Matthew Meszaros
|
fd940d905b
|
feat: answer a click on a Slack approval card that carries no tool call with a private note to ask again or approve in the dashboard
|
2026-10-04 05:23:36 -07:00 |
|
Matthew Meszaros
|
c5ff613c5d
|
feat: start the invite-link clipboard write inside the click so Safari keeps the gesture, say that earlier copied links stop working, and show the new link when the copy fails
|
2026-10-04 05:23:16 -07:00 |
|
Matthew Meszaros
|
df0949a019
|
feat: mask invite and next URL parameters in dashboard and admin analytics, clear a copied invite link when the invitation is sent again, and read hex.info's newest stable release without consuming the gate's package list
|
2026-10-04 05:22:40 -07:00 |
|
Matthew Meszaros
|
5083bcbd54
|
feat: carry webhook and OAuth app signing secrets still stored as whsec_ plaintext into a workspace export as is, so they arrive sealed under the destination key instead of blank
|
2026-10-04 05:21:56 -07:00 |
|
Matthew Meszaros
|
79bf9a15c4
|
feat: refuse a pasted list of addresses where one recipient address is expected, so no listed recipient is silently dropped
|
2026-10-04 05:21:36 -07:00 |
|
Matthew Meszaros
|
3de01f25b3
|
feat: gate MCP and /ai/tools per tool for keys and tokens, with AI_AGENT on the web and playbook tools, and require use_ai for member sessions on /ai/tools
|
2026-10-04 05:21:18 -07:00 |
|
Matthew Meszaros
|
8cb5893e37
|
feat: keep accepting API keys and OAuth tokens in the realtime socket URL as a deprecated fallback for existing clients, preferring the x-warmbly-token header and keeping the value out of logs
|
2026-10-04 05:20:20 -07:00 |
|
Matthew Meszaros
|
ab39429e37
|
feat: send HSTS from the forms service only on FORMS_DOMAIN and strip it in the installer's Caddy block for customer-owned domains, so no customer apex is pinned to HTTPS
|
2026-10-04 05:19:22 -07:00 |
|
Matthew Meszaros
|
c178dadf81
|
feat: keep the key and blob brokers on NODE_BROKER_TOKEN only, and let an operator admit INTERNAL_API_TOKEN on the other node routes with NODE_ACCEPT_INTERNAL_TOKEN=true while nodes joined before the split upgrade
|
2026-10-04 05:18:01 -07:00 |
|
Matthew Meszaros
|
a6e72f1a92
|
feat: keep linking and unlinking Warmbly Cloud and adopting the cloud workspace's mailboxes with the instance administrator, and let members with manage_emails read the link and put their own workspace's mailboxes on it
|
2026-10-04 05:17:20 -07:00 |
|
Matthew Meszaros
|
af1c6cdfcd
|
feat: let a workspace import keep references that name another workspace's row by design (warmup partners, placement seeds, third-party OAuth apps) while every other reference must resolve to the importing workspace
|
2026-10-04 05:16:14 -07:00 |
|
Matthew Meszaros
|
cbf0667d8f
|
feat: hold every API key to its creator's current workspace role on each gated route and AI tool, and stop a key, including on the realtime socket, once its creator leaves the workspace (api_key_holder_left)
|
2026-10-04 05:15:30 -07:00 |
|
Matthew Meszaros
|
5d4b0ad6e5
|
feat: hold the invite_member, update_member_role and rotate_webhook_secret AI tools to the same recent confirmation their REST routes require, answering reauth_required on /ai/tools and refusing them where no confirmed session exists
|
2026-10-04 05:14:30 -07:00 |
|
Matthew Meszaros
|
aca1aff4d6
|
feat: count a completed sign-in as a fresh confirmation for the first five minutes of the session, so accounts with no password or second factor can confirm an action by signing in again
|
2026-10-04 05:13:23 -07:00 |
|
Matthew Meszaros
|
b9b13344b4
|
feat: remember the refresh token each OAuth grant last rotated away from (migration 000261) and revoke the grant when that token is presented again, whether in a race or after the rotation finished
|
2026-10-04 03:49:13 -07:00 |
|
Matthew Meszaros
|
8b842bd6f7
|
feat: give the mailbox erasure live test's snooze fixture its organization, which unibox_snoozes now requires
|
2026-10-04 03:48:12 -07:00 |
|
Matthew Meszaros
|
663c3013d1
|
feat: bind each Remie approval to its tool call and run it once, show every argument and the resolved send on dashboard and Slack approval cards, keep always-allow to settings managers with a revocable list and never for tools that start sending or change access, withhold secrets and unpermitted tool results from the assistant and shared conversations, gate /mcp, /ai/tools and the web and playbook tools on AI_AGENT or use_ai, and scope get_mailbox by organization
|
2026-10-04 03:45:02 -07:00 |
|
Matthew Meszaros
|
886756ae0f
|
feat: share one api_key_mailbox_limited code and keyMailboxLimited check across the campaign, AI tool and MCP handlers
|
2026-10-04 03:43:26 -07:00 |
|
Matthew Meszaros
|
b9d96825a2
|
feat: require an admin to hold every admin permission a grant or revoke takes away from another admin, and keep the last super admin through a grant that would replace the role
