Commit Graph
819 Commits
Author SHA1 Message Date
SUMAN JANA 260898bf20 feat(inbox): automatic tagging and relevance scoring for inbound mail, optional and off by default 2026-09-17 04:57:24 -07:00
Matthew Meszaros ae1a324801 Merge pull request #562 from rocker1166/feat/direct-mail-analytics
feat: add accurate direct-mail analytics and opt-in engagement tracking
2026-09-17 11:47:50 +00:00
Matthew Meszaros 93a0e39371 Merge pull request #568 from warmbly/fix/reported-issue-resolution
feat: preserve binary dashboard API responses so campaign lead exports remain downloadable
2026-09-17 11:28:29 +00:00
Matthew Meszaros 8745dd988d feat: correct direct-mail analytics attribution and publish live engagement updates 2026-09-17 04:27:00 -07:00
Matthew Meszaros 7402898c0d feat: preserve binary dashboard API responses so campaign lead exports remain downloadable (#565) 2026-09-17 04:24:52 -07:00
Matthew Meszaros cc5925fe44 feat: preserve web-search operators and escape participant patterns in unibox search 2026-09-17 04:18:08 -07:00
SUMAN JANA 2134c7a143 feat(analytics): report on mail written by hand, with opt-in open and click tracking per mailbox 2026-09-17 10:26:25 +00:00
SUMAN JANA ebbe432d2c feat(unibox): search people and partial words, and offer to widen a search that found nothing in the current scope 2026-09-17 10:20:17 +00:00
Matthew Meszaros 0f5ca71155 feat: correct mailbox sending metrics and workspace analytics across dashboard surfaces 2026-09-16 21:44:42 -07:00
Matthew Meszaros be78d46e28 feat: hide the self-host nudge on the hosted Accounts page for subscribed workspaces and offer subscribing alongside self-hosting on free ones in CloudPathsPanel 2026-09-16 19:53:35 +02:00
Matthew Meszaros 0334d2c64a feat: prevent ResizeObserver feedback warnings from reaching PostHog and scope worker outage alerts per workspace on shared cloud workers 2026-09-16 17:42:38 +02:00
Matthew Meszaros 6872ebbb23 feat: fix dashboard Stripe checkout, portal eligibility, webhook recovery and audit rendering 2026-09-16 15:23:17 +02:00
Suman Jana 94c7e414e2 feat: preserve private Unibox reply drafts and safely collapse quoted conversation history 2026-09-16 04:35:53 -07:00
Matthew Meszaros f72d1f8d5c feat: prevent sender views from tracking opens and keep sent messages out of the default Inbox (#542) 2026-09-16 03:42:58 -07:00
Matthew Meszaros 16df37d97b fix: stop the unibox reply composer wiping what you are typing (#534)
* feat: stop the unibox reply composer clearing what is being typed, by resetting only on a restore seed instead of on values derived from replyTo, which the thread rebuilds on every render, so any realtime invalidation while a thread was open wiped the draft between keystrokes and a reply could not be written at all

* feat: drop the stray blank line left where the per-render messages build used to sit in ThreadView
2026-09-15 09:41:54 -07:00
Matthew Meszaros ae012dd13f Clear the live error-tracking issues, and the workspace rename that renamed the wrong workspace (#533)
* feat: stop a managed Kafka cluster refusing topic creation from failing the publish, by treating a topic- or cluster-authorization failure from CreateTopics as a topic the cluster owns rather than one that is missing, which on Confluent Cloud dropped every warmup event and filed one issue per message because the topic never became known

* feat: drop a report whose error is a cancelled context in errs rather than at ninety call sites, so a browser navigating away or a container draining on deploy stops filing one issue per query that happened to be in flight, while a deadline this process set and blew through still reports

* feat: stop renaming one workspace from renaming another, by keying the workspace settings editor on the workspace id so a switch re-seeds the name field instead of leaving the previous workspace's name against the new workspace's autosave baseline, and pinning every save on the workspace, sending and tracking pages to the workspace its draft was hydrated from

* feat: drop Script error. and the ResizeObserver notice on the marketing site and the hosted form page the way the dashboard and admin panel already do, since those two carry no stack and no bug and between them were the largest issues in error tracking, all of it from warmbly.com

