Matthew Meszaros
eff2c14a9d
feat: make workspace import write only rows the destination workspace owns by checking every archive key and foreign key against each table's owner scope before a batch lands, scoping overwrite updates to the destination's own rows, warning in the archive check, and documenting the rule
2026-10-04 03:03:34 -07:00
Matthew Meszaros
43a9d004f2
feat: bound user-authored templates (range only over data fields, two-deep nesting, no template calls, 1 MiB output, capped compile cache) for campaign and automation rendering, accept only single addresses and single Message-IDs for to/cc/bcc/in_reply_to on every send path with invalid_recipient and invalid_message_id, refuse multi-line headers in the Gmail, Graph and SMTP writers, always apply a no-script CSP and drop non-http(s)/mailto/tel link targets in email previews, treat only single-slash paths as internal Remie links, accept integration OAuth callbacks only from the API origin, and follow only http(s) form redirects and app install links
2026-10-04 03:02:37 -07:00
Matthew Meszaros
8d0a281934
feat: name AdminMiddleware as the admin second-factor gate in AGENTS.md and note that the instance-wide Cloud link sits behind it
2026-10-04 03:02:22 -07:00
Matthew Meszaros
ff54338806
feat: keep every deal in the pipeline its stage belongs to on create and update, validate pipeline stage names and colours in the CRM service for every caller, bound the AI bulk contact edit to MaxContactBatchIDs parsed ids, and start placement tests for API-key callers only through the REST route that applies the key's mailbox limits
2026-10-04 03:02:15 -07:00
Matthew Meszaros
f9a2e9af10
feat: state dependency floors, the Sentry HTTP client choice and auth cache budgets as the guarantees they hold, with no advisory identifiers or past behaviour in comments
2026-10-04 03:00:56 -07:00
Matthew Meszaros
9ff2e71385
feat: cap CLI sign-in keys with the shared role-to-scope mapping models.APIPermissionsFor and accept an OAuth token on the realtime socket only while its holder is still a member of the grant's workspace
2026-10-04 03:00:18 -07:00
Matthew Meszaros
bf47984cd5
feat: cap every OAuth grant and API key at the delegating member's role (consent narrows scopes and reports the withheld ones, tokens re-check the member's current role at every gate and MCP tool, keys stay within their creator's permissions, mailboxes and IP allowlist), keep OAuth tokens off API key and OAuth app management, require a fresh sign-in to approve an app, revoke a grant whose refresh token is presented twice, count only unexpired grants as installs, seal app webhook secrets under the instance key, name the workspace and flag unverified apps on the consent screen, and let credential managers list and revoke every member's app authorizations
2026-10-04 02:59:10 -07:00
Matthew Meszaros
8bb60e9449
feat: accept only Salesforce domains as an org's API host and call it through the SSRF-guarded client, register the Warmbly Cloud link only on self-hosted instances behind the instance admin with a second factor and dial it through safehttp with fixed error text, keep automation signing secrets in the sealed connection config, answer integration service failures with fixed messages, add security headers to the forms, tracking and docs origins and TLS 1.2+ to the nginx template, compare the captcha bypass in constant time, require TLS 1.2 for IMAP probes, and drop the unused RSA helpers
2026-10-04 02:58:43 -07:00
Matthew Meszaros
59f6d72d3b
feat: bump docs to next 16.3.8, site to patched devalue and http-cache-semantics, and realtime to mint 1.11.0, gate the security workflow on called Go vulnerabilities with a fixed version and on retired or upgradable Hex packages through scripts/govulncheck-gate.sh and scripts/hex-audit-gate.sh with a new Elixir audit job, and keep advisory ids and reachability notes out of .trivyignore, mix.exs and the site pnpm workspace
2026-10-04 02:57:17 -07:00
Matthew Meszaros
610d511307
feat: answer every server-side failure in admin, internal, webhook, warmup routing, Stripe webhook, agent tool and MCP handlers with the fixed internal error and log the detail against the request id, keep correctable webhook and routing refusals as typed errors with their own messages, drop the request URL from MillionVerifier transport errors so the API key never reaches a log or response, and redact :code path parameters in the access log
2026-10-04 02:57:17 -07:00
Matthew Meszaros
32da32a0a8
feat: mask every revealed secret in session replay by tagging API key, client and signing secrets, inbound webhook URLs, join commands, tester passwords, pairing codes and the TOTP QR, block inputs holding credentials, mask token, session and code URL parameters in dashboard analytics, give the admin panel the same masking with console recording off, and update the privacy page to match
2026-10-04 02:57:17 -07:00
Matthew Meszaros
