Matthew Meszaros
49b01c6b67
feat: version the public API under /v1 by mounting the customer surface under both /v1 and the bare paths, adding an API-Version response header and Deprecation/Sunset headers nudging API-key callers off the unversioned aliases
2026-06-13 06:27:01 +02:00
Matthew Meszaros
71abb12a38
feat: stop campaigns silently stalling on a transient scheduler error by retrying instead of completing the task, end past-end-date campaigns cleanly, record scheduler failures to the campaign log, add a campaign-chain reconciler, and surface failures live in the dashboard activity panel
2026-06-13 06:27:01 +02:00
Matthew Meszaros
919af47d29
feat: select the realtime transport by PUBSUB_ENABLED in backend/consumer and auto-provision the Pub/Sub topics and per-topic subscriptions on boot so prod never publishes to a subscription the Elixir fanout never created
2026-06-13 06:26:48 +02:00
Matthew Meszaros
c5911fe37a
feat: fire run_automation on campaign instant branches (reply/open/click) through a wired AutomationRunner instead of stamping the action node sent without ever running the flow
2026-06-13 06:26:48 +02:00
Matthew Meszaros
ba89a932cd
feat: run the label_email action on reply — campaign instant and scheduled paths via advanced LabelThread/LabelLatestThreadForContact, automations via execNativeAction reading thread_id and _user_id from the reply payload — and move the native-actions adapter to a shared package wired into the consumer too so reply/bounce/warmup automation actions stop silently failing
2026-06-12 16:44:16 +02:00
Matthew Meszaros
4762256c49
feat: add the warmbly.label_email native action type and the label_ids action config field across the campaign ActionConfig and the IntegrationAction enum + IsNativeAction
2026-06-12 16:44:07 +02:00
Matthew Meszaros
496e474756
feat: add additive unibox thread-label repo methods — AddThreadLabels (insert-only, category-ownership guarded) and LatestThreadIDForContact (exact from_addr address match, never an ILIKE substring) — to back a reply-only label-email action
2026-06-12 16:44:07 +02:00
Matthew Meszaros
a7a43e0c4c
feat: rename the campaign sequences resource to steps across the API and URL (/campaigns/:id/steps), the JSON fields (target_step_id, step_id/step_name/step_index, analytics steps[], create body steps), the web client/models/route segment/labels, the audit step entity type, and the wire-contract docs; internal Go type names and the Kafka avro schema stay
2026-06-12 09:38:11 +02:00
Matthew Meszaros
8de7e32857
feat: treat a campaign step's own email as the A/B control arm so contacts split across the original plus active variants by weight, and redesign the step variants editor to show the original and variants as one weighted set with live split percentages
2026-06-12 08:04:03 +02:00
Matthew Meszaros
0fd3d03f55
feat: add org-wide team presence privacy columns (presence_show_online, presence_show_activity) with update plumbing and a PRESENCE_POLICY_UPDATED realtime event so a settings change re-gates connected sockets live
2026-06-12 05:59:01 +02:00
Matthew Meszaros
8547fe97eb
feat: scope unibox MarkSeenBulk by organization so a non-owner member opening a thread clears the shared org-wide unread state instead of updating zero rows
2026-06-12 05:14:50 +02:00
Matthew Meszaros
4db027a342
feat: scope unibox GetByThread by organization instead of user_id so non-owner members see the full conversation they already see in the org-scoped inbox list, not an empty thread
2026-06-12 05:10:00 +02:00
Matthew Meszaros
ba3ab98e1e
feat: bridge realtime events over Redis pub/sub when Google Pub/Sub is unconfigured (RedisBus publisher in backend/consumer plus Realtime.Redis.EventSubscriber and a shared EventBroadcaster) so dashboard live updates and presence-driven collaboration actually fire in local dev
2026-06-12 04:49:58 +02:00
Matthew Meszaros
21b4ba4ea0
fix: let members with the integration permission save automations (write was gated on manage-settings while read used use-integrations, so a manager could open the builder but 403 on save) and surface the backend's real error in the save toast instead of a generic message
2026-06-11 18:15:55 +02:00
Matthew Meszaros
6a3b8ac0eb
fix: scope the unibox unread-count endpoint by organization_id so the sidebar Inbox badge counts the workspace's unread mail instead of always showing 0 for non-owner members
2026-06-11 18:05:18 +02:00
Matthew Meszaros
594c696bf6
fix: scope the unibox inbox list and overview by organization_id (via the workspace's email accounts) instead of the logged-in user_id, so every member sees the org's incoming mail; per-user thread labels and snoozes stay personal
2026-06-11 17:57:52 +02:00
Matthew Meszaros
21032a8fce
fix: scope the contacts list by organization_id instead of user_id so all members see the workspace's contacts (and per-contact campaign badges); categories badge still user-scoped pending an organization_id column on categories
2026-06-11 17:52:36 +02:00
Matthew Meszaros
88e241d536
fix: scope the analytics dashboard (overall stats, recent activity, top campaigns, daily trend, account health) by organization_id instead of user_id, so every workspace member sees the org's analytics rather than an empty dashboard
2026-06-11 17:49:39 +02:00
Matthew Meszaros
a21dc57e07
fix: scope campaign list/detail/count queries by organization_id instead of user_id, so all workspace members see the org's campaigns rather than only the creator
2026-06-11 17:47:04 +02:00
Matthew Meszaros
6ae5e52c4e
fix: scope email-account list/detail queries by organization_id instead of the logged-in user_id, so every member of a workspace sees the org's mailboxes (not just the owner who connected them)
2026-06-11 17:43:56 +02:00
Matthew Meszaros
709b77cdc6
fix: notification email links use the configured APP_URL instead of a hardcoded app.warmbly.com, so dev and self-hosted deployments link to the right host
