This website requires JavaScript.
Explore
Help
Sign In
starred
/
warmbly
Watch
1
Star
0
Fork
0
mirror of
https://github.com/warmbly/warmbly.git
synced
2026-10-06 08:02:06 +00:00
Code
Issues
Packages
Projects
Releases
Wiki
Activity
Files
c1606851d82fe457d00a028fca42c2e3a6c734a2
warmbly
/
internal
T
History
Matthew Meszaros
c1606851d8
Merge pull request
#845
from warmbly/devin/1791212676-structured-sender-variables
...
feat: add native Sender mailbox personalization to campaign emails
2026-10-05 16:37:09 +00:00
..
api
feat: provision onboarding-complete reviewer workspaces with expiring Test access, bounded credits and Test header labels
2026-10-05 16:15:56 +00:00
app
feat: provision onboarding-complete reviewer workspaces with expiring Test access, bounded credits and Test header labels
2026-10-05 16:15:56 +00:00
bitmask
feat: make Warmbly Cloud warmup start and explain itself for linked mailboxes: apply the instance's warmup settings, start warmup on adopted mailboxes, read the warmup day mask Monday-first, report the last refused warmup send and the partner cap to the instance and dashboard, hand changed SMTP credentials to the cloud, refuse cleartext mailboxes at enrollment, and show cloud warmup with the warming animation and a clear Cloud marker
2026-10-01 03:01:36 -07:00
cli
fix: address the review on the CLI PR: give the sign-in handshake its own per-IP budget so a 200-poll login cannot lock the address out of the browser login, keep https for a remote host that names a port instead of sending a bearer token in cleartext, report truncation when a paginated walk stops at max-pages, accept a piped secret with no trailing newline, normalise WEBSOCKET_URL on its suffix so a bare /socket becomes a real endpoint, destroy a minted secret the moment its code expires, gate cli-installer-ci on the required status check, print a rejected flag instead of an unbound-variable error, and use a portable sha256 so the packaging runs on macOS
2026-09-04 21:03:58 -07:00
client
feat: refuse to store webhook and OAuth app signing secrets without CREDENTIALS_ENCRYPTION_KEY and never hand out an unreadable sealed secret, require TLS 1.2 on IMAP sync connections, compare the first-run setup token in constant time, and serve customer-owned domains from the installer's Caddy without HSTS
2026-10-04 03:42:36 -07:00
config
feat: provision onboarding-complete reviewer workspaces with expiring Test access, bounded credits and Test header labels
2026-10-05 16:15:56 +00:00
email
feat: accept only Salesforce domains as an org's API host and call it through the SSRF-guarded client, register the Warmbly Cloud link only on self-hosted instances behind the instance admin with a second factor and dial it through safehttp with fixed error text, keep automation signing secrets in the sealed connection config, answer integration service failures with fixed messages, add security headers to the forms, tracking and docs origins and TLS 1.2+ to the nginx template, compare the captcha bypass in constant time, require TLS 1.2 for IMAP probes, and drop the unused RSA helpers
2026-10-04 02:58:43 -07:00
errx
feat: control Gmail mailbox OAuth per frontend deployment and bind callbacks to allowlisted dashboard origins
2026-10-05 12:16:34 +00:00
events
feat: send each mailbox's reply-to as a Reply-To header on campaign, unibox, test and placement mail (never warmup), record it on every campaign send attempt (tasks.reply_to, migration 000236) and credit a reply landing in that shared reply inbox to the campaign and its sending mailbox across reply attribution, the sync priority lane and copied-contact replies, show the sending mailbox on thread messages, recent activity and the reply webhook, start unibox and inbox-agent replies from the mailbox that emailed the contact, flag an untracked reply-to in mailbox settings, let the sandbox simulator answer Reply-To, and document the shared reply inbox (
#756
)
2026-09-30 05:33:34 -07:00
formserver
feat: send HSTS from the forms service only on FORMS_DOMAIN and strip it in the installer's Caddy block for customer-owned domains, so no customer apex is pinned to HTTPS
2026-10-04 05:19:22 -07:00
formwire
