Commit Graph
156 Commits
Author SHA1 Message Date
Matthew Meszaros 663c3013d1 feat: bind each Remie approval to its tool call and run it once, show every argument and the resolved send on dashboard and Slack approval cards, keep always-allow to settings managers with a revocable list and never for tools that start sending or change access, withhold secrets and unpermitted tool results from the assistant and shared conversations, gate /mcp, /ai/tools and the web and playbook tools on AI_AGENT or use_ai, and scope get_mailbox by organization 2026-10-04 03:45:02 -07:00
Matthew Meszaros bf47984cd5 feat: cap every OAuth grant and API key at the delegating member's role (consent narrows scopes and reports the withheld ones, tokens re-check the member's current role at every gate and MCP tool, keys stay within their creator's permissions, mailboxes and IP allowlist), keep OAuth tokens off API key and OAuth app management, require a fresh sign-in to approve an app, revoke a grant whose refresh token is presented twice, count only unexpired grants as installs, seal app webhook secrets under the instance key, name the workspace and flag unverified apps on the consent screen, and let credential managers list and revoke every member's app authorizations 2026-10-04 02:59:10 -07:00
Matthew Meszaros 8bb60e9449 feat: accept only Salesforce domains as an org's API host and call it through the SSRF-guarded client, register the Warmbly Cloud link only on self-hosted instances behind the instance admin with a second factor and dial it through safehttp with fixed error text, keep automation signing secrets in the sealed connection config, answer integration service failures with fixed messages, add security headers to the forms, tracking and docs origins and TLS 1.2+ to the nginx template, compare the captcha bypass in constant time, require TLS 1.2 for IMAP probes, and drop the unused RSA helpers 2026-10-04 02:58:43 -07:00
Matthew Meszaros 3a2d80b8bf feat: accept realtime API keys and OAuth tokens only in the x-warmbly-token handshake header with the ws ticket alone in the query string, filter token and key params from Phoenix connect logs, refuse realtime keys, OAuth tokens and pool link tokens held by a login-banned user or a suspended app with an uncached key check, and send the key as a header from warmbly events tail 2026-10-04 02:56:18 -07:00
Matthew Meszaros f0ec39febd feat: scope automation and sequence unsubscribes to the caller's organization, require manage_settings to create, edit, enable or delete automations, run each integration action only on its own provider's connection (400 action_provider_mismatch), refuse org-permission gates when no organization service is wired, read /integrations/bookings like contacts, scope lead claims, research runs and CRM list cursors to the organization, and bind contact note edits to the contact in the path 2026-10-04 02:47:10 -07:00
Matthew Meszaros bc9caba267 feat: validate OAuth app names through displayname and websites as http(s), clean dynamically registered client names and stop storing their logo_uri, refuse edits and logo uploads on suspended apps or blocked developers, scope logo deletion to the app's own images, keep hidden listings from being unpublished, count only installs from other aged workspaces toward the directory threshold, refresh integration popularity outside the lock, and count only live connections in the Integrations store 2026-10-04 01:10:39 -07:00
Matthew Meszaros 4bc2417618 Merge remote-tracking branch 'origin/main' into feature/integrations-page-redesign
# Conflicts:
#	docs/content/docs/api/error-codes.mdx
#	docs/content/docs/guides/integrations.mdx
#	web/src/app/app/integrations/page.tsx
2026-10-04 00:32:54 -07:00
Matthew Meszaros 7555f641a5 feat: turn Integrations into an app store with sidebar views, search, sorting and filters, list community apps by link until featured or widely installed, redesign the OAuth app registration dialog, store app logos re-encoded per app like the workspace logo, and add admin suspension, token revocation and developer blocks for OAuth apps 2026-10-04 00:31:52 -07:00
Claude e2911fb01a feat: say in the docs/public/openapi.json CampaignSendPlan stale description that a snapshot older than its maximum age is also served as stale when the campaign has not changed 2026-10-04 02:04:41 +00:00
Claude e39ff8318d feat: describe the stored send-plan snapshot in docs/public/openapi.json by adding the required stale flag and computed_at meaning to CampaignSendPlan and noting the background snapshot on GET /campaigns/{id}/send-plan 2026-10-04 02:01:51 +00:00