2bc7ef55f1
feat: mount the confirm-it-is-you prompt on the standalone pool link connect page so approving an instance link can complete its required recent confirmation outside the dashboard layout
2026-10-04 02:56:18 -07:00
Matthew Meszaros
db4fc7b115
feat: require a recent confirmation for 2FA enrollment (a fresh sign-in for accounts with no password or factor), pool link approval, workspace export and import, member invites and role changes, webhook and OAuth app secret reveal and rotation, and the admin fleet join token, admin grant and workspace archive routes, with a confirm-it-is-you dialog and retry in the admin panel
2026-10-04 02:56:18 -07:00
Matthew Meszaros
3a2d80b8bf
feat: accept realtime API keys and OAuth tokens only in the x-warmbly-token handshake header with the ws ticket alone in the query string, filter token and key params from Phoenix connect logs, refuse realtime keys, OAuth tokens and pool link tokens held by a login-banned user or a suspended app with an uncached key check, and send the key as a header from warmbly events tail
2026-10-04 02:56:18 -07:00
Matthew Meszaros
33f99b97e5
feat: end every session on sign-out-everywhere through RevokeOtherSessions with cache eviction after commit, refuse refresh on a revoked session, close a user's realtime sockets on any session revocation via a SESSIONS_REVOKED event, and verify tokens without a purpose claim for no flow
2026-10-04 02:56:18 -07:00
Matthew Meszaros
5bd8dbfab9
feat: bind Warmbly Cloud brokered mailbox sign-ins to PKCE, a single-use state and a cloud consent page naming the requesting instance and workspace that sets the browser cookie the callback requires, return only to the instance's registered address, add PKCE and an OIDC nonce to Workspace and Microsoft 365 admin-proof sign-ins, post OAuth callback codes only to a configured dashboard origin, cap CLI-approved keys to the approver's role behind a fresh sign-in, and accept only same-origin login next paths
2026-10-04 02:53:16 -07:00
Matthew Meszaros
9f7d45a1fb
feat: charge every password, emailed-code and TOTP attempt atomically before comparing it (Redis INCR+expire script) with a per-account TOTP budget across challenges, put the signed-in password change on the reauth budget, set the per-account login limit to 50 per hour, give tester passwords an expiry (users.password_expires_at, migration 000257) and clear them plus every session on revoke, mint warmblyctl reset links with the password-reset purpose, expire fleet join tokens (7 days default, 30 max, reusable inside the window), derive captcha from the resolved Turnstile secret, refuse weak bootstrap argon2id hashes, make registration codes single-use, rate-limit the v1 invitation lookup, and draw RIDs and user codes without modulo bias
2026-10-04 02:52:22 -07:00
Matthew Meszaros
f0ec39febd
feat: scope automation and sequence unsubscribes to the caller's organization, require manage_settings to create, edit, enable or delete automations, run each integration action only on its own provider's connection (400 action_provider_mismatch), refuse org-permission gates when no organization service is wired, read /integrations/bookings like contacts, scope lead claims, research runs and CRM list cursors to the organization, and bind contact note edits to the contact in the path
2026-10-04 02:47:10 -07:00
Matthew Meszaros
e1c4a91ad1
feat: confirm a Slack link only for the Warmbly member whose email matches the Slack account's confirmed profile email (read via users.info with the new users:read and users:read.email scopes, refused as slack_link_email_mismatch), show the Slack account's name and avatar on the link page and after linking, return the Slack connection in GET /integrations/slack/status only to manage_settings or use_integrations, scope agent-thread lookups by organization, and check a Draft a reply card's conversation belongs to the clicker's workspace before starting the assistant
2026-10-04 02:45:04 -07:00
Matthew Meszaros
4cfba5340a
feat: verify every HubSpot app request by its v3 signature over the public backend URL, refuse card-fetch query values on the webhook and workflow action routes, take exactly one portalId, userId and userEmail on card routes and act as the matched accepted member holding the matching campaign and contact permissions, route a portal only to its single live HubSpot-mode workspace, delete mirrored deals and tasks only when HubSpot answers the record is gone, and scope the card's permitted fetch to the card routes
2026-10-04 02:42:12 -07:00
Matthew Meszaros
585c7ff85a
feat: end every credential a login-banned user holds by refusing their API keys, OAuth grants and Slack links at resolution, and run the Slack assistant only for members whose role includes use_ai, matching the dashboard gate
2026-10-04 02:34:01 -07:00
Matthew Meszaros
23c57f35c2
Merge pull request #822 from warmbly/feature/integrations-page-redesign
...
