Matthew Meszaros
ce45ba02d9
docs: document the webhook platform and OAuth app webhooks, add the webhooks guide, and update the endpoint scope map
2026-06-15 08:11:53 +02:00
Matthew Meszaros
2c910dcdeb
feat: make a campaign step's Original a first-class weighted A/B arm driven by a single draggable traffic-split bar, persisting the control share as an is_control variant row
2026-06-15 08:11:53 +02:00
Matthew Meszaros
c5dfa5e4e7
feat: remove the HTTP-request action from campaign steps and automations in favor of signed webhooks, keep fire_event for custom payloads, and drop the now-unused outbound quota plumbing
2026-06-15 08:11:35 +02:00
Matthew Meszaros
c1bd391ceb
docs: add a dependency-free realtime gateway reference client (connect, HELLO, heartbeat loop, seq resume, intents incl CUSTOM), a close-codes table, and OAuth-access-token auth
2026-06-14 11:02:12 +02:00
Matthew Meszaros
ab24d8bbc8
feat: add a 'Fire event' action and campaign step that publish custom events to the realtime gateway (no public URL), an HTTP-request campaign step, a configurable automation dry-run test with per-step toggles, and fix the false 'updated by a teammate' toast on your own save
2026-06-14 09:52:49 +02:00
Matthew Meszaros
fcdb31cda7
feat: OAuth apps always issue a client secret (drop the public/PKCE-only client type, secret required for the token exchange), add an app-logo upload endpoint, and align the docs to OAuth2 with optional PKCE
2026-06-14 09:52:49 +02:00
Matthew Meszaros
0fe1401f8b
feat: document the OAuth 2.1 authorization server (new api/oauth.mdx flow guide, authentication + permissions + endpoints scope-map updates, meta registration)
2026-06-13 14:10:11 +02:00
Matthew Meszaros
20935ef061
feat: add a nil-safe per-org daily outbound-action quota (Redis daily counter, anti-abuse ceiling on the HTTP-request automation node, wired in both backend and consumer, fail-open) to bound webhook relay abuse
2026-06-13 13:41:20 +02:00
Matthew Meszaros
1fa9c65ada
fix: harden every user-supplied-URL outbound path against SSRF with a shared dial-time guard (resolves the host, blocks private/loopback/link-local/metadata IPs, pins the validated IP to defeat DNS rebinding, re-validates redirects) and log automation HTTP requests + blocked attempts with org attribution
2026-06-13 13:34:19 +02:00
Matthew Meszaros
501b5009b4
feat: add an on-error branch to automation action nodes (try/catch routing, rose on-error handle, executor follows the error edge and treats the failure as handled instead of failing the run)
2026-06-13 13:15:41 +02:00
Matthew Meszaros
9aa3300f46
feat: capture per-action output in automation run history (HTTP status/ok, set-variables values, rendered channel/url/message) and render it under each action in the builder History panel
2026-06-13 13:11:58 +02:00
Matthew Meszaros
6f5f05c5a2
feat: document the inbound webhook automation trigger (unique per-automation URL, JSON body as event payload, token security and limits) in the automations guide
2026-06-13 13:08:37 +02:00
Matthew Meszaros
f1cf470121
feat: render Discord notifications as sky-themed rich embeds and Slack notifications as sky-accented attachment cards with contact and subject fields instead of plain text lines
2026-06-13 12:41:26 +02:00
Matthew Meszaros
96f19919ac
feat: document the HTTP request / webhook and Set variables automation actions in the automations guide
2026-06-13 12:20:20 +02:00
Matthew Meszaros
4e2fdec482
feat: document the resumable gateway (resume/replay, seq, resume_failed) in realtime.mdx and publish a machine-readable AsyncAPI 3.1 spec at docs/asyncapi.json describing the org channel, join/resume, HELLO, events, intents, and presence
2026-06-13 11:29:12 +02:00
Matthew Meszaros
3c7c0b6411
fix: finish the opaque-cursor doc sweep — change the offset query params to cursor on the CRM search operations in the OpenAPI spec, and drop the dead SearchContacts.Offset field and its docs (clamped but never used in SQL)
2026-06-13 11:00:59 +02:00
Matthew Meszaros
aed4a06190
feat: unify pagination by making the offset-based CRM deals/tasks search and meetings endpoints expose the same opaque next_cursor and {total, next_cursor, has_more} envelope as every keyset list (offset hidden inside the token), updating web clients, the OpenAPI spec, and the reference docs
2026-06-13 10:47:17 +02:00
Matthew Meszaros
013a73b9be
feat: publish a machine-readable OpenAPI 3.1 spec at docs/openapi.json covering 204 operations across the public API, with an OpenAPI docs page describing how to generate clients from it
