Commit Graph

  • 8de7e32857 feat: treat a campaign step's own email as the A/B control arm so contacts split across the original plus active variants by weight, and redesign the step variants editor to show the original and variants as one weighted set with live split percentages Matthew Meszaros 2026-06-12 08:04:03 +02:00
  • 7b34b96b37 feat: keep the per-user realtime connection cap at 10 but reap dead connections via a periodic liveness sweep and process pids, so the count reflects real presence and stale sockets never hold a slot Matthew Meszaros 2026-06-12 07:46:13 +02:00
  • 5d2882ccf8 feat: strip leaked agent reasoning and select the corrected final draft for campaigns and deliverability reference pages, removing duplicate frontmatter, an em dash, and a Cyrillic placeholder char Matthew Meszaros 2026-06-12 07:39:57 +02:00
  • bfd67bfa2a feat: correct API key prefix examples to the real wmbly_ format and link the endpoint reference from the API docs index Matthew Meszaros 2026-06-12 07:29:45 +02:00
  • 54a1aee753 feat: add full per-resource API endpoint reference under docs/api/reference (mailboxes, campaigns, contacts, unibox, crm, analytics, api-keys, webhooks, integrations, deliverability/ops, account/org) with request and response structures Matthew Meszaros 2026-06-12 07:28:19 +02:00
  • 3cbfc06bc4 feat: add WebSocket intents (selective event-family subscription) and a HELLO-style org join reply advertising heartbeat cadence, and correct realtime docs on connection rejections and at-most-once delivery Matthew Meszaros 2026-06-12 07:17:09 +02:00
  • 50a134c827 feat: document org team-presence privacy controls in the collaboration guide and realtime API reference Matthew Meszaros 2026-06-12 05:59:02 +02:00
  • 6e9f2b4807 feat: add a Team presence section to workspace settings with admin-gated Show who's online and Show activity toggles, and make ToggleRow support a controlled persisted mode Matthew Meszaros 2026-06-12 05:59:01 +02:00
  • 4f1ac8c273 feat: enforce org team-presence privacy in the realtime OrgChannel — gate Presence.track on show_online, strip viewing/editing detail when show_activity is off, and re-track/untrack live on PRESENCE_POLICY_UPDATED Matthew Meszaros 2026-06-12 05:59:01 +02:00
  • 0fd3d03f55 feat: add org-wide team presence privacy columns (presence_show_online, presence_show_activity) with update plumbing and a PRESENCE_POLICY_UPDATED realtime event so a settings change re-gates connected sockets live Matthew Meszaros 2026-06-12 05:59:01 +02:00
  • 8547fe97eb feat: scope unibox MarkSeenBulk by organization so a non-owner member opening a thread clears the shared org-wide unread state instead of updating zero rows Matthew Meszaros 2026-06-12 05:14:50 +02:00
  • 4db027a342 feat: scope unibox GetByThread by organization instead of user_id so non-owner members see the full conversation they already see in the org-scoped inbox list, not an empty thread Matthew Meszaros 2026-06-12 05:10:00 +02:00
  • 81f81fbe20 feat: normalize automation updated_at to a primitive before comparing it (the API client revives it into a Date, so === compared by reference and the editor always flagged its own save as a teammate change) Matthew Meszaros 2026-06-12 04:58:37 +02:00
  • ba3ab98e1e feat: bridge realtime events over Redis pub/sub when Google Pub/Sub is unconfigured (RedisBus publisher in backend/consumer plus Realtime.Redis.EventSubscriber and a shared EventBroadcaster) so dashboard live updates and presence-driven collaboration actually fire in local dev Matthew Meszaros 2026-06-12 04:49:58 +02:00
  • 21f25a5361 feat: use automation updated_at as the remote-version token in AutomationFlow so the editor stops falsely toasting its own save as a teammate change Matthew Meszaros 2026-06-12 04:34:13 +02:00
  • f6540d9f2f feat: rejoin org/user channels and force isConnected toggle on zombie-socket wake so a backgrounded dashboard tab resumes realtime events and presence without a reload Matthew Meszaros 2026-06-12 04:34:13 +02:00
