Commit Graph
332 Commits
Author SHA1 Message Date
Matthew Meszaros 49b01c6b67 feat: version the public API under /v1 by mounting the customer surface under both /v1 and the bare paths, adding an API-Version response header and Deprecation/Sunset headers nudging API-key callers off the unversioned aliases 2026-06-13 06:27:01 +02:00
Matthew Meszaros 71abb12a38 feat: stop campaigns silently stalling on a transient scheduler error by retrying instead of completing the task, end past-end-date campaigns cleanly, record scheduler failures to the campaign log, add a campaign-chain reconciler, and surface failures live in the dashboard activity panel 2026-06-13 06:27:01 +02:00
Matthew Meszaros 919af47d29 feat: select the realtime transport by PUBSUB_ENABLED in backend/consumer and auto-provision the Pub/Sub topics and per-topic subscriptions on boot so prod never publishes to a subscription the Elixir fanout never created 2026-06-13 06:26:48 +02:00
Matthew Meszaros c5911fe37a feat: fire run_automation on campaign instant branches (reply/open/click) through a wired AutomationRunner instead of stamping the action node sent without ever running the flow 2026-06-13 06:26:48 +02:00
Matthew Meszaros ba89a932cd feat: run the label_email action on reply — campaign instant and scheduled paths via advanced LabelThread/LabelLatestThreadForContact, automations via execNativeAction reading thread_id and _user_id from the reply payload — and move the native-actions adapter to a shared package wired into the consumer too so reply/bounce/warmup automation actions stop silently failing 2026-06-12 16:44:16 +02:00
Matthew Meszaros 4762256c49 feat: add the warmbly.label_email native action type and the label_ids action config field across the campaign ActionConfig and the IntegrationAction enum + IsNativeAction 2026-06-12 16:44:07 +02:00
Matthew Meszaros 496e474756 feat: add additive unibox thread-label repo methods — AddThreadLabels (insert-only, category-ownership guarded) and LatestThreadIDForContact (exact from_addr address match, never an ILIKE substring) — to back a reply-only label-email action 2026-06-12 16:44:07 +02:00
Matthew Meszaros a7a43e0c4c feat: rename the campaign sequences resource to steps across the API and URL (/campaigns/:id/steps), the JSON fields (target_step_id, step_id/step_name/step_index, analytics steps[], create body steps), the web client/models/route segment/labels, the audit step entity type, and the wire-contract docs; internal Go type names and the Kafka avro schema stay 2026-06-12 09:38:11 +02:00
Matthew Meszaros 8de7e32857 feat: treat a campaign step's own email as the A/B control arm so contacts split across the original plus active variants by weight, and redesign the step variants editor to show the original and variants as one weighted set with live split percentages 2026-06-12 08:04:03 +02:00
Matthew Meszaros 0fd3d03f55 feat: add org-wide team presence privacy columns (presence_show_online, presence_show_activity) with update plumbing and a PRESENCE_POLICY_UPDATED realtime event so a settings change re-gates connected sockets live 2026-06-12 05:59:01 +02:00
Matthew Meszaros 8547fe97eb feat: scope unibox MarkSeenBulk by organization so a non-owner member opening a thread clears the shared org-wide unread state instead of updating zero rows 2026-06-12 05:14:50 +02:00
Matthew Meszaros 4db027a342 feat: scope unibox GetByThread by organization instead of user_id so non-owner members see the full conversation they already see in the org-scoped inbox list, not an empty thread 2026-06-12 05:10:00 +02:00
Matthew Meszaros ba3ab98e1e feat: bridge realtime events over Redis pub/sub when Google Pub/Sub is unconfigured (RedisBus publisher in backend/consumer plus Realtime.Redis.EventSubscriber and a shared EventBroadcaster) so dashboard live updates and presence-driven collaboration actually fire in local dev 2026-06-12 04:49:58 +02:00
Matthew Meszaros 21b4ba4ea0 fix: let members with the integration permission save automations (write was gated on manage-settings while read used use-integrations, so a manager could open the builder but 403 on save) and surface the backend's real error in the save toast instead of a generic message 2026-06-11 18:15:55 +02:00
Matthew Meszaros 6a3b8ac0eb fix: scope the unibox unread-count endpoint by organization_id so the sidebar Inbox badge counts the workspace's unread mail instead of always showing 0 for non-owner members 2026-06-11 18:05:18 +02:00
Matthew Meszaros 594c696bf6 fix: scope the unibox inbox list and overview by organization_id (via the workspace's email accounts) instead of the logged-in user_id, so every member sees the org's incoming mail; per-user thread labels and snoozes stay personal 2026-06-11 17:57:52 +02:00
Matthew Meszaros 21032a8fce fix: scope the contacts list by organization_id instead of user_id so all members see the workspace's contacts (and per-contact campaign badges); categories badge still user-scoped pending an organization_id column on categories 2026-06-11 17:52:36 +02:00
Matthew Meszaros 88e241d536 fix: scope the analytics dashboard (overall stats, recent activity, top campaigns, daily trend, account health) by organization_id instead of user_id, so every workspace member sees the org's analytics rather than an empty dashboard 2026-06-11 17:49:39 +02:00
