Admin / Site manual Back to the site

Uploading from your iPhone

The operating manual for traveller.org — kept current with every publish that changes a process. Sits with the CMS portal behind the admin door.

The share sheet cannot make an album — make them first (23 August 2026)

The list the shortcut shows is a list of albums that already exist. It has no “new album” row, on purpose: the branch that row needed inside the shortcut was where every failure this recipe has had actually lived.

So for a trip’s worth of new albums, open the upload page in Safari on the phone and press + Create albums for the phone…. Country, year — the trip’s year — and a name, add each to the list, then create them all in one go. They are in the share sheet’s list within seconds, empty and marked ◌ not imported, and you can share straight to them. Full walkthrough: Making albums for the phone.

Each album in that panel can be marked Unlisted as you add it, and the choice sticks to the album: the batch you share to it from the phone days later imports unlisted, with nothing to remember afterwards (24 August 2026).

Film, on the phone (25 August 2026)

The Film button at the top of the phone page now opens a film screen of its own. (Until today it led straight back to Photos — the link kept the page it was on. It is a button now, not a link, so there is nothing to go wrong.)

The same shape as photographs: country — a searchable list, like the album picker — year, the clip, then Title, Where and a Description. One dark button, Upload Film, does the whole job: it uploads the clip and its story, then starts the conversion by itself. There is no second button to forget.

  • The progress is real. A film is one long upload, and the ring counts the actual percentage sent — a 400 MB clip with no progress is indistinguishable from a page that has died.
  • One film per upload, as on the desktop. The clip becomes a web-playable MP4 a few minutes after it lands; your original goes into the emailed zip record and is then removed from storage.
  • Afterwards the form clears itself — title, description, where, and the clip — keeping the country and year, since the next film is almost always the same trip. Upload Another Film goes straight back to it.
  • A file that is not a video is refused on the spot, before anything uploads.
  • A country the site has never had still belongs to the classic page: a film cannot invent one, any more than a batch of photographs can.

Banknotes are still the classic page — the Notes button opens it with the right form showing.

After an upload, the next upload is the button (25 August 2026)

On the receipt at the end of a batch — photographs, film or currency alike — the dark button is now “Upload More” (or “Upload Another Film”, “Upload More Notes”), and View is the quiet one beneath it. The site is there whenever; the phone is in your hand now.

One exception, on purpose: if publishing did not start — the upload landed but the pipeline could not be told — then Retry takes the dark slot instead, because that is genuinely the next thing. It goes back to Upload More the moment the retry works.

The rest of the admin, one tap away (27 August 2026)

At the foot of the phone’s home screen — below Upload settings and below the Upload Photos button, which keeps the position of honour because it is what the screen is for — there is now a Publish to the live site card. Tap it and the Publish page opens — the same page as on a desktop, with the list of what is waiting and the button that sends it. Beneath the card sit the rest: Gallery cleanup, Cards & strips, Banknote pages, All tools and this Manual.

Two things about it are deliberate rather than incidental.

  • They open in a new tab. The uploader screen may already be holding a chosen album and a batch the phone has spent a minute preparing; navigating away would throw both out. Close the tab and the uploader is exactly where you left it.
  • They go to the test site’s admin, not the live one. That is the master set — the same storage, the same pipeline, the newest controls — and it is where the manual has told you to work since 22 August. The live site’s copies sit behind Cloudflare Access, which answers a phone with an email-and-code login before it will show you anything.

Publishing itself is unaffected by which admin you press the button on: the Publish page dispatches the same workflow either way, and what goes out is what is on the trunk.

Currency, on the phone — no naming (25 August 2026)

The Currency button (the tab formerly called Notes, renamed on both pages) opens a screen of its own on the phone, and it drops the one rule a phone cannot follow: the filename. The camera roll says IMG_4979; nothing on a phone can type belgium-100-f.

So: photograph each face separately — one note per frame, on a dark ground, filling most of the frame — select them all, and press Upload N Photographs. They upload at full size (nothing is shrunk; the engraving is what gets read), and then the pipeline does the whole job in post: Claude reads each photograph, names the note (country, denomination, front or back — matched against the countries and notes the site already holds), crops it and stands it upright — Claude reports where the note sits in the frame and which way up it is, the pipeline cuts and turns by that, and the measuring cropper fine-trims the result (25 August 2026: measurement alone shipped the euro 10 back sideways and uncropped, because it rightly refuses a frame it cannot be sure of and a rectangle carries no reading direction) — builds the three display sizes, and files it on the site, write-up and all.

  • Nothing uncertain is ever guessed onto the site. A photograph Claude cannot identify with certainty — blurred, half-cropped, a currency it cannot place — waits in storage instead, and the run’s log names each one and why. Re-shoot it, or name it by hand on the classic page.
  • A wrong identification is corrected where write-ups are: Banknote pages in the admin edits, re-crops or deletes any note.
  • A country the site has never held still needs the classic page — a region and display name are the two things no photograph can supply.
  • Hand-named scans work exactly as before, from the classic page — that is still the way to say a name explicitly (and the only way to upload PSDs).

If the phone page ever comes up blank (25 August 2026)

It should not any more, and if something does go wrong it will now say so on the page instead of showing nothing. The passphrase screen is part of the page itself rather than something the page draws after loading, so even a phone that refuses to run the page’s script — a content blocker set on this address will do it — shows the screen and a line explaining why the form on it will not work.

