Commit Graph
1866 Commits
Author SHA1 Message Date
Matthew Meszaros 5f8954f4a0 Merge pull request #263 from warmbly/feature/cloud-managed-mailboxes
Cloud-managed mailboxes for linked instances: Google/Microsoft sign-in through Warmbly Cloud, brokered tokens, adopt from workspace
2026-08-29 10:14:01 -07:00
Matthew Meszaros 254e41f685 Merge remote-tracking branch 'origin/main' into feature/cloud-managed-mailboxes 2026-08-29 10:08:39 -07:00
Matthew Meszaros d5524a1863 Merge pull request #262 from warmbly/feature/self-hosted-warmup-pool-access
feat: self-hosted instances warm their mailboxes in the hosted pool (Warmbly Cloud link)
2026-08-29 10:08:18 -07:00
Matthew Meszaros 44b2c18906 feat: address review on cloud-managed mailboxes: the consumer now asks the cloud to vouch for a warmup token in a mailbox it warms (GET /pool-link/instance/mailboxes/:id/warmup-tokens/:token) and files anything unverified as ordinary mail instead of dropping on a sender-controlled header, disconnect keeps local mirrors and the link until the cloud confirms the instance is released so managed mailboxes cannot be stranded, and long narrative comments are cut to one line 2026-08-29 10:07:36 -07:00
Matthew Meszaros 1e47648208 feat: show the 'warmup cannot run with one mailbox' pool-size notice only on self-hosted instances, since a hosted workspace warms against the shared pool and one mailbox already has hundreds of partners there 2026-08-29 09:52:19 -07:00
Matthew Meszaros 2a831e9783 feat: let a linked self-hosted instance sign Google and Microsoft mailboxes in through Warmbly Cloud's own OAuth apps and send with cloud-brokered access tokens: the cloud runs the consent (pool_link_mailboxes.managed, brokered state in Redis, the existing /addresses/*/callback completes it and redirects to the instance's /cloud-oauth/done), keeps the refresh grant, mints short-lived tokens at /pool-link/instance/mailboxes/:id/token and refuses them for revoked links, removed, inactive or blocked mailboxes; the instance mirrors such mailboxes without a credential (cloud_link_mailboxes.managed), ships them to the worker as brokered so goog/msgraph init on a token source that pulls from /api/v1/internal/cloud-link/token/:id, lets the consumer ignore cloud warmup tokens for enrolled mailboxes, and can adopt mailboxes connected directly on the workspace; Add account shows the cloud path and the adoptable list, and the Warmbly Cloud guide documents the model 2026-08-29 09:50:52 -07:00
Matthew Meszaros febe5bb0d7 feat: let the /connect code input accept a pasted ABCD-EFGH code by stripping the dash and lowercase through input-otp's pasteTransformer before its alphanumeric pattern check, which was rejecting the whole paste 2026-08-29 09:19:31 -07:00
Matthew Meszaros 41d52723b6 feat: rebuild the Warmbly Cloud /connect approval page on the auth screen's sky as a three step card (code, review, linked) with the OTP slot input for the ABCD-EFGH code, the requesting instance shown as an identity card with a live instance-to-cloud diagram, workspace choice as selectable rows instead of a native select, inline unknown-code recovery, and a way back to the instance once linked 2026-08-29 09:13:46 -07:00
Matthew Meszaros 315509d0da feat: replace the purple lock card with a full-screen plan chooser on the auth screen's sky (warm 10 mailboxes free, self-host and link, or choose a plan), give the hosted Accounts page a two-path panel (connect a mailbox here, or self-host for free and link the instance) that collapses to a usage strip once mailboxes exist, drop indigo from the access dialog, describe the free plan honestly in the catalog, and default the transactional email footer to the real company details (Mindroot Ltd, 16543299, 71-75 Shelton Street) 2026-08-29 08:48:13 -07:00
Matthew Meszaros d621d9b79b feat: sign a new account in as part of registration: createAccount returns the user, both the verification-free and the code-confirm paths mint a session through finishLoginAs (2FA challenge included), /auth/register/confirm answers with that session instead of 204, and the dashboard drops into the workspace right after signing up instead of bouncing to the sign-in form 2026-08-29 08:41:34 -07:00
