Commit Graph
3266 Commits
Author SHA1 Message Date
Matthew Meszaros fd940d905b feat: answer a click on a Slack approval card that carries no tool call with a private note to ask again or approve in the dashboard 2026-10-04 05:23:36 -07:00
Matthew Meszaros c5ff613c5d feat: start the invite-link clipboard write inside the click so Safari keeps the gesture, say that earlier copied links stop working, and show the new link when the copy fails 2026-10-04 05:23:16 -07:00
Matthew Meszaros df0949a019 feat: mask invite and next URL parameters in dashboard and admin analytics, clear a copied invite link when the invitation is sent again, and read hex.info's newest stable release without consuming the gate's package list 2026-10-04 05:22:40 -07:00
Matthew Meszaros 5083bcbd54 feat: carry webhook and OAuth app signing secrets still stored as whsec_ plaintext into a workspace export as is, so they arrive sealed under the destination key instead of blank 2026-10-04 05:21:56 -07:00
Matthew Meszaros 79bf9a15c4 feat: refuse a pasted list of addresses where one recipient address is expected, so no listed recipient is silently dropped 2026-10-04 05:21:36 -07:00
Matthew Meszaros 3de01f25b3 feat: gate MCP and /ai/tools per tool for keys and tokens, with AI_AGENT on the web and playbook tools, and require use_ai for member sessions on /ai/tools 2026-10-04 05:21:18 -07:00
Matthew Meszaros 8cb5893e37 feat: keep accepting API keys and OAuth tokens in the realtime socket URL as a deprecated fallback for existing clients, preferring the x-warmbly-token header and keeping the value out of logs 2026-10-04 05:20:20 -07:00
Matthew Meszaros ab39429e37 feat: send HSTS from the forms service only on FORMS_DOMAIN and strip it in the installer's Caddy block for customer-owned domains, so no customer apex is pinned to HTTPS 2026-10-04 05:19:22 -07:00
Matthew Meszaros c178dadf81 feat: keep the key and blob brokers on NODE_BROKER_TOKEN only, and let an operator admit INTERNAL_API_TOKEN on the other node routes with NODE_ACCEPT_INTERNAL_TOKEN=true while nodes joined before the split upgrade 2026-10-04 05:18:01 -07:00
Matthew Meszaros a6e72f1a92 feat: keep linking and unlinking Warmbly Cloud and adopting the cloud workspace's mailboxes with the instance administrator, and let members with manage_emails read the link and put their own workspace's mailboxes on it 2026-10-04 05:17:20 -07:00
Matthew Meszaros af1c6cdfcd feat: let a workspace import keep references that name another workspace's row by design (warmup partners, placement seeds, third-party OAuth apps) while every other reference must resolve to the importing workspace 2026-10-04 05:16:14 -07:00
Matthew Meszaros cbf0667d8f feat: hold every API key to its creator's current workspace role on each gated route and AI tool, and stop a key, including on the realtime socket, once its creator leaves the workspace (api_key_holder_left) 2026-10-04 05:15:30 -07:00
Matthew Meszaros 5d4b0ad6e5 feat: hold the invite_member, update_member_role and rotate_webhook_secret AI tools to the same recent confirmation their REST routes require, answering reauth_required on /ai/tools and refusing them where no confirmed session exists 2026-10-04 05:14:30 -07:00
Matthew Meszaros aca1aff4d6 feat: count a completed sign-in as a fresh confirmation for the first five minutes of the session, so accounts with no password or second factor can confirm an action by signing in again 2026-10-04 05:13:23 -07:00
Matthew Meszaros b9b13344b4 feat: remember the refresh token each OAuth grant last rotated away from (migration 000261) and revoke the grant when that token is presented again, whether in a race or after the rotation finished 2026-10-04 03:49:13 -07:00
Matthew Meszaros 8b842bd6f7 feat: give the mailbox erasure live test's snooze fixture its organization, which unibox_snoozes now requires 2026-10-04 03:48:12 -07:00
Matthew Meszaros 663c3013d1 feat: bind each Remie approval to its tool call and run it once, show every argument and the resolved send on dashboard and Slack approval cards, keep always-allow to settings managers with a revocable list and never for tools that start sending or change access, withhold secrets and unpermitted tool results from the assistant and shared conversations, gate /mcp, /ai/tools and the web and playbook tools on AI_AGENT or use_ai, and scope get_mailbox by organization 2026-10-04 03:45:02 -07:00
Matthew Meszaros 886756ae0f feat: share one api_key_mailbox_limited code and keyMailboxLimited check across the campaign, AI tool and MCP handlers 2026-10-04 03:43:26 -07:00
Matthew Meszaros b9d96825a2 feat: require an admin to hold every admin permission a grant or revoke takes away from another admin, and keep the last super admin through a grant that would replace the role 2026-10-04 03:43:10 -07:00