One real cause is worth knowing: Settings → Safari → Advanced → Block All Cookies. With that on, Safari raises an error the moment any page touches its storage, which used to stop this page before it drew anything. It no longer does — the page works with storage blocked; it simply cannot remember the passphrase between visits, and it tells you that on the unlock screen. If a blank page ever does appear, the classic page at traveller-upload.brarob.workers.dev/?stay=1 is always there.

Three small things put right (25 August 2026)

  • Your iPhone now offers to save the passphrase. The unlock screen is a real login form, so the first successful unlock brings up iOS’s own Save Password prompt and the keychain autofills it from then on — on this phone, a new phone, or after Safari’s storage is cleared. The page’s own Remember on this phone switch still works exactly as before; the keychain is the layer that survives everything the switch cannot. And if the page ever falls back to the unlock screen because the Worker was briefly unreachable, the remembered passphrase is already in the box — one tap retries, nothing needs retyping.
  • View Films no longer lands on a 404. A country’s films page only exists once it has published films, and the button used to link it regardless — so the first film for a country led nowhere. It now links the films page when that page exists and the country’s own page otherwise, where the Films section appears once converting and the site rebuild finish. View Album got the same care: an album uploaded but never imported has no page yet, so its button aims at the country page until the first import lands.
  • “hashes” is not a country. The duplicate-detection bookkeeping lives in storage under hashes/ and near-dupes/, and the album pickers briefly listed those folders as if they were albums. They are housekeeping, now invisible to every picker — here, on the classic page, and in the Shortcut’s list.

A photograph you have already uploaded (25 August 2026)

Press Upload and, if any of the chosen photographs share a name with one already in that album, the phone asks first — “2 already in Madrid” — names them, and offers three answers (26 August 2026). Nothing is uploaded while the question is on screen.

  • Upload New Photos — the dark button, and usually the one you want. It sends only the photographs that are not already there, so the duplicates never cross the network. The sentence above it says how many that is and roughly how many megabytes skipping saves, which on a phone away from wi-fi is the whole point.
  • Upload all 43, replacing 2 — what the button used to do on its own. Replacing is a real thing to want: a better edit of the same frame keeps its name and takes the place of the old one.
  • Cancel — nothing is sent and the selection stays as it was.

If every photograph you picked is already in the album, skipping would upload nothing at all, so that button is not offered — the sheet says there is nothing else to send and leaves you with Replace or Cancel. The classic page offers the same three answers.

Two more things happen without being asked. A batch can no longer overwrite itself: iOS hands back repeated filenames for edited photographs, and two files under one name used to mean the second quietly replaced the first — they are now filed as image.jpg, image-2.jpg and so on. Since 13 September 2026 the same rule holds against the album, in storage: a same-name file that is a different photograph is filed as IMG_0001-2.JPG rather than over the one already there, unless you answered Replace on this sheet — and the share-sheet Shortcut, which cannot ask, can no longer overwrite anything at all. That is what a shared uploader needs when several cameras all count from IMG_0001. And the import still does what it always did: it compares the pictures, not the names, and removes a photograph that duplicates another in the same album whatever it is called. The finished-import email lists any it removed.

And now across albums as well (25 August 2026). Every photograph on the site has a fingerprint of its picture on file, so when someone uploads one that is already published somewhere else — a different album, a different country, a different trip altogether — the import email says so and names where: “IMG_4471.JPG is already published as mexico/2019/vallarta/IMG_0031.JPG”. Nothing is removed. The same picture in two albums can be exactly what you meant, and only you can tell that from a mistake; if it is a mistake, remove the copy you do not want on its album’s Gallery cleanup page.

Two things the upload page now tells you (24 August 2026)

  • “Preparing photographs…” — after you tick your selection in the photo library, iOS spends a while handing the files over: on a large batch of HEICs it is tens of seconds during which the page has nothing to show and the phone looks stuck. It now says so, with a spinner, from the moment you press the tick until the count of chosen photographs appears. Nothing has gone wrong; it is the phone reading the pictures.
  • The film form empties itself after a film is handed over — title, description, location and the clip — so the next one can be started straight away without clearing four boxes by hand. The country / year is kept on purpose, since the next film is almost always from the same trip.

The icon on your home screen (22 August 2026)

Adding the site to an iPhone home screen now puts a Buddha’s head against a sunset sky there, labelled Traveller’s Tales. Before this it put a screenshot of whatever page you happened to be on — iOS does not fall back to the little browser-tab icon, and the site had no home-screen icon of its own since the 2004 favicon is 16 pixels square, far too small.

The mark is your own photograph, the square crop you supplied, resized into the three files a phone looks for: apple-touch-icon.png (iOS, 180px) and icon-192.png / icon-512.png (Android). Nothing was cropped or recoloured — the file is used as given.

To change it later, put a new square image in the shared Drive folder (traveller-uploads) and say so. A session reads it from there, writes the three sizes and publishes. That folder is the way to hand over any small file — images attached to a chat message can be looked at but not read as files, which is what made this icon take four attempts (22 August 2026).

The browser-tab favicon is still the original 2004 Bagan stupa — it was left alone deliberately, since it is part of the site’s own history. If you would rather the two matched, the same photograph can be cut down to 16 and 32 pixels; say so.

Two ways in, same pipeline

Everything below lands in the same storage and runs the same import as the desktop page — galleries, guardrails, duplicate checks and all. Photos are stood upright from the phone's own orientation data, and HEIC needs no conversion on your side.