Matthew Meszaros 4957214431 feat: redesign the Integrations page with search, category chips, recommended and popularity-ranked integrations, add a community app directory where OAuth apps are published unverified by link and verified in a new admin review queue, with docs and OpenAPI 2026-10-03 09:24:34 -07:00
Claude 3288238cc0 feat: paginate and batch GET /analytics/accounts so account status reads are bounded per page and the overflow past 1000 mailboxes is reachable via cursor 2026-10-03 06:46:20 +00:00
Matthew Meszaros a84b3bbbf3 feat: mark only a conversation's newest received message unread on Mark as unread, never a sent or draft copy, from the reader, the row menu, the selection bar, PATCH /unibox/seen and the mark_thread_seen AI tool, with the guide and API docs updated 2026-10-01 22:22:56 -07:00
Matthew Meszaros e920b61371 feat: clear a reported warmup send failure only on a confirmed delivery, word the not-loaded send failure as a possible cause, leave placement seeds out of the adopted-mailbox warmup repair, and describe send_failure as a failure reason in the API schema 2026-10-01 03:20:41 -07:00
Matthew Meszaros a844c506a0 feat: make Warmbly Cloud warmup start and explain itself for linked mailboxes: apply the instance's warmup settings, start warmup on adopted mailboxes, read the warmup day mask Monday-first, report the last refused warmup send and the partner cap to the instance and dashboard, hand changed SMTP credentials to the cloud, refuse cleartext mailboxes at enrollment, and show cloud warmup with the warming animation and a clear Cloud marker 2026-10-01 03:01:36 -07:00
Matthew Meszaros d64adcc191 Merge remote-tracking branch 'origin/main' into feat/cloud-domain-redirects 2026-09-30 07:18:51 -07:00
Matthew Meszaros e9b802e99c feat: insert the received-mail CSP into the parsed document's real head, tie remote-image consent to the message it was given for, check every RevokeOnRefreshReuse error in the live test, and name the signing-key length refusal in the OpenAPI 400 2026-09-30 07:01:13 -07:00
Matthew Meszaros 75f764dc67 feat: require a verified Cloud Tasks token with a pinned audience on task webhooks, manage_settings on integration OAuth and a fresh membership check at every mailbox and integration OAuth finish, user verification for passkey sign-in, ended sessions before a password reset or ban reports success, and a revoked session when a rotated refresh token is replayed; remove the internal DEK delete route, log credential path parameters by name, hold remote images in received mail until the reader loads them, add Calendly and Cal.com signing keys with inbound URL rotation, keep automation signing secrets out of connection responses, and apply the password rules to the bootstrap password 2026-09-30 06:46:24 -07:00
Matthew Meszaros 41d43f64be feat: check that a verified root redirect actually reaches visitors by opening the domain over http and https and naming what answered instead (Traefik, nginx, Caddy, a rewritten Host header, a missing certificate, a closed port) with per-proxy fix steps in the sending domain drawer, and let a self-hosted instance linked to Warmbly Cloud have Cloud serve and certify its redirects (connect in place from the redirect tab, the bulk dialog or a page banner), with Cloud-side linked-instance redirect endpoints under a per-instance limit, migration 000237, labelled tracking answers and a 503 when the redirect lookup is unavailable, and the sending domains, Warmbly Cloud, data control, install, OpenAPI, API and error code docs updated 2026-09-30 06:04:00 -07:00
Matthew Meszaros 1f0c6ca6d6 feat: send each mailbox's reply-to as a Reply-To header on campaign, unibox, test and placement mail (never warmup), record it on every campaign send attempt (tasks.reply_to, migration 000236) and credit a reply landing in that shared reply inbox to the campaign and its sending mailbox across reply attribution, the sync priority lane and copied-contact replies, show the sending mailbox on thread messages, recent activity and the reply webhook, start unibox and inbox-agent replies from the mailbox that emailed the contact, flag an untracked reply-to in mailbox settings, let the sandbox simulator answer Reply-To, and document the shared reply inbox (#756) 2026-09-30 05:33:34 -07:00
