Documentation
API reference

Start here

Search every guideesc close

Releases

What's new

Everything that has shipped recently, on the server and in the apps, newest first.

102 min read

Every tofa release ships with notes, and this page keeps them all in one place. Your server updates itself from the beta channel (or tells you when a new Docker image is ready), so the newest version here is usually the one you are already running.

iPhone#

The latest TestFlight build (build 17) steadies playback:

  • Scrubbing back and forth quickly no longer gets the player stuck.
  • A stream that dies recovers on its own instead of failing the session.
  • Auto quality stops retrying a rate your connection can't sustain.
  • A first iPad pass: landscape video fits instead of cropping the sides, fill covers the screen, grids use the width, and the welcome tour no longer clips its language pills.
  • A title that isn't in your library can open in the streaming service that carries it, straight from its page.

Build 16 rebuilt most of the app:

  • Titles, people, Settings and Downloads all open as a card over the app, and swipe away downwards.
  • Download moved into a title's options sheet, where it can tell you the file size first and offer its qualities in place.
  • An episode opens as a panel you page sideways with your thumb, and a season says how much of it is left.
  • A pill above the dock follows a download from the tap to the moment it lands, with the title, the percentage, the rate and the time remaining.
  • Switch Profile and Switch Server sit together, and moving to another server no longer signs you out.
  • Browse scrolls its genre lane to the genre that is actually filtering, so a filtered grid never looks unfiltered.
  • New pixel avatars.

Apple TV#

The latest TestFlight build (build 17) bundles a few waves:

  • Switching servers no longer signs you out: Settings, Switch Server.
  • A long synopsis scrolls so you can read all of it.
  • Moving through a card's options no longer loses your place on the shelf.
  • Scrubbing back and forth quickly no longer gets the player stuck, and a stream that dies recovers on its own.
  • Auto quality stops retrying a rate your connection can't sustain.
  • New avatar art, including the pixel set.

Build 15 brought:

  • Home rows come from your server, so a shelf your server starts publishing shows up on the TV without waiting for an app update. The layout editor edits what Home actually draws.
  • Discover is redesigned: a gentler wash over the artwork, cards that move without flashing, and your profile within reach.
  • Subtitles rasterize at the screen's own resolution, and picture subtitles follow the fill zoom instead of drifting outside the caption band.
  • Audio fidelity defaults to lossless, now the ladder is verified on real hardware.

Android TV#

The current closed-testing build (0.1.10) brings:

  • Auto frame rate works. Your TV now switches to the film's own rate when playback starts rather than as you leave it, direct-played MKV files included, and a switch no longer lands the film paused.
  • Discover is the page the Apple TV app has: around thirty shelves filed under Now, Acclaimed, Genres and Decades, with one open card in each row carrying the title logo and the scores.
  • Home rows come from your server, so a shelf your server starts publishing shows up on the TV without waiting for an app update. The row editor edits what Home actually draws, and a layout you rearrange on one device is no longer overwritten by another.
  • PGS subtitles play. Picking one used to end the stream.
  • Dolby Vision is claimed only where the box can genuinely decode it, so a set that cannot is no longer handed a stream it has no way to play.
  • Fill zoom removes black bars baked into the picture, not just the ones the container adds, which is what a 2.39:1 disc remux has always needed.
  • Back with the controls up hides the controls instead of leaving the film, holding left or right seeks at a steady pace on any remote, and the transport icons say what they mean.
  • Posters and the player speak their whole state to a screen reader, and artwork loads without stutter on boxes with no AV1 decoder in silicon.

Server 0.10.0#

Moving from Plex, Emby or Jellyfin#

  • Bring your library setup with you: collections, movie playlists, artwork, custom metadata, audio and subtitle preferences, and your profile picture can now join your watch progress and saved titles. Plex imports also include dated watch and rewatch history.
  • The import walks you through each step and confirms which Tofa profile you're importing into. Compare artwork side by side, keep individual images, or import everything available at once. Admins can map people's watch progress and saved titles to their Tofa profiles and review the shared library once.
  • Keeping Plex around? Collections and artwork can keep following changes there. Pause or resume syncing in Settings, and check everyone's sync status under Integrations. Emby and Jellyfin use a one-time import.
  • Large artwork imports keep their connection alive while they work. A failed history batch no longer stops the rest of a Plex sync, and an unreachable Plex server no longer holds up everyone else's sync.
  • Titles you've dismissed from Continue Watching stay dismissed when old history is imported. Watching them again in Plex brings them back.

Trailers#

  • Watch trailers for movies and shows from their title pages, both in your library and in Discover. On the web, trailers play in a pop-up player so you can keep browsing without leaving Tofa.
  • Our apps get the Trailer button too, in the client updates rolling out over the coming days.
  • Trailers come from YouTube for now. We plan to serve them ourselves, so where they play may change in a later release.

Accounts and access#

  • Household members can watch on a shared TV using their own account and profiles, with their own library access and PIN protection. You’ll need to update your client apps to use this. Those updates will roll out over the coming days.
  • Previously signed-in sessions can recover locally when Tofa's cloud is unreachable, so you can keep using a reachable server during an internet outage. The web app supports this; native apps need an update with local recovery support. Signing in for the first time still needs an internet connection.
  • Temporary cloud failures no longer discard your saved sign-in or incorrectly report that household access has been revoked.
  • Household and security settings are easier to find.

Playback#

  • Firefox connections to a server on the same network are more reliable. We've fixed disconnects when returning to a tab or loading several things at once.
  • We've improved seeking in H.264 files with missing keyframe markers, which could leave you with sound but no picture or a long wait after jumping ahead.
  • In the web player, paused video stays paused when you change audio or playback quality, or retry a failed session.
  • Choosing a show's version now carries through to its episodes. Widescreen 4K copies are correctly labeled as 4K, so they no longer disappear from the version picker.
  • Episodes split across files are recognized when the part marker appears in the middle of the filename, such as "S02E01 pt1 - Peril at End House".
  • A full transcode disk or an incomplete playback segment no longer triggers repeated attempts to convert the video as though its format were the problem. QuickView work started for a viewing session is also kept until playback ends.

Subtitles#

  • Compatible TV apps can show picture-based and styled subtitles without waiting for the whole track to be prepared, including embedded fonts, colors and transparency.
  • Automatic subtitle selection is no longer lost when a title's saved track list is missing. Older apps keep working after the server update, and background cleanup no longer interrupts subtitle preparation.

Browsing and library management#

  • We’ve made quite a few improvements across the web UI, with tidier layouts, clearer settings and small fixes to make everyday browsing and library management feel smoother.
  • Clicking an actor in search results or a title's cast opens their page, with titles from your library and more of their filmography in Discover.
  • Libraries have clearer tables and settings dialogs, a scan button on each row, and activity windows that stay open until the job's final messages arrive.
  • Scans retry missing cast photos even when a title already has some. You can also use "Fill missing" to check again yourself.
  • Deleting large libraries is faster, and removing a season no longer conflicts with deleting its files.
  • Lifecycle rules have a roomier editor, clearer condition groups and errors beside the fields that need fixing.
  • Request approval settings explain "Follow server policy" and "Always approve", including when the server sends requests automatically. TV requests sent to Sonarr now say so.

Running your server#

  • Choose where Tofa stores temporary playback files in Settings > Transcoding, including a RAM disk. We check the folder and show its available space. Anything already playing keeps using its original folder.
  • FillView picks up where it left off after a server restart instead of starting over, and files that fail get a break before another attempt. You can choose whether background work pauses while people browse or watch.
  • Playback problem counts agree across the dashboard, sidebar and email digest. Brief buffering and server restarts are less likely to count as problems, repeated attempts at the same title are grouped together, and you can mark problems as reviewed.
  • We check database backups before removing older ones and keep the newest backup we've verified can be restored. Backup creation and verification no longer get interrupted by competing tasks.
  • Hardware transcoding settings hide modes your server doesn't support. Region pickers use the same country list, and unsupported intro, recap or credits actions are rejected instead of silently becoming a different setting.
  • Mac server updates are no longer missed because Finder left extra metadata files beside the update.

For app and integration developers#

  • Continue Watching includes each episode's air date and the show's synopsis alongside the episode's, so apps can choose what to display without another lookup.
  • The API description now documents batch size limits, refreshed profile-token headers, locked-profile responses and accepted audio-selection options. Unsupported audio-selection values are rejected instead of silently selecting every audio track.

Server 0.9.36#

Highlights#

  • Seeking is fixed. On 0.9.35, the second seek, quality change or audio switch of any session was rejected on every app: web said "Playback session is no longer active", and TV apps snapped back to the original quality or showed a paused screen. The server now accepts these requests for the whole life of a session, and one click means one seek. Related: two devices on the same profile can now watch the same title at the same time without one device's seek or quality change ending the other's stream.
  • You can now change any episode's thumbnail. Upload your own image, pick from the provider's stills, or drop an image file next to the episode file; your choice sticks through metadata refreshes, and a local file always wins over NFO artwork.
  • Intro and credits skips can now be inspected and fixed per title. Every file of a title shows what each detector found, or in plain words why it found nothing, and you can re-run detection for a single title instead of the whole library.
  • Library management has been redesigned. Settings open in a cleaner dialog that works on any screen size, and each library gets its own maintenance panel so scans, refreshes and generation work can be run and watched per library. This is only the first iteration; we are working on more improvements across the whole server admin area.
  • Subtitles can now look the way you want, everywhere. A new Subtitle style section under Settings > Playback sets size, color, background, boldness, outline, and vertical position, and the choice follows your profile to every device signed into your server. Styled subtitles keep their own look unless you turn on plain text, and picture-based subtitles can't be restyled.
  • You can now pick a secondary audio and subtitle language on every app. The player tries your primary language first and falls back to the secondary, and the language list is the same 42 languages everywhere.

Everything else#

  • Heads up if you roll back or run multiple servers on one database: this release upgrades the database, and older server versions can't read the upgraded format. Going back to 0.9.35 means restoring the backup taken before the update, and if several servers share one database they must all be stopped and updated together. Single-server setups just update as normal.
  • QuickView and FillView generation are now under your control. QuickView can be Off, On demand or Full library for each library, with a server-wide switch and schedules in a timezone you can see. FillView has matching generation modes, and each kind of work now shows its own progress, wait or pause reason, and stop action instead of being mixed together. Turning either feature off keeps everything already generated.
  • TV libraries can use TVDB aired ordering as the library's episode numbering.
  • On TVs and other devices set to a non-English language, a fresh profile now starts with that language preferred for audio and subtitles instead of English.
  • A preference saved while your server couldn't reach the cloud no longer stays stuck on that server. The server now retries in the background until it syncs, so the setting reaches your other devices.
  • Prepared subtitle tracks are now stored durably and reused across sessions and restarts instead of being rebuilt every time, so subtitles come up faster on titles you've played before.
  • A manual "check for updates" can no longer sit at Checking forever; a stalled check times out and reports what happened.
  • Collection pages can hide titles that aren't in the collection's library, and remember the choice.
  • The server log is quieter: expected end-of-session requests and files already marked unavailable no longer repeat as warnings, and the warnings that remain say which file and request they're about.
  • Windows: QuickView generation no longer fails while finalizing files, and fresh installs accept the bundled database's checksum files whichever tool generated them.

Server 0.9.35#

Highlights#

  • Subtitles stay in sync again. Since 0.9.33, embedded subtitles on any title the server converts or remuxes for playback (HEVC in a browser, most Apple TV and Android TV streams) could run several seconds late after starting mid-title, seeking or skipping an intro, and the gap grew with every jump. Behind the scenes we rebuilt subtitle handling from the ground up: every stream now shares one content timeline with its subtitles, and every app loads them through the same path, so cues should always stay in sync with the picture whichever client you watch on. If you still see drift anywhere, tell us.
  • Subtitles show up faster on a cold start. Text, ASS and image-based (PGS) subtitles all follow one loading rule now: the first window of cues is shown as soon as it is ready while the full track keeps loading in the background, instead of waiting up to fifteen seconds for the whole track before showing anything.
  • Browse can now act on many titles at once. Select titles (or everything that matches the current filters) and add them to a collection, mark them watched or unwatched, add them to a watchlist, keep them from lifecycle rules, edit their metadata, refresh them, analyze their files, move them to another library, remove them from the library or delete their files. Long jobs run in the background with a progress tray, survive a restart, and can be cancelled.
  • The Windows app now starts on every regional format. Windows set to a non-Latin regional format (Turkish, Greek, Russian and others) could not create the server's database on first start and never came up; the database is now created with a fixed locale, and its health checks read the same way whatever language Windows is set to.