1 — The phone app at /m (24 August 2026)

Opening the upload page on a phone now lands on a page built for the phone, at traveller-upload.brarob.workers.dev/m. Same passphrase, same storage, same pipeline — only the shape changed. The desktop form is untouched, and the phone is sent to /m automatically, so nothing about how you open the page changes: your home-screen icon and bookmarks keep working.

The whole flow is three decisions and one action:

  1. Album — tap the Album card and a list slides up. Type in the search box to find any album by its name, its country or its year ("vall" finds every Vallarta album at once), or scroll the list, which leads with your recent albums and then groups by country. Unlisted albums are marked ⊘ unlisted and never-imported folders ◌ not imported, exactly as everywhere else.
  2. Photos — tap the Photos card to open your photo library and multi-select. While the phone reads a big batch the card says "Preparing photographs…" with a spinner — tens of seconds on a large batch of HEICs, and nothing is wrong.
  3. Upload N Photos — the one dark button. It uploads, and when every photo has landed it starts the import by itself — there is no separate "Start import" any more on the phone. The receipt shows both steps and a View Album link. If any photo fails, nothing publishes: the page names the failures and Retry re-uploads only those, then publishes everything together.

Making a new album lives in the album list now — the + New album row at the top (or at the bottom of a search that found nothing). Country, year — the trip’s year, starting at this year — a name, and an Unlisted switch whose choice is remembered with the album. Create & Select drops you back with it chosen; Create Another makes the next one. Every album made here also appears in the share sheet’s list within seconds, so this replaces the old “+ Create albums for the phone” panel for phone use.

Rarely-touched settings (shrink big photos — on by default — and parallel uploads) are behind Upload settings. Film and Notes at the top open the classic page with the right form already showing. Two things deliberately stay on the classic page: creating a country the site has never had (it needs a region, which only that page asks for), and uploading whole folders with place subfolders. The classic page is always reachable at ?stay=1.

2 — "Share → Upload to traveller.org" from the Photos app

Apple does not let websites appear in the share sheet, so this one-time setup uses the built-in Shortcuts app (about five minutes). Afterwards: select photos in Photos → Share → Upload to traveller.org → pick the gallery → done.

Written for iOS 26, and the two web addresses the recipe calls are verified against the Worker's own code. One thing only a real phone can show — what iOS names a photograph handed over by the share sheet — has a one-photo test built in at the end, with the fix beside it. If your phone disagrees with any step, say what it showed instead and this page will say that.

  1. Open Shortcuts+ (top right) to make a new shortcut. Tap its name at the top ("New Shortcut", with a beside it) → RenameUpload to traveller.org.
  2. Turn on the share sheet first — doing this adds the "Receive" bar at the top of the shortcut for you, which the rest of the recipe then feeds from.
    Tap at the bottom of the editor, next to the action-search field, and switch on Show in Share Sheet. Close the panel: a bar now sits at the top of the shortcut reading "Receive Any input from Share Sheet".
  3. Limit it to photographs, in the bar itself (there is no setting for this in the ⓘ panel — the blue word Any in the bar is the control): tap Any, and in the checklist that opens untick everything except Images (Deselect All first if it's offered, then tick Images). The bar must read "Receive Images input from Share Sheet" — done right, the shortcut stops offering itself when you share a link or a PDF. Leave "If there's no input" on Continue.
  4. Now add these actions in order (find each by name in the search field at the bottom of the editor):
    1. Text — paste the upload passphrase into it. (It stays in your Shortcuts — synced only through your own iCloud, same standing as the browser's "remember".)
    2. Ask for Input — Text, prompt "Destination (country/year/name)". For an existing gallery, its path as the upload page shows it (vietnam/2009/halong-bay); for a new one, a fresh path — the import creates the gallery and titles it from the last part, so vietnam/2026/halong-bay publishes as Halong Bay. (The title is editable afterwards on Gallery cleanup if the capitals come out wrong.) This is the one typed step, and dictation works.

      Or don't type it at all. Three actions in place of this one turn the prompt into a list of every album on the site, tap to choose — the upgrade is further down this page, and section 3 is the same shortcut built from scratch. Build this one through to the end first if you are mid-way: the swap is an upgrade to a working shortcut, not a different recipe.

