Releases: getopenpost/openpost
Releases · getopenpost/openpost
Release list
v3.13.0
Added
- Instance administrators can assign or remove plan overrides for users without requiring Paddle checkout, through a new admin endpoint and plan selection dialog.
Fixed
- Extended button and card touch targets with an invisible bottom area to improve mobile tap usability.
- Removed unnecessary wrapper padding around the Workspace setup guide in the composer.
- Fixed whitespace rendering in feedback dialog radio items.
v3.12.0
Changed
- Retired the Post authoring model end to end. Post HTTP routes, MCP post and draft tools, the legacy
publish_postJob kind, and thepostsservice are removed; the publisher, composer, scheduler, calendar, Engagement, Messaging, and notification paths operate only on Publication and Rendition identifiers. Historical migration files still upgrade older databases, and immutablelegacy_post/legacy_post_variantaliases resolve old links to canonical Publications. The Post compatibility tables (posts,post_destinations,post_media,post_variants,thread_drafts,post_media_deliveries) are dropped after the legacy backfill completes and no Post rows or pendingpublish_postJobs remain. - Added repository-owned Oxlint checks that reject unsafe type widening, unverified runtime boundaries, reflective access, module mocking, and other patterns that weaken type and dependency contracts.
- Split engagement and messaging refresh, persistence, provider seams, recurring Jobs, and retries into independent capability outcomes, and removed the transitional communications runtime.
- Contracted REST, MCP, CLI, browser, and direct application Workspace authorization onto one read, edit, or administer decision, removed middleware-owned and membership-only policy helpers, and kept durable Jobs explicitly scoped without user impersonation.
- Extracted Messaging into an independent application module with internal Workspace authorization, capability-specific provider access, stored conversation reads and mutations, durable sends, typed outcomes, provider-write fencing, and its own recurring collection chain over transitional sync-state storage.
- Extracted Engagement into a transport-independent application module with internal Workspace authorization, a capability-specific provider port, stored read and archive state, typed outcomes, provider-write fencing, and its own recurring Job chain and health state.
- Completed Publication-only composer recovery: media queues now belong to the Composer session module, editor returns are bound once to the original Workspace, Publication, and revision, Workspace changes preserve save, discard, or stay, and old Post links redirect to canonical Publication URLs without mounting a Post-backed composer.
- Publishing, Workspace invitation, and Organization ownership producers now emit typed notification outcomes. Workspace team owns invitation delivery generations and lifecycle updates, while notifications retain only redacted, deduplicated provider delivery evidence.
- Removed the raw notification producer API, sealed topic and delivery policy behind typed outcomes, and split notification email delivery from password reset, verification, and identity email capabilities across SMTP, Resend, and Cloudflare adapters.
- The text-and-thread composer now uses one Publication-backed browser session for new and existing drafts. The session owns serialized revision saves, conflicts, validation, scheduling, immediate publishing, retries, cancellation, deletion, and success reset through the typed Publication client.
- Notification producers can now record sealed domain outcomes whose topic, delivery, Mute, deduplication, action, and presentation policy comes from one backend catalogue. Notification settings use the catalogue's generated API projection while keeping exhaustive English and Portuguese labels, descriptions, and icons in the frontend.
- Moved media usage and lifecycle protection, account and Workspace deletion, background Job scoping, and activity navigation onto canonical Publication, Segment, and Rendition ownership instead of legacy Post authoring state.
- Deprecated retained Post HTTP compatibility routes, recorded their Publication replacements and sunset evidence in the compatibility registry, added OpenAPI migration guidance, and documented the minimum 90-day and two-later-stable-release removal gate.
- Added canonical Publication aliases and terminal legacy delivery evidence to the historical Post migration so published and failed compatibility rows resolve safely without provider calls.
- Moved planner calendar loading and CLI post/thread workflows onto canonical Publication list, creation, update, schedule, and deletion contracts, with Publication calendar filters available to MCP.
- Completed the canonical Publication delivery path with application-owned get, list, history, delete, cancellation, validation, scheduling, publishing, and retry operations; stable transport-neutral error categories; a canonical cancellation contract for REST and MCP; and persisted effective random-delay ranges whose exact Job times are covered by Publication authorization.
- Unified Workspace access behind one application decision for read, edit, and administer actions across request middleware and transactional callers. The decision now combines credential Workspace binding, Organization identity policy, active Workspace membership, and role level while keeping safe denial separate from operational failure.
- Proved the complete UX program through one combined browser and integration matrix covering the first-use journey, daily work, collaboration and safety, local recovery, responsive presentations, themes, locales, keyboard and announced state, automated serious and critical accessibility checks, clean console output, and synchronized Self-hosted claims. Reconciled the audit-remediation backlog to remove the completed UX work and retain external status infrastructure as a separate deferred boundary.
