Commit Graph
928 Commits
Author SHA1 Message Date
Matthew Meszaros 147491ed3c feat: disable imported webhook endpoints whose address fails the same https and public-host check a new endpoint must pass, and document it on the workspace export and import page 2026-10-04 03:03:40 -07:00
Matthew Meszaros 1c29643ecb feat: re-apply the app and form write rules to workspace imports so imported OAuth apps get displayname-checked names, http(s) websites, valid redirect URIs and webhooks, only their workspace's own logos, and stay suspended when suspended at the source or imported under a developer block, imported forms keep only http(s) redirect URLs, valid designs and embed domains, and the hosted form page navigates only to http(s) redirect targets 2026-10-04 03:03:40 -07:00
Matthew Meszaros eff2c14a9d feat: make workspace import write only rows the destination workspace owns by checking every archive key and foreign key against each table's owner scope before a batch lands, scoping overwrite updates to the destination's own rows, warning in the archive check, and documenting the rule 2026-10-04 03:03:34 -07:00
Matthew Meszaros 43a9d004f2 feat: bound user-authored templates (range only over data fields, two-deep nesting, no template calls, 1 MiB output, capped compile cache) for campaign and automation rendering, accept only single addresses and single Message-IDs for to/cc/bcc/in_reply_to on every send path with invalid_recipient and invalid_message_id, refuse multi-line headers in the Gmail, Graph and SMTP writers, always apply a no-script CSP and drop non-http(s)/mailto/tel link targets in email previews, treat only single-slash paths as internal Remie links, accept integration OAuth callbacks only from the API origin, and follow only http(s) form redirects and app install links 2026-10-04 03:02:37 -07:00
Matthew Meszaros f9a2e9af10 feat: state dependency floors, the Sentry HTTP client choice and auth cache budgets as the guarantees they hold, with no advisory identifiers or past behaviour in comments 2026-10-04 03:00:56 -07:00
Matthew Meszaros bf47984cd5 feat: cap every OAuth grant and API key at the delegating member's role (consent narrows scopes and reports the withheld ones, tokens re-check the member's current role at every gate and MCP tool, keys stay within their creator's permissions, mailboxes and IP allowlist), keep OAuth tokens off API key and OAuth app management, require a fresh sign-in to approve an app, revoke a grant whose refresh token is presented twice, count only unexpired grants as installs, seal app webhook secrets under the instance key, name the workspace and flag unverified apps on the consent screen, and let credential managers list and revoke every member's app authorizations 2026-10-04 02:59:10 -07:00
Matthew Meszaros 8bb60e9449 feat: accept only Salesforce domains as an org's API host and call it through the SSRF-guarded client, register the Warmbly Cloud link only on self-hosted instances behind the instance admin with a second factor and dial it through safehttp with fixed error text, keep automation signing secrets in the sealed connection config, answer integration service failures with fixed messages, add security headers to the forms, tracking and docs origins and TLS 1.2+ to the nginx template, compare the captcha bypass in constant time, require TLS 1.2 for IMAP probes, and drop the unused RSA helpers 2026-10-04 02:58:43 -07:00
Matthew Meszaros 59f6d72d3b feat: bump docs to next 16.3.8, site to patched devalue and http-cache-semantics, and realtime to mint 1.11.0, gate the security workflow on called Go vulnerabilities with a fixed version and on retired or upgradable Hex packages through scripts/govulncheck-gate.sh and scripts/hex-audit-gate.sh with a new Elixir audit job, and keep advisory ids and reachability notes out of .trivyignore, mix.exs and the site pnpm workspace 2026-10-04 02:57:17 -07:00
Matthew Meszaros 610d511307 feat: answer every server-side failure in admin, internal, webhook, warmup routing, Stripe webhook, agent tool and MCP handlers with the fixed internal error and log the detail against the request id, keep correctable webhook and routing refusals as typed errors with their own messages, drop the request URL from MillionVerifier transport errors so the API key never reaches a log or response, and redact :code path parameters in the access log 2026-10-04 02:57:17 -07:00
Matthew Meszaros db4fc7b115 feat: require a recent confirmation for 2FA enrollment (a fresh sign-in for accounts with no password or factor), pool link approval, workspace export and import, member invites and role changes, webhook and OAuth app secret reveal and rotation, and the admin fleet join token, admin grant and workspace archive routes, with a confirm-it-is-you dialog and retry in the admin panel 2026-10-04 02:56:18 -07:00