2026-06-11 12:43:17 +02:00
Matthew Meszaros
3c6de16321
fix: forgotten-password reset now revokes all existing sessions, so a reset done because access was lost or compromised fully cuts off prior devices
2026-06-11 12:41:55 +02:00
Matthew Meszaros
f209eca9ad
fix: Slack notification delivery now resolves a real channel (connection config, then the org's configured Slack automation channel) instead of an always-empty connect-time field that silently dropped every message; docs and UI corrected to match
2026-06-11 12:40:31 +02:00
Matthew Meszaros
3c040649c0
fix: changing your password now revokes every other session (keeping the current device), matching the security promise in the sign-in alert and docs
2026-06-11 12:39:24 +02:00
Matthew Meszaros
2d53f4f819
fix: rate-limit POST /me/password so a hijacked session can't brute-force the current password unthrottled
2026-06-11 12:38:07 +02:00
Matthew Meszaros
5bcc2baaa8
feat: implement the coming-soon security features — logged-in change-password (verify current, policy-checked, POST /me/password) with a real dialog, and new-device sign-in alerts (security notification category fired from the token service on an unrecognized OS+browser, delivered in-app and by email), removing the comingSoon stub helper and updating docs
2026-06-11 12:30:44 +02:00
Matthew Meszaros
160dc0bc76
feat: implement the coming-soon notification delivery channels — Email (SES/SMTP to the account email) and Slack (posts to the org's connected workspace via a new integration NotifySlack), wired in both backend and consumer with per-channel gating, real toggles replacing the coming-soon labels, and updated docs
2026-06-11 12:21:48 +02:00
Matthew Meszaros
39a9752d63
feat: real tokenized invite-accept link — public /invite landing page with safe preview (org, inviter, roles), accept-by-token plus the previously-broken accept-by-invitation-id, public preview + admin copy-link endpoints, login next-param redirect, and a Copy button that yields a working /invite?token link
2026-06-11 11:57:45 +02:00
Matthew Meszaros
19f66507b4
feat: fix multi-role review findings — atomic member+roles insert on invite accept (no partial-failure stranding), gate role deletion on the actor holding the role's permissions (blocks team-managers de-privileging admins), and hydrate+chip pending-invitation role sets
2026-06-11 11:32:57 +02:00
Matthew Meszaros
8540f7db15
feat: members can hold multiple roles — join tables for member/invitation role sets (migration 000044) with effective permissions as the bitwise OR recomputed on every assignment and role edit/delete, role_ids in invite/update APIs, multi-select checkbox role picker with colored chips in roster and invite flow, freely deletable roles
2026-06-11 11:24:19 +02:00
Matthew Meszaros
3473d09bcc
feat: fix review findings in the roles redesign — GetMembers role_id column (members endpoint 500), TransferOwnership role_id hygiene, accept-time role re-resolution, race-free in-use delete guard covering invitations, assignment anti-escalation with self-role-change block, canManage-gated members UI, colored RolePills, fresh currentOrganization on refetch, dev JWT_SECRET wiring for make realtime, docs corrections
2026-06-11 10:45:21 +02:00
Matthew Meszaros
091b39f34e
feat: roles become workspace data — seed editable Admin/Manager/Viewer rows per org (migration 000043 with member backfill), require role_id for invites and role changes, add role colors with a shared colored RoleSelect dropdown in the roster and invite flow, and rebuild Roles & access around real roles with an Owner reference column
2026-06-11 10:18:45 +02:00
Matthew Meszaros
edd4524007
feat: custom organization roles backend (organization_roles table with write-through member propagation, CRUD endpoints with anti-escalation and in-use guards, custom-role invites and assignment via role_id, audited as role entity)
2026-06-11 09:39:52 +02:00
Matthew Meszaros
8732805934
feat: replace signed click redirects with server-side link tickets (tracked_links store, internal resolver API, opaque /c/<id> URLs, layered anti-probe caches with miss budget and circuit breaker) removing TRACKING_LINK_SECRET entirely
2026-06-11 09:30:21 +02:00
Matthew Meszaros
2c5e8b2cbd
feat: make TRACKING_LINK_SECRET a required boot-time secret on backend and tracking service with no unsigned mode and no rotation grace, so rotating the key revokes old links immediately
2026-06-11 09:00:04 +02:00
Matthew Meszaros
014cbe79fa
feat: label machine opens (Apple MPP prefetch, UA-less fetchers) with human-open upgrade semantics, exclude them from open-triggered automations, and surface the auto-open count in workspace and campaign analytics (migration 000040)
2026-06-11 08:33:09 +02:00
Matthew Meszaros
8b9277dabf
feat: harden tracking service against abuse with per-IP rate limiting, prefetch/scanner filtering, URL length caps, and HMAC-signed click redirects (TRACKING_LINK_SECRET) closing the open-redirect hole
2026-06-11 08:11:05 +02:00
Matthew Meszaros
fe96eff7b4
feat: audit-log coverage for teams, automations (typed entity), lead-sync sources, and manual meetings so the org activity trail and its realtime spine see every mutation
2026-06-11 07:47:29 +02:00
Matthew Meszaros
abdfd05c34
feat: org-scope realtime events (inbox, campaign, tracking, account health) and emit EMAIL_SENT/EMAIL_REPLIED/EMAIL_DELETED pulses so the whole team's dashboard updates live
2026-06-11 07:43:57 +02:00
Matthew Meszaros
bd7db069ba
Merge origin/main into feature/integrations-3, resolving doc conflicts by accepting the docs-restructure deletions
2026-06-10 18:56:47 +02:00
Matthew Meszaros
14a535701e
feat: fix grammar in the forbidden api error message returned by the backend
2026-06-10 18:27:42 +02:00
Matthew Meszaros
03134317ca
feat: seal integration tokens and config with the organization DEK
...
