Release history

ArabDev patch notes

Every change to ArabDev, release by release: new features, improvements, fixes, security work and changes for developers. Use the filters to see only one kind of change, or type to search.

1.0.0

Latest release: ArabDev 1.0.0, the first public release

Released on .

  • changes
  • new
  • improved
  • fixed
  • security
  • developer

ArabDev 1.0.0

Latest

The first public release of ArabDev: a community for Arabic-speaking developers to write technical posts, follow each other and discover new topics, fully in Arabic and English. Entries marked New describe what ships in this release. Improved and Fixed entries describe changes made while testing the release before launch.

  • A real editor for technical writingHeadings, code blocks, tables, links, three fonts, six sizes and five theme-aware colors, with live preview and drafts.
  • Arabic first, English tooThe whole interface flips between right-to-left and left-to-right, and every paragraph finds its own direction.
  • A feed with an endThree tabs, 20 posts per page and numbered pages instead of infinite scrolling.
  • Honest, predictable adsClearly labelled, after every 8 posts, and never chosen using your personal information.
  • Secure by designArgon2id passwords, rotating sessions with theft detection, sanitised content and cleaned uploads.
  • We never sell your dataNo trackers, no third-party analytics and a plain-language privacy policy.

Accounts and sign-in

  • NewA split landing page: the ArabDev story on one side and sign-in or registration on the other. On phones the two stack vertically.
  • NewCreate an account with a username, email address and password (entered twice). Creating an account signs you in straight away.
  • NewUsernames are 3 to 20 characters, use English letters, numbers and underscores, start with a letter, and are not case-sensitive.
  • NewReserved names such as admin, api, settings, explore and support cannot be registered.
  • NewLive username availability check while you type, with a green check mark or a clear message such as “This username is already taken”.
  • NewThe email field checks that no other account uses the address as soon as you leave it.
  • NewPassword rules: 8 to 128 characters, at least one letter and one number, and not overly repetitive.
  • NewA password strength bar rates your password as weak, fair, good or strong while you type.
  • NewShow and hide buttons on every password field.
  • NewError messages appear under the field they belong to, in your language, instead of as a generic alert.
  • NewThe interface language you use while registering becomes your saved language preference.
  • NewSign in with email and password, with a Keep me signed in option that lasts up to 30 days.
  • NewWithout Keep me signed in, the session ends when the browser closes, and after 12 hours at most.
  • NewForgot-password flow: request a reset link, open it within 30 minutes, choose a new password.
  • NewSign out from the account menu, which ends the session on that browser.
  • NewPages that need an account send guests to sign in and bring them back to where they were afterwards.
  • NewSigned-in visitors who open the sign-in or registration page are taken to their feed instead.
  • NewYour session is restored silently when you reopen ArabDev, without a flash of the sign-in page.
  • SecuritySign-in says only “Email or password is incorrect” and takes the same time whether or not the email is registered.
  • SecurityThe forgot-password form gives the same answer for every address, so it cannot reveal who has an account.
  • SecurityResetting a password ends every existing session for the account.
  • ImprovedGuests no longer make an unnecessary session request on every visit: ArabDev only tries to restore a session in browsers that have signed in before.

First-visit setup

  • NewA four-step setup window opens on your first visit after creating an account.
  • NewA progress bar and a “Step 2 of 4” counter show where you are.
  • NewStep 1: upload a profile picture, with an instant circular preview while it uploads, and replace or remove it.
  • NewStep 2: adjust your username (with the same availability check), set a display name and write a short bio with a character counter.
  • NewStep 3: choose your interests from 25 topics. Selected topics show a check mark as well as a tinted background.
  • NewStep 4: up to eight suggested developers, based on the interests you just chose, each with a follow button.
  • NewEvery step can be skipped, and the window can be closed at any time. Anything skipped can be finished later in Settings.
  • NewFinishing or closing the setup is remembered on your account, so it never appears again on any device.
  • NewThe last step ends with a “Go to my feed” button that opens a feed already shaped by your choices.
  • NewOn phones the setup opens full screen so every step fits comfortably.

Navigation and pages

  • NewA navigation column with labels on wide screens: Home, Explore, Notifications, Bookmarks, Profile, Settings and a Create post button.
  • NewA narrow icon rail with tooltips on tablets.
  • NewA bottom navigation bar on phones with Home, Explore, Create, Notifications and Profile.
  • NewA side column on wide screens with suggested developers, one ad and popular tags.
  • NewAn account menu with Edit profile, Drafts, Bookmarks, Settings, theme and language switches, documentation links and Sign out.
  • NewA Bookmarks page listing everything you saved, newest save first.
  • NewA Drafts page with pagination, excerpts and tags.
  • NewA friendly “page not found” screen with a way back home.
  • NewYour home feed is the dashboard at arabdev.site/dashboard, and arabdev.site takes you straight there (or to sign in).
  • NewA Support link in the account menu and in every footer, which opens an email to support@arabdev.site.
  • NewSettings sections have their own addresses, such as /settings/privacy.
  • NewEach page is loaded only when you first open it, keeping the first visit small.
  • NewPage titles in the browser tab describe the page, such as a post title or a person's name.
  • NewLoading placeholders shaped like the content they stand in for.