feat: keep every recipient-facing and self-host-facing address on the deployment's own domain: mint unsubscribe links on a workspace's verified tracking domain (served by the tracking service, proxied to the backend that owns the pages), attach RFC 8058 one-click only over https, resolve all branding through config.Brand() gated on SelfHosted() so a self-host's email footer, sign-in links, stats card, API example and public form badge name nobody else, drop the app.warmbly.com fallback from AppBaseURL, blank TRACKING_DOMAIN and FORMS_DOMAIN on core-only installs, and have install.sh offer to configure a fresh interactive install instead of silently defaulting to localhost
2026-09-09 06:34:43 -07:00
infrastructure
feat: provision onboarding-complete reviewer workspaces with expiring Test access, bounded credits and Test header labels
2026-10-05 16:15:56 +00:00
jobrun
feat: run the jobrun scheduler tests on the testing/synctest fake clock and cover a claim that errors with or without its write landing, so each slot still runs exactly once
2026-10-01 22:29:39 -07:00
jobs
feat: resume every scheduled job from its stored next_run_at after a restart instead of starting a fresh interval, run a job that came due while the process was down right after its phase offset, and claim each slot with a compare-and-swap on next_run_at so a job hosted by several processes runs once per slot
2026-10-01 22:16:16 -07:00
models
feat: provision onboarding-complete reviewer workspaces with expiring Test access, bounded credits and Test header labels
2026-10-05 16:15:56 +00:00
notify
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
observability
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
pkg
feat: keep worker farewell heartbeats independent of IP discovery and identify CPU-set resource scope accurately
2026-10-05 11:43:16 +00:00
repository
feat: provision onboarding-complete reviewer workspaces with expiring Test access, bounded credits and Test header labels
2026-10-05 16:15:56 +00:00
sandbox
fix: skip the onboarding wizard for seeded, sandbox, bootstrap, and warmblyctl-created accounts
2026-10-04 17:49:23 +00:00
scheduler
feat: make Warmbly Cloud warmup start and explain itself for linked mailboxes: apply the instance's warmup settings, start warmup on adopted mailboxes, read the warmup day mask Monday-first, report the last refused warmup send and the partner cap to the instance and dashboard, hand changed SMTP credentials to the cloud, refuse cleartext mailboxes at enrollment, and show cloud warmup with the warming animation and a clear Cloud marker
2026-10-01 03:01:36 -07:00
seed
fix: skip the onboarding wizard for seeded, sandbox, bootstrap, and warmblyctl-created accounts
2026-10-04 17:49:23 +00:00
tasks
feat: expose typed sender mailbox details in campaign templates, previews and email editor variables
2026-10-05 15:15:12 +00:00
tasksched
feat: add an in-process postgres task scheduler so delayed sends need no cloud tasks
2026-07-20 09:56:02 +02:00
updater
feat: address the review on the installer branch by keeping the database password out of pg_dump's argv, excluding backup bundles from the blob root they are written into, tolerating blobs that change or vanish mid-archive, making the instance-settings bootstrap a single atomic insert, and validating the release tag before it is written into .env
2026-09-04 06:24:05 -07:00
utils
feat: hold mailbox display names to the person naming rules by refusing a rename that breaks them with invalid_name, replacing one from SMTP/IMAP onboarding and import files with an address-derived name, and sending warmup under a displayable name with an address fallback
2026-10-04 03:03:52 -07:00
version
feat: add self-hosted update awareness and one-click updates: every binary is stamped with its version and commit, the backend polls GitHub Releases and a new host-side updater (cmd/updater, compose profile or systemd unit) reports the checkout's commit distance, the admin panel's top bar shows a version pill that turns into an update indicator and opens a dialog with confirmation, live step progress and log, restart tracking and result, the dashboard header shows the same pill to every member of a self-hosted instance with the full update flow for platform admins, Setup and health gains update_available and updater_unreachable checks, warmblyctl status prints the version, make upgrade and scripts/upgrade-bare-metal.sh cover the by-hand paths, and docs gain an Updates page plus configuration, health, deployment and API reference updates
2026-09-03 05:04:30 -07:00