  • 48ce9074eb feat: automation presence reflects intent — editors claim 'editing', view-only members claim 'viewing', so the resource viewers stack and online dropdown show accurate activity Matthew Meszaros 2026-06-11 19:55:01 +02:00
  • c2215a62c1 feat: richer online-presence dropdown — click to pin, profile pictures, a live online + editing count, and clear per-person activity ('Editing an automation', 'Viewing a conversation', 'Replying to a message') with color-coded icons instead of a bare 'editing' Matthew Meszaros 2026-06-11 19:54:44 +02:00
  • 801c6b8619 fix: faster, research-backed websocket reconnect — replace the slow 1s/2s/4s exponential backoff with a fast-start schedule (first retry ~120ms) plus jitter, lower the heartbeat to 25s/8s for quicker dead-connection detection, retry token-fetch failures on the same fast backoff, and clear a Safari-suspended CONNECTING zombie socket on tab refocus so it reconnects instantly instead of hanging Matthew Meszaros 2026-06-11 19:52:55 +02:00
  • 9731083ae2 feat: live-collaborate on automations — the builder canvas now reflects a teammate's save in real time instead of only after a reload (re-seeds when you have no unsaved edits, shows a non-destructive 'load their version / keep mine' banner when you do), fixing the seed-once canvas that never reacted to remote changes Matthew Meszaros 2026-06-11 19:51:05 +02:00
  • 393b683fa2 feat: lock the campaign sequence flow for members without manage-sequences — view-only members can't drag steps, draw branches, or add a step (each attempt pops the permission popup and the Add-step button shows a lock), while pan/zoom/inspect still work Matthew Meszaros 2026-06-11 19:17:20 +02:00
  • 605583c301 feat: proactively lock the automation builder Save button for members without the integration permission, with a lock icon and permission popup Matthew Meszaros 2026-06-11 19:00:45 +02:00
  • 384579a36b feat: proactively lock the campaign Start/Pause, settings Save and schedule Save buttons for members without send/manage-campaign permission (lock icon + permission popup before any request) Matthew Meszaros 2026-06-11 19:00:09 +02:00
  • 9024d6bc21 feat: add proactive write-permission primitives — useWriteGuard (blocks a denied action before any request and pops the permission dialog) and PermissionButton (auto-locks with a lock icon when the member lacks the permission) Matthew Meszaros 2026-06-11 18:51:59 +02:00
  • fd440627fe fix: portal the sidebar access-locked popup to document.body so it covers the whole screen instead of clipping inside the transformed sidebar aside Matthew Meszaros 2026-06-11 18:49:15 +02:00
  • a0221dd312 feat: show one clear, app-wide 'you don't have permission' popup whenever a write action (edit/save/delete) is denied with 403, naming the missing permission or plan, instead of silent failures and generic error toasts across the dashboard Matthew Meszaros 2026-06-11 18:30:53 +02:00
  • 44d7c2a0c1 fix: make the realtime websocket reconnect reliably — reconnect on every unintended close (not just unclean ones), detect silently-dropped connections via a heartbeat watchdog that force-closes to trigger reconnect, and reconnect immediately when the network returns or the tab is refocused Matthew Meszaros 2026-06-11 18:18:24 +02:00
  • 21b4ba4ea0 fix: let members with the integration permission save automations (write was gated on manage-settings while read used use-integrations, so a manager could open the builder but 403 on save) and surface the backend's real error in the save toast instead of a generic message Matthew Meszaros 2026-06-11 18:15:55 +02:00
  • 6a3b8ac0eb fix: scope the unibox unread-count endpoint by organization_id so the sidebar Inbox badge counts the workspace's unread mail instead of always showing 0 for non-owner members Matthew Meszaros 2026-06-11 18:05:18 +02:00