Matthew Meszaros 3a360ad422 feat: list golang.org/x/sync as a direct dependency in go.mod, matching the singleflight import in internal/app/integration 2026-10-04 03:42:48 -07:00
Matthew Meszaros 35635afeff feat: refuse to store webhook and OAuth app signing secrets without CREDENTIALS_ENCRYPTION_KEY and never hand out an unreadable sealed secret, require TLS 1.2 on IMAP sync connections, compare the first-run setup token in constant time, and serve customer-owned domains from the installer's Caddy without HSTS 2026-10-04 03:42:36 -07:00
Matthew Meszaros 14df35e54c feat: compare OAuth client secrets and PKCE challenges in constant time, draw integration OAuth state and verifiers from crypto/rand with no fallback, and fetch the Salesforce identity URL only from a Salesforce host 2026-10-04 03:40:04 -07:00
Matthew Meszaros 3c45c3764c feat: mask token, session, agent_session and code URL parameters in admin panel analytics the same way the dashboard does 2026-10-04 03:38:02 -07:00
Matthew Meszaros a6b72299ae feat: store workspace invitation tokens only as SHA-256 digests (migration 000260 converts pending ones), mint a separate link token each time a manager copies an invite link so the emailed link keeps working, and resolve invitations by either digest 2026-10-04 03:37:41 -07:00
Matthew Meszaros 89c063e718 feat: state in AGENTS.md that every node-only internal route takes NODE_BROKER_TOKEN and the edge token reaches only tracked links, domain redirects, page hits and forms 2026-10-04 03:25:03 -07:00
Matthew Meszaros 497f58bb5a feat: hold a mailbox-limited API key to explicit sender lists of its own mailboxes when it creates, edits or starts a campaign, and refuse it on /ai/tools and /mcp, which act across the workspace, with api_key_mailbox_limited 2026-10-04 03:24:25 -07:00
Matthew Meszaros af912e3b8d feat: narrow the unibox overview's per-tag counts for a mailbox-limited key on the message join so every tag still lists, and keep the query's static prefix preparable 2026-10-04 03:22:09 -07:00
Matthew Meszaros a70811f56a feat: write the mailbox connect and reauth audit entry under the mailbox's own organization when an OAuth flow finishes, so its spine event reaches that workspace 2026-10-04 03:22:09 -07:00
Matthew Meszaros 48c65611b5 feat: require view_contacts / READ_CONTACTS for an AI variable preview rendered against a named contact, matching test sends and template previews 2026-10-04 03:22:09 -07:00
Matthew Meszaros 137f7359ff feat: accept an A/B variant's step_id only when the step belongs to the campaign named in the path 2026-10-04 03:22:09 -07:00
Matthew Meszaros 1c555934a5 feat: authorize warmup ban status and warmup appeals by the caller's organization and its view_campaigns / manage_emails gates, so any member who manages mailboxes can appeal, answering 404 for a mailbox outside the workspace 2026-10-04 03:22:09 -07:00
Matthew Meszaros 6c36be44aa feat: require the actor to hold every permission a role edit, re-role or member removal takes away as well as every one it grants, matching role deletion, with the workspace owner holding all permissions 2026-10-04 03:22:09 -07:00
Matthew Meszaros 5f180f5c76 feat: hold an API key with allowed_email_accounts to its mailboxes across the unibox (list, thread, message, count and overview reads; compose with auto pick within the list, drafts, agent-draft approve and discard, seen, folder, labels and snooze writes), campaign sender pools, analytics account statuses and GET /analytics/accounts/:id, and store a compose draft's mailbox only when it belongs to the caller's organization 2026-10-04 03:22:09 -07:00
Matthew Meszaros 5146ab5a2c feat: name migration 000258 as the source of the tracking host verification trigger 2026-10-04 03:22:09 -07:00
Matthew Meszaros ec77a3e3d2 feat: key unibox snoozes by organization as well as user and thread (migration 000259 backfills from each thread's mailbox organization), scope every snooze read and write and the org-transfer scope to it, and resolve unibox list cursors only within the caller's organization or user 2026-10-04 03:22:09 -07:00
Matthew Meszaros 043d877b58 feat: let one organization per instance verify a custom tracking host across mailbox and campaign tracking domains (database trigger plus 409 tracking_domain_taken on save, verify, sending-domain apply and bulk setup; the sweep leaves a held host unverified), and re-verify tracking domains on the destination after a workspace import 2026-10-04 03:22:02 -07:00
Matthew Meszaros 9d461ad40e feat: gate advisor apply and undo on view_analytics / READ_ANALYTICS and run the fix as the caller: a member under their org permissions, or an API key or OAuth grant under its own scope mask, with a fix for a mailbox outside the key's allowlist refused 2026-10-04 03:21:58 -07:00