Matthew Meszaros 3a2d80b8bf feat: accept realtime API keys and OAuth tokens only in the x-warmbly-token handshake header with the ws ticket alone in the query string, filter token and key params from Phoenix connect logs, refuse realtime keys, OAuth tokens and pool link tokens held by a login-banned user or a suspended app with an uncached key check, and send the key as a header from warmbly events tail 2026-10-04 02:56:18 -07:00
Matthew Meszaros 33f99b97e5 feat: end every session on sign-out-everywhere through RevokeOtherSessions with cache eviction after commit, refuse refresh on a revoked session, close a user's realtime sockets on any session revocation via a SESSIONS_REVOKED event, and verify tokens without a purpose claim for no flow 2026-10-04 02:56:18 -07:00
Matthew Meszaros 5bd8dbfab9 feat: bind Warmbly Cloud brokered mailbox sign-ins to PKCE, a single-use state and a cloud consent page naming the requesting instance and workspace that sets the browser cookie the callback requires, return only to the instance's registered address, add PKCE and an OIDC nonce to Workspace and Microsoft 365 admin-proof sign-ins, post OAuth callback codes only to a configured dashboard origin, cap CLI-approved keys to the approver's role behind a fresh sign-in, and accept only same-origin login next paths 2026-10-04 02:53:16 -07:00
Matthew Meszaros 9f7d45a1fb feat: charge every password, emailed-code and TOTP attempt atomically before comparing it (Redis INCR+expire script) with a per-account TOTP budget across challenges, put the signed-in password change on the reauth budget, set the per-account login limit to 50 per hour, give tester passwords an expiry (users.password_expires_at, migration 000257) and clear them plus every session on revoke, mint warmblyctl reset links with the password-reset purpose, expire fleet join tokens (7 days default, 30 max, reusable inside the window), derive captcha from the resolved Turnstile secret, refuse weak bootstrap argon2id hashes, make registration codes single-use, rate-limit the v1 invitation lookup, and draw RIDs and user codes without modulo bias 2026-10-04 02:52:22 -07:00
Matthew Meszaros f0ec39febd feat: scope automation and sequence unsubscribes to the caller's organization, require manage_settings to create, edit, enable or delete automations, run each integration action only on its own provider's connection (400 action_provider_mismatch), refuse org-permission gates when no organization service is wired, read /integrations/bookings like contacts, scope lead claims, research runs and CRM list cursors to the organization, and bind contact note edits to the contact in the path 2026-10-04 02:47:10 -07:00
Matthew Meszaros e1c4a91ad1 feat: confirm a Slack link only for the Warmbly member whose email matches the Slack account's confirmed profile email (read via users.info with the new users:read and users:read.email scopes, refused as slack_link_email_mismatch), show the Slack account's name and avatar on the link page and after linking, return the Slack connection in GET /integrations/slack/status only to manage_settings or use_integrations, scope agent-thread lookups by organization, and check a Draft a reply card's conversation belongs to the clicker's workspace before starting the assistant 2026-10-04 02:45:04 -07:00
Matthew Meszaros 4cfba5340a feat: verify every HubSpot app request by its v3 signature over the public backend URL, refuse card-fetch query values on the webhook and workflow action routes, take exactly one portalId, userId and userEmail on card routes and act as the matched accepted member holding the matching campaign and contact permissions, route a portal only to its single live HubSpot-mode workspace, delete mirrored deals and tasks only when HubSpot answers the record is gone, and scope the card's permitted fetch to the card routes 2026-10-04 02:42:12 -07:00
Matthew Meszaros 23c57f35c2 Merge pull request #822 from warmbly/feature/integrations-page-redesign
feat: turn Integrations into an app store with search, filters and app pages, add a link-only community directory, a new OAuth app registration dialog, per-app re-encoded logos and admin moderation for OAuth apps
2026-10-04 08:27:13 +00:00
Matthew Meszaros d505508997 feat: audit OAuth app moderation and developer blocks under their own entity types, refuse logo removal on suspended apps, delete a replaced workspace-uploaded app logo once no other app shows it, confirm before revoking every token in the admin panel, open store cards on Space, retry a new logo URL after a failed one, toast only after the clipboard write succeeds, and freeze the listing form baseline while it is open 2026-10-04 01:20:28 -07:00
Matthew Meszaros bc9caba267 feat: validate OAuth app names through displayname and websites as http(s), clean dynamically registered client names and stop storing their logo_uri, refuse edits and logo uploads on suspended apps or blocked developers, scope logo deletion to the app's own images, keep hidden listings from being unpublished, count only installs from other aged workspaces toward the directory threshold, refresh integration popularity outside the lock, and count only live connections in the Integrations store 2026-10-04 01:10:39 -07:00