OAuth access/refresh tokens and pasted credential configs are sealed
and opened with the connection's OrganizationID instead of
ConnectedByUserID, which is now attribution-only. An org's CRM and
Slack connections keep working when the user who connected them is
removed from the organization.
2026-06-10 17:17:03 +02:00
Matthew Meszaros
ae0c433084
feat: seal mailbox validation credentials with the organization DEK
...
SMTP/IMAP passwords on the validation round-trip are now encrypted and
decrypted under the organization DEK, carried as OrgID on
EventWorkerEmailValidation. Onboarding requires an organization before
a mailbox can be validated.
This fixes a latent key mismatch: the payload never set UserID, so the
worker decrypted with the zero-UUID platform key while the backend had
encrypted with the user key.
2026-06-10 17:16:56 +02:00
Matthew Meszaros
ac3c11bf9a
feat: seal outbound email content with the organization DEK
...
The send pipeline (publisher subject/body encryption, the S3 emsg blob,
and the worker-side decrypt) now keys off models.SendEmail.OrgID
instead of UserID. EmailMessage loses its UserID field entirely:
emailSender.Send derives the cipher identity from the email account's
OrganizationID and refuses to send for an account without one.
This also fixes two latent bugs. Emails sent through user_email_task
never set UserID, so they were silently encrypted under the zero-UUID
platform key. campaign_task's discarded Encrypt() pair is replaced with
an explicit DEK warm that fails fast when KMS is unavailable.
2026-06-10 17:16:42 +02:00
Matthew Meszaros
b9a5871308
feat: key the cipher service by organization ID
...
cipher.CipherService.Cipher(ctx, orgID) now resolves, generates, and
caches DEKs per organization (Redis key decrypted_key:<orgID>).
Platform-level secrets keep the zero-UUID identity, renamed to
platformCipherID since it no longer partitions against user keys.
2026-06-10 17:16:26 +02:00
Matthew Meszaros
a6acb97dea
feat: key the worker-facing internal DEK endpoint by organization
...
The /api/v1/internal/dek route parameter is now :orgID to match the
org-scoped encryptedkeys store. Workers fetch the organization DEK for
the account they are operating on instead of a user DEK.
2026-06-10 17:16:07 +02:00
Matthew Meszaros
c800081987
feat: store envelope-encryption DEKs per organization
...
Mailboxes, integration tokens, and message content are organization
assets. Keying their DEK by the connecting user meant offboarding that
user made every ciphertext they created unreadable.
Migration 000039 drops user_encrypted_keys and creates
organization_encrypted_keys keyed by organization_id. The new table has
no FK on purpose: platform secrets live under the zero UUID (no
organizations row), and DEK rows must never cascade-delete because a
lost DEK is unrecoverable.
Pre-production, so there is no data migration; ciphertexts sealed under
the old per-user DEKs are abandoned with the table.
2026-06-10 17:15:47 +02:00
Matthew Meszaros
5954ac53c2
feat: add automation execution safeguards
...
Support chained automation execution from native actions, guard automation recursion depth, carry idempotency context through campaign-launched automations, allow team task assignment in backend action execution, and reject deletes while campaign steps still reference an automation.
2026-06-09 10:56:56 +02:00
Matthew Meszaros
3236ffc459
feat: expand product docs and automation references
...
Restructure the docs navigation into product-focused pages, add automation expression reference content, and refresh related template and personalization surfaces.
2026-06-09 09:07:56 +02:00
Matthew Meszaros
3eb96e33a1
feat: support automation expressions
...
Adds free-form expression conditions for automation graph branches and shares template helper functions with automation action rendering.
2026-06-08 15:04:59 +02:00