- Split Cloudflare edge changes into a read-only preparation and a separate apply that requires the reviewed forward-plan and prepared-operation digests, so operators can inspect the live snapshot and exact rollback before any production write.
- Grouped the marketing and documentation edge rules into the one deployed
openpost.socialCloudflare zone, so each phase is inspected, applied, and rolled back once without one host overwriting the other. - Kept the exact Markdown
Acceptgate within the function set Cloudflare permits in every deployed edge phase, so the reviewed plan can be applied without weakening rejection of mixed, weighted, wildcard, parameterized, repeated, or internally spaced values. - Added a bounded four-hour Cloudflare edge TTL to the exact
Acceptcache variants so repeated HTML and Markdown requests produce real cache hits while remaining separated in both request orders. - Published a dedicated Self-hosted product path with an explicit no-software-fee boundary outside Hosted service plans, complete operator responsibilities, current deployment and source links, responsive no-JavaScript HTML, and an agent-readable Markdown representation.
- Completed local application-state recovery with distinct offline, forbidden, not-found, rejected-request, and server-error guidance; in-place connection recovery; focused and announced error states; and destructive confirmations that retain only unfinished targets and remain open when an operation does not complete. Media and provider-configuration deletion are idempotent so a retry can safely reconcile a response lost after commit.
- Proved the collaboration-and-safety cohort across truthful invitation recovery, atomic Workspace and Organization deletion, accepted ownership transfer, permission-safe audit exports, and responsive, localized Daily email and temporary Mute controls.
- Shared one local Turbo task cache across OpenPost worktrees with a 2 GiB total cap, removed immutable editor models and audio from frontend cache archives and build-tool copy inputs, validated their declared inventory before linking them across generated web, Go embed, and Android trees, and omitted them from CI checkouts that do not build the application. CI keeps exact-run frontend caches ephemeral so source-map uploads still execute.
- Organization Owners can now select and permanently delete any owned Organization without Workspace access after a complete preview, exact-name confirmation, and recent authentication; unconfirmed Paddle subscriptions, outstanding checkouts, pending ownership transfer, provider-scheduled work, other provider work, and cleanup remain explicit blockers, canceled checkouts cannot resume and retain an opaque boundary that terminates late Paddle subscriptions, failure is atomic, affected access, credentials, current and evidenced historical invitation email Jobs, ownership-expiry or notification Jobs end on success, and only content-free lifecycle and required billing evidence remains.
- Updated
golang.org/x/imageto 0.45.0 to fix excessive memory allocation while validating VP8L images. - Added temporary account-wide and Workspace notification Mutes on both Notifications and Settings, with visible absolute end times and an idempotent end-now action. Mutes pause optional Immediate and Daily email without changing saved preferences, conservatively suppress pre-upgrade queued optional mail whose Workspace scope is unknown, resolve the Workspace scope first when scopes overlap, expire automatically, keep in-app notifications immediate, and never suppress Transactional security, access, invitation, or critical billing email. Workspace-bound credentials receive only their Workspace Mutes when they reconcile state. Database upgrades apply migration 100 automatically.
- Organization Owners can now select an Organization without Workspace access, see its current Owner, and nominate an active member after recent authentication and exact confirmation; a nominee can resolve the standalone action without Workspace access. Every ownership read and action enforces the Organization identity and SSO assurance decision without requiring Workspace access, and the transport-independent initiation service requires an unscoped browser credential and consumes one recent-authentication grant. The durable, expiring Transactional action uses semantic English and Portuguese notification content, clears and suppresses actions...
v3.11.0
Added
- Added one canonical hosted-plan catalogue and an expiring signed purchase choice that keeps exact pricing and trial terms through password signup, email verification, refresh, and identity-provider signup without defaulting invalid selections to Founder.
- Added an explicit first-Workspace confirmation that shows the selected plan and trial terms, atomically binds the named Workspace to one checkout attempt, and resumes that attempt after refresh without creating duplicates.
Fixed
- Kept thread remove controls above their textareas, tightened publication-history and meme-picker overlays to their content, highlighted the active sidebar draft, removed the redundant AI alt-text review note, and retried one safe transient Memegen catalog read.
- Restored release gating after the hosted purchase-flow merge by accepting formatter-safe provider-catalog sources and checking marketing links and trial copy against the canonical purchase terms.
v3.10.1
Fixed
- Qualified PostgreSQL provider-delivery upserts so the durable write fence reaches the provider instead of failing before every publication request.
v3.10.0
Changed
- Added a repository map, an agent workflow router, and a read-only doctor for local workflow artifacts and configured GitHub triage labels.
