Matthew Meszaros
|
d5bce77123
|
feat: document the resource-based layout and the full Zapier trigger/action/search catalog in the README and customer guide
|
2026-06-29 06:37:20 +02:00 |
|
Matthew Meszaros
|
f2f13e8a90
|
feat: document the new Zapier edit and delete actions, widened scopes, and destructive-action caution
|
2026-06-29 06:21:41 +02:00 |
|
Matthew Meszaros
|
f6d3ff600a
|
feat: document the GET /v1/me credential-verification endpoint in the API authentication guide
|
2026-06-28 19:28:04 +02:00 |
|
Matthew Meszaros
|
34fb2a77d6
|
feat: add customer-facing Zapier guide covering triggers, actions, searches and register it in the guides nav
|
2026-06-28 19:10:18 +02:00 |
|
Matthew Meszaros
|
90aab1acee
|
feat: document the GET /v1/me identity endpoint in the API endpoint scope map
|
2026-06-28 19:09:37 +02:00 |
|
Matthew Meszaros
|
0baa48991b
|
Publish development docs to docs.warmbly.com
|
2026-06-28 13:25:08 +02:00 |
|
Matthew Meszaros
|
7813d173b1
|
Move development docs to docs/development/
|
2026-06-28 12:25:08 +02:00 |
|
Matthew Meszaros
|
8e3445e4b8
|
Refresh README with mailboxes screenshot and warmup focus
|
2026-06-28 12:02:02 +02:00 |
|
Matthew Meszaros
|
a1cb25fc1d
|
Update README and assets with new banner and dashboard screenshots
|
2026-06-28 11:43:47 +02:00 |
|
Matthew Meszaros
|
4187d15dd0
|
feat: document the referral program guide and the referral and applied-discounts API endpoints in docs
|
2026-06-28 05:10:04 +00:00 |
|
Matthew Meszaros
|
ce45ba02d9
|
docs: document the webhook platform and OAuth app webhooks, add the webhooks guide, and update the endpoint scope map
|
2026-06-15 08:11:53 +02:00 |
|
Matthew Meszaros
|
2c910dcdeb
|
feat: make a campaign step's Original a first-class weighted A/B arm driven by a single draggable traffic-split bar, persisting the control share as an is_control variant row
|
2026-06-15 08:11:53 +02:00 |
|
Matthew Meszaros
|
c5dfa5e4e7
|
feat: remove the HTTP-request action from campaign steps and automations in favor of signed webhooks, keep fire_event for custom payloads, and drop the now-unused outbound quota plumbing
|
2026-06-15 08:11:35 +02:00 |
|
Matthew Meszaros
|
c1bd391ceb
|
docs: add a dependency-free realtime gateway reference client (connect, HELLO, heartbeat loop, seq resume, intents incl CUSTOM), a close-codes table, and OAuth-access-token auth
|
2026-06-14 11:02:12 +02:00 |
|
Matthew Meszaros
|
ab24d8bbc8
|
feat: add a 'Fire event' action and campaign step that publish custom events to the realtime gateway (no public URL), an HTTP-request campaign step, a configurable automation dry-run test with per-step toggles, and fix the false 'updated by a teammate' toast on your own save
|
2026-06-14 09:52:49 +02:00 |
|
Matthew Meszaros
|
fcdb31cda7
|
feat: OAuth apps always issue a client secret (drop the public/PKCE-only client type, secret required for the token exchange), add an app-logo upload endpoint, and align the docs to OAuth2 with optional PKCE
|
2026-06-14 09:52:49 +02:00 |
|
Matthew Meszaros
|
0fe1401f8b
|
feat: document the OAuth 2.1 authorization server (new api/oauth.mdx flow guide, authentication + permissions + endpoints scope-map updates, meta registration)
|
2026-06-13 14:10:11 +02:00 |
|
Matthew Meszaros
|
20935ef061
|
feat: add a nil-safe per-org daily outbound-action quota (Redis daily counter, anti-abuse ceiling on the HTTP-request automation node, wired in both backend and consumer, fail-open) to bound webhook relay abuse
|
2026-06-13 13:41:20 +02:00 |
|
Matthew Meszaros
|
1fa9c65ada
|
fix: harden every user-supplied-URL outbound path against SSRF with a shared dial-time guard (resolves the host, blocks private/loopback/link-local/metadata IPs, pins the validated IP to defeat DNS rebinding, re-validates redirects) and log automation HTTP requests + blocked attempts with org attribution
|
2026-06-13 13:34:19 +02:00 |
|
Matthew Meszaros
|
501b5009b4
|
feat: add an on-error branch to automation action nodes (try/catch routing, rose on-error handle, executor follows the error edge and treats the failure as handled instead of failing the run)
|
2026-06-13 13:15:41 +02:00 |
|
Matthew Meszaros
|
9aa3300f46
|
