Matthew Meszaros
|
e58921484d
|
feat: rebuild mailbox import around column mapping and automatic host and sign-in detection (CSV, XLSX, pasted lists, saved mappings, retryable rows with fixes, migrations 000205-000206), connect whole Google Workspace domains and Microsoft 365 organizations through a proved administrator grant, import from inbox vendors (InboxKit, Zapmail, Mailforge, Infraforge, Maildoso, Cheap Inboxes, ScaledMail) with vendor-managed forwarding and DNS, add a sending domains page with per-domain tracking and verified root redirects, unify Add account into one Google and one Microsoft entry with per-method choices, mark per-mailbox Google sign-in as retiring with in-place moves to the admin grant or an app password, allow the loopback security mode in the credential columns (migration 000207), read semicolon-separated CSVs, and add a mock vendor API to the sandbox
|
2026-09-23 08:41:01 -07:00 |
|
Matthew Meszaros
|
e668a2a36b
|
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
|
2026-09-19 08:18:35 +02:00 |
|
Matthew Meszaros
|
bbe9d9055a
|
feat: let web and admin be served from a static host by teaching each app's own entrypoint to render config.js wherever WARMBLY_CONFIG_OUT points, so one definition of the runtime key set serves both the container that renders it at start and a build:pages script that renders it into dist, ship a _redirects in each so a deep link stops 404ing without nginx try_files, and add scripts/check-pages-build.sh to make lint because a malformed config.js reads fine in a diff and leaves the app blank at runtime
|
2026-09-10 18:03:00 +02:00 |
|
Matthew Meszaros
|
9a67008ea2
|
feat: add a runtime config shim to the dashboard so a single built image reads its API url, app url, tracking domain, and turnstile key from container env via /config.js
|
2026-07-22 18:40:06 +02:00 |
|
Matthew Meszaros
|
a1c9a898b5
|
feat: refresh app favicon assets
|
2026-06-04 08:55:31 +02:00 |
|
Matthew Meszaros
|
6766031cc5
|
feat: add discount code support for checkout and plan changes
|
2026-05-29 05:49:19 +00:00 |
|
Máté Mészáros (Laptop)
|
c06e84e3f2
|
Dashboard with shadcn, tailwind, zustand & react-query
|
2026-01-30 08:47:26 +01:00 |
|