Matthew Meszaros 152f626469 feat: remove the free trial: a new hosted workspace starts on the free plan with no time limit, may hold up to 10 mailboxes (connected directly or through a linked self-hosted instance) and warm them in the free pool, and everything else (campaigns, inbox, contacts, CRM, integrations, API keys, audit) sits behind a Starter lock in the sidebar and a SubscriptionGate overlay until a plan is active; the pool-link allowance now counts every mailbox in the workspace, and the marketing site and guide say free workspace instead of 14-day trial 2026-08-29 08:34:22 -07:00
Matthew Meszaros c8a5da999b feat: drop the webhook step from onboarding (nobody wires a webhook on first sign-in) and make the self-hosted cloud step minimal: a two-line pitch that says it is about warmup, no button of its own, Get started requests the code and turns into Waiting for approval until the link lands, Skip for now stays 2026-08-29 08:21:46 -07:00
Matthew Meszaros b053a1ca80 feat: surface the Warmbly Cloud link where self-hosters already are: a skippable last onboarding step with the shared link card, a connect banner and dialog on the Mailboxes page, a Cloud badge plus the cloud's daily count and warm/pause/resume/remove items in each row's warmup menu, a cloud block in the mailbox drawer that replaces the local controls for enrolled mailboxes, the coverage notice pointing at the dialog instead of the marketing site, reads on /cloud-link open to any member and per-mailbox enrollment gated on manage mailboxes, and the guide updated for the new entry points 2026-08-29 08:05:11 -07:00
Matthew Meszaros 3bdb0fb82d feat: address the Greptile review on the pool link: require https for the cloud URL (loopback exempt for local development) since the instance token and mailbox passwords travel on it, remove the cloud copy when the local enrollment row cannot be written so a mailbox never warms in both places, delete the local enrollment row before the cloud one and restore it if the cloud call fails so a mailbox is never left with no warmup anywhere, and trim the new multi-line comments to the one-line style 2026-08-29 07:17:10 -07:00
Matthew Meszaros 1247c712f3 feat: add make poollink-dev, a two-instance dev environment for the Warmbly Cloud link (a prod-like cloud with DEPLOYMENT_MODE=cloud, Stripe gates on with placeholder keys, Mailpit email verification and the Sunrise Labs pool seeded, next to a fresh unclaimed self-hosted instance whose WARMBLY_CLOUD_URL points at it), with status/setup-link/down/reset subcommands and a local-development docs section 2026-08-29 07:14:04 -07:00
Matthew Meszaros b75fdcf86c Merge remote-tracking branch 'origin/main' into feature/self-hosted-warmup-pool-access
# Conflicts:
#	internal/scheduler/warmup_scheduler.go
2026-08-29 07:10:38 -07:00
Matthew Meszaros 37b60b59d3 feat: let a self-hosted instance warm its mailboxes in the hosted pool: device-code link approved at /connect, instance-token API that enrolls SMTP/IMAP mailboxes as warmup-only accounts (no history import, non-warmup mail dropped), free for 10 mailboxes and unlimited on the seeded $15 pool plan, tier fallback to proven healthy mailboxes when a pool runs thin, local warmup stands down for enrolled mailboxes, Settings > Warmbly Cloud step flow and linked-instances page, docs guide, marketing copy, and fix SetWarmupLifecycle re-reading the row with an org-scoped lookup so every warmup start/pause returned 404 2026-08-29 07:09:04 -07:00
Matthew Meszaros 89ce0c9f5a Merge pull request #261 from warmbly/fix/tracking-static-docker-context
Fix the tracking image build: static/tracking.js is not in the build context
v0.2.3
2026-08-29 06:28:59 -07:00
Matthew Meszaros 580109987d feat: copy tracking/static into the Rust image build context so the tracking service compiles again: handlers.rs serves the website tracker through include_str!("../static/tracking.js"), which is read at compile time, but the Dockerfile only copied Cargo.toml and src, so every Build and Push run since the website-visitor-tracking merge failed on both architectures with "couldn't read src/../static/tracking.js" while the CI cargo job stayed green because it builds from the full checkout 2026-08-29 06:16:33 -07:00
Matthew Meszaros 0253bd7add Merge pull request #259 from warmbly/feature/website-visitor-tracking
