Skip to content

v3.12.0

Choose a tag to compare

@github-actions github-actions released this 17 Aug 14:08
· 9 commits to main since this release
f2439d8

Changed

  • Retired the Post authoring model end to end. Post HTTP routes, MCP post and draft tools, the legacy publish_post Job kind, and the posts service are removed; the publisher, composer, scheduler, calendar, Engagement, Messaging, and notification paths operate only on Publication and Rendition identifiers. Historical migration files still upgrade older databases, and immutable legacy_post / legacy_post_variant aliases resolve old links to canonical Publications. The Post compatibility tables (posts, post_destinations, post_media, post_variants, thread_drafts, post_media_deliveries) are dropped after the legacy backfill completes and no Post rows or pending publish_post Jobs remain.
  • Added repository-owned Oxlint checks that reject unsafe type widening, unverified runtime boundaries, reflective access, module mocking, and other patterns that weaken type and dependency contracts.
  • Split engagement and messaging refresh, persistence, provider seams, recurring Jobs, and retries into independent capability outcomes, and removed the transitional communications runtime.
  • Contracted REST, MCP, CLI, browser, and direct application Workspace authorization onto one read, edit, or administer decision, removed middleware-owned and membership-only policy helpers, and kept durable Jobs explicitly scoped without user impersonation.
  • Extracted Messaging into an independent application module with internal Workspace authorization, capability-specific provider access, stored conversation reads and mutations, durable sends, typed outcomes, provider-write fencing, and its own recurring collection chain over transitional sync-state storage.
  • Extracted Engagement into a transport-independent application module with internal Workspace authorization, a capability-specific provider port, stored read and archive state, typed outcomes, provider-write fencing, and its own recurring Job chain and health state.
  • Completed Publication-only composer recovery: media queues now belong to the Composer session module, editor returns are bound once to the original Workspace, Publication, and revision, Workspace changes preserve save, discard, or stay, and old Post links redirect to canonical Publication URLs without mounting a Post-backed composer.
  • Publishing, Workspace invitation, and Organization ownership producers now emit typed notification outcomes. Workspace team owns invitation delivery generations and lifecycle updates, while notifications retain only redacted, deduplicated provider delivery evidence.
  • Removed the raw notification producer API, sealed topic and delivery policy behind typed outcomes, and split notification email delivery from password reset, verification, and identity email capabilities across SMTP, Resend, and Cloudflare adapters.
  • The text-and-thread composer now uses one Publication-backed browser session for new and existing drafts. The session owns serialized revision saves, conflicts, validation, scheduling, immediate publishing, retries, cancellation, deletion, and success reset through the typed Publication client.
  • Notification producers can now record sealed domain outcomes whose topic, delivery, Mute, deduplication, action, and presentation policy comes from one backend catalogue. Notification settings use the catalogue's generated API projection while keeping exhaustive English and Portuguese labels, descriptions, and icons in the frontend.
  • Moved media usage and lifecycle protection, account and Workspace deletion, background Job scoping, and activity navigation onto canonical Publication, Segment, and Rendition ownership instead of legacy Post authoring state.
  • Deprecated retained Post HTTP compatibility routes, recorded their Publication replacements and sunset evidence in the compatibility registry, added OpenAPI migration guidance, and documented the minimum 90-day and two-later-stable-release removal gate.
  • Added canonical Publication aliases and terminal legacy delivery evidence to the historical Post migration so published and failed compatibility rows resolve safely without provider calls.
  • Moved planner calendar loading and CLI post/thread workflows onto canonical Publication list, creation, update, schedule, and deletion contracts, with Publication calendar filters available to MCP.
  • Completed the canonical Publication delivery path with application-owned get, list, history, delete, cancellation, validation, scheduling, publishing, and retry operations; stable transport-neutral error categories; a canonical cancellation contract for REST and MCP; and persisted effective random-delay ranges whose exact Job times are covered by Publication authorization.
  • Unified Workspace access behind one application decision for read, edit, and administer actions across request middleware and transactional callers. The decision now combines credential Workspace binding, Organization identity policy, active Workspace membership, and role level while keeping safe denial separate from operational failure.
  • Proved the complete UX program through one combined browser and integration matrix covering the first-use journey, daily work, collaboration and safety, local recovery, responsive presentations, themes, locales, keyboard and announced state, automated serious and critical accessibility checks, clean console output, and synchronized Self-hosted claims. Reconciled the audit-remediation backlog to remove the completed UX work and retain external status infrastructure as a separate deferred boundary.
  • Split Cloudflare edge changes into a read-only preparation and a separate apply that requires the reviewed forward-plan and prepared-operation digests, so operators can inspect the live snapshot and exact rollback before any production write.
  • Grouped the marketing and documentation edge rules into the one deployed openpost.social Cloudflare zone, so each phase is inspected, applied, and rolled back once without one host overwriting the other.
  • Kept the exact Markdown Accept gate within the function set Cloudflare permits in every deployed edge phase, so the reviewed plan can be applied without weakening rejection of mixed, weighted, wildcard, parameterized, repeated, or internally spaced values.
  • Added a bounded four-hour Cloudflare edge TTL to the exact Accept cache variants so repeated HTML and Markdown requests produce real cache hits while remaining separated in both request orders.
  • Published a dedicated Self-hosted product path with an explicit no-software-fee boundary outside Hosted service plans, complete operator responsibilities, current deployment and source links, responsive no-JavaScript HTML, and an agent-readable Markdown representation.
  • Completed local application-state recovery with distinct offline, forbidden, not-found, rejected-request, and server-error guidance; in-place connection recovery; focused and announced error states; and destructive confirmations that retain only unfinished targets and remain open when an operation does not complete. Media and provider-configuration deletion are idempotent so a retry can safely reconcile a response lost after commit.