feat: capture per-action output in automation run history (HTTP status/ok, set-variables values, rendered channel/url/message) and render it under each action in the builder History panel
|
2026-06-13 13:11:58 +02:00 |
|
Matthew Meszaros
|
6f5f05c5a2
|
feat: document the inbound webhook automation trigger (unique per-automation URL, JSON body as event payload, token security and limits) in the automations guide
|
2026-06-13 13:08:37 +02:00 |
|
Matthew Meszaros
|
f1cf470121
|
feat: render Discord notifications as sky-themed rich embeds and Slack notifications as sky-accented attachment cards with contact and subject fields instead of plain text lines
|
2026-06-13 12:41:26 +02:00 |
|
Matthew Meszaros
|
96f19919ac
|
feat: document the HTTP request / webhook and Set variables automation actions in the automations guide
|
2026-06-13 12:20:20 +02:00 |
|
Matthew Meszaros
|
4e2fdec482
|
feat: document the resumable gateway (resume/replay, seq, resume_failed) in realtime.mdx and publish a machine-readable AsyncAPI 3.1 spec at docs/asyncapi.json describing the org channel, join/resume, HELLO, events, intents, and presence
|
2026-06-13 11:29:12 +02:00 |
|
Matthew Meszaros
|
3c7c0b6411
|
fix: finish the opaque-cursor doc sweep — change the offset query params to cursor on the CRM search operations in the OpenAPI spec, and drop the dead SearchContacts.Offset field and its docs (clamped but never used in SQL)
|
2026-06-13 11:00:59 +02:00 |
|
Matthew Meszaros
|
aed4a06190
|
feat: unify pagination by making the offset-based CRM deals/tasks search and meetings endpoints expose the same opaque next_cursor and {total, next_cursor, has_more} envelope as every keyset list (offset hidden inside the token), updating web clients, the OpenAPI spec, and the reference docs
|
2026-06-13 10:47:17 +02:00 |
|
Matthew Meszaros
|
013a73b9be
|
feat: publish a machine-readable OpenAPI 3.1 spec at docs/openapi.json covering 204 operations across the public API, with an OpenAPI docs page describing how to generate clients from it
|
2026-06-13 07:29:17 +02:00 |
|
Matthew Meszaros
|
587eae774e
|
feat: serve the entire customer API (auth + resources) only under /v1 with no unversioned alias, and repoint the web and admin clients to the versioned base accordingly
|
2026-06-13 07:18:23 +02:00 |
|
Matthew Meszaros
|
49b01c6b67
|
feat: version the public API under /v1 by mounting the customer surface under both /v1 and the bare paths, adding an API-Version response header and Deprecation/Sunset headers nudging API-key callers off the unversioned aliases
|
2026-06-13 06:27:01 +02:00 |
|
Matthew Meszaros
|
71abb12a38
|
feat: stop campaigns silently stalling on a transient scheduler error by retrying instead of completing the task, end past-end-date campaigns cleanly, record scheduler failures to the campaign log, add a campaign-chain reconciler, and surface failures live in the dashboard activity panel
|
2026-06-13 06:27:01 +02:00 |
|
Matthew Meszaros
|
92a74d9364
|
feat: document the label-email action in the steps and automations guides — reply-only, applies the shared category labels to the conversation the contact replied on, gated to the reply trigger
|
2026-06-12 16:44:29 +02:00 |
|
Matthew Meszaros
|
a7a43e0c4c
|
feat: rename the campaign sequences resource to steps across the API and URL (/campaigns/:id/steps), the JSON fields (target_step_id, step_id/step_name/step_index, analytics steps[], create body steps), the web client/models/route segment/labels, the audit step entity type, and the wire-contract docs; internal Go type names and the Kafka avro schema stay
|
2026-06-12 09:38:11 +02:00 |
|
Matthew Meszaros
|
85d5d04afe
|
feat: clarify in the sequences guide that the A/B original is a control arm in the weighted split with a live per-arm share shown in the editor
|
2026-06-12 08:04:44 +02:00 |
|
Matthew Meszaros
|
5d2882ccf8
|
feat: strip leaked agent reasoning and select the corrected final draft for campaigns and deliverability reference pages, removing duplicate frontmatter, an em dash, and a Cyrillic placeholder char
|
2026-06-12 07:39:57 +02:00 |
|
Matthew Meszaros
|
bfd67bfa2a
|
feat: correct API key prefix examples to the real wmbly_ format and link the endpoint reference from the API docs index
|
2026-06-12 07:29:45 +02:00 |
