All QR endpoints (/api/qr/:code, /api/qr/custom GET+POST) accept
format=png|svg|pdf, ec=L|M|Q|H, and download=1 for attachment responses,
unified behind a shared qr_response() renderer. SVG is generated as a true
vector (one path of modules, crispEdges) with an optional logo embedded as
a data URI over a cleared centre tile; PDF wraps the raster render for
print. A logo always forces error correction H. Dot styles remain
raster-only.
QR Studio: format and error-correction selectors, PDF previews as PNG,
format-aware download button with contextual hints.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- Redirects default to 302 so browsers stop permanently caching the hop —
click analytics stay accurate and destination edits take effect for
returning visitors. 301 is a per-link opt-in (create/edit/API).
- Links can carry a password: visitors get a branded unlock page at /:code
and POST to /:code/unlock. Unlocks always redirect with 302.
- Missing, expired, and quota-limited links now show branded standalone
visitor pages (404/410/429) instead of bouncing to the marketing site
with ?error= query params.
- Clicks are recorded through the async pipeline with bot/crawler tagging
(UA heuristics), GeoLite2 country lookup (ip-api fallback gated behind
GEO_API_FALLBACK), and the IP_ANONYMIZE policy applied at write time.
- Deletes stamp deleted_at for later hard-purge.
- Dashboard: redirect-type selector and password set/replace/remove in the
edit form, lock badge on protected links.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>