* feat: rename the forms Turnstile script module to turnstileScript.ts so it no longer differs only in case from the Turnstile.tsx component, which resolved both imports to one file on a case-insensitive filesystem and failed forms' typecheck with TS1149

* feat: upload source maps from the static build:pages build as well as the image build, so the dashboards served from a static host stop reporting every stack frame as a minified name beside 'Invalid source map: bad json', which is PostHog falling back to fetching the .map from a host that answers with its SPA fallback

* feat: build every admin list in pg_admin.go with make rather than declaring it nil, so an empty page serializes as [] instead of null, and guard the audit table's own empty check, which is what crashed admin.warmbly.com/audit with 'null is not an object (evaluating d.data.length)' whenever a filter matched nothing

* feat: match the whole broker description rather than a substring when deciding a topic create was refused for permissions, since that answer remembers the topic as present, and clear the cached promise and dead tag when the forms Turnstile script fails to load so a blocked first attempt no longer leaves every later mount with the same rejection and the captcha permanently missing
2026-09-15 09:05:53 -07:00
Matthew Meszaros c4c58cc116 feat: report a failed dashboard socket handshake with its actual error, status, code and request id instead of the plain AppError object that console.error rendered as '[WS] Init failed: [object Object]', and keep an offline blip or an already-expired session a warning so only an unexpected answer reaches error tracking (#532) 2026-09-15 05:46:07 -07:00
Matthew Meszaros e2487296d6 feat: rename the campaign entry-delay picker to EntryDelayPicker.tsx and update its three importers, so the component no longer differs only in case from the entryDelay.ts vocabulary module, which resolved every import of it to the wrong file on a case-insensitive filesystem and failed web's typecheck with ten errors 2026-09-15 13:39:05 +02:00
Matthew Meszaros 8740558ffa feat: stop the dashboard socket's onerror handler reporting every WebSocket error event to PostHog as an exception, since the event carries no detail by spec and onclose already drives the reconnect, so a deploy or a laptop sleep logged '[WS] Error: [object Event]' through capture_console_errors 2026-09-15 13:39:05 +02:00
Matthew Meszaros e67b13e57e feat: stop reporting a mailbox's DKIM as missing when its selector was simply never probed, by deriving candidate selectors from the sending domain's own SPF and MX records on top of a wider default set, reporting a miss as the tri-state dkim_status undetermined rather than a red Missing row in the drawer, dropping DKIM from the Advisor's missing-records finding entirely, refusing a revoked p= key, holding the summary back from accusing anything when DNS never answered, and fixing the CLI auth-check table whose columns read mailbox fields the endpoint does not return (#528) 2026-09-15 02:27:38 -07:00
Matthew Meszaros d40a95dff5 fix: give the dashboard's auth errors a real stack and stop reporting an ended session as a crash, by building AuthError per throw instead of sharing two module-level instances whose stack was captured at module evaluation, so every report pointed at "module code" rather than the call that failed, and by dropping AuthError in before_send since normalizeError already turns it into a redirect and UserProvider sends the user to sign in (#527) 2026-09-15 01:52:35 -07:00
Matthew Meszaros dd98187231 fix: shorten recipient unsubscribe links to 22-character, 128-bit stored tickets (#498) (#525)
* feat: shorten every recipient unsubscribe link from a 96-character signed token to a 22-character stored ticket carrying 128 bits from crypto/rand, minted once per recipient per campaign and reused by every step, so the address the text/plain half of a cold email prints in full fits on one line and cannot be guessed, keeping the signed form working for links already in inboxes and as the fallback when the store cannot be written, and answering a failed lookup with a retryable 'try again shortly' instead of telling the recipient their opt-out is invalid (issue #498)

* fix: restore the disabled-signer guard in URLOn, which factoring the URL builder moved behind a token mint that dereferences the signing key, so a nil or origin-less signer returns the empty string every caller reads as 'no link can be minted' instead of panicking (PR #525 review)
2026-09-15 00:42:45 -07:00
Matthew Meszaros 50711a8e66 fix: a campaign's linked segments are its audience, so detaching one withdraws its leads (#510) (#523)
* fix: make a campaign's linked segments the audience rather than an accumulator, so detaching one withdraws the leads it enrolled instead of leaving the old list mixed in with the new, tracked by a new campaign_leads.source that keeps a hand-picked lead, an overlapping segment's member and anyone the campaign has already emailed out of the withdrawal, and reported back as withdrawn/contacted counts the dialog confirms and explains (issue #510)