2026-06-13 07:29:17 +02:00
Matthew Meszaros
587eae774e
feat: serve the entire customer API (auth + resources) only under /v1 with no unversioned alias, and repoint the web and admin clients to the versioned base accordingly
2026-06-13 07:18:23 +02:00
Matthew Meszaros
49b01c6b67
feat: version the public API under /v1 by mounting the customer surface under both /v1 and the bare paths, adding an API-Version response header and Deprecation/Sunset headers nudging API-key callers off the unversioned aliases
2026-06-13 06:27:01 +02:00
Matthew Meszaros
71abb12a38
feat: stop campaigns silently stalling on a transient scheduler error by retrying instead of completing the task, end past-end-date campaigns cleanly, record scheduler failures to the campaign log, add a campaign-chain reconciler, and surface failures live in the dashboard activity panel
2026-06-13 06:27:01 +02:00
Matthew Meszaros
92a74d9364
feat: document the label-email action in the steps and automations guides — reply-only, applies the shared category labels to the conversation the contact replied on, gated to the reply trigger
2026-06-12 16:44:29 +02:00
Matthew Meszaros
a7a43e0c4c
feat: rename the campaign sequences resource to steps across the API and URL (/campaigns/:id/steps), the JSON fields (target_step_id, step_id/step_name/step_index, analytics steps[], create body steps), the web client/models/route segment/labels, the audit step entity type, and the wire-contract docs; internal Go type names and the Kafka avro schema stay
2026-06-12 09:38:11 +02:00
Matthew Meszaros
85d5d04afe
feat: clarify in the sequences guide that the A/B original is a control arm in the weighted split with a live per-arm share shown in the editor
2026-06-12 08:04:44 +02:00
Matthew Meszaros
5d2882ccf8
feat: strip leaked agent reasoning and select the corrected final draft for campaigns and deliverability reference pages, removing duplicate frontmatter, an em dash, and a Cyrillic placeholder char
2026-06-12 07:39:57 +02:00
Matthew Meszaros
bfd67bfa2a
feat: correct API key prefix examples to the real wmbly_ format and link the endpoint reference from the API docs index
2026-06-12 07:29:45 +02:00
Matthew Meszaros
54a1aee753
feat: add full per-resource API endpoint reference under docs/api/reference (mailboxes, campaigns, contacts, unibox, crm, analytics, api-keys, webhooks, integrations, deliverability/ops, account/org) with request and response structures
2026-06-12 07:28:19 +02:00
Matthew Meszaros
3cbfc06bc4
feat: add WebSocket intents (selective event-family subscription) and a HELLO-style org join reply advertising heartbeat cadence, and correct realtime docs on connection rejections and at-most-once delivery
2026-06-12 07:17:09 +02:00
Matthew Meszaros
50a134c827
feat: document org team-presence privacy controls in the collaboration guide and realtime API reference
2026-06-12 05:59:02 +02:00
Matthew Meszaros
f209eca9ad
fix: Slack notification delivery now resolves a real channel (connection config, then the org's configured Slack automation channel) instead of an always-empty connect-time field that silently dropped every message; docs and UI corrected to match
2026-06-11 12:40:31 +02:00
Matthew Meszaros
3c040649c0
fix: changing your password now revokes every other session (keeping the current device), matching the security promise in the sign-in alert and docs
2026-06-11 12:39:24 +02:00
Matthew Meszaros
5bcc2baaa8
feat: implement the coming-soon security features — logged-in change-password (verify current, policy-checked, POST /me/password) with a real dialog, and new-device sign-in alerts (security notification category fired from the token service on an unrecognized OS+browser, delivered in-app and by email), removing the comingSoon stub helper and updating docs
2026-06-11 12:30:44 +02:00
Matthew Meszaros
160dc0bc76
feat: implement the coming-soon notification delivery channels — Email (SES/SMTP to the account email) and Slack (posts to the org's connected workspace via a new integration NotifySlack), wired in both backend and consumer with per-channel gating, real toggles replacing the coming-soon labels, and updated docs
2026-06-11 12:21:48 +02:00
Matthew Meszaros
8540f7db15
feat: members can hold multiple roles — join tables for member/invitation role sets (migration 000044) with effective permissions as the bitwise OR recomputed on every assignment and role edit/delete, role_ids in invite/update APIs, multi-select checkbox role picker with colored chips in roster and invite flow, freely deletable roles