      Let iOS capitalise it if it wants to. The keyboard capitalises the first letter of anything typed or dictated into a prompt, so mexico/2026/vallarta becomes Mexico/2026/vallarta and there is no way to stop it short of deleting the letter every time. The address is folded to lower case on the way in, so both spellings reach the same place (owner hit this, 2026-08-19). Only the destination is folded — each photograph's own filename keeps its capitals exactly.
      A trailing slash is fine too, and a stray space either side. Type spain/2026/vallarta or Spain/2026/vallarta/ and both land in the same album. What the upload will not do is guess a missing gallery name: spain/2026 makes an album called “2026”, so give it the last part.
    3. Repeat with Each over Shortcut Inputcheck this one. Shortcuts pre-fills a new Repeat action with the previous action's output, so it arrives reading "Repeat with each item in Ask for Input", which loops over the destination you typed instead of over the photographs. Tap that blue token and choose Shortcut Input (it's under the variable picker's Shortcut heading). It must read "Repeat with each item in Shortcut Input".
      End Repeat appears by itself the moment you add this action — it is not one of the six you add, and there is no action by that name to search for. It marks the bottom of the loop, and everything from here is placed relative to it: the next action goes between the two, the ones after that go below End Repeat.
    4. Get Contents of URL — the action that sends one photograph. It is the fiddliest of the six, so it is broken into single steps below.
      Before anything else, check where it landed. This action must sit inside the loop — indented, between Repeat with each and End Repeat. Shortcuts adds new actions at the bottom of the shortcut, so it will usually arrive underneath End Repeat. Drag it up by the handle on its right-hand edge until it sits indented under the Repeat. Outside the loop it runs once with nothing to send, and the rest of this step is wasted.
      Then work down the action in this order:
      1. Tap the URL field and type this, and only this:
        https://traveller-upload.brarob.workers.dev/put?key=
        Stop at the =. Do not type the passphrase here. key in this address means the storage path the photograph is filed under — vietnam/2009/halong-bay/IMG_1234.jpg — and the next three steps build it out of variables. It is not the upload key, despite the name; the passphrase goes in the x-upload-key header at step h and nowhere else.
        Typed here it would become part of every photograph's address in storage, and those addresses are served publicly — the passphrase would be readable by anyone who opened a picture. The Worker now refuses such an upload outright and says so (owner did exactly this, 2026-08-19), so nothing is lost if it happens; but if it has already been typed, rotate the passphrase rather than only correcting the field.
      2. Leave the cursor at the end of what you typed. Tap Ask for Input in the variable strip above the keyboard — that is the destination you typed at action 2.
        Pick Ask for Input, not Shortcut Input — they sit in the same strip, one above the other, and only one is right. Ask for Input is the destination path; Shortcut Input is the pile of photographs from the share sheet, which would land where the folder name belongs.
        Once placed, the token may read Provided Input instead — that is Shortcuts' older name for the same thing, and it is correct. This page used to call it that throughout, which sent the owner hunting the strip for a word that is not in it (2026-08-19).
      3. Type one forward slash: /
      4. Tap Repeat Item in the same variable strip.
      5. Tap the Repeat Item token you just placed. A panel slides up from the bottom of the screen. In it:
        1. Under the three buttons (Clear Variable · Reveal Action · Return) is a grey row reading Type, with App on its right and a small after that. That row is a button — tap it. Nothing about it says so except the .
        2. Choose File from the list of content types that opens. (Image works too if it is offered; a photograph is both, and both carry a Name.)
        3. You come back to the same panel, now reading Type: File — and the properties underneath have changed to File Extension, File Size, Creation Date. That change is the confirmation you set the right thing.
        4. Tick Name, then tap Return.
        That is what puts each photograph's own filename on the end of the address.
        Check the Type row before you tick anything. Shortcuts cannot know what a Repeat Item holds until the shortcut runs, so it guesses — and it guesses App. An App has a Name too, so the tick looks right while meaning the wrong thing. The giveaway is the rest of the list: if the properties beneath are Is Running, Is Hidden, Is Frontmost, you are looking at an app. A File offers File Extension, File Size, Creation Date instead.
        Left on App, Name resolves to nothing at run time and each photograph is stored under the destination alone — so the whole batch overwrites itself down to one file, with no error. The Worker now refuses a path with an empty segment rather than storing that, so the failure at least announces itself (owner, 2026-08-19).
        The token keeps reading just Repeat Item either way — it does not display the property. Tapping it and seeing the tick is the only confirmation there is. This page used to claim the token would read Repeat Item · Name; it does not.
        If the Type row will not open, or the list has no File: stop fighting it and use the fallback at the foot of this page — add Get Details of Images inside the loop above the upload action, set it to get Name of Repeat Item, and swap the address's last token for that action's result. One extra action, same outcome.
        The URL field now reads:
        https://traveller-upload.brarob.workers.dev/put?key=[Ask for Input]/[Repeat Item], the second token set to File → Name
        Two variable tokens, one typed slash between them. If yours has more or fewer tokens than that, fix it here before going on.
      6. Tap the at the right-hand end of the action to unfold it. Method, Headers and Request Body do not exist on screen until you do this — if you are hunting for them, this is the step you missed.
      7. Set Method to PUT.
      8. Under Headers, tap Add new header. Type the key x-upload-key. Then tap the value field and insert the Text variable from the strip. Do not retype the passphrase — insert the variable, so rotating it later means editing one action instead of hunting for copies.
