This website requires JavaScript.
Explore
Help
Sign In
starred
/
warmbly
Watch
1
Star
0
Fork
0
mirror of
https://github.com/warmbly/warmbly.git
synced
2026-10-03 16:02:02 +00:00
Code
Issues
Packages
Projects
Releases
Wiki
Activity
Files
4e68bb25620259378de76d2a25b11468f08a9aac
warmbly
/
internal
T
History
Matthew Meszaros
4e68bb2562
feat: sell Warmbly to businesses only by requiring the buying company's legal name on the subscription and credit-pack Stripe Checkout sessions with a business-only and tax-exclusive notice beside the pay button, adding business-use and tax clauses to section 06 of the terms of service, and updating the billing guide to match
2026-09-27 11:10:46 +02:00
..
api
feat: read a campaign's first send inside the summary query instead of a separate untenanted lookup, file campaign hourly stats under the same UTC day as the daily series, treat any instant passed as a campaign period day as its calendar day, share one from/to parser between the analytics API and get_campaign_stats, chart All time from the campaign's creation day alongside the summary so an analytics error cannot leave the overview loading, and roll period presets over at UTC midnight
2026-09-26 23:00:30 -07:00
app
feat: sell Warmbly to businesses only by requiring the buying company's legal name on the subscription and credit-pack Stripe Checkout sessions with a business-only and tax-exclusive notice beside the pay button, adding business-use and tax clauses to section 06 of the terms of service, and updating the billing guide to match
2026-09-27 11:10:46 +02:00
bitmask
New Repository: Add Backend Code
2026-01-17 14:11:14 +00:00
cli
fix: address the review on the CLI PR: give the sign-in handshake its own per-IP budget so a 200-poll login cannot lock the address out of the browser login, keep https for a remote host that names a port instead of sending a bearer token in cleartext, report truncation when a paginated walk stops at max-pages, accept a piped secret with no trailing newline, normalise WEBSOCKET_URL on its suffix so a bare /socket becomes a real endpoint, destroy a minted secret the moment its code expires, gate cli-installer-ci on the required status check, print a rejected flag instead of an unbound-variable error, and use a portable sha256 so the packaging runs on macOS
2026-09-04 21:03:58 -07:00
client
feat: answer a signup for an existing address with 409 conflict and let a concurrent SSO first sign-in resolve against the account it raced, adopt the stored organization DEK when a parallel first use stored one first, classify IMAP SERVERBUG, LIMIT, bare read-command failures and provider ALERT/EXPIRED responses as server-unreachable, throttle or credentials errors and keep the ALERT text, wait up to two minutes for a free connection slot before the boot migration gives up, guard the dashboard's DOM mutations against browser page translation, treat an aborted passkey sign-in as a cancellation, and drop posthog-js request timeouts from error tracking
2026-09-27 08:26:55 +02:00
config
feat: detect each contact's inbox provider from its domain's MX and SPF in a backend sweep, show it as a sortable Email provider column with the provider logo, filter and segment on it across contacts, campaign leads and segments, and use it for campaign ESP matching including Workspace and Microsoft 365 custom domains and the coverage panel's per-provider lead counts
2026-09-26 06:33:44 -07:00
email
feat: race a 587 STARTTLS dial against a mailbox's silent port 465 on every send and connect check so the fleet keeps sending where outbound 465 is blocked, store a connect that passed that way with 587, name the port actually used in a refusal, make the Google app-password hint say Google itself refused the pair and name the alias and wrong-account causes, and render long error toasts wide, dismissable and longer-lived instead of a narrow four-second column
2026-09-20 13:16:52 +02:00
errx
feat: answer a signup for an existing address with 409 conflict and let a concurrent SSO first sign-in resolve against the account it raced, adopt the stored organization DEK when a parallel first use stored one first, classify IMAP SERVERBUG, LIMIT, bare read-command failures and provider ALERT/EXPIRED responses as server-unreachable, throttle or credentials errors and keep the ALERT text, wait up to two minutes for a free connection slot before the boot migration gives up, guard the dashboard's DOM mutations against browser page translation, treat an aborted passkey sign-in as a cancellation, and drop posthog-js request timeouts from error tracking
2026-09-27 08:26:55 +02:00
events
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
formserver
feat: rebuild mailbox import around column mapping and automatic host and sign-in detection (CSV, XLSX, pasted lists, saved mappings, retryable rows with fixes, migrations 000205-000206), connect whole Google Workspace domains and Microsoft 365 organizations through a proved administrator grant, import from inbox vendors (InboxKit, Zapmail, Mailforge, Infraforge, Maildoso, Cheap Inboxes, ScaledMail) with vendor-managed forwarding and DNS, add a sending domains page with per-domain tracking and verified root redirects, unify Add account into one Google and one Microsoft entry with per-method choices, mark per-mailbox Google sign-in as retiring with in-place moves to the admin grant or an app password, allow the loopback security mode in the credential columns (migration 000207), read semicolon-separated CSVs, and add a mock vendor API to the sandbox
2026-09-23 08:41:01 -07:00
formwire
