Changelog
All notable changes to My App.
August 30, 2026
Git-identified production deployments
Fixed
Production health now reports the Git commit baked into the running image, allowing deployment checks to prove which revision is serving instead of accepting a generic healthy response.
Fail-closed staged database releases
Security
Added explicit migration cutoffs, sequential rollout gates, runtime-role assertions, rollback artifacts, and disposable isolation proofs so tenant-policy waves cannot be bundled or skipped accidentally.
Row-level tenant isolation through Wave A
Security
Enabled and forced PostgreSQL row-level security on 28 tenant-owned tables. Runtime database roles cannot bypass RLS, and requests without tenant context return no tenant data.
August 2, 2026
Live product defects closed with end-to-end proof
Fixed
Repaired stale preference sessions, upload-volume ownership, webhook delivery queries, member invitations, and production AI provider configuration. The complete production browser suite reached zero failures with only declared fixture-gated skips.
Expiring and revocable draft share links
Added
Editors can share a draft through a hashed, non-enumerable token with an expiry. Links are rate limited, excluded from indexing, and revoked on publish, deletion, or manual action.
CMS media library with verified image uploads
Added
Added an organization-scoped media library with upload, list, delete, public serve, and editor picker flows. Image uploads are checked by file signature rather than trusting the filename or declared content type.
July 31, 2026
Invitations, webhooks, and deploy verification repaired in production
Fixed
Fixed member invitation failures caused by an invalid Better Auth method and a missing timestamp column. Restored webhook settings for organizations with endpoints, and made deploy verification fail when the running version does not advance.
v1.10.0
July 27, 2026Nine-block visual content editor
Added
Editors can add, configure, remove, and reorder nine validated block types with autosave that no longer floods the revision history.
A usable authenticated application shell
Fixed
Added persistent side navigation across authenticated routes and fixed onboarding loops, new-conversation chat errors, blocked theme styles, and the consent overlay intercepting product controls.
Revision history and safe draft preview
Added
Editors can inspect revisions, roll back changes, and preview drafts through an authorized path that never publishes draft content into the public cache.
SEO, tenant sitemaps, and robots controls
Added
Public pages now ship server-rendered metadata, canonical URLs, JSON-LD, tenant-specific sitemaps, and robots controls with safe per-tenant cache invalidation.
Tenant-branded rendering and custom domains
Added
Published sites render with tenant branding on organization routes and real custom domains. Host forwarding and deployment configuration were corrected so custom-domain tenancy works in production.
Organization-owned public-site CMS
Added
Added organization-scoped pages, blocks, navigation, publishing, and authoring APIs so each tenant can operate a public site from inside the product.
v1.9.0
June 16, 2026Hashed API keys for programmatic access
Security
Organization admins can create scoped API keys that are shown once and stored only as SHA-256 hashes. Bearer-key authentication works alongside browser sessions on versioned API routes.
Database-atomic seat limits
Security
Seat and member caps now enforce inside the database transaction, closing the concurrency race across application and Better Auth invitation paths.
Webhook delivery diagnostics and poison-endpoint protection
Changed
Added test events, delivery-window visibility, cross-organization publish authorization, and automatic deactivation with audit and email when an endpoint repeatedly fails.
Realtime product updates over SSE
Added
Added organization-scoped server-sent events backed by Redis pub/sub, with heartbeats, reconnect support, live feedback updates, and polling fallback when the stream is unavailable.
v1.8.0
June 15, 2026Production observability and operator alerts
Added
Added durable error records, centralized error capture, admin visibility, and production alert emails so server failures are attributable and actionable without paging on ordinary client errors.
v1.7.0
June 15, 2026Signed outbound webhooks with SSRF protection
Security
Organizations can manage signed webhook endpoints and inspect retried delivery attempts. Delivery pins the validated destination address at connection time to block DNS rebinding and private-network access.
Settings and invitation authorization hardening
Fixed
Closed stale preference rendering, no-op notification dispatch, and member-limit gaps across direct member adds, invitation creation, and invitation acceptance.
Per-seat billing and member limits
Added
Checkout, subscription updates, member additions, and Stripe reconciliation now carry an explicit seat quantity with proration-aware admin controls.
Versioned API and live OpenAPI documentation
Added
Added backward-compatible /api/v1 routes, an OpenAPI 3.1 document generated from live schemas, self-hosted interactive API docs, and drift tests that keep implementation and documentation aligned.
Two-factor authentication and organization policy
Security
Added TOTP enrollment, QR setup, recovery codes, second-factor login challenges, and a server-enforced organization policy that covers both pages and API routes.
v1.6.0
June 7, 2026Feedback voting
Added
Members can upvote suggestions once, see live vote totals, and remove their vote. Admins can sort each triage column by demand without weakening organization isolation.