* fix: serialize the linked-segment sweep against a link replacement by taking the same campaign lock, so a sweep that read the old set cannot re-enrol the audience the replacement just withdrew, and word the dialog's confirm and toast so the campaign, not the segment, is what has already emailed a lead

* fix: stop the one-shot segment enrol from re-stamping leads that are already in the campaign, since the Leads tab's Add back runs through it and pinning a whole linked audience as hand-picked because one held-out member was restored is the accumulation this change exists to end

* fix: lock the leads a detachment is about to withdraw before deciding, because a send is reserved by stamping campaign_contact_progress and only then locking the lead row, so a reservation committing mid-pass was invisible to the delete's snapshot and could withdraw a lead whose first email had already gone; and report the already-emailed count on every toast branch, since a detach where the whole audience had been emailed changed no count and said nothing after confirming a removal

* fix: add the campaign_leads.source check constraint NOT VALID, which still enforces every insert and update while skipping a full scan of the largest table in the product under ACCESS EXCLUSIVE to learn that a one-statement-old column holds its own default everywhere
2026-09-14 22:12:15 -07:00
Matthew Meszaros e18f2efc05 feat: hold an out-of-office contact in every campaign they are a lead of instead of only the one the auto-reply was attributed to, through a new HoldLeadEverywhere applying the same per-row guard so a member's own pause and a longer running hold both survive, and leaving completed campaigns alone (issue #518) 2026-09-14 21:54:05 -07:00
Suman Jana 20a56dc41b feat: add a full-screen toggle to the unibox compose window that lifts the same composer to the centre of the screen over a dimmed backdrop, collapses back to the corner on a backdrop click or Escape before a second Escape closes the window, and document it on the unibox composing page (#503) 2026-09-14 21:14:08 -07:00
Matthew Meszaros 92e298b6ec fix: clear every open issue in error tracking by fixing the bugs behind them rather than the reports: a document-level mouseleave handing RippleProvider the document itself, whose classList is undefined; the admin panel posting /getaway without the /v1 its baseURL omits, so its realtime socket 404d on every page; Gmail throttles classified from the 403 status alone and told to re-authorize instead of back off; consumer flag and folder events retrying forever on a message the unibox never stored; a lost token-refresh race answered 500 instead of the documented 401; a nil email_accounts slice crashing the admin user page; Turnstile mounted with an empty sitekey; conditional passkey autofill run after the user navigated away; a boot log filed as an issue; and one publish failure per message on a topic the broker refuses (#519) 2026-09-14 21:06:14 -07:00
Matthew Meszaros 25e128c409 fix: stop the form builder canvas tearing apart when fields are reordered by dropping dnd-kit's rectSortingStrategy, whose scaleX/scaleY are the ratio of two mismatched field rects and stretched every sibling out of the card, for a canvas that holds still behind an insertion caret, plus a real end-of-form drop target so dragging the first field to the bottom lands it last instead of resolving to the pane-sized canvas droppable and doing nothing (issue #497) 2026-09-14 20:59:10 -07:00
Matthew Meszaros ffd27bc46d fix: stop every out-of-office notice and bounce opening a high-priority CRM follow-up by classifying machine replies from their headers and gating the task on a per-intent setting, and give the Tasks page multi-select with select-all-matching, bulk status, priority and delete over new PATCH and DELETE /crm/tasks endpoints (issue #471) 2026-09-14 12:20:47 -07:00
Matthew Meszaros 8d790ede6c feat: send from any address Google has verified a Gmail mailbox to send as and import the signature its owner already wrote in Gmail, reading both through gmail.settings.basic at connect and on demand via GET/POST /emails/:id/identity, validating the choice against the provider's own list in the service and again inside the UPDATE, clearing it when the provider stops verifying it, and never applying it to warmup (#514) 2026-09-14 10:13:36 -07:00
Matthew Meszaros 13e9ce8e10 feat: hold a lead whose mailbox answers out of office until they are back, resuming at the return date it names, plus a manual per-contact pause in one campaign that unsubscribing and the suppression list were the only stand-ins for 2026-09-14 09:26:06 -07:00
Matthew Meszaros b9a98cef8f feat: rebuild the unified inbox as three columns with no metric strip, a flattened scope rail with one row language and bare counts, three-line conversation rows carrying an unread dot in the gutter instead of an avatar and bar, a subject-first thread header with icon-only actions, a filter popover that applies on the spot and shows each added filter as a removable chip that never repeats what the current view already fixes, and real loading throughout: a delayed progress bar over dimmed stale rows, row-shaped skeletons for first load, next page and the thread reader, and optimistic row removal so archive, delete and snooze land instantly 2026-09-14 08:26:03 -07:00
Matthew Meszaros c28f915648 feat: erase everything a disconnected mailbox leaves behind, revoking its OAuth grant at Google and deleting its stored message bodies through a durable retried queue, cascade the nine mailbox foreign keys that had none so warmup receipts, tampering events and provider message maps stop outliving the mailbox, clear thread labels and snoozes on conversations the delete emptied, make workspace deletion possible at all by cascading the four organization foreign keys with no delete action, and put Disconnect in the mailbox row menu and a Settings danger zone since it was only reachable from the selection bar (#506) 2026-09-14 07:55:01 -07:00
Matthew Meszaros d74d5e6836 fix: retire the warmup spam score, a counter that grew with volume rather than misbehaviour and that no band could act on (#508)
* fix: retire the warmup spam score, a ratchet that grew with volume rather than misbehaviour and that no band ever read, dropping the column from the pool row and the reputation ledger and explaining a pool finding with the band's own reason instead (#491)