  • 594c696bf6 fix: scope the unibox inbox list and overview by organization_id (via the workspace's email accounts) instead of the logged-in user_id, so every member sees the org's incoming mail; per-user thread labels and snoozes stay personal Matthew Meszaros 2026-06-11 17:57:52 +02:00
  • 21032a8fce fix: scope the contacts list by organization_id instead of user_id so all members see the workspace's contacts (and per-contact campaign badges); categories badge still user-scoped pending an organization_id column on categories Matthew Meszaros 2026-06-11 17:52:36 +02:00
  • 88e241d536 fix: scope the analytics dashboard (overall stats, recent activity, top campaigns, daily trend, account health) by organization_id instead of user_id, so every workspace member sees the org's analytics rather than an empty dashboard Matthew Meszaros 2026-06-11 17:49:39 +02:00
  • a21dc57e07 fix: scope campaign list/detail/count queries by organization_id instead of user_id, so all workspace members see the org's campaigns rather than only the creator Matthew Meszaros 2026-06-11 17:47:04 +02:00
  • 6ae5e52c4e fix: scope email-account list/detail queries by organization_id instead of the logged-in user_id, so every member of a workspace sees the org's mailboxes (not just the owner who connected them) Matthew Meszaros 2026-06-11 17:43:56 +02:00
  • 4440613d94 feat: sidebar shows a lock on features the member can't access and pops an explanatory access dialog on click, so a locked feature reads as unavailable instead of an empty page mistaken for 'no data'; align Accounts gate on Manage mailboxes Matthew Meszaros 2026-06-11 17:17:48 +02:00
  • 70064e9e1d fix: define OrgChannel.handle_out/3 so presence_diff broadcasts are pushed to clients instead of crashing the channel — the missing callback was terminating the org channel and dropping every websocket connection in a reconnect loop Matthew Meszaros 2026-06-11 13:47:11 +02:00
  • babde3397c feat: apply the explicit no-access message to campaigns, contacts, analytics, and API keys pages too, so every permission-gated tab says which permission is missing instead of showing nothing Matthew Meszaros 2026-06-11 13:21:34 +02:00
  • 72d2af2c3d feat: inbox and email-accounts pages now show an explicit 'you don't have access' message (with the missing permission) instead of a blank or misleading-empty screen when the member lacks unibox/campaign-view access Matthew Meszaros 2026-06-11 13:19:25 +02:00
  • b07d21b907 feat: add usePermission hook + a NoAccess surface that explains which permission a member is missing instead of rendering a blank page Matthew Meszaros 2026-06-11 13:19:24 +02:00
  • 3654ca0809 feat: profile and workspace name fields auto-save ~700ms after typing stops (empty names stay unsaved), replacing manual Discard/Save with the live status indicator Matthew Meszaros 2026-06-11 13:00:27 +02:00
  • 01e23c7596 feat: notifications settings auto-save instantly on toggle with a Saving/Saved header indicator, replacing the manual Discard/Save buttons Matthew Meszaros 2026-06-11 13:00:27 +02:00
  • 14837ed959 feat: guard settings tab switches — block in-app navigation (and warn on reload) when a tab has unsaved or failed auto-save changes, with a Stay/Discard/Save-changes dialog Matthew Meszaros 2026-06-11 13:00:27 +02:00
  • aa9273fe06 feat: add autosave primitives — useAutosave hook (instant for toggles, debounced for text, with dirty/flush/retry status), an unsaved-changes registry context, and a Saving/Saved/retry header indicator Matthew Meszaros 2026-06-11 13:00:18 +02:00
  • 709b77cdc6 fix: notification email links use the configured APP_URL instead of a hardcoded app.warmbly.com, so dev and self-hosted deployments link to the right host Matthew Meszaros 2026-06-11 12:43:17 +02:00
  • 4f6837b395 fix: refresh the active-sessions list and confirm other devices were signed out after a password change, so revoked sessions disappear live Matthew Meszaros 2026-06-11 12:42:44 +02:00
