A roll is dated folders inside dated folders, and the reader who wants April re-read is not a reader who asked for the four years around it. Right-clicking a subfolder row carried the roll's own menu, and RESCAN on it read the whole tree from the top — every folder of every layer opened again, every frame in them asked for its size and its time, to reach the one folder the pointer was on. On a library of a hundred thousand that is a walk of minutes for a folder of twenty. The scan now takes the folder it was pointed at, spelled as the walk spells a path: '' for the picked folder, `2026/04/` for a subfolder. The walk is handed that path as its queue and reads down from there, so the tree is entered three levels in rather than at its root, and the menu row passes the path of the row under the pointer. A right click on the head of the tree still reads the whole roll, which is what a right click on the picked folder has always meant. What a reading kept to one folder must not do is speak for the roll. What it names in the column is a branch of the tree, so the column keeps what it has and the rows outside the folder being re-read stand where they are. What it counts is a branch too, and its numbers drawn over the rows would count a roll down to one folder of itself, so the column falls back on the catalogue until the reading is through — the frame the reader is waiting for is the frame that was re-read, and it is in the column the moment it lands. Nor does it write a position down. `walk/ROLL.json` belongs to the reading that walks the whole roll: a fraction of the tree written into it hands the next visit a roll with the rest of itself missing from the walk, and it clears a file another reading may be in the middle of. One folder is short enough to read again, and the frames it does not re-read are skipped on their size and their time anyway. A jump is refused for the same reason — the reading answers to the folder it was kept to, and a click elsewhere is a different reading's business.
RecipesCam web — self-contained stack
A Docker-hosted web build of RecipesCam. Everything it needs is in this folder: move it to another machine, run two commands, and the app is up. It does not need the React Native project around it.
cp .env.example .env
docker compose up -d --build
# → http://localhost:8090
What runs where
| Service | Image | Role |
|---|---|---|
frontend |
nginx:1.27-alpine (built by frontend/Dockerfile) |
Static SPA + /api/ reverse proxy |
api |
node:22-slim (built by backend/Dockerfile) |
Accounts + saved recipes, SQLite on ./data |
frontend resolves api through Docker's embedded DNS and proxies /api/* to
it — that is why the API container is named api and why it is not published on
the host. Only ${WEB_PORT:-8090} is exposed.
Photos never leave the browser. The CanvasKit render pipeline (grade, frame, watermarks, JPEG encode) runs in the visitor's tab; the API only stores recipes as JSON.
Layout
docker-compose.yml the stack
.env.example WEB_PORT
data/ SQLite (created on first run, gitignored)
backend/ Fastify + better-sqlite3 API, own Dockerfile
frontend/ Vite + React + CanvasKit SPA, own Dockerfile + nginx.conf
shared/ vendored copies of the app's types + utils (see below)
src/engine/ skiaShim.ts (CanvasKit) + exportEngine.ts (render pipeline)
+ session.ts (localStorage/IndexedDB studio persistence)
Vendored files
frontend/shared/{types/index.ts,utils/*.ts} are byte-identical copies of
src/types/index.ts and ten src/utils/*.ts files from the React Native
project (@shopify/react-native-skia is aliased to src/engine/skiaShim.ts in
vite.config.ts + tsconfig.json, so those files compile unchanged):
cinemaShader colorUtils defaultRecipes exifWrite frameUtils jpegDpi
paramDefs recipeShare skiaImage toneShader.
The landing page needs no CDN: frontend/public/assets/fonts/*.woff2 are the
seven self-hosted faces behind the three font groups the Themes menu offers
(Plus Jakarta Sans / Inter / JetBrains Mono, Fraunces / Be Vietnam Pro /
Courier Prime, Be Vietnam Pro / Space Mono — all SIL OFL, pulled from Google
Fonts, vietnamese + latin + latin-ext subsets), and
frontend/public/assets/samples/s*.jpg are the six placeholder negatives the
film strip, preset tester and QR card show (swap them for real graded stills
whenever we have them). Its one foreign request is the QR image from
api.qrserver.com, which degrades to an empty slot offline.
When the app changes one of them, copy it back in — the renderer is only "parity" for as long as these stay in sync:
cd <repo>/docker/frontend/shared/utils
cp <repo>/src/utils/<name>.ts .
Operations
docker compose logs -f api # API log
docker compose restart api # after backend/src changes (rebuild: --build)
docker compose down # stop; ./data survives
Backup is the ./data folder — that is the whole database.
Checks
curl -s http://localhost:8090/api/health # {"ok":true}
curl -sI http://localhost:8090/ # 200, index.html
Then open the UI, drop a photo in, and confirm the preview shows the picture and
EXPORT downloads a JPEG that opens. The preview going solid black while the
export still reports a plausible size is the one failure mode worth knowing: it
means the CanvasKit GPU surfaces lost their shared GrDirectContext (see
frontend/src/engine/skiaShim.ts), and with no GPU the raster fallback renders
the same pipeline correctly, just slower.