Everything else#

  • Continue Watching: fully watched shows no longer come back as "next up" after episodes are marked watched again (a bulk season mark, or a client re-syncing watched state). Only an episode you actually finish playing a second time counts as a rewatch.
  • Tags selected for a Sonarr or Radarr instance are now attached to every title requested through tofa, so you can filter those apps to see what tofa requested. Existing tags are kept, and anime-specific Sonarr tags still take priority when configured.
  • In-app updates work again on macOS. Since 0.9.31 the macOS package contained linked files inside the bundled database that the updater refuses, so every in-app update stopped with "Unsafe archive entry type" and only a command-line reinstall could move the server forward. The package is now built without links, and the release pipeline refuses to publish a package that contains any.
  • Lifecycle: the per-library preset switch now actually saves. It wrote to a request the server ignores, so it snapped back off and a full evaluation returned nothing. The Rules tab also says when your custom rules are paused because the library's preset is off, instead of silently skipping them.
  • TV libraries now show a "Show defaults" card with the library-wide episode numbering, hidden seasons and original title settings that the per-show Advanced dialog already pointed at. Changing the default numbering re-matches the shows that follow it.
  • Activity now says which profile is watching, not just the account, in the Activity page, the activity bell and the feed, so households with several profiles can tell who is playing what.
  • Keyboard chapter navigation in the web player: Page Up jumps to the next chapter and Page Down to the previous one (or back to the start of the current chapter once you are more than ten seconds in).
  • The Browse alphabet rail is back; it had stopped rendering.
  • Fresh installs download the bundled database from our own download host instead of GitHub, so networks that block GitHub can still install.

Server 0.9.34#

Highlights#

  • API keys: server admins can create keys under Server > Settings > API keys for dashboards and scripts that talk to the server directly. A key acts as the admin who created it, can be given an expiry, and can be revoked at any time.
  • A built-in API reference now lives under Server > Settings > API, right below your API keys. It lists every endpoint your server exposes, generated from the exact version you are running, with a filter and a copyable curl example for each call.
  • Libraries can now manage their own shelf life. A per-library lifecycle rule flags titles that nobody has watched in a long time (never watched, not watched recently, or watched and idle, with the number of days up to you), lists them under Hygiene with how much space they would free, and sends a "Leaving soon" notification. By default it only reports; removal is a separate switch, off until you turn it on both server-wide and per library, and every removal waits out a grace period first. Anything on a watchlist, kept by an admin, requested again, playing now, or mid-watch is never touched. Titles managed by your automation tools are only removed through the matching tool and are never unlinked locally.
  • Lifecycle rules: besides the built-in preset, admins can now write their own rules under Server > Lifecycle > Rules, combining conditions such as how long a title has been in the library, when it was last watched, whether anyone requested it, its ratings, and free disk space, with and/or grouping. Rules can target whole titles or single seasons of a show, run in report-only or removal mode, and can be tried against one title before they are turned on. The flagged list shows why each title matched, the Hygiene tab gains select-all Keep and a confirmed Remove now, and an empty flagged page tells you which titles are closest to matching and in how many days. Editing a rule's grace period restarts the countdown for the titles it flags.
  • A new opt-in "Leaving soon" home row shows viewers which titles are scheduled to be removed, so adding one to a watchlist keeps it around.

Everything else#

  • The OpenAPI document your server publishes now carries shapes only: endpoint names, parameters and types. Descriptions come from a reviewed public API document, so engineering notes can no longer end up in it. The API reference card in Settings shows the same reviewed text.
  • Files with several audio tracks now convert only the track you are actually playing instead of all of them at once. On modest hardware this fixes the constant rebuffering those files could have. Picking a different audio track in the web player takes a brief moment while the stream changes over; when no conversion is involved, switching is instant as before.
  • Requests now remember which library title they brought in, so lifecycle reports can say who asked for a title.
  • Deletions made inside your automation tools now mark the affected title's missing files unavailable in tofa right away instead of waiting for the next background check.
  • Watched now means watched: a title counts as seen once someone has played a meaningful part of it, not only when they reached the end, so lifecycle rules and the requester engagement check no longer treat a movie watched to the credits as untouched.
  • Background work such as scans and QuickView generation pauses while somebody is browsing the apps. A new switch on the Background activity card lets you turn that off so the server keeps working while people browse; playback still takes priority.
  • Deleting a title managed by Sonarr or Radarr from its detail page now goes through that tool, so it stops monitoring the title instead of downloading it again. When the tool's record does not match the files on disk, the server refuses and the page shows the reason.
  • Renaming a file that never got an episode number now works. The unplaced-files view kept showing the old name, and a show whose match you had locked refused to place the renamed file, so a season could stay stuck as unplaced no matter what you renamed it to. Renamed files bind on the next scan, and multi-episode names like S01E01E02 keep both episodes.
  • Shows set to TVDB episode order now apply it to Season 0 as well. Specials kept their TMDB numbering while the rest of the show followed TVDB, so the order preview and the actual result disagreed; existing files keep their S00E numbers.
  • Downloads for offline viewing at a lower quality now convert on your graphics card like streaming does, instead of always using the processor, with the same Dolby Vision and HDR handling. When the card is busy the app is told the server is at capacity, cancelling a download stops the conversion right away rather than leaving it running, and these conversions now show up in Health.
  • Request labels now match what the server actually does: people you have allowed to request without approval, and admins, see their requests sent straight away under an approval-required policy instead of being told an admin must approve first.
  • Continue Watching now follows a rewatch: when you finish an episode of a show you have already watched, the next episode shows up again instead of the show disappearing from the row.
  • Diagnostics reports now include up to 500 skipped and unlinked TV files per library instead of 50, sampled evenly across shows, so support can see every affected show without asking for screenshots.
  • Quality and download menus now offer 720p for low-bitrate 1080p files. A 1080p file at 3 Mbps used to jump from Original straight to 540p because our 720p tier targets 4 Mbps; lower tiers are now capped at three quarters of the source bitrate instead of being hidden, and tiers that would end up the same size collapse into the sharper one.
  • Anime in folders without a year now matches using the year repeated in its episode filenames, and an existing automatic match repairs itself when it is clearly from a different era. Correcting a match also removes empty seasons and artwork left behind by the old show.
  • Chapter images now keep making progress when one frame is unusually slow to extract. A timed-out hardware attempt falls back to the processor, completed images are kept when the job retries, and one difficult chapter no longer prevents every later chapter from getting an image.
  • Diagnostics bundles no longer balloon when preview generation has failed on some files. A failing file could store megabytes of repeated ffmpeg output per attempt, and one bundle reached 133MB from 25 such failures; error details are now kept to a few readable kilobytes, both for new failures and when exporting old ones.
  • Fixed high-bitrate 4K HDR and Dolby Vision remuxes failing instantly on Apple TV. The player rejected these titles at start and fell back to a degraded picture; they now open and play with the quality the file carries.
  • Image-based subtitles (PGS) load much faster when several people watch the same title, and subtitle loading no longer competes with playback for disk speed on large files.
  • Home screen posters no longer grow oversized on big monitors. Cards kept scaling up with the window, so on a 1440p or ultrawide screen each row showed a handful of very large posters. Laptop screens look the same as before; larger screens now hold poster size steady and show more titles per row instead.
  • Shows that exist only in TheTVDB can now be matched. Fix Match accepts a pasted thetvdb.com series link or a tvdb tag, and our metadata service now carries those series, so a show with no TMDB entry gets its episodes, artwork and descriptions like any other title.
  • A match you pick by hand now sticks, even when a .nfo file beside the media says otherwise. The sidecar used to put the old title back seconds after every Fix Match. A sidecar that names a different title is now ignored, and one that agrees only fills in what the online sources left empty. Fix Match also tells you when poster or fanart files sit beside the title and lets you prefer the matched title's own artwork instead, per title and reversible from the edit dialog.
  • Episodes named with a punctuated token like "Show - Ep. 01 - Title" now parse correctly. Files an earlier version registered without an episode number are repaired on the next scan, so seasons that looked empty fill in on their own. The Suggested Requests row also gained scroll arrows on wide screens.
  • Movies in a folder named "Title (Year)" whose file name says little, such as a release-group tag or a date stamp, now take their title and year from the folder instead of guessing from the file.
  • Converted playback from an NVIDIA graphics card no longer freezes on Android TV after the first few segments. The encoder was producing segments more than twice as long as the playlist promised, and the Android player gave up waiting; segments now match what the playlist says, and a playlist whose timing cannot be trusted is no longer served.
  • Dolby Vision profile 7 remuxes now play as HDR10 on HDR televisions that do not support Dolby Vision, instead of being converted to 4K H.264 in software. We hand those players the HDR10 base layer the file already carries.
  • A converted stream whose converter had already exited could keep holding one of the server's transcode slots, so other titles were refused as "at capacity" while nothing was running. Slots now free themselves the moment the process is gone, and the at-capacity message says so in plain words instead of an error code.
  • When a title ends and nothing plays next, the web and desktop players now return you to where you came from instead of sitting on the final frame, which on the desktop app could look like a black screen with no way back.
  • The Hygiene card now lists which titles are missing from disk, with the paths that are gone, before you confirm the cleanup, instead of only showing a count.
  • Nightly backup verification no longer leaves multi-gigabyte database dumps behind. A verification interrupted partway through could leave an 8 to 12 GB file inside the container that nothing cleaned up, and one Docker image had grown by 48 GB this way. Verification now streams the backup straight into the database without writing the dump, the server removes what older versions left behind at startup, and in Docker scratch files now land on your data volume.
  • QuickView generation no longer gives up on a title because the disk was full at the time. A full disk used to burn through every retry in about twenty minutes and mark the title as failed for good; it now waits for space and resumes. Titles that failed this way are queued again after updating, and the per-library "Generate now" action also queues chapter images.
  • Health no longer counts titles in libraries that never fetch online metadata as pending, and files that can never be probed, such as disc images or files with a broken header, no longer re-enter QuickView generation over and over.
  • Sonarr no longer receives a fresh webhook registration from the server every five minutes. Existing registrations are reused, and a Sonarr that is unreachable is retried with backoff instead of on every pass. Health also warns when a volume is filling fast enough to run out within two weeks, based on a steady trend, separately from the low-space warning, and routine "segment not ready yet" responses during playback no longer show up as warnings in Server Logs.
  • Samsung and LG televisions using the TV app now appear under their platform name in playback activity instead of "Browser NN".
  • On phones, the Browse letter rail now leads with an All cell and takes less room. Under Server > Libraries, clicking anywhere on a library's row now opens it, not only its name, and the Health storage card no longer leaves an empty column when a server has one or two volumes.