* test: pin the advisor snapshot's pool columns against the scan, since the band's reason now reaches the finding through that select alone (#491)

* fix: hold a warmup sentence's score and reason with the sentence itself, keep the retired spam_score key on the published analytics payload as a deprecated zero, seed the sandbox with severity-shaped scores, and record the raw spam report when the warmup service is absent (#491)
2026-09-14 07:44:34 -07:00
Matthew Meszaros adfe4c17aa Self-hosted pool plan: a price the server resolves, and a checkout that reaches it (#494)
* feat: make the self-hosted pool plan buyable by resolving its Stripe price server-side behind a new /pool-link/offer and /pool-link/checkout pair, adding the plans.price_yearly column the yearly price id never had, and landing the instance's Unlimited button on a dialog that names the workspace and the billing period instead of a plans grid the non-public plan never appears in

* feat: apply the pool dialog's yearly default once per opening rather than on every offer result, so a background refetch cannot move the billing period out from under someone who already chose monthly
2026-09-13 21:22:12 -07:00
Matthew Meszaros 7300b3b021 feat: full PostHog coverage: identify the signed-in user and workspace in the dashboard and admin panel with autocapture, heatmaps, dead and rage clicks, web vitals, network timing, console capture and session replay masking only password fields, send server-side signup, trial and subscription events under the user id with the organization as a group, keep the marketing site and form pages cookieless while capturing everything stateless plus a form funnel, upload the form app's source maps, and add WARMBLY_POSTHOG_SESSION_REPLAY 2026-09-13 20:58:22 -07:00
Matthew Meszaros 6b6efca865 fix: campaign follow-ups opened a new conversation instead of replying in the contact's thread, so carry In-Reply-To/References and the Gmail threadId from the previous send, give every step a reply-in-thread switch, and let a threading step inherit the conversation's subject (issue #472) (#489) 2026-09-13 20:51:41 -07:00
Matthew Meszaros e49a7c4c3a feat: count only dispatched sends against a mailbox's sending profile, so deferral wake-ups and the campaign chain's next queued run stop spending the rolled daily plan (issue #469) (#475) 2026-09-13 06:47:42 -07:00
Matthew Meszaros 1c55b93afb Every shortcut the ? modal shows now runs, and both resize handles share one gesture (#487)
* fix: make the shortcuts modal and the key dispatcher one registry so a row that runs nothing cannot be written, wire j/k/gg/G/Enter/Escape and / to the screen that owns them instead of to store fields nobody wrote, unshadow g k, and give the assistant panel's resize handle the pointer capture, single store write, bounds and separator keyboard the unibox splitter already had

* fix: lock text selection for the assistant window's move and corner drags instead of cancelling their pointerdown, which took the compatibility mousedown with it and left every open popover on screen

* fix: keep a half-typed g sequence from swallowing a modifier combo, so g followed by Ctrl+K opens the command palette instead of navigating, and end the sequence when any other shortcut fires