Matthew Meszaros b2d6d100dd feat: relay unibox Archive, Delete and Move to inbox to the mailbox itself through a new MESSAGE_FOLDER worker command (Gmail label batchModify, Outlook well-known folder moves with the message map re-keyed around each Graph id change, IMAP MOVE after locating each message by Message-ID), answered by relayed UPDATE_FOLDER events that write only provider_folder and the moved handles, relaying every row a filing moved so an Undo right after Archive still reaches the mailbox, with a per-mailbox Mirror Archive and Delete switch (email_accounts.relay_folder_moves, migration 000235, on by default), warmup receipts, drafts and non-Gmail sent copies left in place, and the unibox, mailboxes, API, events and OpenAPI docs updated 2026-09-30 04:41:03 -07:00
Matthew Meszaros 045d13d281 feat: let segment membership writes take the same contact selection limits as every other bulk action, raise select-all to 250,000 contacts and explicit id batches to 10,000, check the research batch cap in the dashboard before confirming, and document the new limits in the guides, error codes and OpenAPI spec 2026-09-30 06:13:14 +02:00
Matthew Meszaros 80ecadb1e6 Merge remote-tracking branch 'origin/main' into feature/batch-inbox-placement-tests 2026-09-29 10:51:41 -07:00
Matthew Meszaros d99a09825f feat: run one inbox placement test across many sending mailboxes as a placement batch (issue #736): server-side sender scopes (a campaign's senders or the whole workspace, filtered by provider, domain, tag and untested days) and sampling (random, percent stratified by provider or domain, per domain, per provider) snapshotted at creation, a runner that starts senders under per-workspace and instance-wide concurrency and a start rate with defer or skip for unavailable mailboxes, aggregate placement by sending domain, sending provider and recipient provider, fleet coverage, cancel, credits agreed per batch, org transfer, operator settings in the admin panel, dashboard pages and dialog, CLI commands, agent tools, OpenAPI and docs 2026-09-29 10:19:46 -07:00
Matthew Meszaros 0ed98a8c55 feat: copy up to two colleagues on every email a campaign sends one lead (campaign_lead_cc, migrations 000230-000231) with a drawer CC editor that suggests same-company contacts, hold a copied contact's own lead so nobody gets two threads, count a copy's reply as the lead's, opt out every copy on a link unsubscribe, drop a bounced or refused copy without bouncing the lead, skip suppressed campaign CC and BCC addresses, and document the endpoints, CLI, skills and OpenAPI 2026-09-29 09:53:27 -07:00
Matthew Meszaros 4c1fc9604b Merge pull request #729 from warmbly/fix/cloud-warmup-standing-gates
feat: hold Warmbly Cloud's warmup standing on a linked self-hosted instance so campaign gates, pacing, lifecycle and account health enforce a cloud quarantine, block or throttle
2026-09-28 17:58:49 +00:00
Matthew Meszaros 53327384b7 feat: carry review-required cloud blocks and the later end of an equal cloud hold into the local pool, keep a cloud hold through a failed unenroll, leave standing changes to the sync so each fires its webhook, skip unchanged standings, read risk bands through the standing-aware health read, report failed standing syncs on the job panel, and document the source field in openapi.json 2026-09-28 09:05:11 -07:00
Matthew Meszaros b3518dd775 feat: resolve the unibox contact panel's sender through the thread's campaign send when the reply comes from an address that is not a contact (alias, second domain, forward, or another workspace mailbox), via thread_id and account_id on GET /contacts/lookup with a match field, gated on unibox access and the API key mailbox allowlist, show a Replied from line and keep a loaded contact on a failed refetch, skip every workspace mailbox when picking the other party, apply the same match to Pause follow-ups when answering the sender, and document it 2026-09-28 09:03:19 -07:00
Matthew Meszaros 6108ef8255 feat: show each mailbox's own profile photo in its drawer header (read at a Microsoft connect, through Google and Microsoft admin grants, and from Zapmail and InboxKit listings, stored as a re-encoded JPEG under avatars/mailboxes with a weekly refresh, migration 000227 and workspace export support), bring back the classic Accounts mailbox cell as two lines with provider-logo avatars and vendor, grant or host chips, and replace the pulsing status and health dots with a text shimmer on live and at-risk states 2026-09-28 08:04:48 -07:00