Server 0.9.33#

  • The poster style setting has two new options: prefer posters with the title text at the bottom, or at the top. When the catalog has no poster with the text where you asked for it, you choose the fallback: a poster with no title text (the default, instead of text in the wrong place) or the standard poster. This feature is still settling in: our artwork service has not analyzed every poster yet, so some titles fall back today that will get a matching poster later, and poster sorting will keep improving over the coming releases without you doing anything. The server log now lists each poster that a style change replaces.
  • New "Reset manual poster picks" action, server-wide and per library: posters you picked or uploaded by hand go back to what the poster style setting chooses. Local artwork files kept next to your media still win.
  • Changing the poster style now asks for confirmation before applying, both server-wide and per library. It updates posters across your whole catalog in the background, so it should not happen on a stray click.
  • "Refresh metadata" on a library now really refreshes everything. It used to skip any title it had already looked up in the last 24 hours and still report that it had finished, so if a show came in with placeholder episode titles or missing episode images there was no way to make the server fetch them again until the next day. Pressing it now re-fetches the whole library.
  • Posters, backdrops, logos and episode images no longer vanish when a refresh cannot reach our artwork service. A single failed download used to clear the picture your server had already stored, so a brief network problem during a refresh left titles blank until the next successful one. Existing artwork is now kept until we have something better to replace it with.
  • The server no longer wakes your media drives every hour to look for files that are not there. Its background metadata pass used to check the disk for a poster and a matching .nfo beside every episode, on every pass, even in a library that has never used those files, which kept spun-down drives spinning up all night. Scans now record which titles actually have .nfo files, and the background pass reads that instead of the drives. Add a .nfo and the next full library scan finds it and applies it, as does refreshing the title yourself.
  • You can now choose when the server is allowed to work on your drives. A new background activity window under Scanning holds scheduled scans, metadata refreshes and QuickView generation until a time you pick, so drives that spin down stay parked for the rest of the day. It is off by default. Playback is never held back, nor is generating QuickView for a title you picked, nor a library that has never been scanned.
  • Libraries on storage that cannot deliver file-change notices no longer sit still until someone runs a manual scan. When the server finds it cannot watch a folder, which is common on network mounts, it now scans that library on its own every fifteen minutes, or hourly when only some folders are affected, and the library settings page shows a "Not watching" notice so you can see why. New files keep appearing either way.
  • Converted playback that freezes partway through a movie now recovers instead of hanging. If the converter goes silent mid-stream, the server notices within half a minute, ends the stalled stream, and your app starts a fresh one from where you were, rather than waiting forever on video that will never arrive.
  • "Fall back to the processor" now also applies after playback has started. It used to help only when a hardware conversion failed to start at all, so a graphics card that gave out a few minutes into every movie left you with a frozen picture and a setting that appeared to do nothing. When that happens the next stream of that title runs on the processor, and a card that keeps failing is rested automatically.
  • Graphics card failures are now named in the log instead of being recorded as an unknown error, so a support report shows which card failed and why.
  • When the converter cannot start, apps now retry for a moment instead of showing an error straight away. Some of these failures clear on their own within a second or two, most often when a previous stream of the same title has not finished releasing the graphics card.
  • "Skip the PIN here for 30 days" now lasts. Three things could quietly end that choice in the web and cloud apps: a brief hiccup in the first request after a page load threw the grant away for good, opening the app as one profile erased every other profile's remembered unlock, and typing your PIN once in Settings shortened the grant back to a few hours. Note that Safari's tracking protection still caps browser storage at seven days, so on Safari the browser may ask again sooner than 30 days.
  • Windows servers now accept direct connections on networks Windows has classified as Public. Our firewall rule covered only Private and Domain networks, and Public is what Windows assigns to a new network by default, so some servers quietly lost direct connections and fell back to the relay. Installing this version, or re-running the installer over an existing server, opens the port for every network type.
  • Switching a shared user from all libraries to specific libraries now saves correctly. Picking individual libraries for someone looked like it worked but had no effect, and they kept access to everything. The choice you make is now the choice that sticks, both for people you have already shared with and for new invites.
  • You can now make your own collections. Anyone with an account on your server can create a collection, name it, describe it, and put any mix of movies and shows from your library in it; the creator or an admin can rename it, change what is in it, or delete it. Collections are shared with everyone on the server, and each person sees only the titles their libraries and rating limit already allow.
  • Collections can now have their own artwork. Set a poster or backdrop from the collection page, or point your server at the folder where tools like tinyMediaManager keep movie set artwork and we will use what is in it, descriptions included.
  • "Always show subtitles" no longer turns on subtitles in a language you do not speak. When a video had no subtitles in your preferred language, the web player picked the first track it found, whatever the language. It now looks for your language, then the language of the audio you are hearing, then an untagged track, and otherwise leaves subtitles off.
  • Subtitles embedded in files whose internal clock does not start at zero, common in WEB-DL releases, no longer disappear or run early by a constant amount during converted playback. Other players read the file directly and were unaffected, which made this look like a player problem on our side only.
  • A server start that fails because a leftover database process still holds the port no longer tries to restore from a backup. The server now says the old process is the problem and that a container or machine restart clears it, and your data is left alone. Startup checks also stopped reading messages from earlier runs when deciding whether the database is damaged.

Server 0.9.32#

  • Subtitles that come as VobSub files next to your videos now work. Discs ripped with their original subtitle tracks often keep them as .idx and .sub files beside the video; the server now picks those up during a scan, and the web and desktop apps draw them over the video the way the disc intended.
  • You can now let the server produce HEVC when it converts video. A new setting under transcoding, off by default, allows HEVC output for devices that support it, which keeps more detail at the same bandwidth. Your server's hardware encoder is used when it has one, and the software encoder got noticeably faster.
  • When Radarr or Sonarr deletes a file, your library now reflects it right away instead of at the next scan.
  • 4K Dolby Vision videos that also carry HDR10+ no longer play as a black screen with sound on Apple TV. We now prepare those files for the player instead of handing them over untouched. Regular HDR10 and Dolby Vision titles play exactly as before.
  • Surround-sound movies are no longer quieter than they should be when converted to stereo. Dialogue now comes through at its proper level and the subwoofer channel is kept in the mix instead of being dropped, with a safety limiter so loud scenes stay clean.
  • Shows that share a name now stay separate when your folders say they are different shows. Two folders like "Ghosts [US]" and "Ghosts [UK]" used to end up as one listing, because the bracket tag is not part of the title and neither folder gave a year. If each folder has its own tvshow.nfo with a provider id, or an id tag in its name, we now read that at scan time and keep the two shows apart, with each folder's episodes on its own listing. Folders that do not state an id behave exactly as before. If a pair already merged, Split Apart can now separate them.
  • The server log no longer warns about every movie folder that carries an id tag alongside an NFO file. Folders named with an {imdb-...} tag next to a matching NFO logged a metadata warning on every refresh even though the match was correct, which on a tagged library could fill the warning log with nothing else. Those warnings are gone; genuine unresolved-id cases still warn.
  • Windows updates now stop the tray before replacing its program. 0.9.31 could still fail on machines where Windows refused to rename the running tray executable, leaving the server on its previous version until the installer repaired it. The server files are now installed and checked first, then the tray is stopped, replaced, restarted, and restored automatically if it cannot resume supervision.
  • Probe concurrency now means the number you selected for every storage profile. Network mounts and hard drives previously kept your choice in Settings but silently ran only one or two probes; changing to one of those profiles now starts conservatively, then any number you explicitly choose is honored immediately. Settings warns you to raise it gradually and watch storage load.
  • Hardware transcoding in Docker now works from the device passthrough alone. Handing the container your GPU with devices: /dev/dri was only half the setup: the server also had to be given the group that owns those devices, and without it every hardware session failed with a permission error that looked like a broken driver, quietly falling back to software. The server now reads the owning groups off the devices you passed in and grants them to itself, so passing the GPU through is the whole setup. A group_add you already have keeps working.
  • QuickView chapter images now generate for very large files. Making one image was given a fixed one minute, which is plenty for an ordinary file but not enough to reach into a 4K remux of several tens of gigabytes, so those titles never got their chapter images. The time allowed now scales with the size of the file, up to ten minutes each. Files that gave up under the old limit are queued again automatically when your server updates, so their chapter images appear without you doing anything.
  • Direct connection now works for servers that have both IPv4 and IPv6 and a manually forwarded port. The server used to leave its public IPv4 address out of its report to the connection service, which on dual-stack connections then only knew about the IPv6 side; if the router firewalls IPv6, every app fell back to the relay even though the forwarded IPv4 port worked. The server now detects and reports the forward's public IPv4 address, the connection service verifies it, and apps connect directly again.
  • A Windows server that took the 0.9.30 update in place could fail to start afterwards, with an access denied error naming postgres.exe. The rename that gives the database process its tofa name is cosmetic, and it can no longer stop the server from starting: if the rename is not permitted, the server logs it and starts normally. If your server is already stuck on that error, run the installer download once and it will repair itself.
  • Linux servers could not apply the 0.9.30 update in place: the update failed with an unsafe archive entry message and the server stayed on its previous version. The update packages no longer contain the file links the updater refuses, so in-place updates work again. Nothing on affected servers was changed by the failed attempts.
  • Opening a video for a few seconds no longer rearranges Continue Watching. A quick accidental play could pin a show's tile to that episode on every device even when you were seasons ahead. Progress is now only saved once you are genuinely into the video, so next up stays where you actually are.
  • Custom access URLs that point at a private network now show "Private network" instead of "Not verified yet". An address that is only reachable inside your network cannot be checked from outside, and that is by design rather than a problem to warn about.

Server 0.9.31#

  • A Windows server that took the 0.9.30 update in place could fail to start afterwards, with an access denied error naming postgres.exe. The rename that gives the database process its tofa name is cosmetic, and it can no longer stop the server from starting: if the rename is not permitted, the server logs it and starts normally. If your server is already stuck on that error, run the installer download once and it will repair itself.
  • Linux servers could not apply the 0.9.30 update in place: the update failed with an unsafe archive entry message and the server stayed on its previous version. The update packages no longer contain the file links the updater refuses, so in-place updates work again. Nothing on affected servers was changed by the failed attempts. Because 0.9.30 was withdrawn, this update also brings everything from it:
  • The server's log folder can no longer fill your disk. Old daily log files were already cleaned up by age, but a component logging heavily could still write gigabytes a day of perfectly fresh files (one report measured 28 GB). The log folder now keeps to a fixed size budget, a component that repeats the same line hundreds of times a minute is trimmed in the file with a note in Server Logs saying so, and single oversized entries are shortened before they are stored. Existing oversized folders shrink on the first start after updating.
  • Downloading diagnostics from Server Logs no longer crashes the page on servers with heavy logs. The bundle is now saved straight to a file instead of being rebuilt in the browser's memory, and oversized log entries are trimmed on the way out, so the file opens in an editor too.
  • The server now shows a startup page while it gets ready. Opening tofa during boot used to sit on a browser error while the database was still coming up; you now get a page that says what the server is doing and hands over to the app once it is ready. There is also a new command, tofa doctor, that checks over a server that will not start and reports what it found.
  • A library's "Watch this folder for changes" switch no longer reads as on when the server is not watching anything. The server needs the server-wide "Auto-scan on file changes" and a storage profile that trusts file events before any library watcher runs, so the switch now shows the effective state and says which setting in Settings, Scanning is holding it. Your library's own choice is kept and takes effect again as soon as the server-wide watcher is back on.
  • Opening an episode from Recently Added or Continue Watching now shows that episode. Both rows link to the show with the episode named in the link, and the web app read only the season, so you got the series description whichever episode you picked. The page now puts the episode number and title above its own description, and Play plays that episode. Episodes we have no description for keep the show's. Continue Watching tiles carry the episode's description too, for the apps that show one.
  • FillView can now measure files on demand. The new mode spends no time walking the rest of your library and starts measuring a title only when somebody plays it, which saves processor time on large libraries. Full library remains the default so Zoom to Fill is ready on first play; an on-demand result is ready the next time that file plays.
  • Format badges (Dolby Vision, HDR10, Atmos) no longer disappear from the detail page when cross-library version merging is on. Movie and episode files on merged titles now carry the same format information as everywhere else, so all apps badge them correctly again.
  • Automatic audio selection now skips commentary tracks. A file whose first audio track is a commentary could start playing with the commentary instead of the main mix; commentary now only plays when you pick it yourself.
  • A profile unlocked with a PIN no longer locks itself again in the middle of an episode. While the profile is actually watching, the unlock now quietly renews itself, up to a day of continuous viewing, so the PIN prompt only comes back between sittings. Client apps pick this up with their next update.
  • Background work now steps aside for what you are watching. A scheduled library scan, or the thumbnail and intro analysis that follows one, could take over a server and stall a stream in progress for minutes. Scheduled scans and the slow metadata refresh now wait for a quiet moment rather than starting while somebody is watching or browsing, and they pick up on their own once the server is idle. Nothing waits indefinitely: a scan on a server that is busy around the clock runs at most about six hours later than its schedule. The analysis and thumbnail work that does run backs off to a few processor cores instead of every one, and reads files at a lower priority than playback.
  • The Browse language filter no longer lists the same language twice. Files disagree about which of a language's two ISO codes to carry (ger and deu are both German), and each spelling got its own entry with its own count; they now fold into one.
  • Fixed clients that play files directly (without conversion) being told a file had no subtitle tracks at all, while the title's detail page listed them. Direct-play apps such as the Kodi client now see the full subtitle list.
  • A single episode split across two files (Part 1 / Part 2) is now recognized: each half is numbered so apps can play them in order and back to back. Multi-part movies already worked this way; this closes the gap for episodes.
  • Playback info now reports the video frame rate on contract checks and dry runs too, when a scan already measured it. Clients use it to switch the display's refresh rate before playing.
  • Windows updates no longer fail with an access denied error on tofa-tray.exe. The tray keeps running across an update, so its previous file stayed locked and blocked the next update from starting. We now work around a locked leftover instead of stopping, clean it up at the next restart of the machine, and skip files the release did not change at all. Starting an update on Windows also no longer raises a second administrator prompt: a repeated Update now joins the update already running instead of starting another one, and a routine update check can no longer reset the update card while an update is being applied.
  • The Windows zip package now bundles the database engine, like the installer and every other package already did. A first boot no longer downloads it, so a rate limit, a proxy, or a captive portal can no longer turn "unzip and run" into a server that hangs or will not start.
  • Removing a server from your tofa account left the server itself with no way back: it still believed it was connected, sign-in had nothing to sign in to, and setup would not run again. The server now remembers that cloud access was cut, keeps saying so after a restart, and lets you connect it again from the setup screen with your tofa account. Your libraries, files, and watch progress on that machine are untouched.
  • Servers running in Docker or on a custom port can now advertise a local network address that apps can actually reach. Set it under Settings, Remote Access, Local network address (or the ADVERTISED_LAN_IP and TOFA_PORT variables), and apps on the same network connect directly instead of going through the relay.
  • Profile avatar artwork is now served at a stable address every client can use. Third-party apps such as the Kodi add-on had to dig the images out of the web app's bundle, which broke whenever the bundle changed shape; they now have a plain listing and a plain image address that stay put across releases.
  • Windows: the desktop app closed itself the moment you clicked anything that picks a file, so changing your profile picture or uploading artwork was impossible. File pickers now open properly, remember the file types the page asked for, and let you pick more than one file where the page allows it.
  • The desktop app could sit on a black screen when its player was unable to open a file directly, retrying the same file over and over until it gave up. It now notices the first failure and falls back once to the server's converted stream, so the title starts playing instead of failing.
  • Dolby Vision titles could play as plain HDR10 on some Apple TV models. The stream listing now announces Dolby Vision in the compatibility form those players expect, so they can engage it.
  • Dolby Vision stored in a separate companion video track is now detected. Files that carry the enhancement alongside a standard track were treated as plain HDR; they now get the same Dolby Vision handling as single-track files. Existing libraries pick this up on their own after the update, as the server re-examines files during idle time.
  • Switching quality back to a previously used setting could leave playback stuck retrying instead of resuming. The stream session now recovers cleanly on switch-back.
  • Settings no longer shows "Auto-scan on file changes" as on when the storage profile is set to Network mount. File events are unreliable on network shares, so the server was already ignoring all of them; the toggle and its debounce are now switched off there and say why, and scheduled or manual scans pick up changes instead. The profile itself also says what it is about: pick Network mount for media read over SMB or NFS, and HDD when tofa runs on the NAS and reads its own disks.
  • "Refresh metadata" now says what it will actually do on a library whose metadata source is not "Online + local". Only that source goes online, so on a Local only library the refresh reads your NFO and artwork files and nothing else, and on a library with metadata off it changes nothing. Both the title's options menu and the library's Refresh card now say so instead of looking like a fetch.
  • Artwork left over from older installs is now cleaned up properly. A leftover copy of every poster, backdrop and logo was being kept beside the current one, which meant deleting artwork we no longer needed freed nothing and the folder could only grow. The old copy is moved across on the first start after this update, and cleanup frees space from then on.
  • Docker: QuickView tiles and audio fingerprints are now stored on your mounted data volume instead of inside the container. They previously piled up inside the container image, which made it grow without limit and lost every tile on each update. Existing tiles are moved across on the first start after this update.
  • Windows: upgrading over an older service-based install no longer leaves a permissions warning repeating in Server Logs on every start. The installer now hands the database password file back to your user account, so the server can keep its permissions in order itself. Running this or any later installer fixes an install already showing the warning.

