This website requires JavaScript.
Explore
Help
Sign In
starred
/
warmbly
Watch
1
Star
0
Fork
0
mirror of
https://github.com/warmbly/warmbly.git
synced
2026-10-07 00:02:07 +00:00
Code
Issues
Packages
Projects
Releases
Wiki
Activity
Files
89c063e7183e6cce6cdd5a96df360d359c39c312
warmbly
/
docs
/
content
/
docs
T
History
Matthew Meszaros
497f58bb5a
feat: hold a mailbox-limited API key to explicit sender lists of its own mailboxes when it creates, edits or starts a campaign, and refuse it on /ai/tools and /mcp, which act across the workspace, with api_key_mailbox_limited
2026-10-04 03:24:25 -07:00
..
api
feat: hold a mailbox-limited API key to explicit sender lists of its own mailboxes when it creates, edits or starts a campaign, and refuse it on /ai/tools and /mcp, which act across the workspace, with api_key_mailbox_limited
2026-10-04 03:24:25 -07:00
development
feat: serve every node-only internal route (data keys, message map, sync lookups, worker config, fleet heartbeat) on NODE_BROKER_TOKEN and leave only tracked links, domain redirects, page hits and forms on INTERNAL_API_TOKEN, render nodes only the node token when one is set, and have the installer generate a distinct NODE_BROKER_TOKEN for new installs and its own UPDATER_TOKEN
2026-10-04 03:21:58 -07:00
guides
feat: require the actor to hold every permission a role edit, re-role or member removal takes away as well as every one it grants, matching role deletion, with the workspace owner holding all permissions
2026-10-04 03:22:09 -07:00
learn
feat: bound user-authored templates (range only over data fields, two-deep nesting, no template calls, 1 MiB output, capped compile cache) for campaign and automation rendering, accept only single addresses and single Message-IDs for to/cc/bcc/in_reply_to on every send path with invalid_recipient and invalid_message_id, refuse multi-line headers in the Gmail, Graph and SMTP writers, always apply a no-script CSP and drop non-http(s)/mailto/tel link targets in email previews, treat only single-slash paths as internal Remie links, accept integration OAuth callbacks only from the API origin, and follow only http(s) form redirects and app install links
2026-10-04 03:02:37 -07:00
meta.json
Publish development docs to docs.warmbly.com
2026-06-28 13:25:08 +02:00