Matthew Meszaros
fd940d905b
feat: answer a click on a Slack approval card that carries no tool call with a private note to ask again or approve in the dashboard
2026-10-04 05:23:36 -07:00
Matthew Meszaros
5083bcbd54
feat: carry webhook and OAuth app signing secrets still stored as whsec_ plaintext into a workspace export as is, so they arrive sealed under the destination key instead of blank
2026-10-04 05:21:56 -07:00
Matthew Meszaros
af1c6cdfcd
feat: let a workspace import keep references that name another workspace's row by design (warmup partners, placement seeds, third-party OAuth apps) while every other reference must resolve to the importing workspace
2026-10-04 05:16:14 -07:00
Matthew Meszaros
5d4b0ad6e5
feat: hold the invite_member, update_member_role and rotate_webhook_secret AI tools to the same recent confirmation their REST routes require, answering reauth_required on /ai/tools and refusing them where no confirmed session exists
2026-10-04 05:14:30 -07:00
Matthew Meszaros
aca1aff4d6
feat: count a completed sign-in as a fresh confirmation for the first five minutes of the session, so accounts with no password or second factor can confirm an action by signing in again
2026-10-04 05:13:23 -07:00
Matthew Meszaros
b9b13344b4
feat: remember the refresh token each OAuth grant last rotated away from (migration 000261) and revoke the grant when that token is presented again, whether in a race or after the rotation finished
2026-10-04 03:49:13 -07:00
Matthew Meszaros
8b842bd6f7
feat: give the mailbox erasure live test's snooze fixture its organization, which unibox_snoozes now requires
2026-10-04 03:48:12 -07:00
Matthew Meszaros
663c3013d1
feat: bind each Remie approval to its tool call and run it once, show every argument and the resolved send on dashboard and Slack approval cards, keep always-allow to settings managers with a revocable list and never for tools that start sending or change access, withhold secrets and unpermitted tool results from the assistant and shared conversations, gate /mcp, /ai/tools and the web and playbook tools on AI_AGENT or use_ai, and scope get_mailbox by organization
2026-10-04 03:45:02 -07:00
Matthew Meszaros
b9d96825a2
feat: require an admin to hold every admin permission a grant or revoke takes away from another admin, and keep the last super admin through a grant that would replace the role
2026-10-04 03:43:10 -07:00
Matthew Meszaros
35635afeff
feat: refuse to store webhook and OAuth app signing secrets without CREDENTIALS_ENCRYPTION_KEY and never hand out an unreadable sealed secret, require TLS 1.2 on IMAP sync connections, compare the first-run setup token in constant time, and serve customer-owned domains from the installer's Caddy without HSTS
2026-10-04 03:42:36 -07:00
Matthew Meszaros
14df35e54c
feat: compare OAuth client secrets and PKCE challenges in constant time, draw integration OAuth state and verifiers from crypto/rand with no fallback, and fetch the Salesforce identity URL only from a Salesforce host
2026-10-04 03:40:04 -07:00
Matthew Meszaros
a6b72299ae
feat: store workspace invitation tokens only as SHA-256 digests (migration 000260 converts pending ones), mint a separate link token each time a manager copies an invite link so the emailed link keeps working, and resolve invitations by either digest
2026-10-04 03:37:41 -07:00
Matthew Meszaros
1c555934a5
feat: authorize warmup ban status and warmup appeals by the caller's organization and its view_campaigns / manage_emails gates, so any member who manages mailboxes can appeal, answering 404 for a mailbox outside the workspace
2026-10-04 03:22:09 -07:00
Matthew Meszaros
6c36be44aa
feat: require the actor to hold every permission a role edit, re-role or member removal takes away as well as every one it grants, matching role deletion, with the workspace owner holding all permissions
2026-10-04 03:22:09 -07:00
Matthew Meszaros
5f180f5c76
feat: hold an API key with allowed_email_accounts to its mailboxes across the unibox (list, thread, message, count and overview reads; compose with auto pick within the list, drafts, agent-draft approve and discard, seen, folder, labels and snooze writes), campaign sender pools, analytics account statuses and GET /analytics/accounts/:id, and store a compose draft's mailbox only when it belongs to the caller's organization
2026-10-04 03:22:09 -07:00
Matthew Meszaros
ec77a3e3d2
feat: key unibox snoozes by organization as well as user and thread (migration 000259 backfills from each thread's mailbox organization), scope every snooze read and write and the org-transfer scope to it, and resolve unibox list cursors only within the caller's organization or user