      9. Set Request Body to File, then set the file to Repeat Item. Plain Repeat Item here — not Repeat Item · Name. The address needs the photograph's name; the body needs the photograph. This is the one place the two are easy to confuse.
    5. Get Contents of URL, the second one — this starts the import once every photograph is up, so it goes after End Repeat, outside the loop. If it lands inside, drag it down.
      1. URL: https://traveller-upload.brarob.workers.dev/dispatch — typed plainly, no variables in it at all.
      2. Unfold it with the , the same as before.
      3. Set Method to POST.
      4. Under Headers, add x-upload-key with the Text variable as its value — same as the last action.
      5. Set Request Body to JSON, and add two fields:
        • kindimport-pathtyped as text
        • pathAsk for Inputinserted as a variable, the same one as the address above, and again not Shortcut Input
    6. Show Notification — and the text is not typed. It is the answer the site sends back, so the notification says what actually happened instead of always saying it went well.
      1. Tap the notification's text field. If it already holds words — "Uploaded — import started." from an earlier version of this recipe — delete them all.
      2. With the field empty, tap Get Contents of URL in the variable strip above the keyboard.
      3. Check you got the right one, because there are two actions by that name. Tap the token you just placed and choose Reveal Action: the editor scrolls to the action the token refers to. It must be the /dispatch action below End Repeat. If it lands on the upload action inside the loop, tap the token again, Clear Variable, and pick the other Get Contents of URL from the strip.
      What it will say now. The site counts what actually arrived in this batch before it starts anything:
      "12 new photograph(s) at spain/2026/vallarta — import started."
      "12 new photograph(s) at spain/2026/vallarta (57 there now) — import started." — adding to an album that already held 45.
      "Nothing at spain/2026/vallarta — no photograph arrived, so no import was started. Check the destination and share them again."
      "Nothing new arrived at spain/2026/vallarta — the 26 photograph(s) there are from before, so no import was started."
      That last one is why the count says NEW. It used to report the folder's total, which answered "did my photographs land?" perfectly for a new album — where the total is the batch — and not at all for an existing one. Two photographs shared to an album already holding 26 were refused, and the phone said "26 file(s) … import started" (owner, 2026-08-21). A batch that never landed reported as a success, which is the one thing this sentence exists to prevent.
      The second one is the whole reason for this step. It used to be indistinguishable from the first (owner lost a Spain batch to it, 2026-08-19): every upload was refused, the import found an empty folder, and the phone said it worked. Nothing is started when nothing arrived — a run certain to fail costs build minutes and tells you less than that sentence does.
    Read it back before the first run. Top to bottom, with the indentation shown, the finished shortcut is exactly this:
    1  Text                  the passphrase
    2  Ask for Input         "Destination (country/year/name)"
    3  Repeat with each item in Shortcut Input
    4      Get Contents of URL   PUT   /put?key=[Ask for Input]/[Repeat Item→File→Name]
    5  End Repeat
    6  Get Contents of URL   POST  /dispatch
    7  Show Notification     [Get Contents of URL]  ← the /dispatch one, line 6
    Line 2 is the one with a better version — an album list you tap instead of a path you type. Two ways there: swap this one action for three, or rebuild the whole shortcut fresh with the list built in — a complete recipe, nothing carried over.
    The two that fail quietly, and so are worth looking at twice: line 3 must say Shortcut Input and not Ask for Input, and line 4 must be indented under the Repeat rather than sitting below End Repeat. Neither shows an error; they simply upload nothing, or upload the destination you typed instead of your photographs.
    The two variables, and which goes where: the Repeat takes Shortcut Input — the photographs off the share sheet. Both URLs take Ask for Input — the destination you typed. They live side by side in the same variable strip, so the one check worth making twice is that neither has the other's.
  5. First run — one photograph, on purpose: open Photos, select a single photo, tap Share, and scroll the sheet down past the app row — Upload to traveller.org is in the list of actions below (if it isn't, scroll to the sheet's foot → Edit Actions… → add it). Send it to an existing gallery. iOS will ask permissions on this first run — to read the photos, and "Allow … to connect to traveller-upload.brarob.workers.dev?": answer Always Allow, or a forty-photo batch will ask forty times.
    Done when: the photo appears under its own name (IMG_…) for that gallery on Gallery cleanup, and the import email arrives. If it shows up nameless or the import finds nothing, use the fix in the box below — that is the one behaviour a page cannot promise for a phone it has never met.
  6. Before the first BIG batch — one switch (23 August 2026). iOS limits how many items the share sheet will hand to a shortcut at once, as a privacy guard against a shortcut quietly hoovering up your library. Cross it and you get a banner — “This action is trying to share 52 Photos… You can allow this in Settings” — and the batch never reaches the shortcut at all. Nothing is uploaded twice and nothing is lost; it simply does not arrive.
    Turn it on once: Settings → Apps → Shortcuts → Advanced → Allow Sharing Large Amounts of Data. (On older iOS the Shortcuts settings sit at the top level: Settings → Shortcuts → Advanced. Searching Settings for “large amounts” finds it either way.)
    Then check the count. The banner said 52 where the picker said 51 selected — after allowing it, confirm the number that lands on Gallery cleanup is the number you sent.
    This is a third prompt, separate from the two above — photo access, and the connection prompt that wants Always Allow. All three are one-time.
If the one-photo test lands nameless or oddly named (or the import says it found none): the address each file is stored under ends in Repeat Item · Name, and photographs handed over by the share sheet do not always carry a filename. The fix stays inside the loop: add Get Details of Images before the upload action, set it to get Name of Repeat Item, and swap the URL's final token to that action's result.

