Matthew Meszaros
43a9d004f2
feat: bound user-authored templates (range only over data fields, two-deep nesting, no template calls, 1 MiB output, capped compile cache) for campaign and automation rendering, accept only single addresses and single Message-IDs for to/cc/bcc/in_reply_to on every send path with invalid_recipient and invalid_message_id, refuse multi-line headers in the Gmail, Graph and SMTP writers, always apply a no-script CSP and drop non-http(s)/mailto/tel link targets in email previews, treat only single-slash paths as internal Remie links, accept integration OAuth callbacks only from the API origin, and follow only http(s) form redirects and app install links
2026-10-04 03:02:37 -07:00
..
2026-10-04 02:57:17 -07:00
2026-10-04 02:57:17 -07:00
feat: cap every OAuth grant and API key at the delegating member's role (consent narrows scopes and reports the withheld ones, tokens re-check the member's current role at every gate and MCP tool, keys stay within their creator's permissions, mailboxes and IP allowlist), keep OAuth tokens off API key and OAuth app management, require a fresh sign-in to approve an app, revoke a grant whose refresh token is presented twice, count only unexpired grants as installs, seal app webhook secrets under the instance key, name the workspace and flag unverified apps on the consent screen, and let credential managers list and revoke every member's app authorizations
2026-10-04 02:59:10 -07:00
2026-07-13 18:15:58 +02:00
2026-07-30 17:15:09 +02:00
2026-09-16 21:44:42 -07:00
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
2026-07-22 17:05:37 +02:00
2026-07-22 17:05:37 +02:00
feat: scope campaign analytics to an optional from/to send cohort (summary, step performance, engagement and the daily chart read the same UTC days, total_contacts and emails_pending stay campaign-wide, date_range reports the resolved period), count the whole last day in campaign compare and daily stats, add a 7d/30d/90d/all-time/custom period picker to the campaign overview and its share image, take the period in get_campaign_stats, the warmbly and warmblyctl CLIs and the Make and Zapier modules, close a date picker's calendar alone on Escape, and document it in the analytics guide, API reference, MCP table and OpenAPI
2026-09-26 22:42:19 -07:00
feat: scope campaign analytics to an optional from/to send cohort (summary, step performance, engagement and the daily chart read the same UTC days, total_contacts and emails_pending stay campaign-wide, date_range reports the resolved period), count the whole last day in campaign compare and daily stats, add a 7d/30d/90d/all-time/custom period picker to the campaign overview and its share image, take the period in get_campaign_stats, the warmbly and warmblyctl CLIs and the Make and Zapier modules, close a date picker's calendar alone on Escape, and document it in the analytics guide, API reference, MCP table and OpenAPI
2026-09-26 22:42:19 -07:00
feat: rebuild the new campaign flow as Leads, Emails, Schedule and Review with a lead-list picker, the full step editor and a live launch plan, keep unlaunched campaigns as server drafts that reopen in the flow from the campaigns list and a Continue setup button, simulate POST /campaigns-estimate day by day under warmup graduation, warmup mail sharing the send spacing, other campaigns, health holds and follow-up waits, retire one-time emails (migration 000229 drops campaigns.kind, the list type filter and badge go), enlarge the step subject field, and lift the editor popovers above dialogs
2026-09-29 01:37:07 -07:00
2026-10-04 03:02:15 -07:00
2026-10-04 02:47:10 -07:00
feat: shared TypeSafe client under internal/pkg/typesafe with inbox tagging phases 2 and 3 (hold, stop, task, suppress behind workspace switches, reversible ones on by default), labels seeded at workspace creation and by the follow-up sweep, premade inbox views (hot leads, needs a reply, follow up, declined, automated), typed reply classification and a reply_intent branch condition, an inbox agent draft gate, Advisor copy judgment with a cached editor re-check, warmup content lint, bounce cause classification that keeps a blocked address sendable, and per-form submission triage
2026-09-19 23:33:37 -07:00
feat: bound user-authored templates (range only over data fields, two-deep nesting, no template calls, 1 MiB output, capped compile cache) for campaign and automation rendering, accept only single addresses and single Message-IDs for to/cc/bcc/in_reply_to on every send path with invalid_recipient and invalid_message_id, refuse multi-line headers in the Gmail, Graph and SMTP writers, always apply a no-script CSP and drop non-http(s)/mailto/tel link targets in email previews, treat only single-slash paths as internal Remie links, accept integration OAuth callbacks only from the API origin, and follow only http(s) form redirects and app install links
2026-10-04 03:02:37 -07:00
2026-10-01 22:22:56 -07:00
2026-09-07 03:39:42 -07:00
2026-09-30 21:02:00 -07:00
2026-10-04 03:02:15 -07:00
2026-09-14 22:12:15 -07:00
2026-09-16 03:31:01 -07:00
2026-07-22 17:05:37 +02:00
feat: org AI skills (playbooks) that every AI feature loads and follows - ai_skills table (org-scoped, unique name per org, 32KB content cap) with a skills service exposing CRUD plus an enabled-skills preamble injected into the dashboard agent, contact research, and reply-draft prompts and a load_skill read-tool that returns a playbook's full content by name, /ai/skills CRUD gated on manage_settings (JWT) or the AI_AGENT scope (API) with an ai_skill audit entity and spine entry, an AI skills settings page (list rows opening a right-side drawer with name, one-line description, enable toggle, and a markdown body), and docs with two example playbooks
2026-07-13 19:46:25 +02:00
2026-09-07 03:39:42 -07:00
feat: complete the ADA CASA v2.1.1 AL1 control set across authentication, sessions, access control, cryptography, input validation and configuration, adding a breached-password denylist and per-account login throttling, enforced multi-factor authentication on the admin panel, step-up confirmation before an action that mints a lasting credential, purpose-scoped session tokens, single-use TOTP steps, tenant verification on every cross-referenced identifier, security headers on every surface, encrypted webhook signing secrets, per-organization idempotency, PKCE and a minimal two-scope Gmail consent on the mailbox OAuth flow, bounded spreadsheet and archive decoding, a patched Go toolchain with govulncheck in CI, and the evidence pack under compliance/casa
2026-09-19 08:18:35 +02:00
2026-09-20 07:16:35 -07:00
2026-07-13 18:15:58 +02:00
2026-07-22 17:05:37 +02:00
2026-09-30 21:02:00 -07:00