feat: website visitor tracking with a consent-gated snippet, abuse-controlled ingest, and page hits in the contact timeline (#255)
2026-08-29 05:23:53 -07:00
Matthew Meszaros e84d47c492 feat: drop a page hit instead of storing it under the wrong contact when tying a browser to a ticket fails after a lost identification race (attach now fails closed and the edge retries), and make the edge dedupe an atomic request-owned claim so a failed concurrent forward can only release its own entry and never a successful request's 2026-08-29 05:20:26 -07:00
Matthew Meszaros 111a5a4034 feat: read the forwarded client address from exactly one operator-named header (TRACKING_CLIENT_IP_HEADER, default x-forwarded-for with the proxy-appended last entry, cf-connecting-ip only when configured) so a client-supplied CF-Connecting-IP passed through a generic trusted proxy can no longer choose the rate-limit bucket or the stored page-hit location, with tests and the configuration, env example and compose entries 2026-08-29 05:11:22 -07:00
Matthew Meszaros 5821fc2a1c feat: merge origin/main into the website tracking branch after PR #260 landed 000106_contact_source, renumber the website tracking migration to 000107, and fold the page_hit timeline type, its query source and its Website filter, meta line and expandable details into the reworked contact Activity tab and models from the contact-activity PR 2026-08-29 04:38:35 -07:00
Matthew Meszaros 1b866a2b2b Merge pull request #260 from warmbly/feat/issue-255-contact-activity
Contact activity timeline, source attribution and per-contact campaign state (#255, PR 2 of 2)
2026-08-29 04:32:25 -07:00
Matthew Meszaros 8daefbe8c4 feat: address the Greptile review on website tracking by believing forwarded-IP headers only from TRACKING_TRUSTED_PROXIES (socket peer otherwise, proxy-appended last X-Forwarded-For entry, applied to pixel, click and page-hit paths), making IdentifyVisitor report whether it claimed the row so a lost identification race re-reads the visitor and splits onto a fresh record instead of attributing the hit to the wrong contact, forgetting the edge dedupe entry when a forward to the backend fails so the retry is counted, and trimming the new Go and Rust comments to the one-line style 2026-08-29 04:16:28 -07:00
Matthew Meszaros 9fd9e082ae feat: address Greptile on PR #260 by only linking meeting join_url values whose scheme is http or https in the contact timeline (both the meta Join link and the expanded detail), projecting the campaign's daily ramp advance in memory before the read-only next-send preview so a preview on a new UTC day budgets with the level the next scheduler pass will persist (with a unit test), and trimming the campaign-state model, preview and service comments to one-line invariants 2026-08-29 03:51:24 -07:00
Matthew Meszaros 896dc4fe3c feat: merge origin/main (campaign lead engagement filters, contact export org scoping) into the issue #255 branch, keeping both the engagement and the next-action sections of the campaigns guide 2026-08-29 03:40:13 -07:00
Matthew Meszaros fb6ba509d1 Merge pull request #257 from warmbly/feature/campaign-lead-engagement-filters
Recipient-level engagement in the campaign Leads view (issue #250)
2026-08-29 03:34:42 -07:00
Matthew Meszaros 7d33544540 feat: pass the organization id, not the user id, from ExportContacts through contactService.Export into contactRepository.ExportAll, because contact Search became organization-scoped with the issue #187 fix and every contact export since then returned only the header row, which also left the new campaign lead_* export columns with nothing to fill (issue #250) 2026-08-29 03:30:59 -07:00