Server 0.9.29#

Highlights#

  • A new set of 44 pixel-art profile avatars replaces the old emoji gallery, with sharper looks and better legibility on TV and in the navbar. Avatars you already picked keep working. The six emoji-only ones (cat, panda, dino, octopus, mushroom, cactus) are gone, and anyone still on one now shows their initials until they pick again.
  • You can now upload your own photo as a profile picture, from Settings or the welcome flow. It follows your account to every device and server you use, the same way the built-in avatars do. Needs a server connected to your tofa account. Client updates with full support for the new avatars and profile pictures will roll out separately, so some apps may not display them correctly yet.
  • Tofa accounts can be protected with two-factor authentication using an authenticator app. One-use recovery codes give you a way back in if you lose access to it.
  • Passkeys are now supported, so you can sign in with your fingerprint, face or device screen lock instead of typing your password.

Improvements and fixes#

  • QuickView generation now sizes itself to your CPU. Worker concurrency defaults to Auto, which runs one job per four cores, so a small NAS works through its backlog one video at a time instead of four and stops sitting pinned at 100% CPU for days after a big scan. Servers still set to the old default of 4 move to Auto, which never runs more than 4; any other number you chose yourself is kept, and you can still pick an exact count in Settings to push a bigger machine harder.
  • Embedded database recovery is safer. A new install interrupted partway through setup can retry cleanly, damaged databases keep a forensic copy, and a failed restore no longer destroys the last usable database.
  • The "Your data is not being saved" warning no longer appears wrongly on servers whose /data mapping is correct, which we saw happen on Unraid. The server now checks the storage itself directly instead of trusting a system report that can be wrong at startup, and it clears the warning on its own if it had appeared.
  • A claimed server whose cloud identity file is missing or damaged now recovers it from the database when possible. If it cannot, the local server still starts and asks the owner to reconnect it instead of requiring a full reset.
  • Shows that are numbered differently from one guide to the next can now be set to "TVDB (Aired)" or "TVDB (Absolute)" in a show's Advanced settings, alongside the orderings that were already there. We only offer an ordering on shows we actually have it for, so the choices you see are the ones that will work.
  • Windows: AMD Radeon cards now convert video in hardware. tofa only had encoders for NVIDIA, Intel and Apple, so a Radeon machine did every conversion on the processor. The encode, which is nearly all of the cost, now runs on the card; decoding stays on the processor in this first release. The Hardware Transcoding card in Settings says when AMD is in use.
  • Intel hardware transcoding now keeps the encoder on the GPU when the driver's scaling or filtering path is broken, instead of falling back to the processor for the whole conversion.
  • A library set to "Local only" now really does read nothing but your own .nfo files and artwork. The setting had no effect before: Local only behaved exactly like Off, and libraries set to Off still went online whenever a title was refreshed.
  • Titles and descriptions read from .nfo files no longer lose everything before an apostrophe or ampersand, so names like "Baltimore's Key Bridge" and "Tom & Jerry" come through whole.
  • TV apps no longer freeze partway through a converted video. The server pauses a conversion once you have plenty buffered, and the resume could fail to fire; playback then stalled with a frozen buffer error.
  • Linux: 10-bit AV1 files no longer fail to start on Intel Arc cards. The card's AV1 decoder passes our check and then fails once those frames reach the conversion step, so we now decode them on the processor and still encode on the card. Windows is unaffected: it uses a different decoder.
  • Importing a large library from Plex no longer stops partway with a timeout. The scan runs as a background job the wizard follows, so a library that takes minutes to read through finishes instead of being cut off.
  • Importing watch history from Plex no longer fills Continue Watching with titles that were only open for a few seconds. The same minimum that applies to your own playback now applies to imports.
  • Files with long release tags in their names no longer show up as a strange extra "edition", which could also make the page open on a lower-quality copy instead of the 4K one.
  • Sending a support report with server diagnostics attached no longer freezes the browser on busy servers, and large reports now get enough time to upload.
  • macOS: watching a large library no longer runs the server out of file handles. We were opening one handle per file and folder being watched, which on big libraries ended in a stream of "Bad file descriptor" errors and a scanner that stopped noticing changes.
  • Setup now tells you when your server's clock is more than 5 minutes out, and that turning on automatic time synchronisation fixes it, instead of failing with "internal error".
  • Firefox: dropdown menus across settings, onboarding and the admin pages are readable again. They were drawing white text on a white background, so the choices looked blank.
  • The import step in the welcome flow now keeps its Import button in view, so a reviewed import can actually be started without hunting for the button below a scrolling list.
  • New and uncustomized home screens now use separate Recently Released Movies and Recently Released TV Shows rows. The original mixed row remains available in the home screen editor.
  • Top Rated rows and sorting by rating now use the review scores we show on your titles, instead of a hidden popularity number. Unrated titles no longer lead the row.
  • A server whose database had lost a constraint on its settings table can now start again. It was refusing to boot even though the settings themselves were intact.
  • Dolby Vision films that have to be converted for a device now play at full resolution on servers whose graphics card can do the Dolby Vision conversion itself. The Hardware Transcoding card in Settings shows whether yours can.
  • Where the graphics card cannot, those films now start at 1080p instead of trying full 4K and stopping partway through, because that conversion step falls to the processor and rarely keeps up at 4K in real time. You can still pick Original from the quality menu to try it.
  • When the server does refuse a video it cannot convert fast enough, it now says so in plain words instead of a generic failure.
  • The server now deletes its old log files automatically, following the same log retention setting as the Logs page (30 days by default). Log folders that had been growing for months, in one report to 25 GB, shrink on the first start after this update.
  • Docker installs that set TOFA_DATA_DIR without setting CACHE_PATH now keep generated cache files under the persistent data directory instead of the process working directory.
  • Desktop detail pages now show a Back button when there is an in-app page to return to.
  • Checkboxes, date fields, scrollbars and other native controls now use the app's dark colours and accent consistently.

Server 0.9.28#

  • The hardware transcoding page on Windows now names the graphics cards it found, and says plainly when a card has no hardware encoder we support yet, instead of showing nothing and telling you to check drivers and GPU passthrough.
  • Episode NFO files next to your videos are now read: title, plot, air date and ratings apply to episodes, including TinyMediaManager exports and multi-episode files.
  • An NFO whose year disagrees with the folder name is no longer silently ignored.
  • Watch state now shows on the Suggested row and on Discover shelves for titles in your library, and marking something watched from its details page updates the rest of the interface immediately.
  • Removing a Continue Watching card no longer drops keyboard or remote focus.
  • Plex-style tags like {tmdb-12345} on TV episode filenames no longer mis-identify the whole show, and specials with tags in the filename now file correctly.
  • Accounts can now have up to 6 profiles, up from 4.
  • The "Local only" library metadata mode now works as described: metadata comes entirely from your NFO and artwork files, with no online lookups. It previously read nothing at all.
  • macOS: the installer now notices when a previously hand-started server is still holding the port and explains how to stop it, instead of leaving the old copy running.
  • The server raises its open-file limit at startup, and repeated media tool failures now show up in system metrics and in diagnostics bundles.
  • Classic 4:3 films and shows with full 1080 line height now show the 1080p badge instead of 720p.
  • The audio and subtitle language settings now offer the full curated language list, including Finnish and the other Nordic languages, instead of nine large markets.
  • A saved language the picker did not list no longer shows as a blank selection in Settings.
  • The details page no longer shows an empty Audio field for files with plain audio like AAC or MP3.
  • External subtitle files now show up in the details page and file info with their language, marked External, instead of the page claiming there are no subtitles.
  • Docker installs whose data folder is not on persistent storage now get a clear warning at startup and a banner in the admin interface, instead of silently losing the whole server setup on the next container update.
  • The hardware transcoding page no longer shows a scary failed test for Quick Sync on Intel GPU generations where it can never work; it now explains that VA-API drives the same hardware.
  • The home screen editor can now add separate Recently Released Movies and Recently Released TV Shows rows, next to the combined one.
  • Radarr and Sonarr library sync no longer gives up on large libraries, and integration errors now say what actually failed.
  • Playback speed no longer sticks at an odd value after watching together, and the speed menu always shows a clean number.
  • Dolby Vision titles without a regular picture underneath (some streaming-sourced files) no longer show green skin and pink colors when Dolby Vision is not engaged. We convert the colors properly instead.
  • Setting a profile picture back to Initials now sticks, and removing a profile's content rating limit works again.
  • The picture in the top right corner now matches the one you picked on the Account page.
  • Fixed unreadable dropdown lists and a cut-off button bar in the admin Add instance dialog.
  • Anime specials now sort where they belong. Folders named like "S1 Specials" or "Season 3 - Specials" used to be filed as season 1 or skipped as unrecognized, and files marked SP03, OVA 2 or OAD 3 were not read as episodes at all. They now come through as specials, and creditless openings and endings are filed as extras instead of piling up as unmatched files. Existing libraries renumber themselves on the next scan.
  • Episode files we cannot place under an episode no longer disappear quietly. The Hygiene page has a new Unplaced episodes tab that lists them per library, so a special that found no match is something you can see and fix.
  • Turning on Plex write-back no longer floods your Plex history. It used to push your whole back catalogue the moment you switched it on, stamping years of watching as watched just now and reshuffling On Deck around it. It now sends only what you watch from the moment you turn it on. Episodes are matched by their own id as well, so shows that number their episodes differently on each service no longer get the wrong ones marked watched.
  • Continue Watching no longer gets stuck on an early episode. Marking one unwatched and then finishing a later episode used to leave the show pinned to the old one.
  • Dolby Vision titles no longer show purple and green scrubbing previews and chapter pictures. These files were being processed with the wrong colors. Previews already made for affected titles are regenerated on their own after you update.