* fix: word the inbox keyboard docs so they hold whichever way the conversation list is sorted

* fix: list the command palette combo at the end of the actions group in the shortcuts modal, where a modifier combo reads as a footnote rather than the first thing a bare-key list shows

* fix: release the page-wide selection lock from a window listener as well, so a floating-window drag interrupted by the panel unmounting cannot leave the whole app stuck at user-select none

* fix: drop the unused test-seam export from the shortcut action registry, which is the same unreferenced-helper shape this branch is deleting everywhere else
2026-09-13 05:28:34 -07:00
Matthew Meszaros 55d712579b feat: collapse the left navigation to an icon rail, drag the unibox conversation list against the thread, and remember the contact rail toggle instead of reopening it on every conversation (#479) 2026-09-13 01:09:29 -07:00
Matthew Meszaros 7f74664c72 fix: a granted plan unlocks nothing, and Turnstile never renders (#474)
* fix: let a granted plan unlock the dashboard, since the client decided paid from the Stripe status a managed subscription never touches, and replace the Turnstile size Cloudflare removed so the widget renders and can issue a token at all

* feat: tell people on a preview deployment that it is a public beta, once in a dialog and thereafter as a header pill they can reopen, driven by a config value rather than a hostname so one image stays reusable, and bind both Turnstile modals through onLoad because the component is not forwardRef and execution=execute never fires without the widget instance

* fix: keep the beta pill outside the desktop-only header group so the notice stays reopenable on a phone, and say in the docs that the value is baked into config.js at container start rather than read per load
2026-09-12 21:45:05 -07:00
Matthew Meszaros d8d929c3f0 fix: stop the contacts and campaign-leads table overflowing its panel on a long company name (#461)
Under auto table layout one long company name set its column's min-content and widened the table past the content panel, putting a horizontal scrollbar under the whole list; `truncate` on the `<td>` gave it nowrap with no width constraint and never rendered an ellipsis. Moves the table to table-fixed with a declared width per column and clipping in every cell, Name the one auto column so it takes all the slack, each free-text column truncating into a native tooltip that only appears where the text was actually cut off, and the column set restaged per breakpoint so the sized columns never sum past the panel at any width.

Also closes the pre-existing overflow at md/lg, where the Leads view's sized columns alone exceeded the panel regardless of content, and gives both status pills an accessible name below sm where the label had been display:none.

Closes #461.
2026-09-12 08:33:15 -07:00
Matthew Meszaros d456bc48c6 feat: fix the Warmbly Cloud pool link across both roles (#262): take an enrolled mailbox out of this instance's own warmup pool so local partners stop writing to it and their unverifiable warmup stops landing in the owner's unibox, recognise the cloud's warmup mail whose verify header did not survive delivery through a new warmup-deliveries lookup that ignores consumed_at because instance and cloud read the same mailbox, move the managed-mailbox access token route behind NODE_BROKER_TOKEN so the internet-facing tracking and forms services can no longer mint a live provider token, scope pause and resume to the caller's workspace, keep an enrolled mailbox listed once it goes inactive, release the cloud copy when the local mirror row cannot be written, refuse the one-time handshake when CREDENTIALS_ENCRYPTION_KEY is missing, blank an expired code's plaintext instance token, and stop errx answering 200 for a status outside its table 2026-09-12 06:58:25 -07:00
Matthew Meszaros c4aece241b feat: scope the tag, category and folder registries and unibox conversation labels to the organization instead of the creating user, so a teammate sees and can edit the labels the owner made, splitting a label two workspaces shared into one copy each and guarding every label write against ids from another workspace (#457) 2026-09-12 03:37:31 -07:00
Matthew Meszaros 47defafa09 feat: fix the six self-host defects reported in issue #439 (#456)
* feat: fix the six defects reported in issue #439 by mapping the IMAP UNAVAILABLE, INUSE and NONEXISTENT response codes to retry-level errors instead of a critical reconnect prompt, synthesising a stable no-msgid key so one message with no Message-ID header can no longer 400 the internal map endpoint and wedge every later sync pass with its cursors held, adding mailhtml.FromText and HasContent so an API or agent-created step with a plain body stops shipping the composer's empty div placeholder as its text/html part (derived on create and plain-only update, exposed as body_html on update_campaign_step, dropped at send and preview time, and refused at campaign start with empty_step_body), honouring sender_strategy='explicit' in ResolveCampaignSenderPool and ValidateCampaignReady so an emptied explicit pool parks the campaign instead of widening it to every mailbox in the workspace, making the paused_no_accounts auto-pause loud with an error log line, an error-level activity-feed entry and an org-scoped CAMPAIGN_PAUSED realtime pulse, gating the admin sign-in's Turnstile widget on GET /v1/auth/config so a self-host with CAPTCHA_PROVIDER=none is not locked out, and parsing NATS_URL down to its host:port so a credentialed bus URL no longer reports NATS down