feat: turn Integrations into an app store with search, filters and app pages, add a link-only community directory, a new OAuth app registration dialog, per-app re-encoded logos and admin moderation for OAuth apps
v0.6.26
2026-10-04 08:27:13 +00:00
Matthew Meszaros
d505508997
feat: audit OAuth app moderation and developer blocks under their own entity types, refuse logo removal on suspended apps, delete a replaced workspace-uploaded app logo once no other app shows it, confirm before revoking every token in the admin panel, open store cards on Space, retry a new logo URL after a failed one, toast only after the clipboard write succeeds, and freeze the listing form baseline while it is open
2026-10-04 01:20:28 -07:00
Matthew Meszaros
bc9caba267
feat: validate OAuth app names through displayname and websites as http(s), clean dynamically registered client names and stop storing their logo_uri, refuse edits and logo uploads on suspended apps or blocked developers, scope logo deletion to the app's own images, keep hidden listings from being unpublished, count only installs from other aged workspaces toward the directory threshold, refresh integration popularity outside the lock, and count only live connections in the Integrations store
2026-10-04 01:10:39 -07:00
Matthew Meszaros
7a785afb94
Merge pull request #824 from warmbly/feat/stripe-no-automatic-tax
...
feat: turn off Stripe automatic tax on checkout, plan changes and previews
v0.6.25
2026-10-04 08:07:40 +00:00
Matthew Meszaros
751dd5e08c
feat: turn off Stripe automatic tax on subscription and credit checkout, plan changes and proration previews in internal/app/stripe/service.go, keeping required billing address, business name and tax ID collection
2026-10-04 09:59:24 +02:00
Matthew Meszaros
2983d3ca1e
Merge pull request #823 from warmbly/feat/remie-assistant
...
feat: Remie, the dashboard AI assistant: animated blob mark, floating panel, live run UI, and Advisor-driven suggestions and tips
2026-10-04 07:59:05 +00:00
Matthew Meszaros
6565197a60
feat: close Remie tips through useClickOutside and put them away when a dialog opens, reset hover on close, read Advisor findings only under View analytics, keep a typed draft when a fix is handed to Remie, celebrate only runs that end without an error or a stop, group suggestions with the Advisor's groupFindings, count the tip day in local time, and scope the dev demo to its own approvals
2026-10-04 00:49:08 -07:00
Matthew Meszaros
1a483cb27f
Merge remote-tracking branch 'origin/main' into feature/integrations-page-redesign
...
# Conflicts:
# internal/app/integration/service.go
# web/src/app/app/integrations/page.tsx
# web/src/hooks/useDocumentTitle.ts
2026-10-04 00:45:48 -07:00
Matthew Meszaros
b2224b0eb5
feat: add the Remie proof flows in qa/flows/remie.flow.ts recording the floating panel with Advisor suggestions and a scripted run through live status, folded tool steps, approval and the answer
2026-10-04 00:38:51 -07:00
Matthew Meszaros
7672924a72
feat: rename the dashboard assistant to Remie with an animated blue blob mark, open it as a floating window by default, show live runs with a shimmering status, elapsed timer, collapsible tool-step trace, streamed text with a blurred tail and a redesigned approval card, and add Remie suggestions and rate-limited tips built from open Advisor findings that Remie fixes through its own approvals
2026-10-04 00:36:27 -07:00
Matthew Meszaros
4bc2417618
Merge remote-tracking branch 'origin/main' into feature/integrations-page-redesign
...
# Conflicts:
# docs/content/docs/api/error-codes.mdx
# docs/content/docs/guides/integrations.mdx
# web/src/app/app/integrations/page.tsx
2026-10-04 00:32:54 -07:00
Matthew Meszaros
7555f641a5
feat: turn Integrations into an app store with sidebar views, search, sorting and filters, list community apps by link until featured or widely installed, redesign the OAuth app registration dialog, store app logos re-encoded per app like the workspace logo, and add admin suspension, token revocation and developer blocks for OAuth apps
2026-10-04 00:31:52 -07:00
Matthew Meszaros
315b19a63a
Merge pull request #821 from warmbly/feature/salesforce-native-crm-integration
...
feat: native Salesforce sync with activity logging, writeback, pause rules, imports and in-app Salesforce cards
2026-10-04 07:21:11 +00:00
Matthew Meszaros
d112657cf2
feat: wire suppression, subscription and hold dependencies into the consumer's Salesforce service, give Salesforce token refreshes their own single-flight keyspace, release the outbox lease in memory after each terminal write so writeback notes land and only on rows with a logged Task, drop stale Salesforce import previews, keep keys from the import row menu from opening the edit dialog, and document the Salesforce callback URL and OAuth variables
2026-10-04 09:10:37 +02:00
Matthew Meszaros
6b7e254e56
feat: add native Salesforce sync with Lead and Contact matching and links, a leased activity outbox that logs sends, replies, bounces, opt-outs and meetings as Tasks, Lead Status and Email Opt Out writeback, a pull loop with CRM pause rules, list view and Campaign imports, sandbox and My Domain OAuth that refreshes expired sessions, a Salesforce settings page with contact and inbox cards in web, and docs
2026-10-04 08:54:27 +02:00
Matthew Meszaros
6c127df9b0
Merge pull request #820 from warmbly/feature/hubspot-native-integration
...