2026-10-04 03:22:09 -07:00
Matthew Meszaros
043d877b58
feat: let one organization per instance verify a custom tracking host across mailbox and campaign tracking domains (database trigger plus 409 tracking_domain_taken on save, verify, sending-domain apply and bulk setup; the sweep leaves a held host unverified), and re-verify tracking domains on the destination after a workspace import
2026-10-04 03:22:02 -07:00
Matthew Meszaros
e852a106a9
feat: serve every node-only internal route (data keys, message map, sync lookups, worker config, fleet heartbeat) on NODE_BROKER_TOKEN and leave only tracked links, domain redirects, page hits and forms on INTERNAL_API_TOKEN, render nodes only the node token when one is set, and have the installer generate a distinct NODE_BROKER_TOKEN for new installs and its own UPDATER_TOKEN
2026-10-04 03:21:58 -07:00
Matthew Meszaros
fba5997922
feat: type the mirrored HubSpot deal status parameter once so the deal mirror update prepares, and let the org transfer order check pass references that ResetOnImport blanks
2026-10-04 03:05:26 -07:00
Matthew Meszaros
eec8e1095e
feat: escape Slack's reserved characters in every text field of the automation Slack card, quote backslashes and double quotes in the Close lead lookup, and route Salesforce automation and push writes only through the native Salesforce sync by removing the unused direct SOQL fallback
2026-10-04 03:04:03 -07:00
Matthew Meszaros
79510c06a8
feat: render workspace and inviter names on the public invitation preview through displayname with the invitation email's fallbacks, and show a community app's developer name in the directory only when it is displayable
2026-10-04 03:03:52 -07:00
Matthew Meszaros
e3f21146a4
feat: hold mailbox display names to the person naming rules by refusing a rename that breaks them with invalid_name, replacing one from SMTP/IMAP onboarding and import files with an address-derived name, and sending warmup under a displayable name with an address fallback
2026-10-04 03:03:52 -07:00
Matthew Meszaros
3d1e117ea6
feat: show campaign names in auto-pause and provider-refusal notifications through displayname.DisplayableOr with a neutral fallback, and leave an inbound reply's subject out of notification emails while the in-app feed keeps it
2026-10-04 03:03:52 -07:00
Matthew Meszaros
12563982cc
feat: pass pool-link instance names and CLI device-code client names and hostnames through the workspace naming rules with displayname.CleanOr, falling back to Self-hosted instance and Warmbly CLI, keep only the machine label of a CLI hostname, and clip versions on rune boundaries
2026-10-04 03:03:52 -07:00
Matthew Meszaros
147491ed3c
feat: disable imported webhook endpoints whose address fails the same https and public-host check a new endpoint must pass, and document it on the workspace export and import page
2026-10-04 03:03:40 -07:00
Matthew Meszaros
1c29643ecb
feat: re-apply the app and form write rules to workspace imports so imported OAuth apps get displayname-checked names, http(s) websites, valid redirect URIs and webhooks, only their workspace's own logos, and stay suspended when suspended at the source or imported under a developer block, imported forms keep only http(s) redirect URLs, valid designs and embed domains, and the hosted form page navigates only to http(s) redirect targets
2026-10-04 03:03:40 -07:00
Matthew Meszaros
eff2c14a9d
feat: make workspace import write only rows the destination workspace owns by checking every archive key and foreign key against each table's owner scope before a batch lands, scoping overwrite updates to the destination's own rows, warning in the archive check, and documenting the rule
2026-10-04 03:03:34 -07:00
Matthew Meszaros
43a9d004f2
feat: bound user-authored templates (range only over data fields, two-deep nesting, no template calls, 1 MiB output, capped compile cache) for campaign and automation rendering, accept only single addresses and single Message-IDs for to/cc/bcc/in_reply_to on every send path with invalid_recipient and invalid_message_id, refuse multi-line headers in the Gmail, Graph and SMTP writers, always apply a no-script CSP and drop non-http(s)/mailto/tel link targets in email previews, treat only single-slash paths as internal Remie links, accept integration OAuth callbacks only from the API origin, and follow only http(s) form redirects and app install links
2026-10-04 03:02:37 -07:00
Matthew Meszaros
ff54338806
feat: keep every deal in the pipeline its stage belongs to on create and update, validate pipeline stage names and colours in the CRM service for every caller, bound the AI bulk contact edit to MaxContactBatchIDs parsed ids, and start placement tests for API-key callers only through the REST route that applies the key's mailbox limits