Matthew Meszaros 2983d3ca1e Merge pull request #823 from warmbly/feat/remie-assistant
feat: Remie, the dashboard AI assistant: animated blob mark, floating panel, live run UI, and Advisor-driven suggestions and tips
2026-10-04 07:59:05 +00:00
Matthew Meszaros 6565197a60 feat: close Remie tips through useClickOutside and put them away when a dialog opens, reset hover on close, read Advisor findings only under View analytics, keep a typed draft when a fix is handed to Remie, celebrate only runs that end without an error or a stop, group suggestions with the Advisor's groupFindings, count the tip day in local time, and scope the dev demo to its own approvals 2026-10-04 00:49:08 -07:00
Matthew Meszaros 1a483cb27f Merge remote-tracking branch 'origin/main' into feature/integrations-page-redesign
# Conflicts:
#	internal/app/integration/service.go
#	web/src/app/app/integrations/page.tsx
#	web/src/hooks/useDocumentTitle.ts
2026-10-04 00:45:48 -07:00
Matthew Meszaros 7672924a72 feat: rename the dashboard assistant to Remie with an animated blue blob mark, open it as a floating window by default, show live runs with a shimmering status, elapsed timer, collapsible tool-step trace, streamed text with a blurred tail and a redesigned approval card, and add Remie suggestions and rate-limited tips built from open Advisor findings that Remie fixes through its own approvals 2026-10-04 00:36:27 -07:00
Matthew Meszaros 4bc2417618 Merge remote-tracking branch 'origin/main' into feature/integrations-page-redesign
# Conflicts:
#	docs/content/docs/api/error-codes.mdx
#	docs/content/docs/guides/integrations.mdx
#	web/src/app/app/integrations/page.tsx
2026-10-04 00:32:54 -07:00
Matthew Meszaros 7555f641a5 feat: turn Integrations into an app store with sidebar views, search, sorting and filters, list community apps by link until featured or widely installed, redesign the OAuth app registration dialog, store app logos re-encoded per app like the workspace logo, and add admin suspension, token revocation and developer blocks for OAuth apps 2026-10-04 00:31:52 -07:00
Matthew Meszaros d112657cf2 feat: wire suppression, subscription and hold dependencies into the consumer's Salesforce service, give Salesforce token refreshes their own single-flight keyspace, release the outbox lease in memory after each terminal write so writeback notes land and only on rows with a logged Task, drop stale Salesforce import previews, keep keys from the import row menu from opening the edit dialog, and document the Salesforce callback URL and OAuth variables 2026-10-04 09:10:37 +02:00
Matthew Meszaros 6b7e254e56 feat: add native Salesforce sync with Lead and Contact matching and links, a leased activity outbox that logs sends, replies, bounces, opt-outs and meetings as Tasks, Lead Status and Email Opt Out writeback, a pull loop with CRM pause rules, list view and Campaign imports, sandbox and My Domain OAuth that refreshes expired sessions, a Salesforce settings page with contact and inbox cards in web, and docs 2026-10-04 08:54:27 +02:00
Matthew Meszaros 37e91fc89f feat: add HubSpot CRM mode where HubSpot deals, pipelines, tasks, notes and owners are mirrored and written through, sends and replies log as HubSpot emails, exit rules hold campaigns, list import, sync health, setup wizard in web, HubSpot app project with record card and workflow action, and docs 2026-10-04 07:47:51 +02:00
Claude e2911fb01a feat: say in the docs/public/openapi.json CampaignSendPlan stale description that a snapshot older than its maximum age is also served as stale when the campaign has not changed 2026-10-04 02:04:41 +00:00
Claude e39ff8318d feat: describe the stored send-plan snapshot in docs/public/openapi.json by adding the required stale flag and computed_at meaning to CampaignSendPlan and noting the background snapshot on GET /campaigns/{id}/send-plan 2026-10-04 02:01:51 +00:00
Matthew Meszaros 8883a1df6b feat: connect Microsoft 365 organizations through Microsoft's v2.0 admin consent page followed by a sign-in on the same state, read the approving admin's directory role from the Graph token as well as the ID token, return an organization-wide approval link for single-mailbox Outlook sign-in (admin_consent_url) and show it in the connect panel, and document publisher verification and the admin approval path 2026-10-03 20:17:38 +02:00
Matthew Meszaros 92456279ed Merge remote-tracking branch 'origin/main' into feature/integrations-page-redesign 2026-10-03 09:24:34 -07:00
Matthew Meszaros 4957214431 feat: redesign the Integrations page with search, category chips, recommended and popularity-ranked integrations, add a community app directory where OAuth apps are published unverified by link and verified in a new admin review queue, with docs and OpenAPI 2026-10-03 09:24:34 -07:00
Matthew Meszaros 232d226211 Merge remote-tracking branch 'origin/main' into feat/dark-theme 2026-10-03 08:49:37 -07:00