  • Proved the collaboration-and-safety cohort across truthful invitation recovery, atomic Workspace and Organization deletion, accepted ownership transfer, permission-safe audit exports, and responsive, localized Daily email and temporary Mute controls.
  • Shared one local Turbo task cache across OpenPost worktrees with a 2 GiB total cap, removed immutable editor models and audio from frontend cache archives and build-tool copy inputs, validated their declared inventory before linking them across generated web, Go embed, and Android trees, and omitted them from CI checkouts that do not build the application. CI keeps exact-run frontend caches ephemeral so source-map uploads still execute.
  • Organization Owners can now select and permanently delete any owned Organization without Workspace access after a complete preview, exact-name confirmation, and recent authentication; unconfirmed Paddle subscriptions, outstanding checkouts, pending ownership transfer, provider-scheduled work, other provider work, and cleanup remain explicit blockers, canceled checkouts cannot resume and retain an opaque boundary that terminates late Paddle subscriptions, failure is atomic, affected access, credentials, current and evidenced historical invitation email Jobs, ownership-expiry or notification Jobs end on success, and only content-free lifecycle and required billing evidence remains.
  • Updated golang.org/x/image to 0.45.0 to fix excessive memory allocation while validating VP8L images.
  • Added temporary account-wide and Workspace notification Mutes on both Notifications and Settings, with visible absolute end times and an idempotent end-now action. Mutes pause optional Immediate and Daily email without changing saved preferences, conservatively suppress pre-upgrade queued optional mail whose Workspace scope is unknown, resolve the Workspace scope first when scopes overlap, expire automatically, keep in-app notifications immediate, and never suppress Transactional security, access, invitation, or critical billing email. Workspace-bound credentials receive only their Workspace Mutes when they reconcile state. Database upgrades apply migration 100 automatically.
  • Organization Owners can now select an Organization without Workspace access, see its current Owner, and nominate an active member after recent authentication and exact confirmation; a nominee can resolve the standalone action without Workspace access. Every ownership read and action enforces the Organization identity and SSO assurance decision without requiring Workspace access, and the transport-independent initiation service requires an unscoped browser credential and consumes one recent-authentication grant. The durable, expiring Transactional action uses semantic English and Portuguese notification content, clears and suppresses actions whenever transfer state cannot be loaded or its URL changes, preserves the current Owner through decline, expiry, or revocation, records every reached initiation failure in domain-owned audit evidence, exposes ownership transfers in the Organization audit filter, and atomically moves creator and subscription authority plus the Owner role to the accepting nominee while demoting the prior Owner to Administrator. Database upgrades apply migration 097 automatically; no operator action is required.
  • Optional notification email topics now support Off, Immediate, or Daily delivery with a saved local time and IANA timezone. Daily items are durably batched and deduplicated per user and window, use bounded Job retries and one idempotency key, and advance only after a confirmed send; Transactional security, access, invitation, and critical billing email remains immediate.
  • Fixed Cloudflare edge cache variance so parameterized and weighted Markdown requests cannot reuse the exact Markdown representation, and kept HTML fallbacks from being mislabeled when a Markdown artifact is unavailable.
  • Permanent Workspace deletion now shows exact removal, retention, recovery, and lifecycle-blocker facts; requires the Organization Owner, the canonical Workspace name, and recent authentication; rechecks blockers atomically; preserves dialog and data state on failure; and retains Organization-scoped audit evidence after success.
  • Added a read-only deployment proof for the public Markdown surfaces that binds the clean reviewed Git revision to both Cloudflare Pages builds by full commit hash, exact local and live artifacts, discovery and native-interface behavior, and a separate 24-hour AI crawl observation. The documentation full corpus now links only to explicit generated Markdown or intentional native machine assets.
  • Instance administrators can now page, filter, and export the same permission-safe audit vocabulary across every Organization, while Organization Owner boundaries remain unchanged and ordinary users, Workspace roles, scoped tokens, and other non-browser credentials cannot request instance-wide evidence.
  • Workspace invitations now distinguish provider-accepted Sent email from webhook-confirmed Delivered email, retain redacted and idempotent callback evidence, ignore stale or terminal-generation callbacks, show accepted and revoked records to administrators, return one safe acceptance error, and protect resends with a one-minute atomic cooldown plus the existing five-per-hour limit. Database upgrades apply migration 096 automatically; operators may configure OPENPOST_EMAIL_DELIVERY_WEBHOOK_SECRET when their mail provider supports delivery callbacks.
  • Added a deterministic Cloudflare plan for both public hosts. It uses the route catalogues to redirect known paths and select Markdown only for exact requests, checks Free-plan limits before changes, inspects conflicts without writing, records apply evidence, and generates a reviewable rollback.
  • Workspace invitations now queue one branded, expiring Transactional email for registered and unregistered recipients, bypass optional notification preferences, keep secrets out of ordinary notification and audit records, and preserve a truthful copy-link fallback when delivery is unavailable or fails. Database upgrades apply migration 094 automatically to add delivery state to existing invitations; no operator action is required.
  • Organization Owners can now page, filter, and export one permission-safe audit projection over identity, Workspace access, Organization-scoped impersonation, billing checkout, MCP, Publication lifecycle and authorization, and provider-write evidence without gaining Workspace content access or exposing emails, content, secrets, tokens, invitation links, credentials, or raw provider responses. Owners who are not Workspace members can use the audit UI, and Android exports use authenticated requests.
  • Proved the complete daily-workflow cohort across paged Engagement and Messages history, request races and retries, all eight exact Rendition outcomes, and responsive, localized Accounts and Paddle billing journeys.
  • Marketing and documentation builds now prove one complete public delivery contract across every eligible HTML and Markdown route, including prerendered meaning, discovery, safety, deterministic output, cache planning, size limits, and explicit artifact content types.
  • Composer destination controls now retain a usable mobile scroll area when first-use guidance is present.
