My App

Changelog

All notable changes to My App.

August 30, 2026

Git-identified production deployments

Fixed
Production health now reports the Git commit baked into the running image, allowing deployment checks to prove which revision is serving instead of accepting a generic healthy response.

Fail-closed staged database releases

Security
Added explicit migration cutoffs, sequential rollout gates, runtime-role assertions, rollback artifacts, and disposable isolation proofs so tenant-policy waves cannot be bundled or skipped accidentally.

Row-level tenant isolation through Wave A

Security
Enabled and forced PostgreSQL row-level security on 28 tenant-owned tables. Runtime database roles cannot bypass RLS, and requests without tenant context return no tenant data.
August 2, 2026

Live product defects closed with end-to-end proof

Fixed
Repaired stale preference sessions, upload-volume ownership, webhook delivery queries, member invitations, and production AI provider configuration. The complete production browser suite reached zero failures with only declared fixture-gated skips.

Expiring and revocable draft share links

Added
Editors can share a draft through a hashed, non-enumerable token with an expiry. Links are rate limited, excluded from indexing, and revoked on publish, deletion, or manual action.

CMS media library with verified image uploads

Added
Added an organization-scoped media library with upload, list, delete, public serve, and editor picker flows. Image uploads are checked by file signature rather than trusting the filename or declared content type.
July 31, 2026

Invitations, webhooks, and deploy verification repaired in production

Fixed
Fixed member invitation failures caused by an invalid Better Auth method and a missing timestamp column. Restored webhook settings for organizations with endpoints, and made deploy verification fail when the running version does not advance.

v1.10.0

July 27, 2026

Nine-block visual content editor

Added
Editors can add, configure, remove, and reorder nine validated block types with autosave that no longer floods the revision history.

A usable authenticated application shell

Fixed
Added persistent side navigation across authenticated routes and fixed onboarding loops, new-conversation chat errors, blocked theme styles, and the consent overlay intercepting product controls.

Revision history and safe draft preview

Added
Editors can inspect revisions, roll back changes, and preview drafts through an authorized path that never publishes draft content into the public cache.

SEO, tenant sitemaps, and robots controls

Added
Public pages now ship server-rendered metadata, canonical URLs, JSON-LD, tenant-specific sitemaps, and robots controls with safe per-tenant cache invalidation.

Tenant-branded rendering and custom domains

Added
Published sites render with tenant branding on organization routes and real custom domains. Host forwarding and deployment configuration were corrected so custom-domain tenancy works in production.

Organization-owned public-site CMS

Added
Added organization-scoped pages, blocks, navigation, publishing, and authoring APIs so each tenant can operate a public site from inside the product.

v1.9.0

June 16, 2026

Hashed API keys for programmatic access

Security
Organization admins can create scoped API keys that are shown once and stored only as SHA-256 hashes. Bearer-key authentication works alongside browser sessions on versioned API routes.

Database-atomic seat limits

Security
Seat and member caps now enforce inside the database transaction, closing the concurrency race across application and Better Auth invitation paths.

Webhook delivery diagnostics and poison-endpoint protection

Changed
Added test events, delivery-window visibility, cross-organization publish authorization, and automatic deactivation with audit and email when an endpoint repeatedly fails.

Realtime product updates over SSE

Added
Added organization-scoped server-sent events backed by Redis pub/sub, with heartbeats, reconnect support, live feedback updates, and polling fallback when the stream is unavailable.

v1.8.0

June 15, 2026

Production observability and operator alerts

Added
Added durable error records, centralized error capture, admin visibility, and production alert emails so server failures are attributable and actionable without paging on ordinary client errors.

v1.7.0

June 15, 2026

Signed outbound webhooks with SSRF protection

Security
Organizations can manage signed webhook endpoints and inspect retried delivery attempts. Delivery pins the validated destination address at connection time to block DNS rebinding and private-network access.

Settings and invitation authorization hardening

Fixed
Closed stale preference rendering, no-op notification dispatch, and member-limit gaps across direct member adds, invitation creation, and invitation acceptance.

Per-seat billing and member limits

Added
Checkout, subscription updates, member additions, and Stripe reconciliation now carry an explicit seat quantity with proration-aware admin controls.

Versioned API and live OpenAPI documentation

Added
Added backward-compatible /api/v1 routes, an OpenAPI 3.1 document generated from live schemas, self-hosted interactive API docs, and drift tests that keep implementation and documentation aligned.

Two-factor authentication and organization policy

Security
Added TOTP enrollment, QR setup, recovery codes, second-factor login challenges, and a server-enforced organization policy that covers both pages and API routes.

v1.6.0

June 7, 2026

Feedback voting

Added
Members can upvote suggestions once, see live vote totals, and remove their vote. Admins can sort each triage column by demand without weakening organization isolation.