Server 0.9.27#

  • Search results now put titles that contain what you typed above loose matches. Before, a long title like an edition listing could be pushed out of the dropdown by short lookalikes, making it seem missing from your library.
  • The pre-play audio and subtitle picker now honors your preferred language for German, French, Dutch, Czech and other languages whose codes have two spellings. Before, a file could carry the other spelling of the same language, the picker did not recognize it as a match, and it quietly fell back to your second choice, usually English, for both audio and subtitles.
  • Settings > Remote Access now tells the truth about IPv6. Before, it printed your server's IPv6 address next to the connection status as though remote clients were already using it, even when nothing had confirmed that address works. It now says whether we have confirmed the address is reachable, or that we have sent it to the cloud and remote playback may still go through the relay while it waits. There is also a new switch to stop advertising your IPv6 address altogether, for owners who would rather not hand it out.
  • Marking a title watched or unwatched now covers every copy of it, including a copy that was just replaced by an upgrade. Before, an episode whose file had been upgraded could refuse to leave Continue Watching no matter how often it was marked watched. Failures of the mark and dismiss actions on the home page now show an error instead of quietly putting the card back.
  • The Libraries page progress bars now track the preview and detection work they sit next to. While previews generate, the bar follows the same numbers as its label instead of pinning to full, so two libraries at different points show visibly different progress.
  • Cancelling a library's background preview work no longer counts the cancelled jobs as failures. Cancelled work now shows up as cancelled, so a stopped library does not look broken.
  • Files that can never finish preview generation, like damaged or unreadable videos, are no longer retried on every scheduled scan forever. After the retries are spent the server leaves the file alone until it changes on disk, and the counts stop climbing on every rescan. The Generate button still retries them on demand.
  • You now decide what happens when an episode finishes. Settings, Playback has a new Next episode choice: play the next one automatically after a short countdown, show it and wait for you to press play, or turn it off entirely. It saves with your account, so it follows you to every device and every app that supports it.
  • New home row: Recently Released. It shows what you own by release date, newest first, with movies and shows together in one row, so a title you added last year but that only just came out is not buried behind your newest imports. It sits next to Recently Added by default, and like every other row you can move it or switch it off under Settings, Home Screen.
  • Deleting a movie in Radarr or a series in Sonarr now cancels the matching request instead of asking for it again. The request shows as cancelled with the reason, so nobody has to keep deleting the same title. Downloads that simply drop out of the queue for a moment still get retried as before.
  • Browse in the web app now has an A to Z index down the right edge, so you can jump straight to a letter in a large library instead of scrolling through thousands of posters. It only offers the letters you actually have titles under, it stays put while you scroll, and it appears once a library is big enough to need it. Click the letter again to go back to everything.
  • On Apple TV you can now jump straight to a letter in a large library instead of holding the remote through thousands of posters. Browse has an A to Z bar that only offers the letters you actually have titles under. Needs the newest Apple TV app.
  • The audio and subtitle track you pick in the player now stays picked. Before, choosing a track mid-playback lasted only for that session, and playing the same title again went back to picking by your language preferences. Your choice, including turning subtitles off, is remembered for that title on that device.
  • High bitrate remuxes now report their real audio format. Before, a DTS-HD Master Audio or Dolby Atmos track on a large file could show as plain DTS in File Info, and because Atmos detection reads the same information, the Apple TV app could be sent the wrong track. We now take a second look at the audio when the first pass comes back incomplete.
  • Episodes that live in one file now say so. A file named S04E19-E20 shows as "S04E19-E20" across the season list, the play button, the player and Up Next, instead of showing only the first episode and making the second look missing.
  • Browsing no longer competes with background work. Preview generation and picture measuring already stepped aside for playback, but a server whose owner was only browsing kept grinding at full speed, so pages loaded partially or not at all. Opening the app is now enough to make that work back off.
  • The Health page credits short lived background work to the right place. Analysis work that only runs for a few seconds at a time used to fall into "Other", which made a busy server look like it was working on something unknown.
  • A database that goes slow because the disk is struggling is no longer restarted over and over. On systems where storage stalls for seconds at a time, the server used to force a recovery on every failed check, which turned a slow patch into repeated freezes. We now wait for a database to prove it is really gone before restarting it, and background work pauses while it recovers instead of piling up errors.
  • Split Apart now separates a folder without a year from a same-named show that has one. Before, a folder like "Dark Matter" that had collapsed onto "Dark Matter (2024)" came back as nothing to split, leaving two shows stuck on one listing with no way out.
  • Matching no longer swaps a correct result for a same-named title in another language. The retry that ignores your language filter now has to be clearly better before it takes over, instead of winning on a hair.
  • Sharing your server now says why an invite was refused, whether the address already has access, an invite went out in the last day, or it is your own address, instead of showing an error code.

Server 0.9.26#

  • New: Notifications, with its own page under Server. Add a destination and your server posts a message the moment new episodes or movies finish importing, straight to Discord or any URL you control (n8n, Home Assistant, your own script). The page shows you exactly what will arrive before you add anything, season packs come through as one tidy summary instead of a flood, and a Test button checks the wiring before you rely on it. If a destination stops delivering, the rail says so.
  • You can now shape what each notification destination sends. Set a mention so the right Discord role gets pinged, rewrite the wording, pick a colour, turn artwork off, or hand a plain URL destination your own JSON body so it matches a shape your automation already parses. The editor draws what will actually arrive as you type, including the season pack and first scan cases you would otherwise never see until they happened.
  • New: tofa desktop player, an app for Mac, Windows and Linux. It signs in the same way as everything else and shows the same libraries, but it plays video with its own player instead of the browser's. A browser can only play a handful of formats, so anything else has to be converted by your server while somebody watches. The desktop app plays far more of your library exactly as it sits on disk, which means less work for your server and a better picture on big files. It is in beta, and the docs have the download links and the steps for each system.
  • Watch history sync with Plex now works both ways. Connected Plex accounts have a new opt-in setting that marks what you watch in tofa as watched on your Plex server too, including your existing tofa history when you first turn it on. It only ever marks things watched: nothing on your Plex server is unwatched, changed or removed, and titles Plex already shows as watched are left alone so view counts stay honest.
  • On macOS 26, the tofa icon in Finder and in the installer window no longer sits on a pale grey square. We now ship the icon in the format macOS 26 expects, so it gets the same rounded shape, depth and lighting as the apps around it. On older macOS versions the icon is unchanged.
  • Playing a title for the first time no longer stalls or fails while the server is still preparing its preview thumbnails. That preparation now waits whenever anything is playing, runs at low priority, and its CPU shows up under its own name on the health page instead of hiding in "Other".
  • Posters in the web app that failed to load during the first moments of a session now recover on their own instead of staying blank until you refresh the page.
  • Two different shows stuck together under one match now come apart again even when a local info file or a manual title edit had renamed the listing. The scan history also names the affected shows when the server needs your help deciding.
  • The server no longer re-uploads your entire watch history to the cloud after every scan that finds new files. Scans now only ask the cloud for history it might hold for the new titles, which cuts a lot of pointless network chatter on servers with download tools attached.
  • Zoom to Fill now works in the web player and the desktop app. It was an Apple TV and Android TV control until now, even though every server measures the pictures for it. A new button in the player controls crops the black bars away on widescreen films and puts the full picture back, including on discs that have the bars baked into the image. It remembers your choice on that device, it stays hidden on titles that already fill your screen, and the keyboard shortcut is Z.
  • Subtitles keep up with Zoom to Fill. Regular subtitles stay where you can read them instead of being cropped away with the bars, and picture-based subtitles from Blu-ray discs stay on screen even when the disc placed them inside the bars.
  • Auto frame rate on Android TV now works. With the latest app, playback switches your TV to the video's native rate (like 24p for films) so motion stays smooth, and it now covers files that play directly without transcoding too.
  • Streams now stop when you do. Leaving the player, closing the tab or quitting the desktop app tells the server right away, so now playing and the active sessions list stop showing titles nobody is watching, and the server stops holding work for them.
  • FLAC audio no longer blocks direct play when we could not measure its bit depth. Only a confirmed depth above 24 bits makes us step in now, so more files play untouched on clients that handle FLAC themselves.
  • TV shows with multiple editions now appear as separate listings. Name the show folder with an edition tag, for example "Spider-Noir (2026) {edition-Black and White Version}", and that edition gets its own entry with its own watched state, matching the Plex folder convention. Existing folders sort themselves out on the next full scan.
  • Upgrading a file no longer leaves a leftover version behind. When a download tool replaces a file with a better copy, we now recognize the swap, keep your watch progress, and stop the title from reappearing in Recently Added.
  • Continue Watching no longer loses a title for days after a file upgrade. If the copy you were watching was replaced, resume continues from the new copy.
  • Clean up now on the Hygiene page also removes leftover versions from earlier upgrades, and the page shows how many there are. Watch progress moves to the remaining copy.

Server 0.9.25#

  • Fixed pixelated playback when converting videos at Original quality, especially 4K files on NVIDIA systems. We now match the conversion quality to the original file.
  • The quality menu now keeps the 1080p option available for efficient HEVC files that need converting.
  • You can now add Discover rows to your home screen from Settings, alongside genre rows. All current and future Discover lists appear there automatically. You can remove added rows, or reorder and hide the standard ones.
  • Setup now introduces FillView on the finishing touches step, with its switch ready to use. It remains on by default.
  • The Apple TV app can now request lossless multichannel FLAC audio or Dolby Atmos when a file includes them. You can choose which takes priority in the app. Needs the newest Apple TV app.
  • Files with 32-bit FLAC audio now play on Apple devices. We convert these tracks to the 24-bit format Apple supports.
  • The Health page now identifies processor use from QuickView tiles and FillView measuring instead of grouping it under Other. The one-time FillView pass after an update also shows its progress on the Libraries page.
  • Fixed the picture jumping every few seconds on Apple TV for some files that did not need video conversion.
  • Error messages appear again when accessing your server over plain HTTP on your local network.
  • Deleting a profile now removes it everywhere, so it cannot come back from another server.
  • The web app no longer gets stuck on the who's watching screen after you switch servers.
  • Discover now opens directly onto its rows instead of repeating the first five titles in a spotlight. Rankings start from the top, and the wide first card now shows add and availability marks like the smaller posters.