  • Split the billing page into Paddle-backed subscription facts, OpenPost usage, and Paddle-managed payment tasks; added verified billing-contact display, purpose-specific payment and cancellation links with a fresh generic portal fallback, qualified list-price estimates, and kept payment methods and invoice documents managed in Paddle.
  • Documentation builds now expand controlled includes, normalize supported VitePress and raw HTML, publish useful no-JavaScript API guidance, and generate a bounded, provenance-preserving llms-full.txt convenience corpus from reviewed catalogue policy.
  • Updated CI and release images to Go 1.26.6 for the latest standard-library security fixes, provisioned Nix before repository policy checks, and made partial browser-job reruns reuse the newest canonical build artifact.
  • Direct and Settings-embedded social account management now share one explicitly configured Workspace component, while each route keeps its own authentication, OAuth continuation, URL cleanup, and one-time feedback without redirect flashes.
  • Moved the canonical source, release links, installation commands, support URLs, badges, and container image namespace to the getopenpost GitHub organization while retaining the published MCP Registry identifier for compatibility.
  • Messages now loads older conversation history near the top with stable cursor pages, an accessible manual control, exact reading-position preservation, deduplication, and stale-request protection across new messages, conversations, and Workspaces.
  • Messages now reaches complete conversation history with stable cursor pages, deduplicated appends that keep newer records, preserved filters and selection, and in-place first-page and older-page retries.
  • Publication details now keep each Rendition's exact queued, submitted, processing, provider-scheduled, live, rejected, ambiguous, or manual-resolution outcome, show safe normalized failure and attempt evidence, and offer retry only when the canonical provider-write result proves another send is safe.
  • Activity, Publication detail, and lifecycle history now share exact destination outcomes and safe recovery controls, while the timeline separates event occurrence from provider attempts, reconciliation, and the latest effective state so older failures cannot appear current.
  • Composer schedule and submit results now keep every destination's exact outcome visible, link to Publication detail, and offer only the canonical safe retry or review action.
  • Every public browser-tool page now keeps purpose, audience, inputs, outputs, limits, privacy behavior, and a next step in no-JavaScript HTML and focused build-generated Markdown.
  • Every ordinary public documentation page now publishes deterministic Markdown with canonical absolute links, per-page HTML discovery, an HTML-only sitemap, and a structured documentation llms.txt derived from the checked-in documentation catalogue.
  • Engagement now reaches complete saved history with stable cursor pages, in-place retries, deduplicated appends, and a searchable, paged Publication filter that keeps older selections.
  • Every platform and comparison page now publishes a build-generated Markdown representation with canonical metadata, provider limits or comparison evidence, HTML alternate discovery, and optional llms.txt sections derived from the marketing route manifest.
  • Marketing and documentation production builds now generate deterministic homepage Markdown and llms.txt discovery files from canonical public sources, advertise them from canonical HTML, and keep sitemaps HTML-only.
  • Proved the complete first-use cohort from verified signup through Workspace Activation with deterministic email, Paddle, and destination adapters, recovery and role coverage, responsive and presentation checks, and clean browser-console assertions.
  • Every static marketing page now has a deterministic Markdown representation, with route metadata owning page identity and discovery policy, curated optional and primary llms.txt links, unlisted legal and changelog files, semantic conversion checks, and a per-page size ceiling.
  • Replaced the frontend formatting and general JavaScript lint passes with Oxfmt and Oxlint, retained ESLint for Svelte template rules, upgraded production builds to Vite 8 and Rolldown, cached independent frontend quality tasks with Turbo, parallelized safe repository checks and tests, and reused the shared Go cache for local backend builds.
  • Replaced the overlapping package, Devenv, CI, hook, and release command graphs with one root task registry for formatting, linting, checks, tests, builds, verification, and release subcommands; added consistent surface scopes and policy selectors; removed obsolete aliases; and made CI and local release checks call the same tasks.
  • Updated the transitive Nano ID security pin so the exhaustive release dependency audit passes without the high-severity zero-size custom-generator advisory.
  • Made the documentation preview accept caller-selected host and port arguments so its isolated browser gate starts reliably.
  • Completed the privacy-limited first-use PostHog journey from signup intent through Workspace Activation, with server-owned lifecycle outcomes, strict browser and backend event allowlists, contract and integration coverage, and an MCP-managed production funnel with personless smoke verification.
  • The first successful Publication schedule or submission now records one server-owned Workspace Activation under retries and concurrency, emits one authoritative analytics event, retires setup guidance, and offers immediate View publication and Create another actions.
  • Workspace setup now recognizes the first meaningful text, media attachment, or thread-mode choice once per Workspace, while focus, destination selection, empty drafts, and repeated composer instances do not count. Its browser event allows only the interaction category and excludes authored content, media, identity, destination, and secret URL data.
  • Successful first-destination OAuth now opens a fresh composer with the new Workspace destination selected, while cancellation and failure return to actionable account management without exposing provider secrets in return parameters.
  • Added a server-derived Workspace setup guide that resumes from subscription, destination, and Publication state on the home, Accounts, and composer surfaces without a separate onboarding step index. Organization Owners receive the complete applicable journey, Organization administrators receive authorized billing guidance, Workspace administrators and editors receive only authorized content actions, viewers receive no setup actions, and self-hosted deployments omit Hosted service billing steps.
  • Shift-activating draft deletion now bypasses the confirmation dialog consistently in the composer, planner, and day-post drawers.
  • Reduced the ordinary local release gate to generated and type checks, lint, and unit tests; production builds, race and security checks, browser suites, and Docker image proof remain available through the explicit full rehearsal and candidate CI.
  • Added one changed-file check for whitespace, conflict markers, formatting and Svelte parsing, Go formatting, shell syntax, and Nix syntax, and installed the same implementation as the pre-commit and pushed-range pre-push hooks.