Reliable production container replacement

Fixed
The deploy workflow now replaces the running application container instead of reporting success while an older image continues serving production.

Public product roadmap

Added
Added a public, organization-scoped roadmap grouped into Building, Ready for Review, and Live. Shipped items link to the changelog while private feedback details and submitter identity remain hidden.

Feedback email notifications and opt-out

Added
Added branded notifications for submissions, status changes, comments, and replies. Self-notifications are skipped, personal opt-outs are honored, and delivery failures never block the product write.

v1.5.0

May 30, 2026

Admin feedback triage board

Added
Added a five-column admin board with drag-to-update status, an in-place response panel, optimistic moves, and automatic rollback when an update fails.

Interaction-safe feedback refresh

Changed
The feedback board refreshes while preserving open panels and in-flight edits, pauses in hidden tabs, and refreshes immediately when the operator returns.

Secure feedback attachments

Added
Added image attachments through an organization-scoped upload and serve pipeline with file validation, path-traversal defenses, persistent storage, and clipboard paste support.

In-app feedback collection and comments

Added
Members can submit organization-scoped feedback, follow its status, and discuss it in a sanitized comment thread. Server-resolved tenancy and strict request schemas prevent organization spoofing.

v1.4.0

May 24, 2026

Production authentication verification tooling

Added
Added a standalone production-readiness check for Better Auth tables, admin columns, and required environment configuration, plus an operator checklist for password-reset verification.

Passwordless magic-link sign-in

Added
Added 10-minute email sign-in links, branded delivery through Mailgun, a password or magic-link login switcher, resend support, and clear expired or invalid-link recovery.

v1.3.0

May 23, 2026

Curated theme preset system

Added
Added Swiss Grid, Editorial Serif, Mono Terminal, and Bold Display themes. Each preset includes a complete light and dark palette plus self-hosted fonts.

Organization theme controls

Added
Organization branding settings now include optimistic theme and accent pickers, with custom-property sanitization preserved for tenant-supplied branding.

Public and authenticated layout split

Changed
Separated the marketing shell from the authenticated application shell so public pages, app navigation, and theme behavior can evolve independently.

Accent palettes and flash-free theme delivery

Added
Added eight accent palettes with dark variants. Server-side theme attributes and an anti-flash bootstrap keep the selected appearance stable from the first rendered frame.

v1.2.0

May 22, 2026

Changelog system

Added
Public changelog page at /changelog with category filtering and version grouping. Database-backed entries with title, version, markdown body, and six categories (added/changed/fixed/removed/deprecated/security). Backfilled from full project git history.

v1.1.0

May 21, 2026

Plan limit optimization

Changed
Plan limit queries now use pre-resolved locals.tenant.limits instead of redundant DB queries. Eliminates 2 DB round-trips per member invite and document create.

Welcome email on signup

Added
Better Auth databaseHooks.user.create.after fires for all signup methods (email/password and OAuth). Fire-and-forget pattern matching existing email sends.

Dead code removal

Removed
Removed unused checkAiRateLimit and checkAiRequestLimit exports. These were stubs from Phase 4 that were never connected to real logic.

Semantic document search

Added
pgvector cosine similarity search via inline search bar on documents page. Result cards with relevance percentage badges and 200-char excerpts. Graceful degradation when Ollama is unavailable (alert banner, list remains functional).

Document management UI

Added
Upload documents (text/markdown, 1MB max). Paginated list with embedding status badges. Detail view with content display. Soft delete with confirmation. Plan limit enforcement on create.

Document CRUD API

Added
GET (paginated list), POST (create with validation), GET /:id (detail), DELETE /:id (soft delete). All org-scoped with membership checks. Binary content rejection via null byte detection.

BullMQ stability fixes

Fixed
Pinned BullMQ to ^5.76.10 for stability. Added 10s graceful shutdown timeout. Fixed admin retry jobId collision using native job.retry().

BullMQ document embedding queue

Added
Async document embedding via BullMQ on existing Redis. 3-attempt retry with exponential backoff. Worker lifecycle tied to server boot/shutdown. Admin retry endpoint for failed jobs.

v1.0.2

May 5, 2026

Forgejo SSH deploy workflow

Added
Added CI deploy step via Forgejo Actions SSH. Deploy manifest for automated production deployments.

Stripe v21 API compatibility

Fixed
Resolved TypeScript errors from Stripe SDK v21 update. Updated type signatures for subscription and checkout flows.

v1.0.1

April 27, 2026

Docker build fixes

Fixed
Resolved Docker build failures. Wired Mailgun and Sentry environment variables through to container runtime.

v1.0.0

April 23, 2026

Streaming chat UI

Added
Full chat interface at /chat with streaming responses, markdown rendering, conversation list, and usage tracking per org.