Profiles

  • NewPublic profiles at /u/username, readable without an account.
  • NewProfiles show picture, display name, @username, bio, location, website and joining month.
  • NewFollowing, followers and posts counts, with the first two opening the full lists.
  • NewA “Follows you” badge when the person follows you.
  • NewInterests are shown as chips that open the matching tag page.
  • NewProfile tabs: Posts (including reposts), Replies (comments with a link to their post) and, on your own profile, Saved.
  • NewEvery profile tab is paginated, 20 items per page.
  • NewFollowers and following pages show each person as a card with bio, interests and a follow button.
  • NewA profile editor for display name (up to 50 characters), username, bio (up to 280), location (up to 60), website (up to 200) and interests.
  • NewThe Save button stays disabled until something changes, and problems are shown under the field concerned.
  • NewWebsite addresses without https:// have it added automatically, and are displayed as a short host name.
  • NewProfile pictures: JPEG, PNG, WebP or GIF up to 5 MB, cropped to a centered square and resized to 400×400.
  • NewPeople without a picture get their initials on a colored circle instead.
  • NewReplacing or removing a profile picture deletes the old file.
  • NewA friendly page for profiles that do not exist, instead of an error.
  • NewPeople who hide their connections show “This account keeps its connections private” on their lists.
  • ImprovedThe profile tabs now stay pinned under the top bar while you scroll.
  • FixedClicking a profile picture no longer shows a stray underline beneath it.

Home feed

  • NewA home feed with three tabs: For you, Following and Latest.
  • NewFor you groups posts by day, then shows people you follow first, then posts matching your interests, then everything else, newest first within each group. Nothing is hidden, only reordered.
  • NewFollowing shows your posts, posts from people you follow, and posts they reposted.
  • NewIf several people you follow repost the same post, it appears once, with a label naming who reposted it.
  • NewLatest shows every post strictly newest first.
  • NewServer-side pagination: 20 posts per page, with Previous, Next and numbered page links. No infinite scroll.
  • NewOn phones the page links are replaced by a compact “Page 2 of 5”.
  • NewThe tab and page number are kept in the address (/dashboard?tab=following&page=2), so reloading or sharing keeps your place.
  • NewChanging page returns you to the top of the feed.
  • NewA “What are you working on?” box at the top of the feed that opens the editor.
  • NewLoading placeholders shaped like posts, instead of spinners.
  • NewHelpful empty states: “No posts yet” with a button to write one, and an empty Following tab that points you to Explore.
  • NewA retry button if the feed cannot be loaded.
  • ImprovedThe current page stays visible, slightly faded, while the next page loads, so the screen never flashes blank.

Post editor

  • NewA rich post editor with an optional title of up to 200 characters.
  • NewParagraphs, headings and subheadings.
  • NewBold, italic, underline, strikethrough and inline code.
  • NewBulleted and numbered lists, including nested lists.
  • NewQuotes, shown with a red bar at the start of the line.
  • NewCode blocks on a dark background, always left-to-right, even inside Arabic posts.
  • NewTables with a header row: insert, add or remove rows and columns, and delete the table.
  • NewLinks through a dialog to add, change or remove a link on the selected text.
  • NewText alignment: start, center, end and justify, following each paragraph's own direction.
  • NewThree fonts: Tajawal, Alexandria and Anton, each shown in its own typeface in the menu.
  • NewSix text sizes: 14, 16, 18, 20, 24 and 30.
  • NewFive text colors (Red, Dark red, Ink, Graphite and Muted) that each have a light-mode and a dark-mode shade, so colored text stays readable in both.
  • NewUndo and redo buttons.
  • NewToolbar buttons are highlighted when their formatting is active at the cursor.
  • NewThe toolbar stays pinned under the top bar while you write long posts, and scrolls sideways on narrow screens.
  • NewKeyboard shortcuts, for example Ctrl + B for bold, Ctrl + E for inline code and Ctrl + Alt + C for a code block.
  • NewMarkdown-style shortcuts while typing: ## for a heading, - for a list, ``` for a code block and **bold** for bold text.
  • NewTab in a table moves to the next cell, and adds a row from the last cell.
  • NewEach paragraph, heading, list item and table cell picks its own direction from its first letters, so Arabic and English mix naturally in one post.
  • NewAttach one image per post (JPEG, PNG, WebP or GIF, up to 5 MB) with an upload progress bar and a remove button.
  • NewLarge images are scaled to fit 1600×1600 and saved as WebP.
  • NewRemoving an image you just uploaded, before saving, deletes it from the server.
  • NewAttach one link that the post is about; it is shown under the post as a card with the site name and address.
  • NewUp to 5 tags per post, entered with Enter, picked from suggestions, or pasted separated by commas.
  • NewA live preview that shows the post exactly as readers will see it: next to the editor on wide screens, behind a Preview tab on smaller ones.
  • NewDrafts: save everything without publishing, including title, body, tags, image and link.
  • NewAfter the first save, a draft gets its own address (/drafts/12), so reloading is safe.
  • NewA Drafts page listing your drafts, most recently edited first, with excerpts, tags and a discard button.
  • NewPublishing a draft turns it into a post and removes the draft.
  • NewA “Discard your changes?” prompt when leaving the editor with unsaved work, plus the browser's own warning when closing the tab.
  • NewEdit your own posts with the same editor; edited posts show an “edited” note.
  • NewClear messages for an empty post or an invalid link, shown where the problem is.
  • ImprovedThe font size menu is wide enough to show its values in full.
  • FixedThe leave-the-editor dialog no longer repeats its question twice.
  • SecurityPasted content keeps only the fonts, sizes and colors the editor offers; everything else is removed on the server when you publish.

Editor shortcuts and Markdown

Every shortcut below was checked against the editor itself. The Formatting reference in the wiki lists them all in one table.