Matthew Meszaros a4739b63ec feat: add first-touch contact source attribution (migration 000106: contacts.source with a CHECK, source_detail, first_seen_at, existing rows stamped unknown) stamped at every creation site (dashboard manual/campaign, file import, Google Sheets sync, API key, AI assistant), write contact_created / campaign_added / campaign_removed / category_added / category_removed lifecycle events into contact_activities inside the same transactions as the links and merge them into the contact timeline, refactor FindNextRoutedPair's routing into a campaignRouter shared with a per-contact RouteContact and split CalculateNextCampaignTime into campaignSenders + placeCampaignSend so a read-only PreviewContactSend derives a contact's next step through the scheduler's own constraints, expose it as GET /contacts/:id/campaigns behind the contact service, render a per-campaign state panel, Campaigns/Lifecycle filter chips and expandable event rows in the Activity tab plus a Source section on Overview, cover it with TestLive* for the timeline events and the next-action preview (step wait, sending window, paused), and document it in the contacts, campaigns and API reference docs (issue #255) 2026-08-29 03:28:16 -07:00
Matthew Meszaros 27630eec0a feat: add website visitor tracking for issue #255 with migration 000106 (website_tracking_settings, website_visitors, website_page_hits, all registered in the orgtransfer spec), a consent-gated dependency-free tracking.js served by the Rust tracking service with a rate-limited, size-capped, prefetch-filtered POST /p ingest that forwards to a new backend internal page-hits endpoint for server-side user-agent and GeoIP enrichment, contact identification only through the click ticket the redirect appends to registered hosts, a per-workspace retention job, page_hit events with an expandable detail view in the contact Activity timeline, a Settings > Website tracking page for the snippet and consent, location and retention configuration, realtime PAGE_HIT fanout, and a website tracking guide plus endpoint, export and configuration docs 2026-08-29 03:25:50 -07:00
Matthew Meszaros d67cdb8562 feat: add recipient-level engagement to the campaign Leads view by adding an engagement search filter (opened, not_opened, clicked, not_clicked, replied, not_replied, bounced) that composes with lead_status as AND and rejects unknown values with stable 400 codes, counting only human opens so machine opens never read as engagement, adding contacted/opened/clicked/replied_any totals to lead_counts, rendering Opened/Clicked/Replied columns and clickable server-backed status and engagement chips in the Leads table with matching Filters sheet sections, offering lead_status/lead_opened/lead_clicked/lead_replied export columns from a campaign, covering every filter value with a live Postgres test, and documenting the columns, filters, error codes and export fields (issue #250) 2026-08-29 03:12:02 -07:00
Matthew Meszaros 7eb495be8d Merge pull request #256 from warmbly/fix/issue-243-stranded-rest
feat: give a resting mailbox an exit when its warmup stops (#243)
2026-08-29 02:19:42 -07:00
Matthew Meszaros d9b4220bf0 feat: drive the resting notice in the mailbox drawer off warmup_health presence, which is the pool row the rebalancer reads, instead of warmup_status, which stays present for paused or unentitled warmup, condense the new lifecycle and drawer comments to one line, and correct the mailboxes guide so it says a rest ends without a signal only when the mailbox leaves its pool, since pausing warmup keeps it there 2026-08-29 02:09:49 -07:00
Matthew Meszaros 3552fffae1 feat: stop stranding a resting mailbox whose warmup stopped by letting lifecycle.Decide run the rest clock on an unknown health signal and resume the mailbox after the 72h window instead of re-stamping probation on every tick, make POST /emails/:id/release the manual exit from resting with its own reason, add a Put back into campaigns action and warmup-aware copy to the resting notice in the mailbox drawer, and document the automatic and manual exits in the mailboxes guide, API reference and endpoint map (issue #243) 2026-08-29 02:04:18 -07:00
Matthew Meszaros 234c6aeead Merge pull request #254 from warmbly/fix/issue-244-reserve-hold
feat: wire reserve to a real mailbox hold and drop the unreachable warming lifecycle state
2026-08-28 23:37:39 -07:00
Matthew Meszaros 5938a4af82 feat: renumber the drop-warming-lifecycle migration from 000104 to 000105 after 000104_org_risk_override reached main first, and merge origin/main into the branch so check-migrations sees one version per number again 2026-08-28 23:33:47 -07:00
Matthew Meszaros 4cee178c7a Merge remote-tracking branch 'origin/main' into fix/issue-244-reserve-hold 2026-08-28 23:33:26 -07:00