AI chat with RAG pipeline

Added
OpenRouter integration (model-agnostic via openrouter/auto). Ollama for local embeddings (mxbai-embed-large, 1024 dims). pgvector cosine similarity search. Conversation persistence with multi-turn context.

CI/CD pipeline (Forgejo Actions)

Added
Automated pipeline on every push: lint (Biome), type check, unit tests (Vitest), production build. 212 passing tests at v1.0 ship.

Sentry error tracking

Added
Sentry SvelteKit SDK integration with source map uploads. Client and server error capture. No-op when SENTRY_DSN is not configured — zero overhead without it.

Redis caching and soft delete

Added
Tenant context caching in Redis. Session secondary storage. Soft delete pattern with deletedAt columns. notDeleted helper for consistent filtering.

Audit logging

Added
Immutable audit_log table recording all state-changing operations. Fire-and-forget audit utility. Actor and org references use SET NULL on delete for record preservation.

GDPR data export

Added
GET /api/account/export returns user's personal data in JSON format with sensitive field exclusion. Compliant with data portability requirements.

Privacy policy and terms of service pages

Added
Legal pages with configurable company details. Cookie consent banner with localStorage-based tracking. CONSENT_VERSION for re-prompting on policy changes.

Onboarding wizard for new users

Added
First-time user redirect to onboarding flow. Step-by-step wizard for profile setup, org creation, and feature introduction.

Loading states and skeleton components

Added
Skeleton loading states for all data-driven pages. Nav loading bar for page transitions. Empty states for list pages.

Toast notifications (svelte-sonner)

Added
Rich toast notifications for success/error/info feedback across all user actions. Integrated with shadcn-svelte Sonner component.

Validate redirect params as same-origin

Security
Redirect parameters in auth flows now validated to prevent open redirect vulnerabilities.

User profile and account management

Added
Profile page with name edit, password change, and account deletion. Delete account sends confirmation email before permanent removal.

Admin dashboard

Added
Full admin panel at /admin with user list, org list, system health overview. Admin guard middleware restricts access to role=admin users.

Plan limit enforcement

Added
Pre-flight limit checks before creating members, documents, or AI requests. Plan features seed script for free/starter/pro/enterprise tiers. Cancel subscription API.

Email verification and invitation acceptance

Added
Email verification banner on dashboard, verification link handling. Invitation acceptance route with org membership creation.

Password reset flow

Added
Forgot password page, reset password page with token validation. Email sent via Mailgun with secure token link.

Transactional email via Mailgun

Added
Mailgun SDK integration with responsive HTML email templates. Supports password reset, email verification, org invitation, and account deletion flows.

Restrict branding endpoint to owner/admin roles

Fixed
PUT /api/org/branding now requires owner or admin role, not just membership.

Organization membership authorization

Security
All org-scoped API routes now enforce membership checks. Role-based authorization (owner/admin/member). Zod validation-first on every handler.

CSS sanitization for branding XSS prevention

Security
Custom CSS input from org branding is sanitized to prevent XSS. Block-structure characters stripped from declaration values.

Redis-backed rate limiting

Security
Rate limiting on auth (5/min), AI chat (20/min), billing (10/min), and general API (100/min) endpoints. Atomic Lua script for Redis INCR+PEXPIRE.

Security headers (CSP, HSTS, X-Frame-Options)

Security
@nosecone/sveltekit integration with CSP nonces, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. All configured via hooks.

Health endpoint with per-service reporting

Changed
GET /api/health returns DB and Redis status with latency measurements. Used by Docker health checks and monitoring.

Server middleware pipeline

Added
Refactored hooks.server.ts to sequence() middleware pattern. Consistent handleError hook with Sentry integration. Standardized API error format with error codes.

Redis client with health check

Added
Shared ioredis connection with automatic reconnect, health check integration, and connection pooling. Redis 7 already provisioned in docker-compose.

Structured logging with Pino

Added
JSON-structured logging with AsyncLocalStorage request context, PII redaction (email, password, token fields), child loggers per request, and pino-pretty for development.

v0.1.0

April 3, 2026

Docker deployment setup

Added
Multi-stage Dockerfile with non-root user, docker-compose orchestration (app + PostgreSQL + Redis), entrypoint script with migration handling and health checks.

Stripe billing integration

Added
Four-tier plan structure (free/starter/pro/enterprise). Checkout, billing portal, and webhook handling. Per-org subscription management.

SaaS multi-tenant foundation

Added
Organizations, members, invitations, roles. Tenant resolution via slug or custom domain. White-label branding per org (display name, logo, colors, favicon, custom CSS).

AI-first SvelteKit 5 app template

Added
Initial template scaffold with SvelteKit 5, Svelte 5 runes, Tailwind CSS v4, shadcn-svelte, PostgreSQL with pgvector, Better Auth, and Drizzle ORM.