Fixed

  • Trimmed the SMTP username so a trailing space in OPENPOST_SMTP_USERNAME cannot send a malformed AUTH identity and fail notification email delivery with an SMTP authentication error.
  • Logged the terminal failure message when a background Job fails and recorded its retryability in error telemetry, so transient delivery failures are diagnosable without inspecting the database.
  • Kept homepage animation cleanup inside the browser lifecycle so marketing prerender no longer calls browser-only animation APIs.
  • Kept unlimited Publication scheduling operational when quota storage is unavailable, while preserving canonical usage accounting whenever counters exist and keeping limited plans fail-closed.
  • Stopped routine autosaves from replaying the Saved animation and from replacing an unchanged Image Editor document, which refreshed page previews after edits.
  • Accepted equivalent absolute and origin-relative canonical redirect locations in the public deployment proof while continuing to require the exact destination and preserved query.
  • Kept the generated public Nix module example on ghcr.io/getopenpost/openpost:latest even when the linked deployment source pins a verified release digest.
  • Restored marketing and documentation page views by requiring their production PostHog build settings, routed hosted browser telemetry through the managed first-party proxy, added matching page-leave events and privacy-limited Core Web Vitals, and kept route templates in SDK-owned URL properties.
  • "Create another" after first Activation now opens a clean composer instead of retaining the published text and draft identity.
  • Made direct documentation builds restore their ignored OpenAPI inputs from the tracked canonical spec before VitePress starts, so clean deployment checkouts cannot depend on generated local files.