Reliable production container replacement
Fixed
The deploy workflow now replaces the running application container instead of reporting success while an older image continues serving production.
Public product roadmap
Added
Added a public, organization-scoped roadmap grouped into Building, Ready for Review, and Live. Shipped items link to the changelog while private feedback details and submitter identity remain hidden.
Feedback email notifications and opt-out
Added
Added branded notifications for submissions, status changes, comments, and replies. Self-notifications are skipped, personal opt-outs are honored, and delivery failures never block the product write.
v1.5.0
May 30, 2026Admin feedback triage board
Added
Added a five-column admin board with drag-to-update status, an in-place response panel, optimistic moves, and automatic rollback when an update fails.
Interaction-safe feedback refresh
Changed
The feedback board refreshes while preserving open panels and in-flight edits, pauses in hidden tabs, and refreshes immediately when the operator returns.
Secure feedback attachments
Added
Added image attachments through an organization-scoped upload and serve pipeline with file validation, path-traversal defenses, persistent storage, and clipboard paste support.
In-app feedback collection and comments
Added
Members can submit organization-scoped feedback, follow its status, and discuss it in a sanitized comment thread. Server-resolved tenancy and strict request schemas prevent organization spoofing.
v1.4.0
May 24, 2026Production authentication verification tooling
Added
Added a standalone production-readiness check for Better Auth tables, admin columns, and required environment configuration, plus an operator checklist for password-reset verification.
Passwordless magic-link sign-in
Added
Added 10-minute email sign-in links, branded delivery through Mailgun, a password or magic-link login switcher, resend support, and clear expired or invalid-link recovery.
v1.3.0
May 23, 2026Curated theme preset system
Added
Added Swiss Grid, Editorial Serif, Mono Terminal, and Bold Display themes. Each preset includes a complete light and dark palette plus self-hosted fonts.
Organization theme controls
Added
Organization branding settings now include optimistic theme and accent pickers, with custom-property sanitization preserved for tenant-supplied branding.
Public and authenticated layout split
Changed
Separated the marketing shell from the authenticated application shell so public pages, app navigation, and theme behavior can evolve independently.
Accent palettes and flash-free theme delivery
Added
Added eight accent palettes with dark variants. Server-side theme attributes and an anti-flash bootstrap keep the selected appearance stable from the first rendered frame.
v1.2.0
May 22, 2026Changelog system
Added
Public changelog page at /changelog with category filtering and version grouping. Database-backed entries with title, version, markdown body, and six categories (added/changed/fixed/removed/deprecated/security). Backfilled from full project git history.
v1.1.0
May 21, 2026Plan limit optimization
Changed
Plan limit queries now use pre-resolved locals.tenant.limits instead of redundant DB queries. Eliminates 2 DB round-trips per member invite and document create.
Welcome email on signup
Added
Better Auth databaseHooks.user.create.after fires for all signup methods (email/password and OAuth). Fire-and-forget pattern matching existing email sends.
Dead code removal
Removed
Removed unused checkAiRateLimit and checkAiRequestLimit exports. These were stubs from Phase 4 that were never connected to real logic.
Semantic document search
Added
pgvector cosine similarity search via inline search bar on documents page. Result cards with relevance percentage badges and 200-char excerpts. Graceful degradation when Ollama is unavailable (alert banner, list remains functional).
Document management UI
Added
Upload documents (text/markdown, 1MB max). Paginated list with embedding status badges. Detail view with content display. Soft delete with confirmation. Plan limit enforcement on create.
Document CRUD API
Added
GET (paginated list), POST (create with validation), GET /:id (detail), DELETE /:id (soft delete). All org-scoped with membership checks. Binary content rejection via null byte detection.
BullMQ stability fixes
Fixed
Pinned BullMQ to ^5.76.10 for stability. Added 10s graceful shutdown timeout. Fixed admin retry jobId collision using native job.retry().
BullMQ document embedding queue
Added
Async document embedding via BullMQ on existing Redis. 3-attempt retry with exponential backoff. Worker lifecycle tied to server boot/shutdown. Admin retry endpoint for failed jobs.
v1.0.2
May 5, 2026Forgejo SSH deploy workflow
Added
Added CI deploy step via Forgejo Actions SSH. Deploy manifest for automated production deployments.
Stripe v21 API compatibility
Fixed
Resolved TypeScript errors from Stripe SDK v21 update. Updated type signatures for subscription and checkout flows.
v1.0.1
April 27, 2026Docker build fixes
Fixed
Resolved Docker build failures. Wired Mailgun and Sentry environment variables through to container runtime.
v1.0.0
April 23, 2026Streaming chat UI
Added
Full chat interface at /chat with streaming responses, markdown rendering, conversation list, and usage tracking per org.
