TV Binge Board Task List
Audit rule
Completed tasks stay in this file with `[x]` so the project history can be audited later. Do not remove completed tasks unless the wording itself reveals a sensitive security detail.
Revision rule
The project has one overall revision in `APP_VERSION`, `CHANGELOG.md`, and the README revision note. Individual file header revisions are file-specific and should only change when that file changes. New files should start with their own file revision instead of inheriting the project revision.
Current state
- TV Binge Board PHP/JSON tracker scaffold, mobile layout, authentication, admin management, seed accounts, manual add, TMDB search, import/export, public sharing, connections, changelog, README, and placeholders.
- rev 1.4.4 - Matt mobile list feedback: Smart sort, Hide 100% / finished, compact cards, progress rollback.
- rev 1.4.5 - poster/backdrop picker.
- rev 1.4.6 - CSV import mapping and downloadable import error report.
- rev 1.4.7 - Matt tester attribution in docs/changelog.
- rev 1.4.8 - screenshot-assisted import review from OCR/AI text.
- rev 1.4.9 - Search as add/import/upload hub and bottom-nav overflow hint.
- rev 1.5.0 - Matt episode list feedback: picture/text toggle and check for new episodes.
- rev 1.5.1 - one-time in-app update notice.
- rev 1.5.2 - Matt next-up/caught-up tracking.
- rev 1.5.3 - PWA polish and install/offline support.
- rev 1.5.4 - JL favicon/app icon asset update.
- rev 1.5.5 - explicit Apple icon/cache-bust pass.
- rev 1.5.6 - direct screenshot image processing.
- rev 1.5.7 - PWA screenshot asset pass.
- rev 1.5.8 - release ZIP helper pass.
- rev 1.5.9 - automatic new episode refresh pass.
- rev 1.5.10 - season-level 403 mitigation pass.
- rev 1.5.11 - persistent remember-me login pass.
- rev 1.5.12 - root-level watch progress endpoint.
- rev 1.5.13 - mark prior episodes from later episode.
- rev 1.5.14 - watched episode checkmarks.
- rev 1.5.15 - Matt feedback gap pass: explicit unmark, current-detail refresh, full season list, prior-progress prompts.
- rev 1.5.16 - friend activity feed on Connections.
- rev 1.5.17 - compact notices, persistent install-card dismissal, and Settings reload/install controls.
- rev 1.5.18 - list comparison between visible public or connected users.
- rev 1.5.19 - remaining non-security feature backlog: smart parsing/fuzzy matching, tags/custom lists, and advanced recommendations.
- rev 1.5.20 - public suggestion and bug board with required email capture.
- rev 1.5.21 - PNG/JPG screenshot attachments for suggestions.
- rev 1.5.22 - gap-aware episode/season prior-progress prompts.
- rev 1.5.23 - Matt list/detail/home progress cleanup.
- rev 1.5.24 - focus episode detail on the season containing the next episode to watch.
Matt feedback
- Do not prompt when marking the very next unwatched episode.
- Prompt only when a selected episode would skip over an unwatched earlier episode.
- Apply the same gap-aware logic to season-level prior-season prompts.
- Open long-running shows at the most recent season with unwatched episodes instead of Season 1.
- Auto-scroll to the selected unwatched season on first item-detail load.
- Keep the List page Hide 100% / caught-up / finished setting persistent per user.
- Hide 100% watched/caught-up/finished shows from Home screen media sections.
- Open the episode detail page at the season containing the next episode to watch, not the latest season with any unwatched episode.
Suggestion board
- Add public suggestion and bug board.
- Require an email address for each submission.
- Pull the email from the logged-in user's saved profile when available.
- Prompt for email if the logged-in user does not have one saved yet.
- Save the first submitted email back to the logged-in user's profile.
- Save submissions to `data/suggestions.json`.
- Show submissions publicly in an issue-style list with type and status filters.
- Mask email addresses on the public board while keeping full email in JSON.
- Add optional screenshot upload to suggestions.
- Restrict suggestion screenshots to PNG/JPG/JPEG.
- Store public screenshot previews under `public-cache/suggestions/`.
- Save attachment metadata to suggestion JSON.
- Document that iPhone screenshots are usually PNG and HEIC photos must be converted first.
List-page update
- Make the top of the List page smaller.
- Remember the last List filter used per user.
- Default to hiding 100% complete/watched/caught-up items.
- Search list results by partial title entry.
- Show only a title search box by default.
- Add an expandable advanced-search area for other criteria.
Import plan
- Create `import.php` page.
- Accept `.csv` and `.json` uploads into `data/users/{username}/imports/`.
- Parse imports into a temporary review JSON file.
- Show parsed rows in a review UI.
- Detect duplicates before confirmation.
- Require final confirmation before importing.
- Write import activity log with timestamp and item count.
- Add custom column-mapping UI for odd CSV headers.
- Add downloadable import error report.
- Add paste-based structured parsing and fuzzy matching.
Screenshot-assisted import plan
- Create `upload-screenshot.php` page.
- Store screenshots in `data/users/{username}/uploads/`.
- Add image validation: extension, MIME type, file size, dimensions.
- Create review queue JSON file.
- Require manual approval before any future screenshot import writes data.
- Keep original screenshot attached to import history for audit/debugging.
- Add OCR/AI processing outside the core save path.
- Display parsed guesses with confidence levels.
- Add manual approve/reject screen for screenshot guesses.
- Add direct image processing from the uploaded screenshot itself.
PWA plan
- Add baseline manifest and app icons.
- Register service worker.
- Add manifest scope, id, orientation, display override, and shortcuts.
- Add offline fallback page.
- Add install/help page.
- Add visible install card.
- Add service-worker update reload prompt.
- Update 192px and 512px PWA icon assets to match the JL favicon/logo direction.
- Add explicit Apple touch icon files.
- Add new icon filenames to avoid iOS caching the old icon URL.
- Add screenshot assets for richer PWA install surfaces.
- Move update/install reminders into a smaller, user-controlled Settings flow.
Social features
- Add public sharing toggle.
- Add connection request/accept flow.
- Add friend activity feed.
- Add list comparison between connected users.
- Add advanced friend/list recommendations.
Organization features
- Add tags/custom lists.
Future non-security enhancements
- Add structured parsing or fuzzy matching service integration.
- Add tags/custom lists.
- Add advanced friend/list recommendations.
Security hardening
- Future security wrap-up: rotate testing values after testing/configuration is complete.
- Future security wrap-up: review public-facing setup documentation before public use.
- Future security wrap-up: disable public registration or restrict it tightly before public use.
- Add login rate limiting.
- Add password change flow.
- Add stronger session cookie settings for HTTPS.
- Add activity log for admin changes.
- Add recurring/manual JSON backup helper.
- Add automatic pre-overwrite JSON restore points.
- Add server-side upload safety scanning if this becomes public/multi-user.
- Add account recovery/reset-by-email workflow.
- Add optional two-factor authentication.
Pause/resume checklist
When resuming on another device:
1. Read `README.md`.
2. Open `CHANGELOG.md` or `changelog.php`.
3. Review this file.
4. Confirm whether `includes/config.local.php` exists on the target server.
5. Confirm that `data/.htaccess` is uploaded.
6. Confirm administrator user management works.
7. Confirm normal user manual add works.
8. Test export/import with a small CSV.
9. Add TMDB key only after the core app loads correctly.
10. Before public use, complete the security-wrap-up tasks above.