feat: keep every recipient-facing and self-host-facing address on the deployment's own domain: mint unsubscribe links on a workspace's verified tracking domain (served by the tracking service, proxied to the backend that owns the pages), attach RFC 8058 one-click only over https, resolve all branding through config.Brand() gated on SelfHosted() so a self-host's email footer, sign-in links, stats card, API example and public form badge name nobody else, drop the app.warmbly.com fallback from AppBaseURL, blank TRACKING_DOMAIN and FORMS_DOMAIN on core-only installs, and have install.sh offer to configure a fresh interactive install instead of silently defaulting to localhost
2026-09-09 06:34:43 -07:00
infrastructure
feat: keep a throttled warmup mailbox in the pool by stamping blocked_at only for a quarantine or block in UpdateParticipantHealth, clear it from throttled rows in migration 000222 so partner selection and the admin pool counts stop treating a throttle as a block, and run the warmup health sweep on consumer boot so a release that changes the rules re-judges every mailbox at once
2026-09-27 10:09:01 +02:00
jobrun
feat: never let the connection clamp hand out more than the server's own share, since a comfort floor of ten on a twenty-connection database would have promised forty, count the phase offset toward a non-boot job's recorded next run so the panel does not show it overdue, and say in the configuration docs that the quarter assumes four clients and applies only when the probe answers
2026-09-19 20:08:11 +02:00
jobs
feat: hold the contact provider sweep lease by owner token with a compare-and-delete and end each run before it can expire, recognise Microsoft 365 tenant onmicrosoft.com domains for ESP matching, count checked domains with no known provider with other rather than undetected, and report an unknown-provider filter when saving it as a segment
2026-09-26 06:47:29 -07:00
models
Merge pull request
#707
from warmbly/feature/campaign-analytics-date-range
2026-09-27 06:16:54 +00:00
notify
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
observability
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
pkg
feat: hold the contact provider sweep lease by owner token with a compare-and-delete and end each run before it can expire, recognise Microsoft 365 tenant onmicrosoft.com domains for ESP matching, count checked domains with no known provider with other rather than undetected, and report an unknown-provider filter when saving it as a segment
2026-09-26 06:47:29 -07:00
repository
feat: keep a throttled warmup mailbox in the pool by stamping blocked_at only for a quarantine or block in UpdateParticipantHealth, clear it from throttled rows in migration 000222 so partner selection and the admin pool counts stop treating a throttle as a block, and run the warmup health sweep on consumer boot so a release that changes the rules re-judges every mailbox at once
2026-09-27 10:09:01 +02:00
sandbox
feat: seed six instance placement seed inboxes on their own domains in the sandbox and have the simulator file each placement copy into the seed's Inbox or Junk as a stand-in spam filter, stricter on Microsoft and Yahoo seeds and on tracked copy
2026-09-25 20:57:47 -07:00
scheduler
feat: detect each contact's inbox provider from its domain's MX and SPF in a backend sweep, show it as a sortable Email provider column with the provider logo, filter and segment on it across contacts, campaign leads and segments, and use it for campaign ESP matching including Workspace and Microsoft 365 custom domains and the coverage panel's per-provider lead counts
2026-09-26 06:33:44 -07:00
seed
feat: record where every warmup email lands (inbox, Gmail tab, spam) per sender, day and recipient host in warmup_placement_daily, serve it from GET /analytics/warmup/placement, cap mailbox health at the measured 7-day inbox rate, and show it as an Inbox column, a mailbox Deliverability tab and a workspace placement section; replace every visible native checkbox in the dashboard with a themed Checkbox and make the mailbox drawer's tab bar scroll
2026-09-24 05:28:51 -07:00
tasks
Merge pull request
#707
from warmbly/feature/campaign-analytics-date-range
2026-09-27 06:16:54 +00:00
tasksched
feat: add an in-process postgres task scheduler so delayed sends need no cloud tasks
2026-07-20 09:56:02 +02:00
updater
feat: address the review on the installer branch by keeping the database password out of pg_dump's argv, excluding backup bundles from the blob root they are written into, tolerating blobs that change or vanish mid-archive, making the instance-settings bootstrap a single atomic insert, and validating the release tag before it is written into .env
2026-09-04 06:24:05 -07:00
utils
feat: keep warmup out of the customer's own mailbox and off their deliverability record: Gmail foldering now removes INBOX and SENT instead of only labelling, sent copies and reply-backs are filed in both directions, filing is configurable per mailbox (folder/inbox/archive via warmup_placement + warmup_folder, migration 000177), IMAP relocates a moved message by Message-ID so read/important stop no-opping, and a warmup send's bounce notice no longer lands in the unibox or suppresses a pool partner
2026-09-17 20:46:03 -07:00
version
feat: add self-hosted update awareness and one-click updates: every binary is stamped with its version and commit, the backend polls GitHub Releases and a new host-side updater (cmd/updater, compose profile or systemd unit) reports the checkout's commit distance, the admin panel's top bar shows a version pill that turns into an update indicator and opens a dialog with confirmation, live step progress and log, restart tracking and result, the dashboard header shows the same pill to every member of a self-hosted instance with the full update flow for platform admins, Setup and health gains update_available and updater_unreachable checks, warmblyctl status prints the version, make upgrade and scripts/upgrade-bare-metal.sh cover the by-hand paths, and docs gain an Updates page plus configuration, health, deployment and API reference updates
2026-09-03 05:04:30 -07:00