  • NewCtrl + B for bold, Ctrl + I for italic and Ctrl + U for underline.
  • NewCtrl + Shift + S for strikethrough.
  • NewCtrl + E for inline code.
  • NewCtrl + Alt + 2 for a heading and Ctrl + Alt + 3 for a subheading.
  • NewCtrl + Shift + 8 for a bulleted list and Ctrl + Shift + 7 for a numbered list.
  • NewCtrl + Shift + B for a quote.
  • NewCtrl + Alt + C for a code block.
  • NewCtrl + Z to undo, and Ctrl + Shift + Z or Ctrl + Y to redo.
  • NewShift + Enter for a line break inside the same paragraph.
  • NewTab and Shift + Tab indent and outdent list items.
  • NewOn Mac, works wherever the shortcuts say Ctrl.
  • NewType ## and a space for a heading, or ### and a space for a subheading.
  • NewType -, * or + and a space for a bulleted list.
  • NewType 1. and a space for a numbered list that starts at that number.
  • NewType > and a space for a quote.
  • NewType ``` and a space for a code block, optionally with a language name such as ```python.
  • NewType --- for a horizontal divider.
  • NewWrap text in ** for bold, * or _ for italic, ~~ for strikethrough and backticks for inline code.
  • NewTyping or pasting a web address followed by a space turns it into a link.
  • NewPasting an address while text is selected turns the selected text into a link.
  • NewThe table dialog lets you choose 1 to 20 rows, 1 to 8 columns and whether the first row is a header.
  • NewInside a table, the table button offers Add row below, Add column after, Delete row, Delete column and Delete table.
  • NewWide tables scroll sideways on small screens instead of squeezing their content.
  • NewLink addresses typed without https:// have it added automatically.
  • NewChoosing the active alignment again removes it, returning the paragraph to its natural alignment.

Reading posts

  • NewPost cards show the author, relative time (with the exact date on hover), title, content, image, link card and tags.
  • NewLong posts are cut in the feed with a gentle fade and a “Read more” link.
  • NewClicking anywhere on a card opens the post, except on links, buttons and text you are selecting.
  • NewA full post page with the complete content, the author's follow button and the discussion.
  • NewAn estimated reading time at the top of every post page.
  • NewPosts without a title are labelled with their author's name instead.
  • NewA ⋯ menu on posts with Copy link for everyone, and Edit post and Delete post for the author.
  • NewDeleting a post asks for confirmation and explains that its comments, likes, reposts and saves go with it.
  • NewMentions (@username) in posts notify the people mentioned, up to 10 people per post.
  • NewLinks inside posts open in a new tab.
  • NewQuotes, lists and tables keep the direction of the language they are written in, even inside the other language's interface.
  • NewImages in posts are described for screen readers using the post title.
  • NewA clear page for posts that were deleted or never existed.
  • FixedThe follow button on a post page now shows whether you already follow the author, instead of always showing “Follow”.
  • FixedTags written in Arabic are now displayed in the correct direction.

Likes, reposts, saves and sharing

  • NewAn action row under every post: comment, repost, like, save and share, each with its count when above zero.
  • NewLikes: the heart fills in red and the count updates instantly.
  • NewReposts share a post with your followers and appear on your profile; select again to undo.
  • NewYou cannot repost your own post, so the button is disabled there.
  • NewSaves (bookmarks) are completely private and listed on the Bookmarks page and your profile's Saved tab.
  • NewShare uses your device's share sheet where available, or copies the link and says “Link copied”.
  • NewEvery change appears immediately and is undone automatically if the server refuses it.
  • NewYour like, save and repost state stays consistent everywhere the same post appears: feed, profile, search and the post page.
  • NewGuests who try to like, repost or save are asked to sign in and brought back to the post.
  • NewUndoing a like or repost before the author reads the notification withdraws the notification.
  • NewButtons announce their state to screen readers, for example “Like (4)” and whether it is pressed.

Comments

  • NewA Discussion section under each post, oldest comment first, 20 per page.
  • NewPlain-text comments of 1 to 2000 characters, with line breaks kept and a character counter.
  • NewSend with the Comment button or Ctrl + Enter.
  • NewReplies: choose Reply to show a “Replying to @username” chip, and remove the chip to cancel.
  • NewAfter posting, the discussion jumps to the page that contains your new comment.
  • NewMentions in comments become links to profiles and notify the people mentioned.
  • NewOne notification per person per comment, even if a comment both replies to and mentions them.
  • NewComments can be deleted by their author, the post's author or an administrator; replies go with them.
  • NewArabic and English comments each align correctly on their own.
  • FixedEvery mention in a comment is now linked; previously every second mention in a comment could be missed.
  • FixedEnglish usernames mentioned inside Arabic sentences no longer jump to the wrong place in the line.

Community and moderation

  • NewCommunity guidelines in the wiki: share generously, credit others, welcome beginners, and write in whichever language serves your readers.
  • NewClear rules against harassment, hate, spam, sharing private information, malware and impersonation.
  • NewGuidance for responsible security research and disclosure.
  • NewPost authors can remove comments on their own posts.
  • NewAdministrators can remove any post or comment that breaks the guidelines, and deactivate accounts for serious or repeated abuse.
  • NewDeactivated accounts cannot sign in and are left out of suggestions and search.

Following and suggestions

  • NewFollow and unfollow from profiles, suggestion cards, people lists and post pages.
  • NewThe Following button turns into a red “Unfollow” on hover or keyboard focus, so the action is clear before you take it.
  • New“Developers to follow” suggestions scored by shared interests (3 points each) and people you follow who follow them (2 points each).
  • NewSuggestions never include you, people you already follow, deactivated accounts, or people who turned off discoverability.
  • NewVisitors who are not signed in see the most-followed developers.
  • NewFollowing someone updates their follower count and your following count everywhere at once.
  • NewUnfollowing before the person reads the notification withdraws it.