Matthew Meszaros a21dc57e07 fix: scope campaign list/detail/count queries by organization_id instead of user_id, so all workspace members see the org's campaigns rather than only the creator 2026-06-11 17:47:04 +02:00
Matthew Meszaros 6ae5e52c4e fix: scope email-account list/detail queries by organization_id instead of the logged-in user_id, so every member of a workspace sees the org's mailboxes (not just the owner who connected them) 2026-06-11 17:43:56 +02:00
Matthew Meszaros 709b77cdc6 fix: notification email links use the configured APP_URL instead of a hardcoded app.warmbly.com, so dev and self-hosted deployments link to the right host 2026-06-11 12:43:17 +02:00
Matthew Meszaros 3c6de16321 fix: forgotten-password reset now revokes all existing sessions, so a reset done because access was lost or compromised fully cuts off prior devices 2026-06-11 12:41:55 +02:00
Matthew Meszaros f209eca9ad fix: Slack notification delivery now resolves a real channel (connection config, then the org's configured Slack automation channel) instead of an always-empty connect-time field that silently dropped every message; docs and UI corrected to match 2026-06-11 12:40:31 +02:00
Matthew Meszaros 3c040649c0 fix: changing your password now revokes every other session (keeping the current device), matching the security promise in the sign-in alert and docs 2026-06-11 12:39:24 +02:00
Matthew Meszaros 2d53f4f819 fix: rate-limit POST /me/password so a hijacked session can't brute-force the current password unthrottled 2026-06-11 12:38:07 +02:00
Matthew Meszaros 5bcc2baaa8 feat: implement the coming-soon security features — logged-in change-password (verify current, policy-checked, POST /me/password) with a real dialog, and new-device sign-in alerts (security notification category fired from the token service on an unrecognized OS+browser, delivered in-app and by email), removing the comingSoon stub helper and updating docs 2026-06-11 12:30:44 +02:00
Matthew Meszaros 160dc0bc76 feat: implement the coming-soon notification delivery channels — Email (SES/SMTP to the account email) and Slack (posts to the org's connected workspace via a new integration NotifySlack), wired in both backend and consumer with per-channel gating, real toggles replacing the coming-soon labels, and updated docs 2026-06-11 12:21:48 +02:00
Matthew Meszaros 39a9752d63 feat: real tokenized invite-accept link — public /invite landing page with safe preview (org, inviter, roles), accept-by-token plus the previously-broken accept-by-invitation-id, public preview + admin copy-link endpoints, login next-param redirect, and a Copy button that yields a working /invite?token link 2026-06-11 11:57:45 +02:00
Matthew Meszaros 19f66507b4 feat: fix multi-role review findings — atomic member+roles insert on invite accept (no partial-failure stranding), gate role deletion on the actor holding the role's permissions (blocks team-managers de-privileging admins), and hydrate+chip pending-invitation role sets 2026-06-11 11:32:57 +02:00
Matthew Meszaros 8540f7db15 feat: members can hold multiple roles — join tables for member/invitation role sets (migration 000044) with effective permissions as the bitwise OR recomputed on every assignment and role edit/delete, role_ids in invite/update APIs, multi-select checkbox role picker with colored chips in roster and invite flow, freely deletable roles 2026-06-11 11:24:19 +02:00
Matthew Meszaros 3473d09bcc feat: fix review findings in the roles redesign — GetMembers role_id column (members endpoint 500), TransferOwnership role_id hygiene, accept-time role re-resolution, race-free in-use delete guard covering invitations, assignment anti-escalation with self-role-change block, canManage-gated members UI, colored RolePills, fresh currentOrganization on refetch, dev JWT_SECRET wiring for make realtime, docs corrections 2026-06-11 10:45:21 +02:00
Matthew Meszaros 091b39f34e feat: roles become workspace data — seed editable Admin/Manager/Viewer rows per org (migration 000043 with member backfill), require role_id for invites and role changes, add role colors with a shared colored RoleSelect dropdown in the roster and invite flow, and rebuild Roles & access around real roles with an Owner reference column 2026-06-11 10:18:45 +02:00
Matthew Meszaros edd4524007 feat: custom organization roles backend (organization_roles table with write-through member propagation, CRUD endpoints with anti-escalation and in-use guards, custom-role invites and assignment via role_id, audited as role entity) 2026-06-11 09:39:52 +02:00
Matthew Meszaros 8732805934 feat: replace signed click redirects with server-side link tickets (tracked_links store, internal resolver API, opaque /c/<id> URLs, layered anti-probe caches with miss budget and circuit breaker) removing TRACKING_LINK_SECRET entirely 2026-06-11 09:30:21 +02:00
Matthew Meszaros 2c5e8b2cbd feat: make TRACKING_LINK_SECRET a required boot-time secret on backend and tracking service with no unsigned mode and no rotation grace, so rotating the key revokes old links immediately 2026-06-11 09:00:04 +02:00