* feat: act on the self-review of the issue #439 fixes by dropping the campaign wizard's own escapeHtml body_html builder, which entity-escaped the quotes in a conditional and made the template fail to parse at send time, and letting the backend's FromText render that part instead so wizard-written steps also get their bare URLs linked for click tracking, correcting the docs and openapi description that claimed an explicit sender pool never falls back when it still unions its tags as migration 000013 designed, extracting the duplicated blank-HTML-part guard into dropBlankHTMLPart shared by the send path and the preview, and recording why the no-msgid key keeps the folder name despite a RENAME changing it

* feat: address the CodeRabbit review on the issue #439 fixes by holding the admin sign-in's Turnstile widget unmounted until /v1/auth/config resolves so an instance with no route to Cloudflare cannot raise a widget error on a screen nobody submitted, failing StartCampaign closed when the sequence read errors rather than skipping both the malformed-template and empty-body refusals, giving TCPCheck the default port its protocol assumes so a portless NATS_URL is no longer reported down, leaving a URL that carries a merge field unanchored because the send path renders bodies with text/template and a quoted contact value would break out of the href, and correcting the sequences guide and the Campaign and CampaignUpdate openapi descriptions that named the wrong tag field
2026-09-12 03:13:38 -07:00
Matthew Meszaros dc9ce403de feat: stop one un-sendable lead parking a whole campaign and stop the contact drawer's next-action time walking forward on every refresh (issue #437): route up to config.CampaignPlacementCandidates due leads per pass instead of one, classify a placement refusal that belongs to a single lead (ESP-strict finding no mailbox for that recipient's provider, a bound lead inside its own mailbox's minimum gap or waiting for it to reopen, a recipient's send-time-optimized hours) as the new ErrLeadDeferred so the pass moves to the lead behind them and only defers the campaign when every candidate is refused, log the ESP-strict deferral once a day rather than once per refused lead per tick, and make PreviewContactSend a pure read that answers unchanged state identically on every call by running placement with the even-distribution, jitter, conflict-resolution, distribution-curve and sub-minute layers off, taking a behaviour profile's gap at its floor instead of drawing it, picking the mailbox deterministically instead of re-rolling rotation, reporting the next sending day's first open minute instead of a jittered twenty-four-hours-from-now, and reporting a due step's time as the campaign chain's own stored wakeup 2026-09-12 02:58:48 -07:00
Matthew Meszaros ea8d15374e Merge branch 'main' into feature/editor-image-links-and-buttons 2026-09-11 22:56:16 -07:00
Matthew Meszaros 1f1112fe93 feat: drop the AI edit's parked review selection when the popover closes, because a result that changes nothing commits no new value and so leaves the layout effect nothing to run on, and the range would then be worn by whatever unrelated edit commits next and yank the caret back into a rewrite the user had already dismissed 2026-09-11 22:42:50 -07:00
Matthew Meszaros f41eac289d Merge branch 'main' into fix/issue-432 2026-09-11 22:35:43 -07:00
Matthew Meszaros 4bf412c226 feat: decide the AI edit's No change signal from the value the composer will actually hold rather than from the model's answer, since a rewrite whose every added character falls past the body-length cap leaves the textarea exactly as it was and reporting Rewritten over an unchanged body is the one thing that signal exists to prevent 2026-09-11 22:30:32 -07:00
Matthew Meszaros ea321ebefb feat: put the AI edit's review selection back after React commits the value rather than before it, since React writes the textarea's value during commit and that write moves the cursor to the end, leaving the rewrite unselected and Undo's restored range never reaching the DOM, and strengthen the Undo test to assert the range a follow-up run targets instead of the restored value, which Undo sets regardless and which therefore pinned none of the behaviour the commit before it fixed 2026-09-11 22:22:55 -07:00