Matthew Meszaros f8221384f6 feat: let contact file uploads use their own 50 MB cap instead of the global 10 MB one and say when a file is too large, refuse an import list limit below one, hold an imported update to the contact size limit, keep a company logo laid out while it lazy-loads, neutralize formula cells in the sync error download, settle the draft save indicator when an edit is undone, and document the draft save route 2026-09-27 22:10:02 -07:00
Matthew Meszaros f4f219b7c5 feat: run contact file imports as background jobs (upload once, a whole-file check of new, existing, repeated and invalid rows, a chunked leased runner with live CONTACT_IMPORT_PROGRESS, history, cancel, a draft that autosaves and survives a reload, remembered mappings, and a failed-rows CSV under the file's own headers), match existing contacts across the workspace, batch updates and fail a bad row alone, keep imported verdicts on update, scope every import write to the importing workspace, rebuild the import wizard with icons and inline segment creation, show company logos and the inbox provider on the contact avatar, and hide contact columns the list has no data for 2026-09-27 21:50:10 -07:00
Matthew Meszaros b716164393 feat: settle every finished paid placement test once with the credits it got back recorded, refund an ambiguous charge's own key and clean up after a refused charge past request cancellation, net keyed refunds against the charge they return in spend windows, leave an unreadable balance to the server, show the server's seed and budget refusals, and renumber the migration to 000224 after 000223 landed on main 2026-09-27 21:17:40 -07:00
Matthew Meszaros 62fac73c3d feat: write a paid placement test before charging it and roll it back on a refused charge, take the agreed price as max_credits, refuse hand-picked seeds the sender's day cannot cover or that are not connected by name, refund only what a monthly reset has not expired and net refunds out of spend limits, bound the refund pass with a partial index, and re-filter a cloud panel's seeds by provider 2026-09-27 21:16:12 -07:00
Matthew Meszaros 4924d2c88d feat: let a placement test target chosen seed inboxes or providers, add a quick pace that sends copies seconds apart, charge credits with explicit consent for tests past the monthly free allowance with automatic refunds for tests that deliver nothing, and add a Seeds picker to the compose window 2026-09-27 21:16:12 -07:00
Matthew Meszaros 25075fcdd8 feat: take the warmup inbox rate and its daily rolling line at Google, Microsoft and Yahoo only (small hosts ride beside it and never make the headline), and rebuild the Accounts mailbox list in the Leads style with host logos, sender and connection line, a status naming whether the mailbox is sending, warming or both, sortable Sent today, animated Warmup, Inbox and pulsing Health columns, with docs and OpenAPI updated 2026-09-27 20:40:45 -07:00
Matthew Meszaros 49e7fec849 Merge pull request #707 from warmbly/feature/campaign-analytics-date-range
feat: date range filtering for campaign analytics as a send cohort
2026-09-27 06:16:54 +00:00
Matthew Meszaros 0b809dee40 feat: scope campaign analytics to an optional from/to send cohort (summary, step performance, engagement and the daily chart read the same UTC days, total_contacts and emails_pending stay campaign-wide, date_range reports the resolved period), count the whole last day in campaign compare and daily stats, add a 7d/30d/90d/all-time/custom period picker to the campaign overview and its share image, take the period in get_campaign_stats, the warmbly and warmblyctl CLIs and the Make and Zapier modules, close a date picker's calendar alone on Escape, and document it in the analytics guide, API reference, MCP table and OpenAPI 2026-09-26 22:42:19 -07:00
Matthew Meszaros 81c578a879 feat: keep watch and throttled mailboxes in cold rotation at their dampened volume and rest only quarantined or blocked ones, hold a watch or throttle past its line only when placement set it, fall back to the all-host headline when the major providers lack a sample without capping health on it, count a partner's junked mail through its own receipts, reset the released ledger rows' standing, and correct the resting, rolling-rate and scope docs 2026-09-26 22:26:58 -07:00