Matthew Meszaros 35e8f95f2a feat: make a release from the mailbox hold land where the rebalancer would put it by running lifecycle.Decide against the mailbox's current warmup health through a new GetLifecycleCandidate repository read, so an unhealthy mailbox goes straight to resting instead of sending cold for up to an hour before the hourly pass rests it again, report that outcome in the drawer toast and the API reference, and condense the new hold comments in the email service, backend wiring, repository, hook, client and drawer to the one-line form the repo convention asks for 2026-08-28 23:30:15 -07:00
Matthew Meszaros 3b27b32089 Merge pull request #253 from warmbly/fix/issue-241
fix: a suspended workspace can never be un-suspended
2026-08-28 23:12:42 -07:00
Matthew Meszaros 934a4868a5 feat: correct the operator docs after the class-model merge, since import quality is no longer a finding that ages out: it is a running assessment across everything a workspace has imported and withdraws itself, so the expiry paragraph now names the detectors that genuinely have no way back (a signup's origin, a run of anomalous sign-ins) and says which kind the panel's Ages out column is reporting 2026-08-28 23:08:39 -07:00
Matthew Meszaros 84700bae8d Merge remote-tracking branch 'origin/main' into fix/issue-241
# Conflicts:
#	cmd/consumer/main.go
#	docs/content/docs/guides/deliverability.mdx
#	internal/app/auth/login_risk.go
#	internal/app/auth/provision.go
#	internal/app/contact/import.go
#	internal/app/orgrisk/service.go
2026-08-28 23:06:07 -07:00
Matthew Meszaros 713faa0217 Merge pull request #251 from warmbly/fix/issue-245-resolution
Judge a workspace's posture on what it did, not on what it looks like
2026-08-28 23:00:24 -07:00
Matthew Meszaros c9693dabce Merge remote-tracking branch 'origin/main' into fix/issue-241 2026-08-28 22:51:44 -07:00
Matthew Meszaros 6bb2a3d0c2 Merge remote-tracking branch 'origin/main' into fix/issue-245-resolution 2026-08-28 22:51:37 -07:00
Matthew Meszaros 4ead1b200f feat: answer the review on #251 by filing a signup's throwaway-domain finding separately from its soft ones so the aggregate score no longer carries one class, and by measuring import quality across everything a workspace has imported instead of the newest file, so a small clean upload cannot retract a large bad list whose addresses are still stored while the finding still fades as good data outweighs it, with the running counts kept as evidence on the finding and a finding filed before those counts existed folded in as the smallest list that could have flagged it 2026-08-28 22:51:23 -07:00
Matthew Meszaros 4c2f5f87be Merge pull request #252 from warmbly/fix/issue-143-investigation
feat: fix two defects in the per-provider warmup placement signal and cover its routing feedback end to end
2026-08-28 22:50:17 -07:00
Matthew Meszaros 5c832461b0 feat: wire the unreachable reserve send-lifecycle state to a real per-mailbox hold (POST /emails/:id/hold and /release behind manage_emails and WRITE_EMAILS, SetSendHold on the email service forcing the lifecycle past the rebalancer guard, a Hold from campaigns toggle on the mailbox drawer's Overview tab with the reserve notice rewritten to point at it, warmblyctl mailbox hold/release, and docs in the mailboxes guide, API reference and scope map), and drop the warming state nothing ever set from the model, the web type, the docs table and the DB check via migration 000104, which folds any legacy warming row back to active 2026-08-28 22:47:31 -07:00
Matthew Meszaros 0ab947dc5d Merge remote-tracking branch 'origin/main' into fix/issue-241 2026-08-28 22:47:28 -07:00
Matthew Meszaros 2fd22cafd3 feat: answer 404 rather than 500 when a risk mutation names an organization that does not exist, by having every org-risk repository path return nil for a missing row and one resolved() helper turn that into the not-found the GET already gave, and stop showing an admin who holds only view_organizations the Set posture, Lift override and retract controls, which the backend can only ever answer 403, so the Abuse posture panel reads as evidence for them and as evidence plus actions for an admin who can actually act 2026-08-28 22:47:24 -07:00