This repository was archived by the owner on Jul 22, 2026. It is now read-only.
Repository navigation
Releases: Adandu/UtilityMate
Releases · Adandu/UtilityMate
Release list
UtilityMate v1.10.2
Fixes
- Corrected a bug in v1.10.1's association statement column detection: a shared/common-area water column was being counted twice (once as "Apă părți comune" and once as a phantom "Apă meteorică" column) whenever both label fragments appeared in a statement's header, which over-counted the real column total and forced most statements — including the specific month the fix targeted — back into the old borrowed-profile guessing it was meant to replace. Verified against all 9 real imported statements: every one now detects its own columns confidently, with no borrowed profile and no false review flags.
UtilityMate v1.10.1
Fixes
- Association statement (avizier) imports no longer guess a column layout by borrowing a different month's profile when the export template changes. Each statement's own header row is now read directly to detect its actual columns, including when a reading-fee column is duplicated instead of replaced (a real drift we found affecting recent imports, where amounts landed under the wrong charge category from one month to the next).
- Association statements now carry a
needs_reviewflag and an explanatory note whenever the parser can't confidently match a statement's header to its own row data, instead of silently trusting a fallback guess. - Existing imported statements are automatically re-parsed and corrected on the next app restart using this improved detection, with no manual data fix needed.
- Fixed a due-date extraction bug on Hidroelectrica and Engie invoices where an unrelated line of text between the "due date" label and its value could prevent the date from being found at all.
UtilityMate v1.10.0
Security
- Fixed a cross-tenant data leak: creating or updating a budget no longer accepts a
location_id/household_idthat doesn't belong to the current user. - Rate limiting now sees the real client IP instead of the internal nginx address, so login/register/upload throttling applies per client again instead of sharing one global bucket.
- Added rate limiting to the change-password endpoint.
- Adding a household member now validates the referenced user exists before creating the membership.
- Bumped
pyjwt,python-multipart, andstarletteto versions with known CVEs patched.
Improvements
- Invoice and association-statement number parsing now correctly detects US vs. European decimal/thousands separators instead of assuming European formatting whenever both
,and.appear. - Meter-index parsing no longer strips the decimal point, fixing a 100x error on non-integer readings.
- Generic-provider invoice parsing requires a plausible amount label/currency anchor instead of matching the first number near the word "total".
- Parsed invoices with an implausible amount or date are now flagged for review with an explanation instead of being silently accepted.
- PDF parsing for invoices and association statements now runs off the request thread so large uploads no longer block the API.
- PDF text extraction failures (encrypted, corrupted, or genuinely scanned files) are now logged with the actual cause instead of failing silently.
- Association statement imports now show a review screen listing every parsed line item after import.
- The invoice edit screen can now correct amount, invoice date, consumption value, provider, and location — not just status and notes.
- Invoice and association statement uploads now time out and can be cancelled instead of leaving the modal stuck on a hung request; error messages now show the actual backend reason.
- Fixed a memory leak where exported file downloads on the raw data and operations pages never released their object URLs.
Verification
- Backend test suite (18 tests, including new locale/decimal-parsing regression tests) passed inside the production container image against the updated source.
- Frontend TypeScript and production build checks passed.
UtilityMate v1.10.1
Fixes
- Association statement (avizier) imports no longer guess a column layout by borrowing a different month's profile when the export template changes. Each statement's own header row is now read directly to detect its actual columns, including when a reading-fee column is duplicated instead of replaced (a real drift we found affecting recent imports, where amounts landed under the wrong charge category from one month to the next).
- Association statements now carry a
needs_reviewflag and an explanatory note whenever the parser can't confidently match a statement's header to its own row data, instead of silently trusting a fallback guess. - Existing imported statements are automatically re-parsed and corrected on the next app restart using this improved detection, with no manual data fix needed.
- Fixed a due-date extraction bug on Hidroelectrica and Engie invoices where an unrelated line of text between the "due date" label and its value could prevent the date from being found at all.
UtilityMate v1.10.0
Security
- Fixed a cross-tenant data leak: creating or updating a budget no longer accepts a
location_id/household_idthat doesn't belong to the current user. - Rate limiting now sees the real client IP instead of the internal nginx address, so login/register/upload throttling applies per client again instead of sharing one global bucket.
- Added rate limiting to the change-password endpoint.
- Adding a household member now validates the referenced user exists before creating the membership.
- Bumped
pyjwt,python-multipart, andstarletteto versions with known CVEs patched.
Improvements
- Invoice and association-statement number parsing now correctly detects US vs. European decimal/thousands separators instead of assuming European formatting whenever both
,and.appear. - Meter-index parsing no longer strips the decimal point, fixing a 100x error on non-integer readings.
- Generic-provider invoice parsing requires a plausible amount label/currency anchor instead of matching the first number near the word "total".
- Parsed invoices with an implausible amount or date are now flagged for review with an explanation instead of being silently accepted.
- PDF parsing for invoices and association statements now runs off the request thread so large uploads no longer block the API.
- PDF text extraction failures (encrypted, corrupted, or genuinely scanned files) are now logged with the actual cause instead of failing silently.
- Association statement imports now show a review screen listing every parsed line item after import.
- The invoice edit screen can now correct amount, invoice date, consumption value, provider, and location — not just status and notes.
- Invoice and association statement uploads now time out and can be cancelled instead of leaving the modal stuck on a hung request; error messages now show the actual backend reason.
- Fixed a memory leak where exported file downloads on the raw data and operations pages never released their object URLs.