  • 3c6de16321 fix: forgotten-password reset now revokes all existing sessions, so a reset done because access was lost or compromised fully cuts off prior devices Matthew Meszaros 2026-06-11 12:41:55 +02:00
  • f209eca9ad fix: Slack notification delivery now resolves a real channel (connection config, then the org's configured Slack automation channel) instead of an always-empty connect-time field that silently dropped every message; docs and UI corrected to match Matthew Meszaros 2026-06-11 12:40:31 +02:00
  • 3c040649c0 fix: changing your password now revokes every other session (keeping the current device), matching the security promise in the sign-in alert and docs Matthew Meszaros 2026-06-11 12:39:24 +02:00
  • 2d53f4f819 fix: rate-limit POST /me/password so a hijacked session can't brute-force the current password unthrottled Matthew Meszaros 2026-06-11 12:38:07 +02:00
  • 5bcc2baaa8 feat: implement the coming-soon security features — logged-in change-password (verify current, policy-checked, POST /me/password) with a real dialog, and new-device sign-in alerts (security notification category fired from the token service on an unrecognized OS+browser, delivered in-app and by email), removing the comingSoon stub helper and updating docs Matthew Meszaros 2026-06-11 12:30:44 +02:00
  • 160dc0bc76 feat: implement the coming-soon notification delivery channels — Email (SES/SMTP to the account email) and Slack (posts to the org's connected workspace via a new integration NotifySlack), wired in both backend and consumer with per-channel gating, real toggles replacing the coming-soon labels, and updated docs Matthew Meszaros 2026-06-11 12:21:48 +02:00
  • 39a9752d63 feat: real tokenized invite-accept link — public /invite landing page with safe preview (org, inviter, roles), accept-by-token plus the previously-broken accept-by-invitation-id, public preview + admin copy-link endpoints, login next-param redirect, and a Copy button that yields a working /invite?token link Matthew Meszaros 2026-06-11 11:57:45 +02:00
  • 19f66507b4 feat: fix multi-role review findings — atomic member+roles insert on invite accept (no partial-failure stranding), gate role deletion on the actor holding the role's permissions (blocks team-managers de-privileging admins), and hydrate+chip pending-invitation role sets Matthew Meszaros 2026-06-11 11:32:57 +02:00
  • 8540f7db15 feat: members can hold multiple roles — join tables for member/invitation role sets (migration 000044) with effective permissions as the bitwise OR recomputed on every assignment and role edit/delete, role_ids in invite/update APIs, multi-select checkbox role picker with colored chips in roster and invite flow, freely deletable roles Matthew Meszaros 2026-06-11 11:24:19 +02:00
  • 80d080b982 feat: fix realtime UUID param encoding crashing org-channel joins, remove the permission matrix from Roles & access, compact the role dropdown, and drop the redundant Integrations tab from settings nav Matthew Meszaros 2026-06-11 11:16:13 +02:00
  • 3473d09bcc feat: fix review findings in the roles redesign — GetMembers role_id column (members endpoint 500), TransferOwnership role_id hygiene, accept-time role re-resolution, race-free in-use delete guard covering invitations, assignment anti-escalation with self-role-change block, canManage-gated members UI, colored RolePills, fresh currentOrganization on refetch, dev JWT_SECRET wiring for make realtime, docs corrections Matthew Meszaros 2026-06-11 10:45:21 +02:00
  • 2badeb7f50 feat: align team-roles docs with data-driven roles (seeded editable defaults, owner as status, color in the role editor) and drop dead accent maps from the members page Matthew Meszaros 2026-06-11 10:20:41 +02:00