2026-10-04 03:02:15 -07:00
Matthew Meszaros
f9a2e9af10
feat: state dependency floors, the Sentry HTTP client choice and auth cache budgets as the guarantees they hold, with no advisory identifiers or past behaviour in comments
2026-10-04 03:00:56 -07:00
Matthew Meszaros
9ff2e71385
feat: cap CLI sign-in keys with the shared role-to-scope mapping models.APIPermissionsFor and accept an OAuth token on the realtime socket only while its holder is still a member of the grant's workspace
2026-10-04 03:00:18 -07:00
Matthew Meszaros
bf47984cd5
feat: cap every OAuth grant and API key at the delegating member's role (consent narrows scopes and reports the withheld ones, tokens re-check the member's current role at every gate and MCP tool, keys stay within their creator's permissions, mailboxes and IP allowlist), keep OAuth tokens off API key and OAuth app management, require a fresh sign-in to approve an app, revoke a grant whose refresh token is presented twice, count only unexpired grants as installs, seal app webhook secrets under the instance key, name the workspace and flag unverified apps on the consent screen, and let credential managers list and revoke every member's app authorizations
2026-10-04 02:59:10 -07:00
Matthew Meszaros
8bb60e9449
feat: accept only Salesforce domains as an org's API host and call it through the SSRF-guarded client, register the Warmbly Cloud link only on self-hosted instances behind the instance admin with a second factor and dial it through safehttp with fixed error text, keep automation signing secrets in the sealed connection config, answer integration service failures with fixed messages, add security headers to the forms, tracking and docs origins and TLS 1.2+ to the nginx template, compare the captcha bypass in constant time, require TLS 1.2 for IMAP probes, and drop the unused RSA helpers
2026-10-04 02:58:43 -07:00
Matthew Meszaros
610d511307
feat: answer every server-side failure in admin, internal, webhook, warmup routing, Stripe webhook, agent tool and MCP handlers with the fixed internal error and log the detail against the request id, keep correctable webhook and routing refusals as typed errors with their own messages, drop the request URL from MillionVerifier transport errors so the API key never reaches a log or response, and redact :code path parameters in the access log
2026-10-04 02:57:17 -07:00
Matthew Meszaros
33f99b97e5
feat: end every session on sign-out-everywhere through RevokeOtherSessions with cache eviction after commit, refuse refresh on a revoked session, close a user's realtime sockets on any session revocation via a SESSIONS_REVOKED event, and verify tokens without a purpose claim for no flow
2026-10-04 02:56:18 -07:00
Matthew Meszaros
5bd8dbfab9
feat: bind Warmbly Cloud brokered mailbox sign-ins to PKCE, a single-use state and a cloud consent page naming the requesting instance and workspace that sets the browser cookie the callback requires, return only to the instance's registered address, add PKCE and an OIDC nonce to Workspace and Microsoft 365 admin-proof sign-ins, post OAuth callback codes only to a configured dashboard origin, cap CLI-approved keys to the approver's role behind a fresh sign-in, and accept only same-origin login next paths
2026-10-04 02:53:16 -07:00
Matthew Meszaros
9f7d45a1fb
feat: charge every password, emailed-code and TOTP attempt atomically before comparing it (Redis INCR+expire script) with a per-account TOTP budget across challenges, put the signed-in password change on the reauth budget, set the per-account login limit to 50 per hour, give tester passwords an expiry (users.password_expires_at, migration 000257) and clear them plus every session on revoke, mint warmblyctl reset links with the password-reset purpose, expire fleet join tokens (7 days default, 30 max, reusable inside the window), derive captcha from the resolved Turnstile secret, refuse weak bootstrap argon2id hashes, make registration codes single-use, rate-limit the v1 invitation lookup, and draw RIDs and user codes without modulo bias
2026-10-04 02:52:22 -07:00
Matthew Meszaros
f0ec39febd
feat: scope automation and sequence unsubscribes to the caller's organization, require manage_settings to create, edit, enable or delete automations, run each integration action only on its own provider's connection (400 action_provider_mismatch), refuse org-permission gates when no organization service is wired, read /integrations/bookings like contacts, scope lead claims, research runs and CRM list cursors to the organization, and bind contact note edits to the contact in the path