|
Matthew Meszaros
|
54a1aee753
|
feat: add full per-resource API endpoint reference under docs/api/reference (mailboxes, campaigns, contacts, unibox, crm, analytics, api-keys, webhooks, integrations, deliverability/ops, account/org) with request and response structures
|
2026-06-12 07:28:19 +02:00 |
|
Matthew Meszaros
|
3cbfc06bc4
|
feat: add WebSocket intents (selective event-family subscription) and a HELLO-style org join reply advertising heartbeat cadence, and correct realtime docs on connection rejections and at-most-once delivery
|
2026-06-12 07:17:09 +02:00 |
|
Matthew Meszaros
|
50a134c827
|
feat: document org team-presence privacy controls in the collaboration guide and realtime API reference
|
2026-06-12 05:59:02 +02:00 |
|
Matthew Meszaros
|
f209eca9ad
|
fix: Slack notification delivery now resolves a real channel (connection config, then the org's configured Slack automation channel) instead of an always-empty connect-time field that silently dropped every message; docs and UI corrected to match
|
2026-06-11 12:40:31 +02:00 |
|
Matthew Meszaros
|
3c040649c0
|
fix: changing your password now revokes every other session (keeping the current device), matching the security promise in the sign-in alert and docs
|
2026-06-11 12:39:24 +02:00 |
|
Matthew Meszaros
|
5bcc2baaa8
|
feat: implement the coming-soon security features — logged-in change-password (verify current, policy-checked, POST /me/password) with a real dialog, and new-device sign-in alerts (security notification category fired from the token service on an unrecognized OS+browser, delivered in-app and by email), removing the comingSoon stub helper and updating docs
|
2026-06-11 12:30:44 +02:00 |
|
Matthew Meszaros
|
160dc0bc76
|
feat: implement the coming-soon notification delivery channels — Email (SES/SMTP to the account email) and Slack (posts to the org's connected workspace via a new integration NotifySlack), wired in both backend and consumer with per-channel gating, real toggles replacing the coming-soon labels, and updated docs
|
2026-06-11 12:21:48 +02:00 |
|
Matthew Meszaros
|
8540f7db15
|
feat: members can hold multiple roles — join tables for member/invitation role sets (migration 000044) with effective permissions as the bitwise OR recomputed on every assignment and role edit/delete, role_ids in invite/update APIs, multi-select checkbox role picker with colored chips in roster and invite flow, freely deletable roles
|
2026-06-11 11:24:19 +02:00 |
|
Matthew Meszaros
|
3473d09bcc
|
feat: fix review findings in the roles redesign — GetMembers role_id column (members endpoint 500), TransferOwnership role_id hygiene, accept-time role re-resolution, race-free in-use delete guard covering invitations, assignment anti-escalation with self-role-change block, canManage-gated members UI, colored RolePills, fresh currentOrganization on refetch, dev JWT_SECRET wiring for make realtime, docs corrections
|
2026-06-11 10:45:21 +02:00 |
|
Matthew Meszaros
|
2badeb7f50
|
feat: align team-roles docs with data-driven roles (seeded editable defaults, owner as status, color in the role editor) and drop dead accent maps from the members page
|
2026-06-11 10:20:41 +02:00 |
|
Matthew Meszaros
|
0b253337fc
|
feat: integrate custom roles across Roles & access settings (manager replaces the coming-soon placeholder, custom roles join the permission matrix and summary cards, permission-aware canManage gating via the org context bitmask)
|
2026-06-11 10:08:46 +02:00 |
|
Matthew Meszaros
|
9992eb65c4
|
feat: document custom roles in the team-roles guide (creation flow, start-from presets, propagation and anti-escalation rules, limits)
|
2026-06-11 09:46:15 +02:00 |
|
Matthew Meszaros
|
014cbe79fa
|
feat: label machine opens (Apple MPP prefetch, UA-less fetchers) with human-open upgrade semantics, exclude them from open-triggered automations, and surface the auto-open count in workspace and campaign analytics (migration 000040)
|
2026-06-11 08:33:09 +02:00 |
|
Matthew Meszaros
|
7079efe21a
|
feat: document the developer realtime WebSocket (channels, presence, limits, close codes), add the live collaboration guide, and note bot filtering in analytics docs
|
2026-06-11 08:13:56 +02:00 |
|