Matthew Meszaros 2b1a35dfe1 feat: make warmup spam placement only slow a mailbox down (watch at 10%, half-volume throttle at 20%, never quarantine, block or appeal) and judge it only at Google, Microsoft and Yahoo over verified deliveries, keep small-host spam out of the health bands, warmup and cold ramps and the advisor while still showing it beside the headline rate on the drawer and Deliverability, draw small-host partners whose own filter junks warmup mail less often, send each quarantine or block webhook once plus health_changed, release placement-only quarantines in 000220, and update the warmup, deliverability, advisor and API docs 2026-09-26 22:26:58 -07:00
Matthew Meszaros 9d0f60801c feat: file an offline notification unasked when the action check fails, bring a reopened verdict's message back to the inbox, skip empty notices and require the built-in check on --recheck-notifications, keep workspace labels saved before a built-in took the name, keep the sender's subject out of the action-required notification and send it off the ingest path, and default omitted outreach settings fields on PATCH 2026-09-26 21:36:11 -07:00
Matthew Meszaros 90f3f57eb9 feat: keep automated notifications that need the recipient's action (failed payment, suspended account, suspicious sign-in, sending limit, expiring service) in the inbox with an Action required label, view and mail-that-needs-action notification, let workspace tagging questions also run on automated notifications, add warmblyctl inbox-tag backfill --recheck-notifications, and document it 2026-09-26 21:28:06 -07:00
Matthew Meszaros d95a1075de Merge pull request #699 from warmbly/feature/contact-email-provider
feat: detect each contact's inbox provider from its domain's MX and SPF, show, sort and filter it across contact lists and segments, and use it for campaign ESP matching
2026-09-26 13:52:02 +00:00
Matthew Meszaros 2c156ec07e feat: hold the contact provider sweep lease by owner token with a compare-and-delete and end each run before it can expire, recognise Microsoft 365 tenant onmicrosoft.com domains for ESP matching, count checked domains with no known provider with other rather than undetected, and report an unknown-provider filter when saving it as a segment 2026-09-26 06:47:29 -07:00
Matthew Meszaros 8812cba439 feat: detect each contact's inbox provider from its domain's MX and SPF in a backend sweep, show it as a sortable Email provider column with the provider logo, filter and segment on it across contacts, campaign leads and segments, and use it for campaign ESP matching including Workspace and Microsoft 365 custom domains and the coverage panel's per-provider lead counts 2026-09-26 06:33:44 -07:00
Matthew Meszaros 014ba06b3a feat: weight warmup partners by the sender's verified spam rate per recipient mail host instead of per address domain, report deliverability warmup placement and the placement_in_spam webhook by mail host, mark IMAP warmup mail not-junk before it leaves Junk, send single-part text mail over SMTP with a fixed header order, and update the warmup, deliverability, analytics, webhook and OpenAPI docs 2026-09-26 06:30:22 -07:00
Matthew Meszaros c6027fecde Merge pull request #694 from warmbly/fix/premium-warmup-pool-partners
feat: borrow the best proven free warmup mailboxes whenever a premium mailbox has too few outside-workspace partners, reserve a quarter of every inbox's daily warmup capacity for premium senders, and show the pool and partner cap in the mailbox drawer
2026-09-26 05:07:38 +00:00
Matthew Meszaros af8b08d27a feat: rank borrowed free warmup mailboxes strictly by provider then tenure then activity, build the two inbound-share candidate suffixes once, and correct the partner-limit wording in the drawer, OpenAPI, warmup and Warmbly Cloud docs and AGENTS.md 2026-09-25 21:52:45 -07:00
Matthew Meszaros 6e62c500c3 feat: borrow the best proven free warmup mailboxes whenever a premium mailbox has fewer outside-workspace partners than max(25, its warmup ceiling) so siblings no longer block borrowing, keep a quarter of every inbox's daily warmup capacity for premium senders, and show the pool and any partner cap on today's target in the mailbox drawer 2026-09-25 21:47:36 -07:00
Matthew Meszaros 291ed2ae15 feat: document inbox placement tests in a new guide and API reference page, with the endpoints, error codes, realtime event, notification categories, placement settings, Warmbly Cloud seed panel, export and import behavior, CLI commands, assistant tools, admin Seed panel page and sandbox seed inboxes, and add the endpoints to openapi.json 2026-09-25 21:01:58 -07:00
Matthew Meszaros 6b9df08f3e Merge remote-tracking branch 'origin/main' into feature/domain-bulk-setup 2026-09-25 09:30:36 -07:00