Matthew Meszaros 014cbe79fa feat: label machine opens (Apple MPP prefetch, UA-less fetchers) with human-open upgrade semantics, exclude them from open-triggered automations, and surface the auto-open count in workspace and campaign analytics (migration 000040) 2026-06-11 08:33:09 +02:00
Matthew Meszaros 8b9277dabf feat: harden tracking service against abuse with per-IP rate limiting, prefetch/scanner filtering, URL length caps, and HMAC-signed click redirects (TRACKING_LINK_SECRET) closing the open-redirect hole 2026-06-11 08:11:05 +02:00
Matthew Meszaros fe96eff7b4 feat: audit-log coverage for teams, automations (typed entity), lead-sync sources, and manual meetings so the org activity trail and its realtime spine see every mutation 2026-06-11 07:47:29 +02:00
Matthew Meszaros abdfd05c34 feat: org-scope realtime events (inbox, campaign, tracking, account health) and emit EMAIL_SENT/EMAIL_REPLIED/EMAIL_DELETED pulses so the whole team's dashboard updates live 2026-06-11 07:43:57 +02:00
Matthew Meszaros bd7db069ba Merge origin/main into feature/integrations-3, resolving doc conflicts by accepting the docs-restructure deletions 2026-06-10 18:56:47 +02:00
Matthew Meszaros 14a535701e feat: fix grammar in the forbidden api error message returned by the backend 2026-06-10 18:27:42 +02:00
Matthew Meszaros 03134317ca feat: seal integration tokens and config with the organization DEK
OAuth access/refresh tokens and pasted credential configs are sealed
and opened with the connection's OrganizationID instead of
ConnectedByUserID, which is now attribution-only. An org's CRM and
Slack connections keep working when the user who connected them is
removed from the organization.
2026-06-10 17:17:03 +02:00
Matthew Meszaros ae0c433084 feat: seal mailbox validation credentials with the organization DEK
SMTP/IMAP passwords on the validation round-trip are now encrypted and
decrypted under the organization DEK, carried as OrgID on
EventWorkerEmailValidation. Onboarding requires an organization before
a mailbox can be validated.

This fixes a latent key mismatch: the payload never set UserID, so the
worker decrypted with the zero-UUID platform key while the backend had
encrypted with the user key.
2026-06-10 17:16:56 +02:00
Matthew Meszaros ac3c11bf9a feat: seal outbound email content with the organization DEK
The send pipeline (publisher subject/body encryption, the S3 emsg blob,
and the worker-side decrypt) now keys off models.SendEmail.OrgID
instead of UserID. EmailMessage loses its UserID field entirely:
emailSender.Send derives the cipher identity from the email account's
OrganizationID and refuses to send for an account without one.

This also fixes two latent bugs. Emails sent through user_email_task
never set UserID, so they were silently encrypted under the zero-UUID
platform key. campaign_task's discarded Encrypt() pair is replaced with
an explicit DEK warm that fails fast when KMS is unavailable.
2026-06-10 17:16:42 +02:00
Matthew Meszaros b9a5871308 feat: key the cipher service by organization ID
cipher.CipherService.Cipher(ctx, orgID) now resolves, generates, and
caches DEKs per organization (Redis key decrypted_key:<orgID>).
Platform-level secrets keep the zero-UUID identity, renamed to
platformCipherID since it no longer partitions against user keys.
2026-06-10 17:16:26 +02:00
Matthew Meszaros a6acb97dea feat: key the worker-facing internal DEK endpoint by organization
The /api/v1/internal/dek route parameter is now :orgID to match the
org-scoped encryptedkeys store. Workers fetch the organization DEK for
the account they are operating on instead of a user DEK.
2026-06-10 17:16:07 +02:00
Matthew Meszaros c800081987 feat: store envelope-encryption DEKs per organization
Mailboxes, integration tokens, and message content are organization
assets. Keying their DEK by the connecting user meant offboarding that
user made every ciphertext they created unreadable.

Migration 000039 drops user_encrypted_keys and creates
organization_encrypted_keys keyed by organization_id. The new table has
no FK on purpose: platform secrets live under the zero UUID (no
organizations row), and DEK rows must never cascade-delete because a
lost DEK is unrecoverable.

Pre-production, so there is no data migration; ciphertexts sealed under
the old per-user DEKs are abandoned with the table.
2026-06-10 17:15:47 +02:00
Matthew Meszaros 5954ac53c2 feat: add automation execution safeguards
Support chained automation execution from native actions, guard automation recursion depth, carry idempotency context through campaign-launched automations, allow team task assignment in backend action execution, and reject deletes while campaign steps still reference an automation.
2026-06-09 10:56:56 +02:00
Matthew Meszaros 3236ffc459 feat: expand product docs and automation references
Restructure the docs navigation into product-focused pages, add automation expression reference content, and refresh related template and personalization surfaces.
2026-06-09 09:07:56 +02:00
Matthew Meszaros 3eb96e33a1 feat: support automation expressions
Adds free-form expression conditions for automation graph branches and shares template helper functions with automation action rendering.
2026-06-08 15:04:59 +02:00