Explore, trending and tags

  • NewAn Explore page open to everyone, with search, trending posts, popular tags and developers to follow.
  • NewTrending this week ranks the last 7 days' posts by likes plus twice their comments plus twice their reposts, favouring conversation.
  • NewIf nothing was posted in the last week, Trending falls back to the all-time ranking instead of showing nothing.
  • NewPopular tags ranked by use over the last 30 days, with the top three highlighted.
  • NewTag pages at /tags/name with the tag's posts, newest first, and how many posts use it.
  • NewTags are tidied automatically: lower-case, spaces become hyphens, a leading # is removed, and Arabic tags are supported.
  • NewCommon spellings are merged into one tag, for example jsjavascript, c++cpp and node.jsnodejs.
  • New25 interests, from JavaScript and Rust to Cybersecurity and UI/UX, each linked to a tag so posts and people meet.
  • NewInterest names are translated into Arabic where developers use an Arabic name, and kept as-is for languages and frameworks.
  • NewOn smaller screens, popular tags and suggestions move to the top of Explore.
  • ImprovedTag pages show the number of posts with correct Arabic and English plural forms.

Notifications

  • NewNotifications for likes, comments and replies, new followers, reposts and mentions.
  • NewA red unread badge on the Notifications item, refreshed every 30 seconds.
  • NewUnread notifications have a tinted background, a bold name and a “New” label, so they stand out without relying on color.
  • NewEach notification shows who acted, what they did, the post title and, for comments, the comment itself.
  • NewSelecting a notification marks it as read and opens the post or profile.
  • NewMark all as read.
  • NewNo notifications for your own actions, and no duplicates for repeated likes, follows or reposts.
  • NewEach kind of notification can be switched off in Settings.
  • NewChoose who can notify you with a mention: everyone, people you follow, or no one.
  • NewThe notifications list is paginated, 20 per page, and refreshes every minute while open.

Settings

  • NewSettings grouped into Account, Profile, Appearance, Privacy and Notifications, as a side list on wide screens and tabs on phones.
  • NewChange your email address, confirmed with your current password.
  • NewChange your password; other devices are signed out and the current one stays signed in.
  • NewTheme: Light, Dark or System, which follows your device.
  • NewLanguage: العربية or English.
  • NewTheme and language are saved to your account and follow you to other devices.
  • NewPrivacy: “Show me in search and suggestions” and “Show my followers and following lists”.
  • NewFive notification switches: likes, comments and replies, new followers, reposts and mentions.
  • NewSwitches save immediately with a “Settings saved” message, and go back if saving fails.
  • NewDelete my account, confirmed with your password, which permanently removes the account and everything linked to it.
  • NewQuick theme and language switches in the account menu.
  • NewA link to the privacy policy from the Privacy section.

Clear messages

  • New“Too many attempts. Wait a moment and try again.” when a rate limit is reached.
  • New“Your session has expired. Please sign in again.” when a session has ended.
  • New“This username is reserved.” for names the site uses itself.
  • New“Passwords don't match.” when the two password fields differ.
  • New“Mix letters and numbers so it's harder to guess.” for weak passwords.
  • New“Images must be 5 MB or smaller.” and “Use a JPEG, PNG, WebP or GIF image.” for rejected uploads.
  • New“This file isn't a valid image.” for damaged or disguised files.
  • New“This image is too small.” and “This image's dimensions are too large.”, with the exact limits in the wiki.
  • New“Write something before publishing.” when a post has no body.
  • New“Enter a valid link starting with http:// or https://.” for invalid attached links.
  • New“You can't repost your own post.” when trying to repost yourself.
  • New“Can't reach the server.” when the connection drops, with a retry button where it helps.
  • NewEvery message exists in Arabic and English, and the wiki's Troubleshooting article explains each one.

Ads

  • NewAds in feeds after every 8 posts, so at most two on a 20-post page, never at random positions.
  • NewOne ad slot in the side column on wide screens.
  • NewEvery ad has a boxed “Sponsored” label, says who promotes it, and uses a dashed frame and tinted background so it cannot be mistaken for a post.
  • NewAn information icon explains why ads are shown.
  • NewAds are chosen only by placement, language and page number, and rotate predictably between pages.
  • NewAds can target Arabic, English or both, and can have start and end dates.
  • NewImpressions and clicks are counted as totals, never linked to people.
  • NewArabDev launches with its own house ads, labelled “Promoted by ArabDev”.
  • NewNo ads inside posts, comments, profiles, search results, notifications or settings, and no pop-ups.
  • FixedThe “Sponsored” label now uses normal capitalisation instead of shouting in capitals.
  • FixedLists that never show ads, such as profile tabs, no longer request them.

Arabic, English and right-to-left

  • NewA complete Arabic interface, which is the default, and a complete English interface.
  • NewSwitching language flips the entire layout at once: navigation, menus, drawers, spacing and alignment.
  • NewDirection-sensitive icons, such as back arrows, pagination arrows and undo, are mirrored in Arabic.
  • NewProper Arabic plural forms for counts: one, two, a few and many each have their own wording.
  • NewDates and relative times in the interface language, for example “3 hr. ago” and «منذ 3 ساعات».
  • NewWestern digits (0–9) in both languages, which read best next to code.
  • NewUsernames, email addresses and code are always shown left-to-right, even in Arabic sentences.
  • NewError messages from the server arrive in your language.
  • NewThe page's language and direction are set before it first appears, so there is no flicker on load.
  • NewAll interface text lives in two translation files, so nothing is hard-coded in one language.
  • FixedThe language switch is now available on phones before signing in.

Design and dark mode

  • NewThe ArabDev identity: “Arab” in red and “Dev” in black (white in dark mode), set in Anton.
  • NewAlexandria for headings, Tajawal for body text and Anton for the logo and statistics, all hosted by ArabDev itself.
  • NewA red and white visual identity with a carefully tuned dark mode.
  • NewDark mode that follows your device by default, with a manual choice in Settings and the account menu.
  • NewNo flash of the wrong theme while pages load.
  • NewA three-column layout on wide screens, an icon rail on tablets and a bottom navigation bar on phones.
  • NewA red Create button in the middle of the phone navigation bar.
  • NewAn ArabDev favicon.
  • FixedThe phone header no longer wraps onto two lines.