Server 0.9.24#

Highlights#

  • Dolby Vision on Apple TV, for profile 7 files. These come from UHD Blu-ray and carry a second layer Apple TV cannot decode, so it used to show the HDR10 picture inside them. We convert them as we send the video. The file on disk does not change. Needs the newest Apple TV app.
  • FillView, new in Settings under Transcoding. It finds the real picture inside a letterboxed file, which is what Zoom to Fill needs on files with black bars baked into the image. New files are measured after a scan finishes, your existing library once after updating, always behind playback. The Libraries page shows how many files are left while it runs, next to the QuickView line. It is on by default. Turn it off on a small or battery powered server and everything already measured keeps working. Zoom to Fill itself needs the newest Apple TV app.
  • Discover, redesigned. A spotlight strip you move through at your own pace sits over full rows you can scroll, instead of tiles you had to open first, and nothing rotates on a timer. The rows arrive in groups, Now, Acclaimed, Genres and Decades, so you get one set at a time instead of close to thirty at once. Sort a row or narrow it by decade and you are browsing the whole catalog behind it, page after page, instead of the forty titles it was showing. The main lists take a genre too. The three release rows, Out Now at Home, In Cinemas and Coming Soon, stay what they say they are, the dated titles your server has synced.
  • Close to thirty lists in Discover, most of them new, and the ones that were already there rebuilt. Essential Films and Essential Series, New and Noteworthy, New Series Worth Starting, every decade from before 1980 to the 2020s, Documentaries and Documentary Series, Westerns, Anime Films and Anime Series, Kids Movies and Kids Shows, Reality TV, Stand-Up, Nature and Adult Animation. Trending follows what is getting attention now rather than how famous a title is, and In Cinemas holds films inside a real theatrical window instead of anything that ever played.
  • tofa ratings, one pair of scores everywhere. Every screen shows Critics and Audience from 0 to 100, composed by us, instead of a mix of outside services and their logos. Poster cards show one, and you pick which in Settings under Rating badge: Audience, Critics, or off. A title with no critic score shows the audience one.

Also new#

  • Library Hygiene can now accept a title no catalog carries. Home videos and local productions sat in the unknown titles count forever, and the only way to clear one was to hide its folder from scanning, which took it out of your library. Accept as is leaves the title exactly as it is, clears it from the unknown count, moves it to an Accepted as is list you can undo from, and stops the retries.
  • You can mark a whole season watched or unwatched in one go, from the season poster or the menu next to the episode list heading. It covers titles you keep in more than one quality.
  • New in Settings under Privacy: Reset watch status. It clears every watched mark and resume position on this server for the profile you are using, which is the way back after an import brought in history you did not want. Other profiles keep theirs, and if you sync history to your tofa account you can delete that copy at the same time.

Fixes#

  • A title could stop playing from the beginning while resuming it still worked, and stay that way. Two plays of the same file could tear down each other's conversion, and once an attempt died half finished every later play reused the wreck instead of starting over. A dead attempt is now thrown away and replaced.
  • Text subtitles now start on very large files. The web player loads the part around where you are watching instead of waiting for the whole track, and no longer turns your subtitles off after a few failed attempts. Styled ASS subtitles show a plain version until the styled one is ready.
  • The web player loads PGS subtitles in pieces, the way the TV apps do, so they appear within seconds on very large files. Preparing the full track in the background no longer crowds out playback, and a player that asks for it too early gets a try-again answer instead of a stalled request.
  • Skip Intro no longer appears over a long cold open that an episode's chapter marks label as the intro, and no longer skips past where the intro actually ends. When we are not sure, we show no button. Your library re-checks its episodes once after updating, and if a show's intro really does start late, the server log names the setting that lets detection look further.
  • Files in a library's second and later folders now play directly and download. Anything outside the first folder answered "not found", which on Apple devices looked like playback failing at the start.
  • Watch history and watchlist sync no longer repeat the same upload forever. Marking a whole show watched, or importing history, could leave a server re-sending one batch every half minute and filling the log with sync warnings. Large libraries now finish.
  • A title you remove from your watchlist stays removed, even when a connected Plex or Jellyfin account still lists it. Background syncing used to put it back at the top of your list.
  • Connected accounts now show when they last synced, what they found, when the next run is due, and why a sync failed.
  • Two shows that ended up identified as the same series are separated again. On the next scan we release a folder whose year contradicts the show it was attached to, and folders whose names clearly belong to a different show, and identify them again. A pair an earlier scan merged separates once you update and rescan. Where we cannot tell which folder belongs to which show, we leave them alone.

Profiles and parental controls#

  • Parental controls are tighter across the apps. Restricted titles no longer reach capped profiles through the recent-changes feed or artwork reactions, an age rating limit we do not recognize now blocks everything instead of allowing everything, and profiles synced from the cloud get the same kids defaults as ones created on the server.
  • Profiles with an age rating limit no longer see unrated titles. A title with no rating counts as restricted for capped and kids profiles everywhere: browsing, search, home rows, watchlists, requests, artwork and playback. Set a rating on the title's admin edit page to make it visible again.
  • PIN errors now say what actually went wrong. The keypad respects the server's wait after too many attempts, and tells you when a profile was removed or is not yours instead of telling you the PIN was wrong. A parental lock no longer shows up as "server unreachable" or "session expired".
  • Changing or removing a profile PIN on one device no longer wedges your other signed-in devices. They re-prompt instead of failing silently or dropping to the main profile's view.
  • Switching profiles applies the new profile's restrictions immediately. Posters and live library updates could keep following the profile you switched away from for a few minutes.
  • Signing in to the web app now finishes when the main profile has a PIN. Linking a device could stall for minutes, and once you approved it the app stopped instead of showing the who's watching screen where the PIN goes.

Server 0.9.23#

  • Multiple profiles per account. A household sharing one login can now add up to 4 profiles, each with its own watch history, continue watching, watchlist, recommendations, and look. The app asks who's watching when it opens, and you can switch profiles anytime from the user menu.
  • Parental controls and kids mode. Give a profile an age rating limit and the server only shows and plays titles within it, everywhere. Mark a profile as a kids profile for a simpler app with just Home, Browse, and Search. Profiles can be locked with a 4 digit PIN, and once the main profile has one, profile settings can only be changed by someone who knows it.
  • Profiles now sync across your servers and the cloud app. Each profile's watch history, continue watching, watchlist, and preferences follow it to app.tofa.tv and to your other servers, instead of everything collapsing into the main profile. Kids mode now also applies in the cloud app, and the who's watching screen there lets you switch servers if the wrong one was picked.
  • Playback no longer spins forever when a title cannot play. Every waiting screen now has a deadline, and when a title truly cannot play the message names the reason instead of loading endlessly: the quality menu explains why a title is being converted, TV apps show a proper error with a working Back button, and a stream that keeps dying stops after three attempts. When your browser cannot decode a file and the server cannot convert it in real time, the error says so in plain words and suggests what to try, like Safari or Chrome, a lower quality, or on Windows the HEVC Video Extension, instead of showing an internal code like bufferAddCodecError.
  • A title the server could not convert fast enough is now refused instantly on the next try instead of spinning up another doomed conversion. Picking a lower quality still works and clears on its own after a few minutes.
  • When an admin stops your stream, you now see "Playback stopped" right away instead of the player quietly restarting or blaming your connection. Deliberate server refusals also show their real reason in the cloud app at app.tofa.tv now, which used to fall back to a generic "server can't be reached" and retry conversions the server had already refused.
  • HDR titles now play in the browser without being converted first. Chrome, Edge and Safari on macOS and Windows decode HDR video themselves, so the server hands them the original stream instead of re-encoding it. On servers without a GPU this is the difference between a 4K HDR title failing with "ffmpeg failed" and playing in a few seconds. Dolby Vision files that carry no standard HDR10 layer, mostly profile 5, are still converted, since a browser would show them with wrong colors.
  • Firefox can now play HEVC video directly. Firefox added HEVC support on Windows and macOS this year, so we no longer force every HEVC title through a re-encode there. On servers without a GPU this turns "playback failed" into instant playback for those titles.
  • Wrong browser capability guesses now recover instead of failing. If a browser claims it can decode a format but then can't, playback pauses for a moment, switches to a converted stream at the same position, and remembers the failure until the next browser update. Safari 18.4 and newer also gets WebM files directly now.
  • Android TV devices that cannot decode a video at full resolution now automatically get a version scaled to what the hardware can handle, instead of a failed playback attempt. The app already knew each decoder's limit; it now tells the server.
  • Safari is much smoother on big libraries. Browsing hundreds of posters no longer freezes the page, and moving between Home, Browse, and Discover is snappier because the app now stops loading the page you just left instead of letting those requests finish in the background.
  • Media tagged with provider ids in the folder name ({tvdb-...}, {imdb-...}, {tmdb-...}) that was added before your server understood those tags now picks them up on the next restart and matches automatically. Items the server had given up matching get one fresh attempt after the update, and an id tag the catalog cannot resolve no longer blocks a confident name match.
  • Shows can now be split apart, the same repair that already existed for movies. When two folders ended up bound to one show, so one folder's episodes showed as extra versions of the other's, open the show's menu and choose Split. Each folder becomes its own show again, taking its episodes and watch history with it, and stays separate through future scans.

Server 0.9.22#

Apps#

  • The Android TV app got a big visual overhaul: crisper, more consistent artwork, text, and buttons throughout, and a much sharper look on 1080p TVs, along with a batch of playback and stability fixes. Update from the Play Store to get it.

Server#

  • Servers running on a VPS or dedicated host, where the machine only has a public address and no local network address, no longer show as offline. The server was reporting its public address as a local one, which the cloud rejects; it now leaves the local address blank and stays reachable over the internet or the relay.
  • Collections no longer count movies that are not out yet toward the total. A franchise you own in full now reads as complete instead of showing one short because of an announced sequel, and those unreleased entries still appear in the collection.
  • Admins can now split a wrongly grouped movie apart. If two different movies ended up merged into one entry, open the ... menu on the movie, choose "Split into its own item", and the extra file becomes its own title again, re-identified from its filename.
  • Admins can now merge two movie entries into one. Open the ... menu on the duplicate, choose "Merge into another title", and pick the title to keep: the duplicate's files move over as extra versions, watch history comes along, and the duplicate tile disappears. Together with the split action above, this covers both directions of fixing a wrongly grouped movie.
  • Merge now works for TV shows too, not just movies. Merging one show into another folds its seasons and episodes in (episodes both shows share become alternate versions), watch history comes along, and the kept show remembers the old show's name: future episodes found under the old folder join it automatically instead of re-creating the duplicate.
  • Movies you have finished now show a small check on their poster, so you can see at a glance what you have already watched. It is on by default and can be turned off in Settings under Appearance.
  • Absolute-numbered shows, common for anime, can now appear as one continuous list of episodes instead of being split into seasons, and the episode-order picker always offers Aired and Absolute order, plus DVD order where the catalog provides it. Pick the order per show in its settings.
  • Fixed some titles that played with no sound, or would not play at all, because of the way their audio tracks were laid out. They now play correctly.
  • When an admin stops someone's playback from the server, it now stays stopped and the viewer is told their stream was ended, instead of the stream quietly starting again.
  • The Activity view now shows how each playing client is connected, on your local network, over the internet, or through the tofa relay, so you can see at a glance how someone is streaming.
  • In the artwork picker you can now give each poster or background a thumbs up or down, and every option shows a combined "Tofa score" from across servers instead of raw vote counts. Artwork you set by hand still takes priority.
  • Sending a problem report no longer spins forever when the upload stalls. If collecting the diagnostics or sending them times out, you now get a clear error telling you to retry or send without the server bundle attached.
  • Fixed the search box on the Identify screen, where the title field was squeezed to nothing and the Search button was pushed off the edge of the dialog. Searching by title and year works normally again.
  • tofa now recognizes a cover image named exactly after the movie file (for example "A Real Pain (2024).jpg" next to "A Real Pain (2024).mkv") and uses it as the poster, alongside the poster.jpg and name-poster.jpg forms already supported.
  • When a file is replaced on disk by a better copy (say a 1080p episode upgraded to 4K), the old entry now disappears from your library about a week later instead of lingering forever, and any watch progress on it carries over to the new copy. Until then, File Info marks such entries as "Missing from disk" so they are not mistaken for a playable version. Titles that go missing entirely keep today's grace period and come back untouched if the drive returns.
  • You can now pick quality, audio, and subtitles before pressing Play. The Play button on a title's page gained a small arrow that opens the choices; picking nothing keeps today's automatic behavior, and Play itself still starts instantly. Quality offers the original file or a smaller stream, your picks are remembered per title, and the player's quality menu shows the tier you chose.
  • People on your server now appear by the tofa username they picked on their account, instead of a name derived from their email address. Requests, the user picker, and the admin user list all use it, and it stays in sync when someone changes their username.
  • Episode cards on the show page now give titles two full lines instead of cutting them off after a few words, and the cards themselves are a little larger. The synopsis moved off the card into a new Episode Details view (in the episode's ... menu, replacing File Info) that shows the full description, air date, format, and file details, with Play and Mark Watched right there.
  • Folders tagged with a TVDB id like {tvdb-131741} (the Sonarr and Plex convention) now pin the show's identity, the same way TMDB and IMDb tags already did.
  • Episodes now take their name from the filename when our metadata source has no title for them, so older or niche shows no longer show rows of untitled episodes. A proper title from the catalog still replaces the filename one when it exists.
  • Sonarr and Radarr webhooks now default to the server's LAN IP address instead of its machine name. If your Sonarr or Radarr logged "Connection refused" errors when testing the Tofa notification, this fixes the guess; you can still set the exact address under Integrations if needed.
  • Fixed the Update now button always failing when clicked from the server's own web interface. The request was rejected before the update could even start; updating from the local UI works again. Updating from app.tofa.tv was not affected.
  • When the server does refuse an update, the card now shows the actual reason instead of an unhelpful "bad_request" message, and tells you up front when in-app updating will not work on your install, with the command to run instead.