A name that arrives without its extension is no longer a problem — the photograph stored as IMG_1234 with no .heic/.jpg. That happened for real on 27 August, to four photographs of Madrid: they reached storage, the import counted them as stray files, and none was published while the run reported success. The site now names such a file from the photograph's own contents — as it is stored, and again at import for anything already sitting in the bucket — and the review email lists each one. Nothing in the Shortcut changes. See the pipeline page.

The Shortcut sends full-size originals. The on-device shrink is a feature of the upload page, not of Shortcuts — a share-sheet batch is roughly four times the data of the same batch sent from the app, and lands at identical published pixels either way. On cellular, or for a batch of more than a few dozen, the app is the cheaper route.

Two things the phone cannot do, and one it now does for you. It cannot create a country: that needs a display name and a region, and a share sheet has nowhere to ask — so a destination naming a country the site has never had is refused immediately, on the phone, before anything uploads. A country’s first batch goes through the upload page; after that the Shortcut can send to it like any other. It cannot mark an album unlisted either — that switch is on the upload page, or on Gallery cleanup afterwards. What it does do for you is spelling: type united-states/2026/sonoma-house and the country is folded onto the site’s own spelling (unitedstates) at both ends of the upload, so the photographs land where the import will look for them. Either shape of address works: country/year or country/year/name.

“1 new photograph(s)” when you sent thirty-five. The count in that message is read from storage, not from what the phone believed it sent, so it is telling the truth: that many files arrived. The notification now names them when only one, two or three do — “1 new photograph(s) at australia/2019/sydney — IMG_4936.jpeg — import started” — so you can see which photograph that was without opening anything. A real batch is counted and not listed; forty names is not a notification.
If the name is the single photograph you used to create the album, the batch itself never left the phone. The usual cause is the share-sheet limit above: iOS refuses a large share whole and silently, and what is left in the album is the one you seeded it with. Turn on Allow Sharing Large Amounts of Data and send again.
If the name is a photograph you did not choose at all, and the same one keeps arriving at different albums, that is a different fault: the upload action in the shortcut is bound to a fixed file rather than to the repeat’s own item. Open the shortcut, find the Get Contents of URL that uploads, and make sure the file attached to it is Repeat Item — not [Ask Each Time], Shortcut Input, or a token left over from an earlier recipe. iOS draws them all as the same blue pill.

The /dispatch call accepts either a full path, or country + year + name parts — it assembles and slugifies the address server-side, so the Shortcut never has to manipulate text. If the passphrase is ever rotated, edit the one Text action.

Already built the typed version? Swap in the album list

This section is the upgrade path for a shortcut built from section 2: it swaps the typed destination box for a list of every album you tap. If you would rather not edit in place — or you have never built the shortcut at all — section 3 below is the complete recipe from scratch, and it is the simpler document.

Delete action 2 (Ask for Input) and put these three in its place, in order:

  1. Get Contents of URL — URL https://traveller-upload.brarob.workers.dev/albums.txt, typed plainly. Unfold the , leave Method GET, add one header: key x-upload-key, value the Text variable from action 1 (insert it from the strip — do not retype the passphrase).
  2. Split Text — Separator New Lines. (It pre-fills from the previous action, which is right.)
  3. Choose from List — from Split Text. This is the screen you see on every upload: every album on the site, one per line, a search field at the top.

Two marks in that list

The list is nothing but paths, so until 22 August 2026 a hidden album looked exactly like a published one. A line now begins with a mark when it is not on the public site.

What you see when you tap Upload

peru/2010/inca-trail
morocco/2021/fez
morocco/2026/tangier
peru/2004/reunion
peru/2010/cuzco
Unlisted album A real album — imported, with a page of its own — that you deliberately took off the site’s lists. Reachable by its address and listed nowhere. Not private: anyone with the link can open it.
Uploaded, never imported Photographs that reached storage and were never processed. No page, no thumbnails, no record yet. Sending more to it is fine — they join the rest and import together.
none
An ordinary published album On the site, in the counts, in the sitemap.

The list stays in alphabetical order: it is sorted on the path and marked afterwards, so a marked album keeps its place rather than bunching with the others that share its glyph.

Nothing in the Shortcut changes. Tap a marked line exactly as before. The upload address and the dispatch both remove the mark at the Worker — which is why it sits at the front of the line and not the end: a photograph’s filename can contain spaces, and a place subfolder travels in the same address, so a mark at the end could not be told apart from a real name.

Then re-point the two fields that still hold the deleted token. The upload URL and the dispatch body both carried Ask for Input, and a deleted action's token does not go away by itself:
• the PUT action inside the Repeat — its address becomes …/put?key=[Selected Item]/[Repeat Item]
• the POST action's JSON path field — also Selected Item
(Your phone may label the variable Chosen Item — same thing, the output of Choose from List.)
Deleting the old action does not clear its token — iOS quietly replaces it with [Ask Each Time], which is a different variable that looks like any other blue token. Both addresses must be checked by eye and re-pointed by hand; the owner's dispatch was correct while the upload address held [Ask Each Time], and nothing on screen said so (2026-08-21).
What missing one looks like (owner, 2026-08-21, twice): the album list appears, you pick an album — and either every photograph is refused with “the storage path needs a folder and a filename”, or the phone says “Nothing new arrived … the N photograph(s) there are from before”. The uploads went nowhere; the stale token resolved to nothing.

The list is live — read from the site each time, so an album imported yesterday is in today's list, unlisted albums and not-yet-imported folders included; albums marked legacy are left out, since their photographs live on the old server. There is no “new album” row any more: the typed fallback it fed was the source of every failure this recipe has had, and the owner retired it (2026-08-21). A new album starts on the upload page (way 1), which can ask the questions a new album needs; from then on it is a line in this list. An older shortcut that still carries the If block keeps working — with no list row containing “New album” its If simply never fires, and the album you tapped passes straight through.

3 — Build the Shortcut from scratch, step by step

The complete recipe, written for someone who has never opened the Shortcuts app. Nothing is typed on upload day: you share photos, tap an album from a list, done. There is no typed destination and no If in this version — the site keeps the album list, the shortcut only shows it. About ten minutes to build.

Two ground rules before you start. Build this as a new shortcut beside any existing one — the old one keeps working until the new one passes its test, and only then do you delete it. And a brand-new album starts on the upload page (way 1, the home-screen app), because a new album needs questions answered that a list cannot ask; once imported it appears in this shortcut's list like every other album.