Accessibility

  • NewA “Skip to content” link on the first press of Tab.
  • NewEvery control can be reached and used with the keyboard, with a clear red focus outline.
  • NewIcon-only buttons have spoken names, and toggles announce whether they are on.
  • NewSearch suggestions follow the standard combobox pattern for screen readers.
  • NewDialogs keep focus inside them until they are closed.
  • NewLoading areas are marked as busy, and messages such as “Link copied” are announced.
  • NewState is never shown by color alone: unread notifications have a “New” label and selected interests a check mark.
  • NewContrast that meets common guidelines in both light and dark mode.
  • NewAnimations are turned off when your device asks for reduced motion.
  • NewPages zoom without losing content, from small phones to wide screens.
  • NewEvery page has a meaningful title, such as the post title or the person's name.

Performance

  • NewThe server sends at most 20 posts at a time, and each page is fetched with a fixed number of database queries, however many posts it contains.
  • NewThe editor is loaded only when you open it, so reading ArabDev stays fast.
  • NewThe interface library and the editor are split into separate, cacheable bundles.
  • NewRecently viewed data is reused instantly and refreshed quietly in the background.
  • NewPopular tags and the interests list are cached on the server.
  • NewUploaded images are served with long-lived cache headers because their names never change.
  • NewLarge API responses are compressed.
  • NewFonts are self-hosted as WOFF2 and shown with font-display: swap, so text is readable immediately.
  • NewSearch suggestions wait for you to pause typing, instead of querying on every keystroke.
  • NewSQLite runs in write-ahead-log mode so reading and writing do not block each other.

Security

  • SecurityPasswords are hashed with Argon2id and upgraded automatically if hashing settings get stronger.
  • SecurityShort-lived access tokens (15 minutes) kept only in the page's memory, never in browser storage.
  • SecurityLong-lived sign-in tokens are random, stored only as SHA-256 hashes, and delivered in an HttpOnly cookie limited to the sign-in endpoints.
  • SecuritySign-in tokens rotate on every use; reuse of an old token ends the whole session family.
  • SecurityChanging or resetting your password immediately invalidates every outstanding access token.
  • SecuritySession renewal and sign-out require a custom header that other websites cannot send, blocking cross-site request forgery.
  • SecurityPassword reset links are single-use, expire after 30 minutes and are stored only as hashes.
  • SecurityRate limits on sign-in, registration, password reset, publishing, commenting, interactions, follows, uploads and search.
  • SecurityRate limits are shared between server processes through Redis when it is configured.
  • SecurityPosts are sanitised on the server with a strict allow-list of tags, attributes, fonts, sizes, colors and link schemes.
  • SecurityPosts are sanitised again in the browser before being displayed, as a second line of defence.
  • SecurityLinks in posts only allow http, https and mailto, and are marked noopener noreferrer nofollow ugc.
  • SecurityUploads are decoded as real images and re-encoded; anything else is refused.
  • SecurityUpload size is limited to 5 MB, and extreme image dimensions are rejected.
  • SecuritySecurity headers stop other sites from framing ArabDev and stop browsers from guessing file types.
  • SecurityEvery permission is checked on the server: only authors can edit their posts, and only the right people can delete comments.
  • SecurityChanging your email address or deleting your account requires your current password.
  • SecurityImages can only be attached by the account that uploaded them.
  • SecurityThe API refuses to start in production without a real secret key.
  • SecurityBrowser access to the API is limited to configured origins.
  • SecurityEnded sign-in sessions and old password reset links are deleted automatically: when the API starts, then every six hours on a server or once a day on Vercel.
  • FixedTwo tabs renewing the session at the same moment no longer sign you out: a 20-second grace period tells this apart from real token theft.

Limits that keep ArabDev fair

Normal use never comes close to these limits. They exist to stop automated abuse.

  • SecuritySign in: 10 attempts per minute per network.
  • SecurityCreate account: 10 per hour per network.
  • SecurityForgot password: 5 requests per 15 minutes.
  • SecurityReset password and change password: 10 each per 15 minutes.
  • SecurityUsername and email availability checks: 60 per minute.
  • SecuritySession renewal: 60 per minute.
  • SecurityPublishing posts: 30 per hour.
  • SecurityComments: 60 per 10 minutes.
  • SecurityLikes, saves and reposts: 300 per hour.
  • SecurityFollows: 120 per hour.
  • SecurityImage uploads: 30 per 10 minutes.
  • SecuritySearch: 120 per minute.
  • SecurityAd click counting: 60 per minute, so totals cannot be inflated.
  • NewPosts: up to 5 tags of 30 characters each, a 200-character title, and one attached link of up to 500 characters.
  • NewA single post notifies at most 10 mentioned people.

Privacy

  • NewA full Privacy Policy in Arabic and English, organised by topic, with a promise that ArabDev never sells user information.
  • NewNo third-party analytics, trackers, advertising pixels or social widgets.
  • NewOnly one cookie, which keeps you signed in. No cookie banner is needed because nothing tracks you.
  • NewLocation and camera metadata are removed from every uploaded image.
  • NewAds never use personal information, and advertisers receive nothing about users.
  • NewBookmarks and drafts are private, and authors are never told who saved their posts.
  • NewTurn off discoverability to leave suggestions and people search.
  • NewHide your followers and following lists.
  • NewAccount deletion removes your content, interactions, uploads and sessions immediately, and recalculates counts on other posts.
  • NewEmail addresses are never shown to other users.
  • NewSearch terms are not stored.

