Skip to content

Releases: agentinsync/agent-in-sync

v0.3.3

Choose a tag to compare

@alonle alonle released this 25 May 07:57
74ce502
feat(frontend): add /welcome onboarding step for domain org discovery…

v0.3.2: feat(frontend): add GitHub repo link to marketing navbar and footer (#9)

Choose a tag to compare

@alonle alonle released this 19 May 13:23
f1d61fb
Surface the open-source repo (github.com/agentinsync/agent-in-sync) on the
marketing pages: a GitHub icon link in the desktop navbar, an entry in the
mobile menu, an "Open Source" item in the footer Product column, and the
footer social icon now points at the repo (was the org-level URL).

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

v0.3.1: fix(frontend): declare APP_VERSION in turbo build env (#8)

Choose a tag to compare

@alonle alonle released this 17 May 20:40
13791aa
* feat(frontend): bake release tag into sidebar version

Wire the release workflow's git tag through a Docker build-arg
(APP_VERSION) into Vite's __APP_VERSION__ define, so the sidebar
in the production image reflects the tag that built it instead of
a hand-bumped root package.json.

Local pnpm dev still falls back to package.json — no process change
for dev.

* fix(frontend): declare APP_VERSION in turbo build env

Turbo runs each task in a sanitized child environment and hides any
env var not declared in turbo.json. After v0.3.0, the release image
still rendered "v0.1.0" in the sidebar because the Docker build did
set APP_VERSION=v0.3.0 in the RUN env, but Turbo stripped it before
launching Vite — so process.env.APP_VERSION was undefined and the
config fell back to root package.json (0.1.0).

Declaring "env": ["APP_VERSION"] on the build task both exposes the
var to Vite and (correctly) makes Turbo treat changes to it as a
cache-bust.

v0.3.0: feat(frontend): bake release tag into sidebar version (#7)

Choose a tag to compare

@alonle alonle released this 17 May 19:10
264ea9d
Wire the release workflow's git tag through a Docker build-arg
(APP_VERSION) into Vite's __APP_VERSION__ define, so the sidebar
in the production image reflects the tag that built it instead of
a hand-bumped root package.json.

Local pnpm dev still falls back to package.json — no process change
for dev.

v0.2.0: fix(security): close auth & PII findings from security review (#6)

Choose a tag to compare

@alonle alonle released this 17 May 18:44
11d24b2
* fix(security): close auth & PII findings from security review

- auth: mark Better Auth `domainId`/`isSuperAdmin` additionalFields as
  `input: false`. Without this, any authenticated user could POST
  `{ isSuperAdmin: true }` to `/api/auth/update-user` and self-promote
  to super-admin, bypassing every org/role/ownership check.
- middleware: API-key requests can no longer be redirected to a
  different organization via `:orgId` / `x-organization-id`.
  Mismatched header returns 403 instead of silently rewriting the
  bound org. Session-based auth behavior is unchanged.
- search: drop `users.email` from `getIssueDetail`'s issue / solution /
  comment selects and response shape. Previously any authenticated
  user could enumerate Public-org issue UUIDs and harvest author
  emails. Also drops `email` from the shared `authorSchema` so types
  stay consistent.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(mcp-server): drop email from IssueDetail type after backend change

CI build failed because mcp-server's local IssueDetail type still
required `author.email`, which the backend service no longer returns.
The formatter never rendered email anyway, so drop it from the type
and update the test fixtures.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>