Inkwell 2.7.0
2.7.0 is a large release focused on making the Writer genuinely useful for Standard.site's full document model, keeping unpublished work safe, and tightening the foundation across the stack.
The Writer on both platforms can now edit the full metadata a Standard.site document supports: tags, contributors (with optional role and display name), cover images, a Bluesky post reference, and self-labels/content warnings. Unknown fields are preserved on edit so nothing is accidentally lost on round-trip.
Autosave is also in. Your draft survives an app kill, a crash, or an accidental swipe away. It is scoped to your account DID, debounced so typing does not hit disk on every keystroke, and cleared only after a successful publish or an explicit discard. If the remote document changed since you started editing, you will see a conflict prompt rather than a silent overwrite.
Both platforms handle inkwell://document?uri= AT-URI deep links with strict validation, and the HTTPS universal link / App Link infrastructure is in place on the website. Two placeholders (Apple Team ID and Android release certificate SHA-256) need filling before OS-level verification goes fully live.
Android OAuth sessions are now sealed with AES-256-GCM under a non-exportable Keystore key. The legacy READ/WRITE_EXTERNAL_STORAGE and READ_PHONE_STATE permissions are removed, and CI validates the exact permission allowlist against the shipped APK.
This release also brings Android instrumentation tests on a real KVM-backed emulator in CI, French localisation for Android with a lint rule to catch hardcoded strings, pa11y-ci for the website, and Lexicon drift detection before it can break a build. The release workflow now attests a release manifest and SBOMs for both platforms.
- Writer metadata: tags, contributors, cover image, content warnings, Bluesky post reference — full round-trip on edit.
- Autosave with conflict detection on both iOS and Android.
- iOS document content spill to blob storage when records exceed the size ceiling.
- Deep link handling (
inkwell://document?uri=) on both platforms; HTTPS universal link infrastructure in place. - Android OAuth sessions sealed with AES-256-GCM under a Keystore key.
- Android APK permission surface audited and gated in CI.
- Android instrumentation test suite on a real emulator in CI.
- Android French localisation; website locale-aware routing.
- Release manifest attestation and SBOMs (Android Gradle + iOS SPM) published with each release.
Historical platform tags: ios-v2.7.0 and android-v2.7.0.