Server 0.9.21#

  • Gave the admin area a consistent redesign: the same layout and status colors on every page (Direct Play green, Transcode amber), with the running version in the sidebar linking to any update.
  • Fixed 4K HDR and Dolby Vision episodes that spun forever on iPhone and iPad. When transcoded, they now play as a tone-mapped standard picture instead of a format Apple rejects.
  • Sending a problem report with the server diagnostics attached no longer fails on servers with lots of log activity. The report builder could run the browser out of memory while packing the logs; it now packs them efficiently and trims the oldest lines to fit the upload limit.
  • A library can now span several folders. Add extra folders when creating a library or later from its settings, and everything under them shows up as one collection; a show with seasons on two disks is finally one show. Swapping a folder for a new location still keeps watch state, and removing a folder removes its items from the library without touching your files.
  • Individual shows can now carry their own settings. Open a show and adjust how its episodes are ordered, how its seasons are shown, or whether it displays its original title, without changing anything else in your library.
  • tofa now uses artwork you keep beside your files. Drop a poster.jpg or fanart.jpg in a movie or show folder, or season posters next to the episodes, and tofa picks them up on the next scan. Artwork you set by hand still takes priority over both local files and our catalog.
  • The update card now tells you when the server cannot reach the update service, instead of quietly showing the last known status. A failed check appears as a clear warning with the reason.
  • Seeking during playback is much more reliable. If you skipped around while the server was still preparing the stream, the player could get stuck on "Reconnecting" and never come back; it now recovers on its own and lands where you seeked.
  • Fixed 4K Dolby Vision titles dropping their Dolby Vision presentation, or failing outright on Apple TV, after skipping forward or back. Seeking now keeps the same picture quality the title started with.
  • Intel hardware transcoding on Windows now handles Dolby Vision files. Before this fix those titles fell back to software conversion, which weaker machines could not keep up with.
  • The Hygiene page no longer floods with "unknown titles" during a first scan of a big library. While matching is still running it now shows a calm progress note ("Identifying N titles in the background") that counts down on its own, and only titles we genuinely could not identify are listed for manual review.
  • Fixed a bug where a show whose sidecar NFO file carried an id in web address form (for example "61511-father-brown") could never load season and episode details. We now read the numeric id out of such values, and existing libraries heal on their next refresh.

Server 0.9.20#

To everyone who joined the beta recently: thank you for testing tofa and giving us a chance. Nearly everything in this update comes straight from your reports, so please keep them coming. TL;DR: a TON of matching and parsing fixes, much faster Plex imports, Intel hardware transcoding on Windows, and one click updates on macOS.

  • Format badges (4K, HDR, Dolby Vision, Atmos) on posters are now off by default for a cleaner look. You can turn them back on in Settings under Appearance.
  • All the naming fixes below apply to your existing library automatically: a one time repair pass runs after the update and corrects episode numbers and multi episode spans that were read wrong before, and misread movie titles get looked up again with their proper name. Anything you fixed by hand stays exactly as you set it.
  • Movies whose titles end in a word like Short, Sample, or Trailer (The Big Short, The DNA Sample) are no longer mistaken for bonus content and hidden from your library. Bonus-content detection now also checks the file type, so a stray trailer.mp3 stays out of it too.
  • Files that pack several episodes together (S01E23-E24-E26, 02x03x04x15) now record the whole span instead of stopping after the second episode.
  • Season folders named in more languages now work: Kausi, Säsong, Sezon, Sezona, Sezonul, plus the digit-first German style (3.Staffel).
  • Episodes named with just a number now parse correctly: 02 - Pilot, 2. Infestation, 16 Some Title, and trailing absolute numbers like The Simpsons 82. Files named 7 - 12 Angry Men now read episode 7 instead of grabbing the 12.
  • The S01x02 naming style (an x instead of E) is now recognized, and daily shows with space-separated dates (Jeopardy 2023 07 14) now match by air date.
  • Show folders that carry season markers in their name (The Show Season 10, The.Show.S01.COMPLETE) now resolve to the clean show name instead of creating oddly named duplicates.
  • A year in parentheses now always wins over stray numbers later in the filename, so My Movie (1997) - SomeGroup 2019 files match the 1997 film, and date-stamped filenames no longer mistake the date for a release year.
  • Multi-part movies with quality tags right before the part number now group into one entry, and a mismatched extra part file no longer sneaks into a numbered set.
  • Alternate versions of a movie kept as suffix named files in its folder (Movie (2010) - 4K Remux.mkv next to Movie (2010) - Director's Cut.mkv) now group into one entry with selectable versions instead of showing up as duplicates. Sequels, franchise films, and different years stay separate.
  • TV episodes kept in per episode release folders (each episode in its own long release named folder) now resolve to the right show name instead of picking up a generic parent folder like downloads.
  • Importing watch history from Plex is much faster on large libraries. The scan now only reads items you have watched or started, instead of walking the whole library, and matches items against your tofa library in parallel, so it no longer times out for libraries with tens of thousands of episodes.
  • Plex import is also more dependable. Sign-in and server selection wait longer on slow connections, a brief Plex hiccup no longer marks a whole show as unmatched, and watch histories are read completely on servers that cap page sizes.
  • Intel Quick Sync hardware transcoding now works on Windows servers with an Intel GPU, cutting CPU use during transcodes the same way it already does on Linux.
  • macOS servers can now install updates with one click from the update card, the same way Linux and Windows servers do, with automatic rollback if the new version fails to start.
  • If you are reading this on a Mac: installing this particular update still needs the one command shown on the update card (tofa update). That is a one-time step, not the normal experience. It unlocks one-click updates, so from the next version on you just press the button here.
  • Cloud features like support uploads, watch history sync, watchlist sync, and version history now work immediately after claiming your server. They used to need a server restart to wake up.
  • Updating while people are watching is now your call. The update card still waits by default, but it tells you how many streams are active and offers Update anyway; viewers reconnect automatically after the restart.
  • A TV episode misfiled in a movie library no longer floods the metadata service with retry searches that can never match. It now gets one lookup and then rests in Library Hygiene, where you can spot the misfiled folder.
  • Short films collected under a series name, where the filename puts the series first and the film's title after the year, now match on the film's own title and year instead of collapsing into one listing named after the series.
  • We no longer accept a clearly wrong match just because it was the closest one. When your file's year says 2020 and the only same-named title we know is from 1986, or the best candidate barely resembles the filename, the item now stays in Library Hygiene as unmatched, where it heals automatically once our catalog gains the right title, instead of showing the wrong movie.
  • Files that fail to open because they are damaged, for example an interrupted download, now show up with their own count in library health and the support bundle so you know they need re-downloading. They used to look healthy while silently failing every scan.
  • Disc image files like .iso now say plainly that they cannot be played directly and suggest extracting or remuxing, instead of reading like file corruption.
  • The opt-in daily beta health snapshot now includes a small sample of unmatched titles and flagged episodes with their file paths, so we can diagnose matching problems from the report instead of asking you for more details.
  • A poster or logo our image service is missing now logs one warning instead of warning again on every retry, forever.
  • A burst of file changes on union filesystems like mergerfs no longer floods the log with duplicate messages when the change queue fills up.
  • Support bundles now carry much stronger playback evidence: a timeline of how fast each stream was prepared with its log, whether each play used your home network or the relay, recent relay connection drops, and on Windows the disk, firewall, and network profile details that explain why devices at home end up on the relay. Streams the server stopped for falling behind now appear as errors in playback history instead of vanishing.
  • Extras folders like Featurettes, Interviews, or Behind The Scenes now keep working when you sort them into subfolders. Files inside them no longer show up as errors in Library Hygiene.
  • Adding a .tofaignore or .nomedia file to a folder now clears that folder's entries from Library Hygiene right away. They used to stick around until the next full library scan, which made the ignore file look broken.
  • The tofa icon now appears in the macOS menu bar and its menu opens on click. The tray app used to run invisibly, with no way to reach the server controls.
  • The tray menu's Scan Library button, which silently did nothing, is now Manage Libraries and opens the libraries page where scans show their progress.

Server 0.9.19#

  • The Browse page got a cleaner header and filters. The section you are viewing is the page title, with Watchlist and Collections as labeled buttons beside it, filters share one dropdown style with counts for each option, the filter bar stays with you as you scroll, and genre menus no longer hide behind the posters. Filtering to nothing now offers a one-click way to clear the filters.
  • The interface is calmer. Status indicators no longer pulse or glow, and the little colored dots next to states like Online or Active are gone. Things that are fine stay quiet, problems show as plain colored text, and activity like scanning or downloading shows real progress instead of a blinking dot.
  • Movies downloaded through your request system now match the right title far more reliably. Imports pin the exact movie the download tool reported instead of guessing from the file name, files tagged with an IMDb id use it directly, and a same-year lookalike can no longer steal the match. This also fixes requests staying "unfulfilled" after the download actually arrived.
  • Library browse sorting and filtering got a major upgrade. Every sort now has an ascending/descending toggle, and we added new sort options: runtime, last watched, times watched, and a shuffle that stays stable while you scroll. You can filter by watch status (watched, unwatched, in progress) and pick multiple genres at once, with the heavy lifting done on the server so filtered grids page correctly even in huge libraries.
  • Searching inside a library now respects your active filters and sort instead of ignoring them. Type in the search box with a genre or quality filter set and the results stay filtered.
  • Filter menus now reflect what your library actually contains. Clients can ask the server which genres, years, quality levels and watch-status counts exist in each library, so empty options no longer appear.

Server 0.9.18#

  • Libraries can now generate scrub previews on demand. A new per-library mode creates previews only for titles people actually play, starting the moment playback begins, so big libraries no longer need an upfront generation pass or the disk space for titles nobody watches.
  • Starting playback on a title without scrub previews now moves it to the front of the preview generation queue, and newly added titles generate before older ones. Previously the queue worked strictly alphabetically, so a fresh import could wait behind the whole library.
  • Preview generation is substantially faster. Thumbnails are now composed in a single pass per file instead of one pass per resolution plus a separate assembly step, and credits detection skips its frame scan when the audio detector has already found the credits.
  • Scrub previews and chapter images from HDR titles now show correct colors instead of washed-out grey. We tone map HDR sources when generating thumbnails.
  • Intro and credits detection no longer gives up on TV episodes in large libraries. Waiting for related episodes to finish their audio analysis used to count against the job's retry limit, which could permanently fail detection when the queue was deep.
  • Searching for an actor or director now works even when your library has none of their titles. Type a name, and we suggest matching people from our catalog, misspellings included; opening one shows their full filmography with anything you can request.
  • Your resume position now survives Sonarr and Radarr quality upgrades more reliably. We use the upgrade's own details to carry watch progress to the new file, including when it replaces same-sized files or a file in another folder, cases the old matching had to give up on.
  • Library scans do far less filesystem work per folder, which makes scans and import pickups noticeably faster on network storage such as NFS or SMB mounts.