feat: HubSpot CRM mode with write-through deals, tasks and notes, email activity logging, exit rules, list import, setup wizard and in-HubSpot card and workflow action
2026-10-04 06:24:56 +00:00
Matthew Meszaros
900806f328
feat: make HubSpot sync jobs lease-safe with per-claim tokens and one-at-a-time claims, log each email once across retries with the interested-reply outcome as its own job, move merged HubSpot contacts in a transaction, run backfill as one cursor job that skips refused records, rebuild the HubSpot client after a reconnect, accept a single portalId on card requests, and remember the Warmbly property group only after it exists
2026-10-04 08:18:16 +02:00
Matthew Meszaros
37e91fc89f
feat: add HubSpot CRM mode where HubSpot deals, pipelines, tasks, notes and owners are mirrored and written through, sends and replies log as HubSpot emails, exit rules hold campaigns, list import, sync health, setup wizard in web, HubSpot app project with record card and workflow action, and docs
2026-10-04 07:47:51 +02:00
Matthew Meszaros
b84d70c31d
Merge pull request #818 from warmbly/claude/api-contract-2026-10-04
...
feat: describe the stored send-plan snapshot in the OpenAPI document (stale flag on CampaignSendPlan)
2026-10-04 05:31:35 +00:00
Claude
71f69f1856
feat: advance campaigns.updated_at in setForCampaignTx when linking segments inserts new campaign_segments rows so the send-plan snapshot is invalidated when an audience grows
2026-10-04 05:14:34 +00:00
Claude
de230af27d
feat: advance campaigns.updated_at when a segment set change detaches linked segments in setForCampaignTx, including clearing the set, so the send-plan snapshot is invalidated after leads are withdrawn
2026-10-04 05:02:11 +00:00
Claude
51482769f5
feat: advance campaigns.updated_at when a campaign's senders are replaced and when a tag or folder-only update runs so the send-plan snapshot keyed on it is invalidated and stops being served with stale false
2026-10-04 04:48:44 +00:00
Claude
e2911fb01a
feat: say in the docs/public/openapi.json CampaignSendPlan stale description that a snapshot older than its maximum age is also served as stale when the campaign has not changed
2026-10-04 02:04:41 +00:00
Claude
e39ff8318d
feat: describe the stored send-plan snapshot in docs/public/openapi.json by adding the required stale flag and computed_at meaning to CampaignSendPlan and noting the background snapshot on GET /campaigns/{id}/send-plan
2026-10-04 02:01:51 +00:00
Matthew Meszaros
2032b0492c
Merge pull request #817 from warmbly/fix/microsoft-admin-consent
...
feat: Microsoft 365 organization grant through the v2.0 admin consent page, and an admin approval link for single-mailbox Outlook sign-in
v0.6.24
2026-10-03 18:38:25 +00:00
Matthew Meszaros
75840247c8
feat: replace the stored Outlook admin approval link on every Outlook sign-in start in useMailboxOAuth, clearing it when the start response carries none
2026-10-03 20:33:53 +02:00
Matthew Meszaros
8883a1df6b
feat: connect Microsoft 365 organizations through Microsoft's v2.0 admin consent page followed by a sign-in on the same state, read the approving admin's directory role from the Graph token as well as the ID token, return an organization-wide approval link for single-mailbox Outlook sign-in (admin_consent_url) and show it in the connect panel, and document publisher verification and the admin approval path
2026-10-03 20:17:38 +02:00
Matthew Meszaros
e43b9e837e
Merge pull request #816 from warmbly/docs/agent-qa-pr-video-research
...
feat: add the qa/ proof harness that records scripted Playwright flows as 1080p H.264 walkthroughs and stills against an isolated per-worktree stack and publishes them to the PR with gh --attach
2026-10-03 16:56:27 +00:00
Matthew Meszaros
efb9d0b433
feat: add the qa/ proof harness that records scripted Playwright flows as 1080p H.264 walkthroughs and stills against an isolated per-worktree stack (lite, full, sandbox) and publishes them to the PR with gh --attach, with before/after follow-up comments, a machine-wide recording lock, idle auto-stop, a qa-ci typecheck job and AGENTS.md rules for when to record
2026-10-03 09:54:59 -07:00