|
2026-10-04 03:43:10 -07:00 |
|
Matthew Meszaros
|
3a360ad422
|
feat: list golang.org/x/sync as a direct dependency in go.mod, matching the singleflight import in internal/app/integration
|
2026-10-04 03:42:48 -07:00 |
|
Matthew Meszaros
|
35635afeff
|
feat: refuse to store webhook and OAuth app signing secrets without CREDENTIALS_ENCRYPTION_KEY and never hand out an unreadable sealed secret, require TLS 1.2 on IMAP sync connections, compare the first-run setup token in constant time, and serve customer-owned domains from the installer's Caddy without HSTS
|
2026-10-04 03:42:36 -07:00 |
|
Matthew Meszaros
|
14df35e54c
|
feat: compare OAuth client secrets and PKCE challenges in constant time, draw integration OAuth state and verifiers from crypto/rand with no fallback, and fetch the Salesforce identity URL only from a Salesforce host
|
2026-10-04 03:40:04 -07:00 |
|
Matthew Meszaros
|
3c45c3764c
|
feat: mask token, session, agent_session and code URL parameters in admin panel analytics the same way the dashboard does
|
2026-10-04 03:38:02 -07:00 |
|
Matthew Meszaros
|
a6b72299ae
|
feat: store workspace invitation tokens only as SHA-256 digests (migration 000260 converts pending ones), mint a separate link token each time a manager copies an invite link so the emailed link keeps working, and resolve invitations by either digest
|
2026-10-04 03:37:41 -07:00 |
|
Matthew Meszaros
|
89c063e718
|
feat: state in AGENTS.md that every node-only internal route takes NODE_BROKER_TOKEN and the edge token reaches only tracked links, domain redirects, page hits and forms
|
2026-10-04 03:25:03 -07:00 |
|
Matthew Meszaros
|
497f58bb5a
|
feat: hold a mailbox-limited API key to explicit sender lists of its own mailboxes when it creates, edits or starts a campaign, and refuse it on /ai/tools and /mcp, which act across the workspace, with api_key_mailbox_limited
|
2026-10-04 03:24:25 -07:00 |
|
Matthew Meszaros
|
af912e3b8d
|
feat: narrow the unibox overview's per-tag counts for a mailbox-limited key on the message join so every tag still lists, and keep the query's static prefix preparable
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
a70811f56a
|
feat: write the mailbox connect and reauth audit entry under the mailbox's own organization when an OAuth flow finishes, so its spine event reaches that workspace
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
48c65611b5
|
feat: require view_contacts / READ_CONTACTS for an AI variable preview rendered against a named contact, matching test sends and template previews
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
137f7359ff
|
feat: accept an A/B variant's step_id only when the step belongs to the campaign named in the path
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
1c555934a5
|
feat: authorize warmup ban status and warmup appeals by the caller's organization and its view_campaigns / manage_emails gates, so any member who manages mailboxes can appeal, answering 404 for a mailbox outside the workspace
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
6c36be44aa
|
feat: require the actor to hold every permission a role edit, re-role or member removal takes away as well as every one it grants, matching role deletion, with the workspace owner holding all permissions
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
5f180f5c76
|
feat: hold an API key with allowed_email_accounts to its mailboxes across the unibox (list, thread, message, count and overview reads; compose with auto pick within the list, drafts, agent-draft approve and discard, seen, folder, labels and snooze writes), campaign sender pools, analytics account statuses and GET /analytics/accounts/:id, and store a compose draft's mailbox only when it belongs to the caller's organization
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
5146ab5a2c
|
feat: name migration 000258 as the source of the tracking host verification trigger
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
ec77a3e3d2
|
feat: key unibox snoozes by organization as well as user and thread (migration 000259 backfills from each thread's mailbox organization), scope every snooze read and write and the org-transfer scope to it, and resolve unibox list cursors only within the caller's organization or user
|
2026-10-04 03:22:09 -07:00 |
|
Matthew Meszaros
|
043d877b58
|
feat: let one organization per instance verify a custom tracking host across mailbox and campaign tracking domains (database trigger plus 409 tracking_domain_taken on save, verify, sending-domain apply and bulk setup; the sweep leaves a held host unverified), and re-verify tracking domains on the destination after a workspace import
|
2026-10-04 03:22:02 -07:00 |
|
Matthew Meszaros
|
9d461ad40e
|