API and developers

  • DeveloperA versioned REST API under /api/v1 covering everything the app does.
  • DeveloperInteractive documentation at /api/docs and /api/redoc, and an OpenAPI description at /api/v1/openapi.json.
  • DeveloperEvery list endpoint uses the same pagination: page and limit in, {items, page, limit, total, pages} out.
  • DeveloperConsistent errors: a readable detail, a stable code, and field or errors for validation problems.
  • DeveloperError messages are translated using the Accept-Language header.
  • DeveloperRate-limited responses return HTTP 429 with a Retry-After header.
  • DeveloperAuthentication endpoints: register, login, refresh, logout, availability, forgot-password and reset-password.
  • DeveloperAccount endpoints for profile, username, email, password, interests, settings, onboarding, avatar, bookmarks and deletion.
  • DeveloperFeed endpoint with tab=for_you|following|latest and an optional tag filter, plus a trending endpoint.
  • DeveloperPost, draft, comment, like, bookmark, repost and follow endpoints.
  • DeveloperSearch with type=all|posts|users|tags, popular tags, tag details and the interests list.
  • DeveloperNotification endpoints with an unread count, mark-one and mark-all.
  • DeveloperMedia upload and deletion of unused uploads.
  • DeveloperAd serving and click counting, plus administrator endpoints to create, update and delete ads.
  • DeveloperA health endpoint that reports database and Redis status.
  • DeveloperA layered backend: routes, services and repositories, with Pydantic schemas for every request and response.
  • DeveloperA typed SQLAlchemy 2 data model with 19 tables and Alembic migrations.
  • DeveloperA storage abstraction for uploads, with a local-disk backend ready to be swapped for object storage.
  • DeveloperAn email abstraction; without a provider, emails are written to the server log.
  • DeveloperA typed frontend API client with automatic, single-flight session renewal.
  • DeveloperQuery keys and cache updates organised so one change updates every list that shows the same post or person.

Data model

  • Developerusers, profiles and user_settings: accounts, public profile details and preferences, one row each per person.
  • Developerinterests and user_interests: the 25 topics and who chose them.
  • Developerposts, tags and post_tags: published posts and their tags, with tag names normalised.
  • Developerdrafts: unpublished posts, private to their author.
  • Developercomments: comments and replies, each linked to its post and, for replies, to the comment it answers.
  • Developerlikes, bookmarks, reposts and follows: one row per interaction, with composite keys that make duplicates impossible.
  • Developernotifications: who did what to whom, and whether it has been read.
  • Developermedia: uploaded images with owner, kind, size and dimensions.
  • Developerads: ad content, placement, language, schedule and aggregate counters.
  • Developerrefresh_tokens and password_reset_tokens: hashed tokens only, never the raw values.
  • DeveloperPost counters (likes, comments, reposts) are stored on the post and recalculated when accounts or comments are deleted, so lists never need expensive counting.
  • DeveloperDeleting an account or a post removes every dependent row through database-level cascades.
  • DeveloperAll timestamps are stored in UTC and returned with a time zone.

Backend architecture

  • DeveloperRoutes stay thin: they validate input, check permissions and call a service.
  • DeveloperServices hold the business rules: authentication, users, posts, interactions, comments, notifications, discovery, ads and media.
  • DeveloperRepositories hold the database queries, including the For you ranking, the following feed and trending.
  • DeveloperPresenters build API responses for a whole page at once, loading authors, tags and your interaction state in a few batched queries.
  • DeveloperValidation errors carry stable codes that the frontend translates, instead of English sentences.
  • DeveloperSettings are typed and loaded from the environment, with safe development defaults.
  • DeveloperA cache layer that uses Redis when available and memory otherwise.
  • DeveloperImages are processed with Pillow: decoded, checked, resized, stripped of metadata and saved as WebP.
  • DeveloperThe HTML sanitiser allows only the markup the editor produces, including its fonts, sizes, theme colors, alignment and text direction.
  • DeveloperSeed data: 25 interests and 6 house ads, inserted idempotently.
  • DeveloperDemo data: ten fictional developers with posts, follows, likes and comments, for trying ArabDev locally.
  • DeveloperEnded sessions and old reset links are deleted by a background task every six hours on a server, and by a scheduled job on Vercel; both reuse the same clean-up.

Frontend architecture

  • DeveloperOrganised by feature: auth, onboarding, posts, editor, comments, discovery, search, notifications, profile, users, ads and preferences.
  • DeveloperEvery page is a lazily loaded route, with guards for signed-in only and signed-out only pages.
  • DeveloperServer data is cached for 30 seconds and kept for 5 minutes; client errors are not retried, and server errors are retried twice.
  • DeveloperOptimistic updates for likes, saves, reposts, follows and settings, rolled back on failure.
  • DeveloperA single API client adds the access token and language to every request and renews the session once when several requests fail together.
  • DeveloperTheme built on CSS variables for light and dark schemes, so switching theme does not re-render the app.
  • DeveloperA right-to-left style cache that mirrors layout styles automatically for Arabic.
  • DeveloperPost content uses logical CSS properties, so content keeps its own direction regardless of the interface language.
  • DeveloperAll text comes from ar.json and en.json, with Arabic plural rules.
  • DeveloperA small, shared set of building blocks: empty states, error states, skeletons, pagination, confirmation dialogs and notifications.
  • DeveloperPage titles and language attributes are managed centrally.