Matthew Meszaros e852a106a9 feat: serve every node-only internal route (data keys, message map, sync lookups, worker config, fleet heartbeat) on NODE_BROKER_TOKEN and leave only tracked links, domain redirects, page hits and forms on INTERNAL_API_TOKEN, render nodes only the node token when one is set, and have the installer generate a distinct NODE_BROKER_TOKEN for new installs and its own UPDATER_TOKEN 2026-10-04 03:21:58 -07:00
Matthew Meszaros fba5997922 feat: type the mirrored HubSpot deal status parameter once so the deal mirror update prepares, and let the org transfer order check pass references that ResetOnImport blanks 2026-10-04 03:05:26 -07:00
Matthew Meszaros eec8e1095e feat: escape Slack's reserved characters in every text field of the automation Slack card, quote backslashes and double quotes in the Close lead lookup, and route Salesforce automation and push writes only through the native Salesforce sync by removing the unused direct SOQL fallback 2026-10-04 03:04:03 -07:00
Matthew Meszaros 79510c06a8 feat: render workspace and inviter names on the public invitation preview through displayname with the invitation email's fallbacks, and show a community app's developer name in the directory only when it is displayable 2026-10-04 03:03:52 -07:00
Matthew Meszaros e3f21146a4 feat: hold mailbox display names to the person naming rules by refusing a rename that breaks them with invalid_name, replacing one from SMTP/IMAP onboarding and import files with an address-derived name, and sending warmup under a displayable name with an address fallback 2026-10-04 03:03:52 -07:00
Matthew Meszaros 3d1e117ea6 feat: show campaign names in auto-pause and provider-refusal notifications through displayname.DisplayableOr with a neutral fallback, and leave an inbound reply's subject out of notification emails while the in-app feed keeps it 2026-10-04 03:03:52 -07:00
Matthew Meszaros 12563982cc feat: pass pool-link instance names and CLI device-code client names and hostnames through the workspace naming rules with displayname.CleanOr, falling back to Self-hosted instance and Warmbly CLI, keep only the machine label of a CLI hostname, and clip versions on rune boundaries 2026-10-04 03:03:52 -07:00
Matthew Meszaros 147491ed3c feat: disable imported webhook endpoints whose address fails the same https and public-host check a new endpoint must pass, and document it on the workspace export and import page 2026-10-04 03:03:40 -07:00
Matthew Meszaros 1c29643ecb feat: re-apply the app and form write rules to workspace imports so imported OAuth apps get displayname-checked names, http(s) websites, valid redirect URIs and webhooks, only their workspace's own logos, and stay suspended when suspended at the source or imported under a developer block, imported forms keep only http(s) redirect URLs, valid designs and embed domains, and the hosted form page navigates only to http(s) redirect targets 2026-10-04 03:03:40 -07:00
Matthew Meszaros eff2c14a9d feat: make workspace import write only rows the destination workspace owns by checking every archive key and foreign key against each table's owner scope before a batch lands, scoping overwrite updates to the destination's own rows, warning in the archive check, and documenting the rule 2026-10-04 03:03:34 -07:00
Matthew Meszaros 43a9d004f2 feat: bound user-authored templates (range only over data fields, two-deep nesting, no template calls, 1 MiB output, capped compile cache) for campaign and automation rendering, accept only single addresses and single Message-IDs for to/cc/bcc/in_reply_to on every send path with invalid_recipient and invalid_message_id, refuse multi-line headers in the Gmail, Graph and SMTP writers, always apply a no-script CSP and drop non-http(s)/mailto/tel link targets in email previews, treat only single-slash paths as internal Remie links, accept integration OAuth callbacks only from the API origin, and follow only http(s) form redirects and app install links 2026-10-04 03:02:37 -07:00
Matthew Meszaros 8d0a281934 feat: name AdminMiddleware as the admin second-factor gate in AGENTS.md and note that the instance-wide Cloud link sits behind it 2026-10-04 03:02:22 -07:00
Matthew Meszaros ff54338806 feat: keep every deal in the pipeline its stage belongs to on create and update, validate pipeline stage names and colours in the CRM service for every caller, bound the AI bulk contact edit to MaxContactBatchIDs parsed ids, and start placement tests for API-key callers only through the REST route that applies the key's mailbox limits 2026-10-04 03:02:15 -07:00