Verification
- Backend test suite (18 tests, including new locale/decimal-parsing regression tests) passed inside the production container image against the updated source.
- Frontend TypeScript and production build checks passed.
UtilityMate v1.10.0
Security
- Fixed a cross-tenant data leak: creating or updating a budget no longer accepts a
location_id/household_idthat doesn't belong to the current user. - Rate limiting now sees the real client IP instead of the internal nginx address, so login/register/upload throttling applies per client again instead of sharing one global bucket.
- Added rate limiting to the change-password endpoint.
- Adding a household member now validates the referenced user exists before creating the membership.
- Bumped
pyjwt,python-multipart, andstarletteto versions with known CVEs patched.
Improvements
- Invoice and association-statement number parsing now correctly detects US vs. European decimal/thousands separators instead of assuming European formatting whenever both
,and.appear. - Meter-index parsing no longer strips the decimal point, fixing a 100x error on non-integer readings.
- Generic-provider invoice parsing requires a plausible amount label/currency anchor instead of matching the first number near the word "total".
- Parsed invoices with an implausible amount or date are now flagged for review with an explanation instead of being silently accepted.
- PDF parsing for invoices and association statements now runs off the request thread so large uploads no longer block the API.
- PDF text extraction failures (encrypted, corrupted, or genuinely scanned files) are now logged with the actual cause instead of failing silently.
- Association statement imports now show a review screen listing every parsed line item after import.
- The invoice edit screen can now correct amount, invoice date, consumption value, provider, and location — not just status and notes.
- Invoice and association statement uploads now time out and can be cancelled instead of leaving the modal stuck on a hung request; error messages now show the actual backend reason.
- Fixed a memory leak where exported file downloads on the raw data and operations pages never released their object URLs.
Verification
- Backend test suite (18 tests, including new locale/decimal-parsing regression tests) passed inside the production container image against the updated source.
- Frontend TypeScript and production build checks passed.
UtilityMate v1.9.15
Security
- Replaced
python-josewithPyJWTfor HS256 token handling, removing the unused transitive ECDSA dependency flagged by CVE scanning. - Slimmed Docker runtime package installs by removing compiler, development library, curl, and recommended package installs from production images.
- Removed unused transitive crypto packages from the backend lockfile, including
ecdsa,rsa, andpyasn1. - Reduced the main Docker image OS package footprint from 167 scanned packages to 104 scanned packages.
Improvements
- Kept JWT behavior compatible with the existing
HS256access-token flow. - Replaced the container startup health probe with Python standard library HTTP checks so
curlis no longer required at runtime. - Added a writable Matplotlib cache directory for the container runtime to avoid startup cache warnings.
Verification
- CVE MCP backend dependency scan: no known vulnerabilities found across 59 scanned Python packages.
- CVE MCP main image package scan: reduced findings from 14 vulnerable package groups to 10 vulnerable package groups.
- Backend tests passed: 7 tests.
- Frontend TypeScript and production build checks passed.
- Main and backend Docker images built successfully.
UtilityMate v1.9.14
New Features
- Added CI verification gates for frontend lint/build and backend tests before publishing Docker images.
- Added Alembic scaffolding so future schema changes can be managed through migrations.
Improvements
- Hardened PDF upload handling with shared size-limited reads for invoice and association statement imports.
- Reduced bearer token persistence by moving frontend auth storage to session-only storage and shortening the default token lifetime to 8 hours.
- Removed internal PDF filesystem paths from API response schemas.
- Pinned backend Python dependencies and switched frontend Docker installs to
npm ci. - Aligned backend CI and Docker runtime on Python 3.12.
- Added Docker build context exclusions for local caches, invoices, data, and generated artifacts.
- Removed tracked Python bytecode artifacts and ignored future bytecode caches.
Bug Fixes
- Resolved frontend lint failures so the new CI lint gate can run cleanly.
- Refreshed frontend dependencies to clear
npm auditsecurity advisories.
UtilityMate v1.9.13
New Features
- No new features in this release.
Improvements
- No general improvements in this release.
Bug Fixes
- Fixed rent-page utility allocation so heating and electricity usage entered for an unassigned room is split equally across all utility-paying tenants instead of being skipped or left implicit.
UtilityMate v1.9.12
New Features
- No new features in this release.
Improvements
- Made Avizier profile detection header-aware so unknown future months can reuse the correct known BlocManager column layout without requiring another month-specific parser update.
Bug Fixes
- Preserved compatibility with older Avizier PDFs that end rows with trailing apartment-and-balance tokens such as
1 280,00while keeping support for split values like1 640,49and- 106,90.
UtilityMate v1.9.11
New Features
- No new features in this release.
Improvements
- Hardened Avizier parsing for the March 2026 BlocManager statement export by supporting the latest statement profile and split amount tokens such as
1 640,49and- 106,90.
Bug Fixes
- Restored association statement imports for
2026-04-23 - Avizier Martie 2026.pdfand similar Avizier PDFs that split negative or four-digit totals across multiple extracted tokens.
UtilityMate v1.9.10
New Features
- No new features in this release.
Improvements
- Widened the rent export per-person breakdown card table so long
Adjustment Notecontent wraps cleanly without overlapping adjacent columns.
Bug Fixes
- No new bug fixes in this release.
UtilityMate v1.9.9
New Features
- No new features in this release.
Improvements
- Split the frontend bundle by route and major vendor groups so the initial Vite production bundle no longer ships the entire application in one chunk.
Bug Fixes
- No new bug fixes in this release.