation prompts and the PDF vision OCR are not covered; see ADR-004: Text Formats as Schema-Validated Structured Output.
Added
- Four text formats: executive summary, FAQ, social posts and newsletter text, each one schema-validated nr-llm call, off by default. See ADR-004: Text Formats as Schema-Validated Structured Output.
New database columns: run the database analyzer after the update.
Version 0.5.3 (2026-09-24)
Changed
- Accepts nr-llm 0.37 (
^0.).35 | | ^0. 36 | | ^0. 37
Version 0.5.2 (2026-09-23)
Changed
- Accepts nr-llm 0.36 (
^0.).35 | | ^0. 36
Fixed
- The permissions
generate_andaudio generate_are enforced. Editors whose groups do not carry them no longer get podcast audio and AI imagery. See Backend capability permissions and ADR-008: Capability Permissions Checked Before Spend.vision
Version 0.5.1 (2026-09-17)
Fixed
ext_declaresemconf. php nr_, matchingllm 0. 35. 0- 0. 35. 99 composer..json
Version 0.5.0 (2026-09-17)
Changed
- Requires nr-llm
^0..35
Fixed
- The
nr_preset is declared once; the duplicate made nr-llm's Configurations module answer with an error.repurpose_ text - Resolving the
nr_configuration passes the value object nr-llm 0.35 expects; a string raised arepurpose_ text Typethat would have bypassed the fallback to the instance-default configuration.Error
Version 0.4.9 (2026-09-03)
Fixed
- The
nr_preset asks only for therepurpose_ text chatcapability, so it can be imported. ext_declaresemconf. php nr_.vault
Version 0.4.8 (2026-09-03)
Added
- The Content Repurpose Starter use-case pack. See The starter pack.
Changed
- Requires nr-llm
^0..34
Version 0.4.7 (2026-08-21)
Changed
- Requires nr-llm
^0..33
Version 0.4.6 (2026-08-21)
Added
- Every nr-llm call names this extension and its pipeline step, so nr-llm's
analytics attribute usage and cost to
nr_.repurpose
Changed
- Requires nr-llm
^0..32
Version 0.4.5 (2026-08-20)
Changed
- Requires nr-llm
^0..31
Version 0.4.4 (2026-08-19)
Changed
- Requires nr-llm
^0..30
Version 0.4.3 (2026-08-13)
Changed
- Accepts nr-llm 0.29 alongside 0.28.
Version 0.4.2 (2026-08-11)
Added
- The extension setting technicalBeUserUid.
Fixed
- Generation jobs no longer fail in the analysis step with a denied nr-vault read, once a technical backend user is configured.
Changed
- Requires nr-vault
^0..15
Version 0.4.1 (2026-08-10)
Changed
- Requires nr-llm
^0..28
Version 0.4.0 (2026-08-07)
Changed
- Requires nr-llm
^0..26
Removed
- The public alias for nr-llm's capability permission service, which nr-llm 0.26 removed.
Version 0.3.1 (2026-07-31)
Changed
- Accepts nr-vault 0.12 (
^0.).10. 0 | | ^0. 11. 0 | | ^0. 12. 0
Fixed
Documentation/states the released version.guides. xml
Version 0.3.0 (2026-07-24)
Changed
- Requires nr-llm
^0..25
Version 0.2.3 (2026-07-22)
Changed
- Accepts Symfony 8 for
symfony/andprocess symfony/.messenger
Fixed
- Composer resolves the latest tag: the explicit
versionfield is removed fromcomposer..json
Version 0.2.2 (2026-07-22)
Added
- nr-llm 0.23 support (
complete), and a documentation render job in CI.Structured ()
Fixed
- The documentation renders again (repaired
guides.).xml
Version 0.2.1 (2026-07-21)
Changed
- Backend icons in the TYPO3 v14 style, and a record icon for artifacts.
- Accepts nr-vault 0.11.
Fixed
- Borders in the job detail view follow the dark scheme.
Version 0.2.0 (2026-07-18)
Added
- One-click nr-llm configuration presets for
nr_,repurpose_ text nr_andrepurpose_ image nr_.repurpose_ tts - Text generation routes through the
nr_configuration.repurpose_ text
Changed
- Requires nr-llm
^0..22. 0
Version 0.1.0 (2026-06-12)
Initial alpha release.
Added
- Three artifact generators. From one source (URL or PDF) the pipeline
derives a single
Contentvia nr-llm and generates a persona-aware podcast with one to three speakers (TTS + ffmpeg stitch + WebVTT subtitles), a Schaubild diagram in three variants (HTML, HTML-with-AI-background, full AI image), and a multi-slide 9:16 Instagram story carousel.Brief - Prompt-snippet steering. Persona, tone, audience, image-style and
layout selectors in the job form, backed by nr-llm's prompt-snippet
library; layout snippets carry an
imagemetadata key that drives gpt-image-2 output dimensions per channel.Size - Live progress and prompt transparency. The job detail view shows fine-grained per-step progress with auto-refresh while a job runs and, for every artifact, the complete creation parameters: the exact system, user and image prompts, models, image sizes and voices.
- Central usage and cost tracking. Image and speech models resolve
through nr-llm Configuration records (
nr_,repurpose_ image nr_), so every call is attributed per model and per configuration in the nr-llm analytics module.repurpose_ tts - Ingestion. URL fetch with deterministic DOM main-content extraction, and
a tiered PDF reader (embedded text → Vision OCR for sparse pages → poppler
layout extraction for tabular pages), selectable per job via
pdf_.mode - Asynchronous generation. Job submission dispatches a
Generateonto a Symfony Messenger transport; a long-running worker consumes it and runs the orchestrator. See ADR-001: Asynchronous Generation via Symfony Messenger.Artifacts Message - Node + Playwright renderer. A bundled CommonJS script
(
render.) drives the aptcjs chromiumbinary throughplaywright-to turn branded Fluid HTML into PNGs. See ADR-002: Node + Playwright Renderer for Image Composition.core - Backend module. Repurpose (
web_) with a job list, a submission form, and a result view that plays the podcast and shows every generated image.nrrepurpose - CLI command.
nr_runs the full pipeline synchronously for ops and debugging.repurpose: generate <job Uid> - Vault-backed OpenAI key. The OpenAI key is stored in nr-vault and read
by identifier (
nr_) by nr-llm. See ADR-003: Provider Credentials Delegated to nr-llm.repurpose_ openai