2026-10-04 02:47:10 -07:00
Matthew Meszaros
e1c4a91ad1
feat: confirm a Slack link only for the Warmbly member whose email matches the Slack account's confirmed profile email (read via users.info with the new users:read and users:read.email scopes, refused as slack_link_email_mismatch), show the Slack account's name and avatar on the link page and after linking, return the Slack connection in GET /integrations/slack/status only to manage_settings or use_integrations, scope agent-thread lookups by organization, and check a Draft a reply card's conversation belongs to the clicker's workspace before starting the assistant
2026-10-04 02:45:04 -07:00
Matthew Meszaros
4cfba5340a
feat: verify every HubSpot app request by its v3 signature over the public backend URL, refuse card-fetch query values on the webhook and workflow action routes, take exactly one portalId, userId and userEmail on card routes and act as the matched accepted member holding the matching campaign and contact permissions, route a portal only to its single live HubSpot-mode workspace, delete mirrored deals and tasks only when HubSpot answers the record is gone, and scope the card's permitted fetch to the card routes
2026-10-04 02:42:12 -07:00
Matthew Meszaros
585c7ff85a
feat: end every credential a login-banned user holds by refusing their API keys, OAuth grants and Slack links at resolution, and run the Slack assistant only for members whose role includes use_ai, matching the dashboard gate
2026-10-04 02:34:01 -07:00
Matthew Meszaros
23c57f35c2
Merge pull request #822 from warmbly/feature/integrations-page-redesign
...
feat: turn Integrations into an app store with search, filters and app pages, add a link-only community directory, a new OAuth app registration dialog, per-app re-encoded logos and admin moderation for OAuth apps
2026-10-04 08:27:13 +00:00
Matthew Meszaros
d505508997
feat: audit OAuth app moderation and developer blocks under their own entity types, refuse logo removal on suspended apps, delete a replaced workspace-uploaded app logo once no other app shows it, confirm before revoking every token in the admin panel, open store cards on Space, retry a new logo URL after a failed one, toast only after the clipboard write succeeds, and freeze the listing form baseline while it is open
2026-10-04 01:20:28 -07:00
Matthew Meszaros
bc9caba267
feat: validate OAuth app names through displayname and websites as http(s), clean dynamically registered client names and stop storing their logo_uri, refuse edits and logo uploads on suspended apps or blocked developers, scope logo deletion to the app's own images, keep hidden listings from being unpublished, count only installs from other aged workspaces toward the directory threshold, refresh integration popularity outside the lock, and count only live connections in the Integrations store
2026-10-04 01:10:39 -07:00
Matthew Meszaros
7a785afb94
Merge pull request #824 from warmbly/feat/stripe-no-automatic-tax
...
feat: turn off Stripe automatic tax on checkout, plan changes and previews
2026-10-04 08:07:40 +00:00
Matthew Meszaros
751dd5e08c
feat: turn off Stripe automatic tax on subscription and credit checkout, plan changes and proration previews in internal/app/stripe/service.go, keeping required billing address, business name and tax ID collection
2026-10-04 09:59:24 +02:00
Matthew Meszaros
2983d3ca1e
Merge pull request #823 from warmbly/feat/remie-assistant
...
feat: Remie, the dashboard AI assistant: animated blob mark, floating panel, live run UI, and Advisor-driven suggestions and tips
2026-10-04 07:59:05 +00:00
Matthew Meszaros
1a483cb27f
Merge remote-tracking branch 'origin/main' into feature/integrations-page-redesign
...
# Conflicts:
# internal/app/integration/service.go
# web/src/app/app/integrations/page.tsx
# web/src/hooks/useDocumentTitle.ts
2026-10-04 00:45:48 -07:00
Matthew Meszaros
7672924a72
feat: rename the dashboard assistant to Remie with an animated blue blob mark, open it as a floating window by default, show live runs with a shimmering status, elapsed timer, collapsible tool-step trace, streamed text with a blurred tail and a redesigned approval card, and add Remie suggestions and rate-limited tips built from open Advisor findings that Remie fixes through its own approvals
2026-10-04 00:36:27 -07:00
Matthew Meszaros
4bc2417618
Merge remote-tracking branch 'origin/main' into feature/integrations-page-redesign
...
# Conflicts:
# docs/content/docs/api/error-codes.mdx
# docs/content/docs/guides/integrations.mdx
# web/src/app/app/integrations/page.tsx
2026-10-04 00:32:54 -07:00