Skip to content

Platform releases & updates

Follow the latest updates, architectural improvements, client guides, and security enhancements to Tokens.

Unreleased

Current cycle

Security

  • Enforced AAL2 MFA requirement for `super_admin` and `operator` roles in `requirePermission` and `verifyAdminAuth` with redirect to `/account/security`.
  • Added secret encryption in database (`0040_security_credentials.sql`) with AES-256-GCM authenticated encryption and sealed credentials.
  • Masked all secrets from admin read endpoints (`/api/admin/settings`).
  • Added trusted proxy IP resolution helper (`getClientIp`) and header-based WHMCS webhook secret authentication.
  • Sanitized `next` redirect parameter in OAuth and register flows with an explicit domain-relative allowlist.
  • Added safe JSON-LD escaping helper (`safeJsonLd`) replacing `<` to prevent `<script>` tag injection across all public SEO pages.
  • Restricted CMS file uploads to verified magic bytes for image MIME types (PNG, JPEG, GIF, WebP) and excluded SVG vectors.
  • Sanitized markdown links in content renderer to permit only safe schemes (`http:`, `https:`, `mailto:`, relative).
  • Added role and permission enforcement for every admin API route, with super admin only operations such as role changes, settings, balance adjustments, and key security state.
  • Payment mock branches require `DEV_MODE=true` outside production. Real provider signatures, amounts, currencies, payment references, and plan state are required.
  • Internal database and provider errors are not returned to customers in production.
  • Security response headers include frame protection, MIME protection, referrer policy, permissions policy, and production HSTS.

Fixed

  • Fixed manual payment disable bug: toggling off manual payment methods immediately hides manual payment UI and rejects manual checkout attempts across all client surfaces.
  • Fixed non-sold currency FX projection: `/pricing` only displays pricing cards in enabled/sold currencies and eliminates fabricated fallback rates.
  • Fixed marketing badge discrepancy: removed hardcoded "bKash, Nagad, Rocket" badges and replaced with dynamic `<PaymentMethodBadges />` based strictly on configured methods.
  • Fixed multiplier badge parsing to correctly render `{n}×` on all pricing and dashboard billing views.
  • Fixed stale cache on admin plan and pricing metadata mutations with comprehensive path revalidation (`revalidatePath('/')`, `revalidatePath('/pricing')`, `invalidatePlansCache()`, `invalidateCommerceConfig()`).
  • Restored the known-good `0041`/`0043` bodies for `settle_provider_payment`, `approve_manual_payment`, `admin_grant_plan` and `_apply_payment_side_effects` in the unapplied `0045` migration (only `v_plan.interval::text` differs), removing the invalid enum, missing-column, wrong-ledger-column and ambiguous-overload defects; the `checkoutSource = 'platform'` guard and skipped-side-effect audits are restored.
  • Fixed `settle_usage_charge`'s `ON CONFLICT` target to repeat the partial-index predicate on `omniroute_log_id` (PostgreSQL 42P10), and made the pool backfill idempotent for periods that have already ended.
  • Replaced the no-op advisory provisioning lock with a durable per-user claim (`omniroute_key_claims` + claim/release RPCs).
  • Removed remaining customer-facing USD from usage analytics (credits only), unified the active-pool predicate across gate/summary/quota, and fixed the BDT cache-price fallback order (explicit BDT → USD cache × FX → BDT input).
  • Removed the token-only settlement branch (Case B): a subscription without a usable credit pool now debits the PAYG wallet under `payg_fallback` or records the usage explicitly unbilled, and the pre-request gate blocks exhausted plans (`0046_usage_credit_billing.sql`).
  • Rolling usage windows are measured from `subscription_window_state` in credits; the dashboard no longer invents token windows for plans without configured limits.
  • Made inference settlement strictly idempotent with unique `gw_${uuid}` request IDs and pending settlements retry queue (`0042_gateway_metering.sql`).
  • Eliminated token counting discrepancies in Anthropic and OpenAI SSE streams; added injected usage chunk filtering.
  • Prevented double payouts on referral milestones with atomic database locking and idempotency constraints (`0043_referral_integrity.sql`).
  • Corrected referral commission calculations to evaluate from final paid amount rather than original list price.
  • Fixed database schema drift across billing, subscription credit pools, and plan usage windows in Drizzle ORM.
  • Fixed CMS fallback to only fall back on database errors, returning empty datasets when zero rows exist.
  • Scheduled the daily reports digest cron via pg_cron + pg_net (`0044_reports_digest_cron.sql`).
  • Fixed admin promotion query condition to check for confirmed email and listed admin status.

Changed

  • Set dark mode as default experience across `theme-script`, `theme-context`, and `theme-toggle` per `DESIGN.md`.
  • Filtered admin shell navigation dynamically according to viewer permissions (`hasAdminPermission`).
  • Removed dead `tokens_authz` authorization cookie setting and verification in favor of server session authority.
  • Tokenized UI colors across dashboard, admin shell, and security pages using semantic design tokens.
  • Customer identity now comes from the live Supabase session through the server API boundary. Caller supplied identity headers, unsigned cookies, and fixed demo identities are no longer trusted.
  • Billing, notifications, admin, provider, and developer services fail closed instead of returning process memory or fabricated financial state.
  • Provider settlement uses the atomic database RPC after webhook preconditions. Unknown, mismatched, failed, and duplicate events are handled explicitly.
  • Subscription cancellation schedules period end. Referral payout and refund transitions require explicit lifecycle RPCs.
  • Public content now documents OpenCode and OpenAI compatible clients rather than the deprecated Command Code direction.
  • Production URLs, OmniRoute endpoint, Supabase endpoint, feature flags, security headers, and cron authentication are explicit.
  • Middleware is limited to protected and auth pages. Runtime access uses Supabase Auth and PostgREST; direct PostgreSQL is limited to migrations and tooling.
  • The preview now treats the legacy `admin` role as `super_admin` during the migration window and keeps the server admin layout authoritative over stale middleware metadata.
  • Browser-safe role helpers use the shared permissions subpath, preventing `node:crypto` key utilities from entering the middleware client bundle.