Running and deployment

  • DeveloperSQLite as the database, with write-ahead logging, foreign keys and a busy timeout enabled.
  • DeveloperConfiguration through environment variables and .env files, with documented examples.
  • DeveloperRedis is optional: without it, rate limiting and caching fall back to memory.
  • Developerpython -m app.cli seed adds the 25 interests and house ads, and is safe to run repeatedly.
  • Developerpython -m app.cli seed --demo adds ten fictional developers and their posts for local testing.
  • Developerpython -m app.cli make-admin USERNAME grants administrator rights.
  • Developerpython -m app.cli purge-tokens deletes ended sessions and old reset links on demand.
  • DeveloperDocker Compose setup with Redis, the API and an nginx container serving the app on port 8080.
  • DeveloperThe API container applies migrations and seeds reference data when it starts.
  • DeveloperPersistent volumes for the database file and uploaded media.
  • DeveloperThe frontend builds to a static site, ready for Vercel or any static host.
  • DeveloperThe development server proxies /api and /media to the API.
  • DeveloperThe wiki, privacy policy and patch notes are self-contained static sites, with their own fonts and icon, deployed without a build step to wiki.arabdev.site, privacy.arabdev.site and patch.arabdev.site.
  • DeveloperThe development server serves those sites locally at /wiki/, /privacy/ and /patch-notes/, and links between them stay local on your machine.
  • DeveloperThe app build publishes the license at arabdev.site/LICENSE.txt.
  • DeveloperVITE_API_ORIGIN lets the app reach an API hosted on another address; the documentation addresses can be overridden the same way.
  • DeveloperRuns on Vercel: vercel.json builds the app and serves the API from api/index.py in one project, so both share an address.
  • DeveloperPostgreSQL support for hosted deployments (Neon on Vercel), with SQLite still the default for development and single-server hosting. The tests run against both.
  • DeveloperHosted Postgres URLs (postgres://, postgresql://) are pointed at the psycopg 3 driver automatically, and Neon's connection pooler is handled.
  • DeveloperOn Vercel the API migrates and seeds the database itself when an instance starts; a PostgreSQL lock keeps instances that start together from colliding.
  • DeveloperUploaded images can be kept in the database (STORAGE_BACKEND=database) for hosts without a disk, and are served with long-lived cache headers.
  • DeveloperA scheduled endpoint for the daily clean-up, protected by CRON_SECRET and hidden when it is not configured.
  • ImprovedMySQL support was removed. ArabDev uses SQLite for development and single-server hosting, and PostgreSQL when hosted on Vercel.
  • ImprovedImages between 4 and 5 MB are re-encoded in the browser before uploading, so they fit hosting limits. The server re-encodes every image anyway, so nothing visible changes.

Documentation

  • NewThe ArabDev Wiki: 25 articles in Arabic and English covering every feature, safety, troubleshooting and development.
  • NewWiki search that runs in your browser, with Arabic-aware matching and a / shortcut.
  • NewGenerated contents boxes, section links and previous/next navigation in every wiki article.
  • NewA 28-section Privacy Policy with plain-language summaries, a contents list that follows your reading, and print support.
  • NewThese patch notes, with type filters, live counts and search.
  • NewWiki articles for newcomers: Getting started, a Frequently asked questions page and a Glossary of ArabDev and developer terms.
  • NewWiki guides for every feature: profiles, the home feed, writing posts, a formatting reference, tags and interests, comments, following, search, notifications and settings.
  • NewWiki articles on trust and safety: privacy and safety, account security, ads and community guidelines.
  • NewA Troubleshooting article that explains every common message and what to do about it.
  • NewDeveloper articles: an architecture overview, running and self-hosting, a full API reference, and contributing and license.
  • NewWiki pages show one article at a time with a sidebar of every article, and keep working as one long page without JavaScript.
  • NewThe privacy policy has an “In short” summary for every section, tables of cookies, storage keys and retention periods, and a list of the data protection laws of nine Arab countries.
  • NewThe privacy policy highlights the section you are reading and shows your reading progress.
  • NewAll documentation sites work on phones, print cleanly, support dark mode and have skip links for keyboard users.
  • NewThe app opens each documentation site in your language, and switching language on them keeps your place.
  • NewA Contact and support article in the wiki: support@arabdev.site for help, bugs, reports, privacy and security, and hi@arabdev.site for sponsorship, contributions, partnerships and questions.
  • NewLinks to the wiki, privacy policy, patch notes and license in the app's side column, account menu and sign-in pages, opening in a new tab.
  • NewArabDev is free software under the GNU General Public License v3, with the full license published at /LICENSE.txt.
  • NewA README covering features, architecture, setup, configuration, deployment and backups.

Tests and code quality

  • Developer51 automated backend tests covering authentication, sessions, posts, feeds, comments, interactions, notifications, uploads, search, account deletion and serverless hosting. They run against SQLite and PostgreSQL.
  • DeveloperEvery test runs against a fresh in-memory database.
  • DeveloperStrict TypeScript across the frontend, checked with npm run typecheck.
  • DeveloperConsistent formatting with Prettier (npm run format).
  • DeveloperBuilt on current major versions: React 19, Material UI 9, React Router 8, TanStack Query 5, TipTap 3, Vite 8 and TypeScript 7.
  • DeveloperOn the server: FastAPI, Pydantic 2, SQLAlchemy 2 and Alembic.
  • FixedSeveral icons that were renamed in Material UI 9 now load correctly.
  • FixedStyling that relied on features removed in Material UI 9 was rewritten, which also removed a console warning.

Changed during pre-release testing

Before launch, ArabDev was tested page by page, in both languages, on wide and narrow screens. These are the changes that testing produced; most also appear under their area above.