Part one — create it and turn on sharing

  1. Open the Shortcuts app. Tap + (top right).
  2. Tap the name at the top (“New Shortcut”, with a small beside it) → Rename → type Upload to traveller.org 2. (The 2 is temporary — it keeps this build apart from any old one while you test.)
  3. Tap the button at the bottom of the screen and switch on Show in Share Sheet. Close that panel. A bar appears at the top of the shortcut reading “Receive Any input from Share Sheet”.
  4. In that bar, tap the blue word Any. Untick everything except Images (tap Deselect All first if it is offered). The bar must end up reading “Receive Images input from Share Sheet”. Leave “If there's no input” on Continue.

    What the top of your shortcut now shows

    Receive Images from Share Sheet
    If there's no input: Continue

Part two — add the seven actions

Find each action by typing its name into the Search Actions field at the bottom of the editor, then tap it to add it. Each new action lands at the bottom of the shortcut, which is where it belongs — except the upload action at step 6, which gets dragged one place up.

  1. Text — tap the empty box and paste the upload passphrase into it. This is the only place the passphrase is ever typed; every later step inserts this Text variable instead of typing it again. (It stays in your own Shortcuts, synced only through your own iCloud.)
  2. Get Contents of URL — this fetches the album list.
    1. Tap the blue URL box and type, exactly: https://traveller-upload.brarob.workers.dev/albums.txt
    2. Tap the at the end of the action to unfold it — Method and Headers are hidden until you do.
    3. Leave Method on GET.
    4. Under Headers, tap Add new header. In the key box type x-upload-key. Then tap the value box — a strip of blue variable buttons appears above the keyboard — and tap Text in that strip. Do not type the passphrase here; the Text token stands for it.

    The finished action

    Get contents of https://traveller-upload.brarob.workers.dev/albums.txt
    Method GET  ·  Header x-upload-key = Text
  3. Split Text — it arrives already reading “Split Contents of URL by New Lines”, which is exactly right. Touch nothing.
  4. Choose from List — arrives reading “Choose from Split Text, also right. This is the album list you will see on every upload, with a search field at the top.
  5. Repeat with each — tap the empty token and choose Shortcut Input from the variable list (the photographs off the share sheet). It must read “Repeat with each item in Shortcut Input — not Selected Item, which would loop over the album name instead of your photographs. Shortcuts adds the End Repeat row by itself.
  6. Get Contents of URL (a second one) — the upload itself. It lands below End Repeat; press and hold it and drag it up one place, so it sits indented between Repeat and End Repeat. Then, in order:
    1. Tap the URL box and type https://traveller-upload.brarob.workers.dev/put?key= — and stop at the =. Never the passphrase here: key means the storage path, not the upload key, and this address is public. (The full story is at section 2, step d-a.)
    2. With the cursor at the end, tap Selected Item in the variable strip. (Your phone may label it Chosen Item — same thing, the output of Choose from List; it carries the same blue list icon.) Not Ask Each Time, which sits near it in the same strip and is a different variable altogether — it makes the address ask you at run time instead of using the album you tapped.
    3. Type one forward slash: /
    4. Tap Repeat Item in the strip.
    5. Now tap the Repeat Item token you just placed. In the panel that opens, the grey row reading Type with App beside it is a button — tap it, choose File, tick Name, tap Return. If the panel offers File Extension, File Size, Creation Date, you set the right thing; if it offers Is Running, Is Frontmost, the Type is still App — go back and change it. (Why, at section 2 step d-e.)
    6. Unfold with . Set Method to PUT.
    7. Under Headers: x-upload-key with the Text variable, same as before.
    8. Set Request Body to File, and the file to plain Repeat Item — the address carries the photograph's name; the body carries the photograph itself.

    The finished upload action, indented inside the repeat

    Repeat with each item in Shortcut Input
    Get contents of https://traveller-upload.brarob.workers.dev/put?key=Selected Item/Repeat Item
    Method PUT  ·  Header x-upload-key = Text  ·  Body File → Repeat Item
    End Repeat
  7. Get Contents of URL (a third one) — tells the site the batch is complete so the import starts. It belongs where it lands: below End Repeat.
    1. URL: https://traveller-upload.brarob.workers.dev/dispatch — typed plainly, no variables.
    2. Unfold. Method: POST.
    3. Headers: x-upload-key → the Text variable.
    4. Request Body: JSON. Add two fields: kind → type the word import-path; path → insert the Selected Item variable (not typed — the same token as in the upload address).
  8. Show Notification — leave its text box empty of typed words and insert the Get Contents of URL variable, so the phone shows the site's real answer instead of always claiming success. There are three actions by that name now: tap the token you inserted → Reveal Action, and confirm it jumps to the /dispatch action from step 7. If it jumps anywhere else, tap the token, Clear Variable, and pick another until it lands right.