Server 0.9.17#

  • Imports from Sonarr and Radarr now show up right away even when they see your media at a different path than your server does (common with Docker). We match the reported file against your library folders automatically, so no path mapping setup is needed.
  • Requests now use the quality profile you configured as the instance default in Sonarr and Radarr. The request form used to quietly send the first profile in the list instead, so everything downloaded with the wrong profile.
  • Requesting a show that has a Specials season works again. Season 0 used to fail the whole request with a "season must be between 1 and 200" error. Specials now appear in the season picker and are only requested when you tick them.
  • If you remove and re-add a Sonarr or Radarr instance, we now clean up the outdated webhook it left behind in that app, so imports and download updates reach your server instead of erroring forever.
  • When a request fails, the request form now shows the actual reason instead of a generic error line.
  • Requests whose download stalls out no longer retry forever. We now tell Sonarr or Radarr the stalled release failed so it grabs a different one, retry with growing pauses, and mark the request failed with a clear message if nothing works.
  • When Sonarr or Radarr reports a finished download at a path outside your library folders, the warning now shows up in the admin log view so path mapping problems are visible instead of silent.
  • Shows already in your library can now grow. When a show is missing seasons, the show page offers to request just the seasons you don't have.
  • The library History tab now lists scans triggered by a Sonarr or Radarr import, labelled "import" so you can tell them apart from a scheduled scan or the folder watcher at a glance.
  • Fixed movies sometimes being marked as watched well before the end. A chapter with a name like "Ending" partway through the movie could be mistaken for the start of the credits; markers that implausibly early no longer count, so your resume position is kept.
  • Playing or seeking in a file with broken timestamps no longer fails with an error. We detect the failure and automatically fall back to a full conversion that regenerates clean timestamps.
  • You can now choose which preview thumbnail resolutions we generate. Keeping both the small and high quality tracks stays the default and gives the smoothest scrubbing, including over remote connections; on a storage-tight server you can drop to one. Removing a resolution only stops generating it for files scanned from then on, and never deletes previews already on disk.
  • Preview thumbnail generation now pauses cleanly when its data folder is missing or unwritable (for example an unmounted drive), instead of failing every queued job. The settings page shows a warning until the folder is reachable again, and generation resumes on its own.
  • Preview thumbnails and chapter images now generate correctly for videos that use full-range color, which used to fail with an encoder error.
  • Importing your Plex watchlist works again. Plex tightened a page size limit on its side, which made every watchlist fetch fail.
  • Titles on the admin Hygiene page now link to their detail page, so you can jump straight to the show or movie you are fixing.

Server 0.9.16#

  • Sending a support diagnostic from a busy server works now. Larger reports used to fail with "Request failed" once the bundle outgrew the upload limit.
  • Saving one library setting no longer risks resetting the others: the server now changes only the fields you actually saved. Clearing a library's preferred language or region back to the server default works now too.
  • Your configured skip-intro prompt timings now apply to everyone on the server. Non-admin viewers used to fall back to the built-in defaults, and each of their playbacks logged a needless permission error.
  • Saving a preference in a browser tab that had been open for days no longer reverts newer preferences you saved on other devices in the meantime.
  • Library settings toggles (like "Follow symlinks outside this folder") now show their real saved state. They always looked switched off before, even when the setting was on, and saving one setting could quietly reset the others for that library.
  • The "Merge versions across libraries" toggle also shows its real state now. It always looked on before, so merging could be switched off but never back on from the settings drawer.
  • Adding or removing a custom access URL now waits until your saved URLs have loaded, so a save can no longer wipe the existing list.

Server 0.9.15#

<!-- 0.9.14 was burned: its Docker image published with the Android TV poster regression before the fix landed, and published versions are immutable. Everything below shipped for the first time in 0.9.15. -->

  • Posters and hero images now load again on older Android TV devices, including Android 11 models like the Nvidia Shield. The server was sending these devices an image format they could not display.
  • Your watch history can now live in your tofa account — strictly opt-in, off for everyone until you turn it on. Once on, your history follows you across your servers and stays safe even if a server is lost or rebuilt. Turn it on under Settings → Privacy, where you can also permanently delete the copy in your account at any time.
  • Everyone gets asked about watch history sync exactly once: new users in the welcome tour, existing users through a one-time note on Home. Either answer sticks, and nothing is synced unless you say yes.
  • Bringing over a large watch history from Plex, Jellyfin or Emby now works. Imports of tens of thousands of items used to stop with "Request failed" every time. They now go over in batches, show progress as they run, and finish far faster.
  • The import preview can now bring over just what you have finished, or just what you are part way through, and it tells you how many items are selected so you can check the number looks right before you start.
  • Files that arrive while a library scan is running now show up right after that scan finishes, instead of waiting for the next scheduled scan. This works even on network storage.
  • Sonarr and Radarr imports now show up and are ready to play moments after import, even while a library scan is running. The import triggers its own quick targeted scan that no longer waits for the big scan to finish, so a replaced or freshly downloaded episode is current right away.
  • Preview generation errors in the server logs now include the underlying cause. If previews cannot be written (for example a data path the service is not allowed to write to), the log now says so directly instead of only "failed to create directory".
  • Show and season posters now show how many episodes you have left to watch, as a small count badge in the corner. You can turn it off under Settings.

Server 0.9.13#

  • The app.tofa.tv web app now hides settings and features your server version does not have yet, instead of showing controls that do nothing. Updating your server brings them back.
  • Release notes no longer disappear once you update. A new Version history link at the bottom of the update card opens the notes for recent releases, grouped by version, so you can re-read what shipped at any time.
  • Libraries built from symlinks now scan correctly. A new "Follow symlinks outside this folder" option (in a library's settings) picks up files linked in from a separate location, such as a downloads mount. It stays off by default, so libraries that do not use symlinks keep skipping links that point outside the folder.
  • When something goes wrong you can now send us a diagnostic report straight from the server. A new "Report a problem" button on the Server Logs page collects a bundle of health and log details (you choose what to include) and opens a support ticket you can follow up on. You can also opt in, off by default, to a once-a-day health snapshot so we can spot beta problems before you hit them.
  • Turning on "Absolute numbering" for a show now takes effect right away, even when its episodes were already partly filled in. Previously the toggle only logged a refresh and left episodes stuck in "Episodes to confirm".
  • Playing the next episode no longer stops early when an episode in the middle is missing. If you own episodes 1, 2 and 4 but not 3, the player now continues to 4 instead of saying "You're all caught up".
  • Low-powered servers stay responsive during background work. Preview generation now matches its worker count to your CPU, so a small box no longer runs several heavy jobs at once and stutters playback.
  • The web player changes quality more smoothly and recovers faster. It steps back up to full quality on its own after a rough patch, and no longer waits out a long stall when the server has already moved on.

Server 0.9.12#

  • The update card now shows what changed in every version you are about to install, not just the newest one. If your server is a few releases behind, "What's new" groups the changes by version so you can see everything you missed. Long release notes now open in a panel instead of filling the settings page.
  • Format badges now match everywhere. Dolby Vision, HDR10+, HLG, Atmos and DTS labels are decided once by the server, so posters, detail pages, and File Info all show the same names. Titles that carry both Dolby Vision and HDR10+ now show both, and Dolby Vision details name the correct base layer.
  • Format badges share one look: every badge sits on the same dark plate the Dolby Vision badge uses. Atmos badges name their carrier, so you can tell TrueHD Atmos from DD+ Atmos at a glance, and the detail page audio badge includes the channel layout, like "TrueHD Atmos 7.1".
  • Long movies no longer stop with a playback error partway through. Sessions used to expire after 2 hours of wall-clock time, including time spent paused, so films longer than that (or a long dinner-break pause) failed near the 2 hour mark.
  • Converting 4K HDR video to SDR on machines without a GPU is now about 3x faster, so many titles that previously stopped with "can't transcode in realtime" now play.
  • Fixed a case where burned-in subtitles could show the wrong track (or none at all) if the same title had already been played with a different subtitle choice.
  • Streams abandoned during startup (for example closing the app while a video is still preparing) no longer keep running invisibly in the background. Enough of these could previously make every new stream fail with a capacity error until the server restarted.
  • Dolby Vision streaming to Apple devices no longer copies the entire movie to the server's disk cache at full speed while you watch. The server now paces itself to stay ahead of your playback position, protecting small cache disks.
  • Two people watching the same title at the same quality no longer interrupt each other. Previously, one viewer stopping, seeking, or changing quality could briefly freeze or restart the other viewer's stream.
  • File Info is now available on individual episodes, from the episode's menu on the show page. Movie pages also gained a File Info entry in their menu.
  • The hygiene page's "Episodes to confirm" section now shows each episode's filename (hover a chip, or use the new Show filenames button), so you can check the file against the numbering before confirming.
  • Libraries now remember your sort choice. Pick a sort order for a library and it stays that way next time you visit, on every device you sign into.
  • Shows with absolute-numbered files (common for anime, like "Show - 125.mkv") now match much better. Detection is automatic where possible, and you can set it per show: "Absolute numbering" in the show page's admin menu or on the hygiene page. Turning it on also confirms episodes that were previously stuck in "Episodes to confirm".
  • Shows whose name cannot be worked out from their folder layout now stay unmatched, waiting for you on the hygiene page, instead of being matched to the wrong title and wearing another show's artwork. Once you set the right match, they pick up metadata normally.
  • Shows filed directly in a folder without a "Season" subfolder (for example a folder holding S01E01, S01E02, and so on) are now read from the folder name instead of scanning as "Unknown". If several such shows previously merged into a single "Unknown" entry, the next library scan splits them back into the right shows and repairs their titles automatically.
  • Correcting a title's match now also refreshes its artwork to the newly selected show, instead of keeping the previous show's poster and backdrop.
  • Running separate Sonarr instances for anime and everything else now works properly. Mark an instance as "Receives anime requests" in the integrations settings and anime requests route there automatically, added with the anime series type and your anime root folder and quality profile. No extra steps when requesting.

Server 0.9.11#

  • Fixed Intel Quick Sync failing the hardware test in Docker ("Error creating a MFX session") while VAAPI worked. The Docker image was missing Intel's Quick Sync runtime library; it is now included, so Intel GPUs from 11th-gen Tiger Lake onward can use Quick Sync for transcoding.
  • The home screen spotlight no longer shows a black panel for newly scanned titles that are still waiting on artwork. Titles without artwork stay out of the spotlight, and if artwork ever fails to load the spotlight shows a styled fallback instead of going dark.
  • A brand-new server's home screen now says the library is being scanned, with a live count of files found, instead of claiming the library is empty while the first scan runs.
  • Scan progress bars are more honest on big libraries. The bar now keeps moving while files are being analyzed instead of freezing near 70%, and rescans that find no new files say "Checking existing files" instead of a frozen "0/0 files".
  • If the server restarts during a scan, the scan now shows up as interrupted in the library's scan history instead of silently disappearing.
  • The setup wizard now recovers from a page refresh without losing your libraries, and shows a clear retry option if a scan fails to start instead of waiting forever.
  • Preview thumbnails now use your GPU by default, matching hardware transcoding. Generation on large libraries gets much faster, and it still falls back to software when no GPU is available.
  • Docker: preview thumbnails are now stored on your /data volume. Previously they lived inside the container and were lost on every update, so previews regenerated from scratch each time. They will regenerate once more after this update and then survive all future updates.
  • Preview generation now processes 4 videos at a time by default (was 1), so the first pass on a large library finishes much sooner. It still runs at the lowest CPU priority, and you can change the concurrency in Settings.
  • New: a generation window for preview thumbnails. Turn it on in Settings to run heavy generation only during certain hours, for example overnight.
  • Scrub previews and chapter images no longer show stale frames after a file is replaced or preview settings change.
  • If a scan finishes with QuickView generation turned off for a library, the server log now says so instead of silently generating nothing.
  • Fixed the QuickView job counter showing more finished jobs than queued (for example 268/10) when previews carried over across scans. The count now reflects the real queue.
  • Fixed playback stopping on Apple devices after a quality change when a title carries two audio tracks in the same language. The player rejected the stream because both tracks shared one name; each track now gets a distinct name.
  • Admins now see available updates everywhere in the admin area: a version pill in the header, a dot on Settings, and a note on the Health page.
  • Release notes now appear in the update card, so you can see what changed before updating.

Server 0.9.10#

  • Import your watch history from Emby, alongside Plex and Jellyfin.
  • Blu-ray image subtitles (PGS) now render correctly in the web player instead of coming out garbled, and no longer force a transcode.
  • Choosing an audio track now sticks. The player honors your selection instead of falling back to the default language.
  • When your server cannot keep up with a demanding transcode, playback now steps down in quality instead of stopping.