Matthew Meszaros f1e3ea5bd9 feat: add a Linear-style dark theme to the dashboard (web/) with Light, Dark and System options in the user menu, Settings > Profile > Appearance and the command palette, light by default, and an Appearance guide in docs 2026-10-03 08:49:37 -07:00
Matthew Meszaros 0a95444c2f feat: send Slack inbox replies once in the background, keep AI drafts only after draft_reply succeeds, refuse thread locks on Redis errors, log Slack delivery failures and keep unreadable Slack connection config 2026-10-03 15:53:01 +02:00
Matthew Meszaros 61d16dfe9a feat: add Warmbly for Slack with the AI assistant in DMs, mentions and the assistant pane, unified inbox threads with reply, AI draft and lead actions, per-category notification routing and DMs, account linking, dashboard Slack settings, manifest and docs 2026-10-03 15:35:11 +02:00
Claude bb580164e6 feat: compute each active campaign's send plan in a background snapshotter (internal/app/campaign) stored in campaign_send_plan_snapshots so GET /campaigns/:id/send-plan serves a stored snapshot instead of walking the planner on the request 2026-10-03 11:04:22 +00:00
Matthew Meszaros c3da0d684b Merge pull request #805 from Skylinerffm97/feat/unibox-long-press-menu
feat(unibox): open the row menu on a long press on touch screens
2026-10-03 07:57:35 +00:00
Claude 3288238cc0 feat: paginate and batch GET /analytics/accounts so account status reads are bounded per page and the overflow past 1000 mailboxes is reachable via cursor 2026-10-03 06:46:20 +00:00
Matthew Meszaros 9ef54798dc Merge pull request #804 from Skylinerffm97/fix/unibox-mark-unread
fix(unibox): make Mark as unread stick, and let it reach a sent-only conversation
2026-10-03 05:11:39 +00:00
Skylinerffm97andClaude Opus 5.5 3f6617000a feat(unibox): open the row menu on a long press on touch screens
iOS Safari fires no contextmenu on a long press, so the conversation rows and the scope rail had no way to reach the right-click menu on a phone. useAnchoredMenu now opens the same menu after a 500 ms touch hold at the finger, cancels on a move over 10 px, swallows the click and touchend that follow the hold (so the row does not open and no menu item under the finger fires), and ignores Android's native contextmenu after a fired hold. Mouse and pen are unchanged.

Herkunft: [Claude]

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-02 16:14:35 +02:00
Skylinerffm97andClaude Opus 5.5 c433a483ec fix(unibox): make Mark as unread stick, and let it reach a sent-only conversation
useMarkSeen invalidated every ["unibox"] query after an unread, including the body queries ["unibox", "email", id]. A body GET marks the message read server side (GetByID), so the still-mounted reader undid the unread. Bodies never change once synced, so the unread path now skips them.

MarkSeenByThreads skipped every sent copy, so a conversation with no received message could not be marked unread at all. It now falls back to the newest sent copy when nothing was received. Received mail still wins, drafts never turn unread, and explicit ids and folder sweeps keep refusing sent and draft copies.

Herkunft: [Claude]

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-02 15:31:48 +02:00
Matthew Meszaros a09ba27b0c feat: confirm a missing SPF or DMARC record with the sending domain's own authoritative nameservers before reporting it, look names up fully qualified so a resolver failure is never retried under the host's search domains and read as not found, look up internationalized domains in ASCII, record the verdict when a mailbox manager presses Check in the drawer, and show an unanswered lookup as unverified rather than missing 2026-10-02 06:13:37 -07:00
Matthew Meszaros 50d50d0fbc Merge pull request #793 from warmbly/fix/inbox-follow-up-sweep-paging
feat: page the hourly inbox follow-up sweep through each mailbox newest first in bounded keyset pages that resolve thread state only for the threads on the page, resume each workspace's cycle from a cursor persisted in inbox_follow_up_sweeps under a per-pass time budget, check recently active threads first every pass, and add the unibox_emails (email_id, internal_date, id) index the walk reads
2026-10-02 06:33:14 +00:00
Matthew Meszaros 0bcbab91ac Merge remote-tracking branch 'origin/main' into fix/inbox-follow-up-sweep-paging
# Conflicts:
#	internal/app/orgtransfer/spec.go
2026-10-01 23:20:32 -07:00
Matthew Meszaros e883e60c3d Merge pull request #795 from warmbly/fix/worker-465-egress
feat: name a worker's own blocked outbound 465 instead of blaming the mailbox's server
2026-10-02 06:12:30 +00:00
Matthew Meszaros e79551867f feat: have a worker learn from its own dials when its network blocks outbound 465, dial 587 at once there, tell a mailbox whose server only takes 465 that the block is on the sending side instead of blaming its server, report the block on every heartbeat as the node's last error, rename the admin Workers filter to Has node error, and document the outbound ports a worker needs 2026-10-02 08:02:36 +02:00
Matthew Meszaros b8a8ec4743 Merge remote-tracking branch 'origin/main' into feat/unibox-rail-layout-per-member 2026-10-01 22:58:31 -07:00