OrgFlow 2.4.0-rc.2 — unsigned release candidate
Pre-releaseOrgFlow 2.4.0-rc.2
Unsigned release candidate. This release is ready for evaluation, not a signed production desktop rollout. Apple notarization, Windows signing, and a real signed N → N+1 upgrade drill remain required before stable promotion. Existing stable installations do not automatically receive this prerelease.
Changes
- Native desktop Open / Save As, recent org charts, external-file conflict protection, and explicit browser file reconnection.
- Check for updates → Download → Save and restart, with required saves before installation. Windows automatic updates require the
windows-setup.exeinstaller; the portable EXE remains available for manual replacement. - Authoritative IndexedDB storage, transactional pending server edits, concurrent-tab protection, isolated account caches, complete recovery checkpoints, and safer journal rotation.
- Working offline interactive HTML with expandable teams, search, zoom and redacted data.
- Verified OIDC login, browser-bound state, invitation-based membership, expiring scoped API tokens, proposal idempotency and assigned-reviewer approval.
- Consistent database backup/restore, readiness checks, retention, non-root containers, expanded OpenAPI documentation and updated Electron dependencies.
Validation
112 domain/server tests; a 28-test browser suite across Chromium, Firefox and WebKit; native Electron lifecycle checks on Windows, macOS and Linux; lint, syntax/wiring checks and dependency audit. Firefox/WebKit skip user-picked writable-file tests because they use downloaded backups. Operating-system dialogs are automated in native tests; signing and real update delivery are not certified by mocked updater tests.
See validation, production gates, and host operations.
Before upgrading
Export a .orgflow backup and retain the previous data directory until recovery is verified. Legacy API tokens migrate to read-only and expire within 30 days; issue scoped replacements. Empty production OIDC tenants require BOOTSTRAP_ADMIN_EMAIL. Shared-host reviewers must be administrator email addresses. macOS ZIP supports Intel and Apple Silicon; Linux and Windows builds are x64.
All release tests and builds passed. Update manifest filenames and sizes match the uploaded artifacts. Candidate 1 was not published because CI found an empty signing-secret packaging configuration; candidate 2 fixes that build configuration.