Platform releases & updates
Follow the latest updates, architectural improvements, client guides, and security enhancements to Tokens.
Unreleased
Current cycleSecurity
- Enforced AAL2 MFA requirement for `super_admin` and `operator` roles in `requirePermission` and `verifyAdminAuth` with redirect to `/account/security`.
- Added secret encryption in database (`0040_security_credentials.sql`) with AES-256-GCM authenticated encryption and sealed credentials.
- Masked all secrets from admin read endpoints (`/api/admin/settings`).
- Added trusted proxy IP resolution helper (`getClientIp`) and header-based WHMCS webhook secret authentication.
- Sanitized `next` redirect parameter in OAuth and register flows with an explicit domain-relative allowlist.
- Added safe JSON-LD escaping helper (`safeJsonLd`) replacing `<` to prevent `<script>` tag injection across all public SEO pages.
- Restricted CMS file uploads to verified magic bytes for image MIME types (PNG, JPEG, GIF, WebP) and excluded SVG vectors.
- Sanitized markdown links in content renderer to permit only safe schemes (`http:`, `https:`, `mailto:`, relative).
- Added role and permission enforcement for every admin API route, with super admin only operations such as role changes, settings, balance adjustments, and key security state.
- Payment mock branches require `DEV_MODE=true` outside production. Real provider signatures, amounts, currencies, payment references, and plan state are required.
- Internal database and provider errors are not returned to customers in production.
- Security response headers include frame protection, MIME protection, referrer policy, permissions policy, and production HSTS.
Fixed
- Fixed manual payment disable bug: toggling off manual payment methods immediately hides manual payment UI and rejects manual checkout attempts across all client surfaces.
- Fixed non-sold currency FX projection: `/pricing` only displays pricing cards in enabled/sold currencies and eliminates fabricated fallback rates.
- Fixed marketing badge discrepancy: removed hardcoded "bKash, Nagad, Rocket" badges and replaced with dynamic `<PaymentMethodBadges />` based strictly on configured methods.
- Fixed multiplier badge parsing to correctly render `{n}×` on all pricing and dashboard billing views.
- Fixed stale cache on admin plan and pricing metadata mutations with comprehensive path revalidation (`revalidatePath('/')`, `revalidatePath('/pricing')`, `invalidatePlansCache()`, `invalidateCommerceConfig()`).
- Restored the known-good `0041`/`0043` bodies for `settle_provider_payment`, `approve_manual_payment`, `admin_grant_plan` and `_apply_payment_side_effects` in the unapplied `0045` migration (only `v_plan.interval::text` differs), removing the invalid enum, missing-column, wrong-ledger-column and ambiguous-overload defects; the `checkoutSource = 'platform'` guard and skipped-side-effect audits are restored.
- Fixed `settle_usage_charge`'s `ON CONFLICT` target to repeat the partial-index predicate on `omniroute_log_id` (PostgreSQL 42P10), and made the pool backfill idempotent for periods that have already ended.
- Replaced the no-op advisory provisioning lock with a durable per-user claim (`omniroute_key_claims` + claim/release RPCs).
- Removed remaining customer-facing USD from usage analytics (credits only), unified the active-pool predicate across gate/summary/quota, and fixed the BDT cache-price fallback order (explicit BDT → USD cache × FX → BDT input).
- Removed the token-only settlement branch (Case B): a subscription without a usable credit pool now debits the PAYG wallet under `payg_fallback` or records the usage explicitly unbilled, and the pre-request gate blocks exhausted plans (`0046_usage_credit_billing.sql`).
- Rolling usage windows are measured from `subscription_window_state` in credits; the dashboard no longer invents token windows for plans without configured limits.
- Made inference settlement strictly idempotent with unique `gw_${uuid}` request IDs and pending settlements retry queue (`0042_gateway_metering.sql`).
- Eliminated token counting discrepancies in Anthropic and OpenAI SSE streams; added injected usage chunk filtering.
- Prevented double payouts on referral milestones with atomic database locking and idempotency constraints (`0043_referral_integrity.sql`).
- Corrected referral commission calculations to evaluate from final paid amount rather than original list price.
- Fixed database schema drift across billing, subscription credit pools, and plan usage windows in Drizzle ORM.
- Fixed CMS fallback to only fall back on database errors, returning empty datasets when zero rows exist.
- Scheduled the daily reports digest cron via pg_cron + pg_net (`0044_reports_digest_cron.sql`).
- Fixed admin promotion query condition to check for confirmed email and listed admin status.
Changed
- Set dark mode as default experience across `theme-script`, `theme-context`, and `theme-toggle` per `DESIGN.md`.
- Filtered admin shell navigation dynamically according to viewer permissions (`hasAdminPermission`).
- Removed dead `tokens_authz` authorization cookie setting and verification in favor of server session authority.
- Tokenized UI colors across dashboard, admin shell, and security pages using semantic design tokens.
- Customer identity now comes from the live Supabase session through the server API boundary. Caller supplied identity headers, unsigned cookies, and fixed demo identities are no longer trusted.
- Billing, notifications, admin, provider, and developer services fail closed instead of returning process memory or fabricated financial state.
- Provider settlement uses the atomic database RPC after webhook preconditions. Unknown, mismatched, failed, and duplicate events are handled explicitly.
- Subscription cancellation schedules period end. Referral payout and refund transitions require explicit lifecycle RPCs.
- Public content now documents OpenCode and OpenAI compatible clients rather than the deprecated Command Code direction.
- Production URLs, OmniRoute endpoint, Supabase endpoint, feature flags, security headers, and cron authentication are explicit.
- Middleware is limited to protected and auth pages. Runtime access uses Supabase Auth and PostgREST; direct PostgreSQL is limited to migrations and tooling.
- The preview now treats the legacy `admin` role as `super_admin` during the migration window and keeps the server admin layout authoritative over stale middleware metadata.
- Browser-safe role helpers use the shared permissions subpath, preventing `node:crypto` key utilities from entering the middleware client bundle.