    The last two actions

    Get contents of https://traveller-upload.brarob.workers.dev/dispatch
    Method POST  ·  JSON: kind = import-path, path = Selected Item
    Show notification Contents of URL
Read it back before the first run. Top to bottom, indentation included, the finished shortcut is exactly this:
1  Text                  the passphrase
2  Get Contents of URL   GET   /albums.txt   (header x-upload-key = [Text])
3  Split Text            by New Lines
4  Choose from List      from Split Text
5  Repeat with each item in Shortcut Input
6      Get Contents of URL   PUT   /put?key=[Selected Item]/[Repeat Item→File→Name]
7  End Repeat
8  Get Contents of URL   POST  /dispatch   path = [Selected Item]
9  Show Notification     [Get Contents of URL]  ← the /dispatch one, line 8
The three variables, and where each one goes — this is the whole machine:
Text (the passphrase) → the three x-upload-key headers, nowhere else
Shortcut Input (the photographs) → the Repeat on line 5, nowhere else
Selected Item (the album you tapped) → the two URLs, lines 6 and 8

Part three — prove it, then retire the old one

  1. One-photo test: open Photos, select a single photograph, tap Share, and choose Upload to traveller.org 2 from the sheet (scroll down; if it is missing, the sheet's foot has Edit Actions…). The album list appears — pick a small existing album. Answer Always Allow to the connection prompt, or a forty-photo batch will ask forty times.
  2. Done when the notification reads “1 new photograph(s) at … — import started” and the photo appears under its own name on Gallery cleanup. If it says “Nothing new arrived” instead, a token in the two URLs is wrong — the check below finds which.
  3. Then: long-press the old Upload to traveller.org in Shortcuts → Delete, and rename the new one to drop the 2. One name in the share sheet, and it is the one that works.

Check it against these three things before the first run

Reading a finished shortcut back on screen, three of its settings are invisible — the tokens look identical whether they are right or wrong. Each one fails silently, so each is worth one tap to confirm.

  1. The album token in the two URLs. The PUT address and the POST path must both read Selected Item (or Chosen Item — two labels, one variable). The classic miss is a leftover token from the typed recipe. It wears one of two disguises: [Ask for Input] if that action still exists, or [Ask Each Time] if you deleted it — iOS substitutes that automatically, and it renders as an ordinary blue token with nothing to mark it as wrong. Tap the token in the PUT action's address and check the word; do the same in the POST action's path field (unfold it with ).
    Symptom: every photograph refused with "the storage path needs a folder and a filename", or the notification reads "Nothing new arrived … the N photograph(s) there are from before".
  2. The Repeat Item's property in the PUT address. The token reads Repeat Item whether or not its Type is File and Name is ticked — it never displays the property. Tap it and look. The panel, and the App/File trap.
    Symptom: a whole batch arrives as a single photograph, or the import finds nothing.
  3. The passphrase header on all three Get Contents of URL actions. Unfold each and confirm x-upload-key is present with the Text variable — not retyped, and not missing.
    Symptom: "wrong passphrase", or the album list never appears.
Then the one-photo test, which is the only check that proves all three at once: share a single photograph to an existing album and confirm it lands under its own name on Gallery cleanup. Pick an existing album deliberately — the typed-new-album branch is the one that keeps working when the destination token is wrong, so testing that half first proves the least.

Giving the Shortcut to someone else

Never share it with the passphrase still in it. Action 1 is a Text action holding the upload passphrase as plain, readable text, and it travels inside the shared link — anyone who opens that link, or anyone it is forwarded to, can tap that action and read it. The passphrase is the only lock on the upload Worker: it grants writing photographs into the bucket and starting imports that commit to the site. Treat handing it over as handing over the ability to publish.

So share a copy with the field emptied, and send the passphrase by a different route. Five steps:

  1. Duplicate your own Shortcut — in the Shortcuts app, press and hold it and choose Duplicate. Yours stays working; the copy is the one that travels.
  2. Open the copy, tap the Text action at the top, and delete the passphrase, leaving the field empty. Rename the copy something like Upload to traveller.org (setup) so the two are never confused on your own phone.
  3. Open the copy's (or the share button) → ShareCopy iCloud Link. That makes a public, unlisted icloud.com/shortcuts/… address.
  4. Send the link. The person opens it, Shortcuts shows what the shortcut can reach, and they tap Add Shortcut.
  5. Send the passphrase separately — a different message, ideally a different app from the one carrying the link. They tap the empty Text action once and type it in. Nothing else needs setting up.

Two things worth knowing afterwards. The iCloud link stays live until you open the copy and choose Stop Sharing — it is not tied to who you sent it to, so revoke it once everyone has added the shortcut. And rotating the passphrase means everyone retypes their one Text action; that is the price of a single shared secret, and it is the reason for the note below.

One passphrase, shared by everyone. The Worker checks a single UPLOAD_KEY, so every phone carries the same secret: you cannot cut off one person without cutting off all of them, and nothing in the pipeline records which phone sent which batch. That is fine for a couple of people you would trust with the repository itself. If the Shortcut is going to more phones than that, ask in a session for per-person keys — the Worker can hold a list instead of one value, so a key can be revoked on its own and the import email can say whose upload it was.

If a recipient is told the shortcut cannot be added: older iOS had a Settings → Shortcuts → Allow Untrusted Shortcuts switch that had to be on before a shared shortcut would install. Current iOS scans the shortcut and shows what it can reach instead, so this rarely comes up — but that setting is the thing to look for.

Shooting and sending tips

  • Share sheet and photo picker both deliver the photo's real file (HEIC or JPEG) — either is fine, and orientation is handled.
  • iCloud "Optimize iPhone Storage" means some photos download from iCloud before they upload — a long pause before the first progress is that, not a hang.
  • Currency notes have their own flow — see Updating the site → banknote scans: name the file for the note and drop it on the upload page's Notes tab (that tab's picker also opens the photo library on a phone).