AI chat with RAG pipeline
Added
OpenRouter integration (model-agnostic via openrouter/auto). Ollama for local embeddings (mxbai-embed-large, 1024 dims). pgvector cosine similarity search. Conversation persistence with multi-turn context.
CI/CD pipeline (Forgejo Actions)
Added
Automated pipeline on every push: lint (Biome), type check, unit tests (Vitest), production build. 212 passing tests at v1.0 ship.
Sentry error tracking
Added
Sentry SvelteKit SDK integration with source map uploads. Client and server error capture. No-op when SENTRY_DSN is not configured — zero overhead without it.
Redis caching and soft delete
Added
Tenant context caching in Redis. Session secondary storage. Soft delete pattern with deletedAt columns. notDeleted helper for consistent filtering.
Audit logging
Added
Immutable audit_log table recording all state-changing operations. Fire-and-forget audit utility. Actor and org references use SET NULL on delete for record preservation.
GDPR data export
Added
GET /api/account/export returns user's personal data in JSON format with sensitive field exclusion. Compliant with data portability requirements.
Privacy policy and terms of service pages
Added
Legal pages with configurable company details. Cookie consent banner with localStorage-based tracking. CONSENT_VERSION for re-prompting on policy changes.
Onboarding wizard for new users
Added
First-time user redirect to onboarding flow. Step-by-step wizard for profile setup, org creation, and feature introduction.
Loading states and skeleton components
Added
Skeleton loading states for all data-driven pages. Nav loading bar for page transitions. Empty states for list pages.
Toast notifications (svelte-sonner)
Added
Rich toast notifications for success/error/info feedback across all user actions. Integrated with shadcn-svelte Sonner component.
Validate redirect params as same-origin
Security
Redirect parameters in auth flows now validated to prevent open redirect vulnerabilities.
User profile and account management
Added
Profile page with name edit, password change, and account deletion. Delete account sends confirmation email before permanent removal.
Admin dashboard
Added
Full admin panel at /admin with user list, org list, system health overview. Admin guard middleware restricts access to role=admin users.
Plan limit enforcement
Added
Pre-flight limit checks before creating members, documents, or AI requests. Plan features seed script for free/starter/pro/enterprise tiers. Cancel subscription API.
Email verification and invitation acceptance
Added
Email verification banner on dashboard, verification link handling. Invitation acceptance route with org membership creation.
Password reset flow
Added
Forgot password page, reset password page with token validation. Email sent via Mailgun with secure token link.
Transactional email via Mailgun
Added
Mailgun SDK integration with responsive HTML email templates. Supports password reset, email verification, org invitation, and account deletion flows.
Restrict branding endpoint to owner/admin roles
Fixed
PUT /api/org/branding now requires owner or admin role, not just membership.
Organization membership authorization
Security
All org-scoped API routes now enforce membership checks. Role-based authorization (owner/admin/member). Zod validation-first on every handler.
CSS sanitization for branding XSS prevention
Security
Custom CSS input from org branding is sanitized to prevent XSS. Block-structure characters stripped from declaration values.
Redis-backed rate limiting
Security
Rate limiting on auth (5/min), AI chat (20/min), billing (10/min), and general API (100/min) endpoints. Atomic Lua script for Redis INCR+PEXPIRE.
Security headers (CSP, HSTS, X-Frame-Options)
Security
@nosecone/sveltekit integration with CSP nonces, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. All configured via hooks.
Health endpoint with per-service reporting
Changed
GET /api/health returns DB and Redis status with latency measurements. Used by Docker health checks and monitoring.
Server middleware pipeline
Added
Refactored hooks.server.ts to sequence() middleware pattern. Consistent handleError hook with Sentry integration. Standardized API error format with error codes.
Redis client with health check
Added
Shared ioredis connection with automatic reconnect, health check integration, and connection pooling. Redis 7 already provisioned in docker-compose.
Structured logging with Pino
Added
JSON-structured logging with AsyncLocalStorage request context, PII redaction (email, password, token fields), child loggers per request, and pino-pretty for development.
v0.1.0
April 3, 2026Docker deployment setup
Added
Multi-stage Dockerfile with non-root user, docker-compose orchestration (app + PostgreSQL + Redis), entrypoint script with migration handling and health checks.
Stripe billing integration
Added
Four-tier plan structure (free/starter/pro/enterprise). Checkout, billing portal, and webhook handling. Per-org subscription management.
SaaS multi-tenant foundation
Added
Organizations, members, invitations, roles. Tenant resolution via slug or custom domain. White-label branding per org (display name, logo, colors, favicon, custom CSS).
AI-first SvelteKit 5 app template
Added
Initial template scaffold with SvelteKit 5, Svelte 5 runes, Tailwind CSS v4, shadcn-svelte, PostgreSQL with pgvector, Better Auth, and Drizzle ORM.