  • 091b39f34e feat: roles become workspace data — seed editable Admin/Manager/Viewer rows per org (migration 000043 with member backfill), require role_id for invites and role changes, add role colors with a shared colored RoleSelect dropdown in the roster and invite flow, and rebuild Roles & access around real roles with an Owner reference column Matthew Meszaros 2026-06-11 10:18:45 +02:00
  • 0b253337fc feat: integrate custom roles across Roles & access settings (manager replaces the coming-soon placeholder, custom roles join the permission matrix and summary cards, permission-aware canManage gating via the org context bitmask) Matthew Meszaros 2026-06-11 10:08:46 +02:00
  • 9992eb65c4 feat: document custom roles in the team-roles guide (creation flow, start-from presets, propagation and anti-escalation rules, limits) Matthew Meszaros 2026-06-11 09:46:15 +02:00
  • 63b2b046f9 feat: custom roles dashboard UI (roles manager with built-in reference rows, permission-checkbox editor with start-from presets, custom roles in member role picker and invite flow, realtime spine refresh) Matthew Meszaros 2026-06-11 09:45:23 +02:00
  • edd4524007 feat: custom organization roles backend (organization_roles table with write-through member propagation, CRUD endpoints with anti-escalation and in-use guards, custom-role invites and assignment via role_id, audited as role entity) Matthew Meszaros 2026-06-11 09:39:52 +02:00
  • 8732805934 feat: replace signed click redirects with server-side link tickets (tracked_links store, internal resolver API, opaque /c/<id> URLs, layered anti-probe caches with miss budget and circuit breaker) removing TRACKING_LINK_SECRET entirely Matthew Meszaros 2026-06-11 09:30:21 +02:00
  • 2c5e8b2cbd feat: make TRACKING_LINK_SECRET a required boot-time secret on backend and tracking service with no unsigned mode and no rotation grace, so rotating the key revokes old links immediately Matthew Meszaros 2026-06-11 09:00:04 +02:00
  • 515efce991 feat: support TRACKING_LINK_SECRET_PREVIOUS rotation grace on the tracking service so rotating the click-signing key never breaks links in already-delivered emails Matthew Meszaros 2026-06-11 08:53:29 +02:00
  • 014cbe79fa feat: label machine opens (Apple MPP prefetch, UA-less fetchers) with human-open upgrade semantics, exclude them from open-triggered automations, and surface the auto-open count in workspace and campaign analytics (migration 000040) Matthew Meszaros 2026-06-11 08:33:09 +02:00
  • 8af2950d0b feat: reconcile missed realtime events by invalidating all queries when the websocket reconnects after a gap Matthew Meszaros 2026-06-11 08:25:00 +02:00
  • a365aa1605 feat: document realtime collaboration architecture (audit spine, presence conventions, org event gating) and tracking anti-abuse layer in agent notes Matthew Meszaros 2026-06-11 08:17:04 +02:00
  • 9cc9240dd5 feat: document TRACKING_LINK_SECRET and TRACKING_RATE_LIMIT_PER_MIN rollout knobs in the deploy env example Matthew Meszaros 2026-06-11 08:15:00 +02:00
  • 7079efe21a feat: document the developer realtime WebSocket (channels, presence, limits, close codes), add the live collaboration guide, and note bot filtering in analytics docs Matthew Meszaros 2026-06-11 08:13:56 +02:00
  • 8b9277dabf feat: harden tracking service against abuse with per-IP rate limiting, prefetch/scanner filtering, URL length caps, and HMAC-signed click redirects (TRACKING_LINK_SECRET) closing the open-redirect hole Matthew Meszaros 2026-06-11 08:11:05 +02:00
  • a06a525cf9 feat: live team presence across the dashboard (online avatar stack in header, viewing/replying indicators on unibox threads and rows, editing collaborators in the automation builder, campaign and contact viewers) plus audit-spine query invalidation Matthew Meszaros 2026-06-11 08:04:11 +02:00
  • 371fe0c0a3 feat: add Phoenix.Presence org collaboration layer (online members, viewing/editing/replying activity) with permission-gated org event fanout in the realtime service Matthew Meszaros 2026-06-11 07:51:34 +02:00