  • FixedProfile tabs stopped sticking to the top of the screen after the page was scrolled.
  • FixedThe follow button on a post page always said “Follow”, even when you already followed the author.
  • FixedIn a comment with several mentions, some mentions were not turned into links.
  • FixedArabic tags were shown in the wrong direction.
  • FixedThe ad label was displayed in capital letters.
  • FixedThe phone header wrapped onto two lines on narrow screens.
  • FixedThere was no language switch on phones before signing in.
  • FixedProfile pictures used as links showed an underline.
  • FixedEnglish usernames inside Arabic comments could appear at the wrong end of the sentence.
  • FixedThe unsaved-changes dialog repeated its text.
  • FixedThe font size menu in the editor was cut off.
  • FixedVisitors who had never signed in triggered a failed session request on every page load.
  • FixedA styling rule caused a warning in the browser console.
  • FixedProfile tabs and other lists requested ads they never displayed.
  • FixedOpening ArabDev in two tabs could sign you out when both renewed the session at once.
  • FixedSome icons were missing after upgrading the interface library.
  • ImprovedThe number of posts on a tag page now uses proper plural wording in both languages.
  • ImprovedFollowing-feed and repost queries were reworked to be stricter and faster.
  • ImprovedFollowing yourself is prevented by the server with a clear error, instead of relying on the database.
  • ImprovedThe database layer was simplified to SQLite, then taught PostgreSQL as well so ArabDev could be hosted on Vercel with a Neon database.
  • SecurityExpired and ended sessions and old password reset links are now cleaned up automatically, as described in the privacy policy.
  • NewThe GNU GPL v3 license, the wiki, the privacy policy and these patch notes were added before launch.

1.0.0 by the numbers

  • 2 complete interface languages, Arabic and English, with right-to-left and left-to-right layouts.
  • 3 feed tabs and 20 posts per page.
  • 5 kinds of notifications, each with its own switch.
  • 25 interests linked to tags.
  • 3 fonts, 6 sizes and 5 theme-aware colors in the editor.
  • 19 database tables and 49 API paths.
  • 51 automated backend tests.
  • 25 wiki articles, a 28-section privacy policy, and these patch notes, each in both languages.
  • 1 cookie, and 0 trackers.

The 25 interests at launch

Chosen during setup or in Settings, and matched to the tag shown after each name.

  • JavaScript javascript
  • TypeScript typescript
  • Python python
  • C++ cpp
  • Rust rust
  • Go go
  • Java java
  • C# csharp
  • React react
  • Vue vue
  • Angular angular
  • Node.js nodejs
  • FastAPI fastapi
  • Django django
  • AI ai
  • Machine Learning machine-learning
  • Cybersecurity cybersecurity
  • Linux linux
  • DevOps devops
  • Cloud cloud
  • Databases databases
  • Game Development game-development
  • Mobile Development mobile-development
  • UI/UX ui-ux
  • Open Source open-source

Try 1.0.0 locally

The quickest way to run the whole stack is Docker Compose from the project folder:

cp .env.example .env        # set SECRET_KEY
docker compose up --build   # then open http://localhost:8080

To work on the code, run the API and the frontend separately:

cd backend
python -m venv .venv
.venv/Scripts/activate      # macOS/Linux: source .venv/bin/activate
pip install -e ".[dev]"
alembic upgrade head
python -m app.cli seed --demo
uvicorn app.main:app --reload --port 8000

cd ../frontend
npm install
npm run dev                 # http://localhost:5173

The Running and self-hosting article in the wiki covers configuration, deployment and backups in detail.

Where to get help

  • Start with the Getting started and FAQ articles in the wiki.
  • If something shows an error, the Troubleshooting article explains each message.
  • Account problems, bugs, content reports and privacy requests: write to support@arabdev.site. The Contact and support article explains what to include.
  • Found a security problem? Report it privately to support@arabdev.site with the subject “Security”, not in a public post.
  • Sponsorship, contributions, partnerships and other questions: write to hi@arabdev.site.
  • Developers can explore the live API documentation at /api/docs.

Known limitations

Things ArabDev 1.0.0 does not do yet. None of them are promises of a date, but they are the first areas we are looking at.

  • There are no private messages between members.
  • No email provider is connected, so password reset links are written to the server log instead of being emailed. Self-hosters can connect one in email_service.py.
  • There is no report button for posts, comments or profiles yet; send reports to support@arabdev.site.
  • Ads can only be managed through the API; there is no administration screen.
  • Posts can have one image each.
  • Comments are plain text; they do not support formatting or images.
  • There is no self-service data download yet; copies of your data are available on request.
  • Notifications appear inside ArabDev only; there are no email or push notifications.
  • With SQLite the API runs as a single process; hosting on Vercel uses PostgreSQL instead.

Requirements and upgrade notes

  • Browsers: current versions of Chrome, Edge, Firefox and Safari, on desktop and mobile.
  • To run the API: Python 3.11 or newer. To build the frontend: Node.js 20.19 or newer (or 22.12 and later).
  • This is the first release, so there is nothing to upgrade from. New installations run alembic upgrade head to create the database.
  • Set SECRET_KEY, and in production also ENVIRONMENT=production and COOKIE_SECURE=true behind HTTPS.
  • Back up arabdev.db and the media folder regularly.

Credits

ArabDev stands on the shoulders of excellent open-source work. Thank you to everyone behind:

  • Alexandria typeface · SIL Open Font License
  • Tajawal typeface · SIL Open Font License
  • Anton typeface · SIL Open Font License
  • React user interface
  • Material UI and Emotion components and styling
  • stylis-plugin-rtl right-to-left styles
  • React Router routing
  • TanStack Query data fetching and caching
  • TipTap and ProseMirror the post editor
  • i18next translations
  • DOMPurify browser-side sanitising
  • Axios HTTP client
  • Vite and TypeScript build tooling
  • FastAPI and Starlette the API
  • Pydantic validation
  • SQLAlchemy and Alembic database and migrations
  • SQLite the database
  • argon2-cffi password hashing
  • PyJWT access tokens
  • nh3 server-side sanitising
  • Pillow image processing
  • Redis optional shared limits and caching
  • pytest testing