feat: gate advisor apply and undo on view_analytics / READ_ANALYTICS and run the fix as the caller: a member under their org permissions, or an API key or OAuth grant under its own scope mask, with a fix for a mailbox outside the key's allowlist refused
|
2026-10-04 03:21:58 -07:00 |
|
Matthew Meszaros
|
e852a106a9
|
feat: serve every node-only internal route (data keys, message map, sync lookups, worker config, fleet heartbeat) on NODE_BROKER_TOKEN and leave only tracked links, domain redirects, page hits and forms on INTERNAL_API_TOKEN, render nodes only the node token when one is set, and have the installer generate a distinct NODE_BROKER_TOKEN for new installs and its own UPDATER_TOKEN
|
2026-10-04 03:21:58 -07:00 |
|
Matthew Meszaros
|
fba5997922
|
feat: type the mirrored HubSpot deal status parameter once so the deal mirror update prepares, and let the org transfer order check pass references that ResetOnImport blanks
|
2026-10-04 03:05:26 -07:00 |
|
Matthew Meszaros
|
eec8e1095e
|
feat: escape Slack's reserved characters in every text field of the automation Slack card, quote backslashes and double quotes in the Close lead lookup, and route Salesforce automation and push writes only through the native Salesforce sync by removing the unused direct SOQL fallback
|
2026-10-04 03:04:03 -07:00 |
|
Matthew Meszaros
|
79510c06a8
|
feat: render workspace and inviter names on the public invitation preview through displayname with the invitation email's fallbacks, and show a community app's developer name in the directory only when it is displayable
|
2026-10-04 03:03:52 -07:00 |
|
Matthew Meszaros
|
e3f21146a4
|
feat: hold mailbox display names to the person naming rules by refusing a rename that breaks them with invalid_name, replacing one from SMTP/IMAP onboarding and import files with an address-derived name, and sending warmup under a displayable name with an address fallback
|
2026-10-04 03:03:52 -07:00 |
|
Matthew Meszaros
|
3d1e117ea6
|
feat: show campaign names in auto-pause and provider-refusal notifications through displayname.DisplayableOr with a neutral fallback, and leave an inbound reply's subject out of notification emails while the in-app feed keeps it
|
2026-10-04 03:03:52 -07:00 |
|
Matthew Meszaros
|
12563982cc
|
feat: pass pool-link instance names and CLI device-code client names and hostnames through the workspace naming rules with displayname.CleanOr, falling back to Self-hosted instance and Warmbly CLI, keep only the machine label of a CLI hostname, and clip versions on rune boundaries
|
2026-10-04 03:03:52 -07:00 |
|
Matthew Meszaros
|
147491ed3c
|
feat: disable imported webhook endpoints whose address fails the same https and public-host check a new endpoint must pass, and document it on the workspace export and import page
|
2026-10-04 03:03:40 -07:00 |
|
Matthew Meszaros
|
1c29643ecb
|
feat: re-apply the app and form write rules to workspace imports so imported OAuth apps get displayname-checked names, http(s) websites, valid redirect URIs and webhooks, only their workspace's own logos, and stay suspended when suspended at the source or imported under a developer block, imported forms keep only http(s) redirect URLs, valid designs and embed domains, and the hosted form page navigates only to http(s) redirect targets
|
2026-10-04 03:03:40 -07:00 |
|
Matthew Meszaros
|
eff2c14a9d
|
feat: make workspace import write only rows the destination workspace owns by checking every archive key and foreign key against each table's owner scope before a batch lands, scoping overwrite updates to the destination's own rows, warning in the archive check, and documenting the rule
|
2026-10-04 03:03:34 -07:00 |
|
Matthew Meszaros
|
43a9d004f2
|
feat: bound user-authored templates (range only over data fields, two-deep nesting, no template calls, 1 MiB output, capped compile cache) for campaign and automation rendering, accept only single addresses and single Message-IDs for to/cc/bcc/in_reply_to on every send path with invalid_recipient and invalid_message_id, refuse multi-line headers in the Gmail, Graph and SMTP writers, always apply a no-script CSP and drop non-http(s)/mailto/tel link targets in email previews, treat only single-slash paths as internal Remie links, accept integration OAuth callbacks only from the API origin, and follow only http(s) form redirects and app install links
|
2026-10-04 03:02:37 -07:00 |
|
Matthew Meszaros
|
8d0a281934
|
feat: name AdminMiddleware as the admin second-factor gate in AGENTS.md and note that the instance-wide Cloud link sits behind it
|
2026-10-04 03:02:22 -07:00 |
|
Matthew Meszaros
|
ff54338806
|
feat: keep every deal in the pipeline its stage belongs to on create and update, validate pipeline stage names and colours in the CRM service for every caller, bound the AI bulk contact edit to MaxContactBatchIDs parsed ids, and start placement tests for API-key callers only through the REST route that applies the key's mailbox limits
|
2026-10-04 03:02:15 -07:00 |
|