Fixed
- Updated the marketing browser contract to verify the fictional workflow disclosure after removal of the unproved customer-logo rail.
- Made the changed-file pre-push formatter load the Svelte parser explicitly so marketing component changes are checked instead of blocking every push.
- Removed unproved customer-logo usage claims, labeled generated personas and workflows as fictional examples, and added a dated register that validates proof-claim owners, evidence, review dates, and expiry.
- Kept failed conversation read-state writes visible and retryable instead of clearing unread state locally, and made Android releases fail closed rather than publishing an unsigned APK under the installable asset name.
- Bound hosted checkout completion to its opaque billing attempt, persisted a validated same-origin return path with the selected plan and period, and made that path one-time so unrelated subscriptions, refreshes, and replay cannot redirect a user.
- Moved analytics account filtering, ordering, exact totals, and cursor paging to the stored-data API so workspaces with more than 50 post results keep complete newest/history views and account summaries.
- Made remote destination pickers page through provider options, deduplicate appended results, bind requests to current setting context, and clear incompatible child selections when a parent changes.
- Scrubbed engagement author and attachment metadata when a provider reports deletion or a provider-side delete succeeds, instead of retaining those fields after the body was removed.
- Bound account capability caches to the full settings and target context, output profile, intent, media shape, locale, and region so one community, location, or policy mode cannot reuse another target's provider rules.
- Extended the shared capability contract with hard and recommended title, body, description, alt-text, dimension, codec, frame-rate, audio, and local-time rules; provider catalogues and cross-transport parity coverage can now adopt those constraints incrementally.
- Added the schema and API foundation for provider subdestination targets, including target-aware authorization, retry, delete, uniqueness, and legacy Mastodon backfill behavior; provider-setting binding remains a follow-up gate before subtargets are advertised.
- Added a canonical provider-delivery projection with queued, submitted, processing, provider-scheduled, live, rejected, ambiguous, and manual-resolution states, exact reconciliation timing, and a stale-attempt fence, and exposed it on publication destinations.
- Removed the redundant gap between the desktop sidebar's draft list and workspace-navigation divider.
v3.9.6
Fixed
- Escaped LinkedIn's reserved commentary characters at the provider boundary so ordinary post text with parentheses or other markup symbols is published in full instead of rendering only the prefix.
v3.9.5
Fixed
- Aligned the hosted production privacy-policy version with the current application contract so candidate configuration validation and PostHog-enabled deployment use the same managed runtime environment.
v3.8.0
Added
- Added an optional Memegen-backed meme maker to the shared media picker with cached template search, editable captions and image slots, validated AI suggestions, bounded previews, Media-library imports, source metadata, and durable generation recipes.
Changed
- Split Profile, Security, Developer, Billing, Schedule, Brand, Instance, and workspace preferences into tab-owned Settings modules that each keep loading, mutation, dirty-state, and rendering behavior local while the route owns only navigation and composition.
- Added an executable release lifecycle that shares Conventional Commit and workflow-run decisions with local preparation and verifies the identity-preserving complete-draft-to-published transition in hosted delivery.
- Made one Publication application boundary own access checks, creation, updates, validation, scheduling, immediate publishing, and retry orchestration across REST, MCP, CLI, and retained Post compatibility adapters.
- Centralized all durable job kinds, construction defaults, execution dispatch, retry classification, recurrence, stale-worker recovery, and ambiguous provider-write fencing in the job registry so producers, migrations, and workers share one policy.
- Added repository-owned engineering workflow skills and documented the GitHub issue tracker, triage labels, and single-context domain-document conventions used by agents.
Fixed
- Kept disconnected historical account rows out of workspace provider-readiness decisions so an active verified X or Mastodon connection is not marked for reconnection by an older inactive destination.
- Kept AI meme suggestion previews recoverable when hosted rendering is slow or interrupted, retried one safe transient image download, and stopped canceled requests from appearing as expired sessions.
v3.7.3
Fixed
- Kept configured cloud providers and active migrated accounts usable while certification evidence is being populated, without making uncertified providers publicly claimable. Migration 085 validates only linked, active, non-revoked legacy grants with stored encrypted access credentials. Cloud operators can opt into strict operational evidence enforcement with
OPENPOST_PROVIDER_CERTIFICATION_ENFORCED=trueafter the required runtime controls, approvals, tests, and scope evidence exist.
v3.7.2
Fixed
- Allowed the image-promotion job to read the private draft release with its GitHub token before verifying the complete asset set.