  • fe96eff7b4 feat: audit-log coverage for teams, automations (typed entity), lead-sync sources, and manual meetings so the org activity trail and its realtime spine see every mutation Matthew Meszaros 2026-06-11 07:47:29 +02:00
  • abdfd05c34 feat: org-scope realtime events (inbox, campaign, tracking, account health) and emit EMAIL_SENT/EMAIL_REPLIED/EMAIL_DELETED pulses so the whole team's dashboard updates live Matthew Meszaros 2026-06-11 07:43:57 +02:00
  • fa83e55763 Merge pull request #47 from warmbly/feature/redesign-developers-page Matthew Meszaros 2026-06-11 07:18:26 +02:00
  • 65455b907d feat: redesign developer page content Matthew Meszaros 2026-06-11 05:15:56 +00:00
  • 78b8a73fa8 feat: refactor developer page data model Matthew Meszaros 2026-06-11 05:15:34 +00:00
  • 5a2d62b030 Merge pull request #46 from warmbly/feature/marketing-automation Matthew Meszaros 2026-06-11 06:28:44 +02:00
  • dcc68f6eb4 feat: add automations navigation and featured product entry Matthew Meszaros 2026-06-11 06:11:42 +02:00
  • 79935060ef feat: add automations landing page and homepage showcase Matthew Meszaros 2026-06-11 06:11:33 +02:00
  • d540f2227d Merge pull request #45 from warmbly/feature/integrations-3 Matthew Meszaros 2026-06-10 19:02:45 +02:00
  • 15cf150f9e feat: remove the stale worker assignment operator doc from docs/, matching the earlier operator markdown cleanup Matthew Meszaros 2026-06-10 18:56:59 +02:00
  • bd7db069ba Merge origin/main into feature/integrations-3, resolving doc conflicts by accepting the docs-restructure deletions Matthew Meszaros 2026-06-10 18:56:47 +02:00
  • cc0c9a84ea Merge pull request #44 from warmbly/chore/update-docs Matthew Meszaros 2026-06-10 18:46:21 +02:00
  • 49a4e1e8ec feat: shorten verbose code comments in the docs app and add a one-line comment rule to the agent notes Matthew Meszaros 2026-06-10 18:36:29 +02:00
  • 1e4116ab0f Merge remote-tracking branch 'origin/main' into chore/update-docs Matthew Meszaros 2026-06-10 18:35:12 +02:00
  • 519aeacfc7 feat: require docs updates for user-visible changes and tighten commit message guidance in the agent notes Matthew Meszaros 2026-06-10 18:27:42 +02:00
  • 6a6ee42a23 feat: remove the operator markdown files from docs/ and drop their references from the root readme and contributing guide Matthew Meszaros 2026-06-10 18:27:42 +02:00
  • 5b735bb528 feat: replace ascii architecture diagrams in the realtime readme and resources docs with prose and tables Matthew Meszaros 2026-06-10 18:27:42 +02:00
  • 14a535701e feat: fix grammar in the forbidden api error message returned by the backend Matthew Meszaros 2026-06-10 18:27:42 +02:00
  • 9706458b10 feat: move the marketing site learn articles into a docs learn tab and point every site learn link at docs.warmbly.com Matthew Meszaros 2026-06-10 18:27:42 +02:00
  • d8a14ba14a feat: split docs content into guides and api sidebar tabs with per-page icons, remove duplicated h1 titles and em dashes, normalize reference-page copy, and add an api overview page Matthew Meszaros 2026-06-10 18:27:42 +02:00
  • 24079d9df6 feat: rebrand the docs app with the warmbly theme and nav, wire copy-markdown page actions, add a custom 404 and a root redirect to guides, and make the build a fully static export with trailing-slash urls Matthew Meszaros 2026-06-10 18:26:55 +02:00
  • c4628104ea Merge pull request #43 from warmbly/feature/blog Matthew Meszaros 2026-06-10 18:26:37 +02:00
  • fc33acc64d feat: document the per-organization DEK model Matthew Meszaros 2026-06-10 17:17:19 +02:00
  • 03134317ca feat: seal integration tokens and config with the organization DEK Matthew Meszaros 2026-06-10 17:17:03 +02:00
  • ae0c433084 feat: seal mailbox validation credentials with the organization DEK Matthew Meszaros 2026-06-10 17:16:56 +02:00
  • ac3c11bf9a feat: seal outbound email content with the organization DEK Matthew Meszaros 2026-06-10 17:16:42 +02:00
  • b9a5871308 feat: key the cipher service by organization ID Matthew Meszaros 2026-06-10 17:16:26 +02:00