2026-06-11 11:24:19 +02:00
Matthew Meszaros
3473d09bcc
feat: fix review findings in the roles redesign — GetMembers role_id column (members endpoint 500), TransferOwnership role_id hygiene, accept-time role re-resolution, race-free in-use delete guard covering invitations, assignment anti-escalation with self-role-change block, canManage-gated members UI, colored RolePills, fresh currentOrganization on refetch, dev JWT_SECRET wiring for make realtime, docs corrections
2026-06-11 10:45:21 +02:00
Matthew Meszaros
2badeb7f50
feat: align team-roles docs with data-driven roles (seeded editable defaults, owner as status, color in the role editor) and drop dead accent maps from the members page
2026-06-11 10:20:41 +02:00
Matthew Meszaros
0b253337fc
feat: integrate custom roles across Roles & access settings (manager replaces the coming-soon placeholder, custom roles join the permission matrix and summary cards, permission-aware canManage gating via the org context bitmask)
2026-06-11 10:08:46 +02:00
Matthew Meszaros
9992eb65c4
feat: document custom roles in the team-roles guide (creation flow, start-from presets, propagation and anti-escalation rules, limits)
2026-06-11 09:46:15 +02:00
Matthew Meszaros
014cbe79fa
feat: label machine opens (Apple MPP prefetch, UA-less fetchers) with human-open upgrade semantics, exclude them from open-triggered automations, and surface the auto-open count in workspace and campaign analytics (migration 000040)
2026-06-11 08:33:09 +02:00
Matthew Meszaros
7079efe21a
feat: document the developer realtime WebSocket (channels, presence, limits, close codes), add the live collaboration guide, and note bot filtering in analytics docs
2026-06-11 08:13:56 +02:00
Matthew Meszaros
15cf150f9e
feat: remove the stale worker assignment operator doc from docs/, matching the earlier operator markdown cleanup
2026-06-10 18:56:59 +02:00
Matthew Meszaros
49a4e1e8ec
feat: shorten verbose code comments in the docs app and add a one-line comment rule to the agent notes
2026-06-10 18:36:29 +02:00
Matthew Meszaros
1e4116ab0f
Merge remote-tracking branch 'origin/main' into chore/update-docs
...
# Conflicts:
# site/src/components/Header.astro
# site/src/layouts/Learn.astro
# site/src/pages/learn/cold-email-rules.astro
# site/src/pages/learn/deliverability.astro
# site/src/pages/learn/email-warmup.astro
# site/src/pages/learn/glossary.astro
# site/src/pages/learn/inbox-placement.astro
# site/src/pages/learn/index.astro
# site/src/pages/learn/personalization.astro
# site/src/pages/learn/reputation-recovery.astro
# site/src/pages/learn/spf-dkim-dmarc.astro
# site/src/pages/learn/warmup-pools.astro
2026-06-10 18:35:12 +02:00
Matthew Meszaros
6a6ee42a23
feat: remove the operator markdown files from docs/ and drop their references from the root readme and contributing guide
2026-06-10 18:27:42 +02:00
Matthew Meszaros
9706458b10
feat: move the marketing site learn articles into a docs learn tab and point every site learn link at docs.warmbly.com
2026-06-10 18:27:42 +02:00
Matthew Meszaros
d8a14ba14a
feat: split docs content into guides and api sidebar tabs with per-page icons, remove duplicated h1 titles and em dashes, normalize reference-page copy, and add an api overview page
2026-06-10 18:27:42 +02:00
Matthew Meszaros
24079d9df6
feat: rebrand the docs app with the warmbly theme and nav, wire copy-markdown page actions, add a custom 404 and a root redirect to guides, and make the build a fully static export with trailing-slash urls
2026-06-10 18:26:55 +02:00
Matthew Meszaros
3236ffc459
feat: expand product docs and automation references
...
Restructure the docs navigation into product-focused pages, add automation expression reference content, and refresh related template and personalization surfaces.
2026-06-09 09:07:56 +02:00
Matthew Meszaros
eac99628bb
feat: enforce worker pool assignment safety
...
Reserve dedicated worker allocation for the control plane, auto-promote spare capacity when needed, and keep risky or quarantined mailboxes off clean shared workers.
2026-06-02 16:38:49 +02:00
Matthew Meszaros
3943b8a2e7
feat: update docs for postgres-backed secrets
...
Refresh developer docs, deployment notes, and public-site copy to describe the Postgres-backed encrypted key and message-map model after DynamoDB removal.
2026-06-02 15:55:01 +02:00