Skip to content

Releases: getsphericon/sphericon

Release list

v0.1.1

Choose a tag to compare

@github-actions github-actions released this 11 Oct 01:53
b58c80e

0.1.1 (2026-10-10)

Features

  • infra: host on AWS (ECS Fargate, RDS, Route 53, SES), supersede ADR 0028 (48ad17b)
  • infra: move the product to getsphericon.app, managed entirely by Terraform (0c24e2c)

Bug Fixes

  • release: publish the image under the getsphericon organization (b306731)

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 10 Oct 21:54
04a0b28

0.1.0 (2026-10-10)

⚠ BREAKING CHANGES

  • segments: remove Segment type; a Segment is always a rule

Features

  • api: add-suppression and unsubscribe operations in /api and MCP (#55) (5bce053)
  • api: broadcast drafts, audience, test-send and report in /api and MCP (dfd78b2)
  • api: manage Integrations through the external API (402306f)
  • api: manage Sending domains through the external API (5d0e0b4)
  • api: rails-style resourceful URLs via TypeSpec CRUD templates (0628507)
  • api: read-only custom fields, sending domains and complaint/bounce rates (#54) (3ebda14)
  • api: segments CRUD and preview in the external API (be9cbda)
  • api: templates and webhooks in /api (a50b2a2)
  • apitokens: one module mints and revokes API tokens; a token cannot grant what it lacks (2cae730)
  • auth: a single login route; remove the library /auth/ and avatar routes (30feed3)
  • auth: add login link to register page (b3f70de)
  • auth: email Users when a Second factor is required and before their grace ends (6bd3a2a), closes #191
  • auth: enforce session expiry and carry user id and epoch in the session token (ceb8d75)
  • auth: enforced session expiry, session epoch, TOTP second factor and two-step login (ADR 0020) (a54fb7c)
  • auth: enforced session expiry, session epoch, TOTP second factor and two-step login (ADR 0020) (#195) (a54fb7c)
  • auth: enroll a TOTP Second factor with Recovery codes (ad0c3b8)
  • auth: let a withheld Owner or Admin lift the requirement from the SPA (cb88630)
  • auth: mark the JWT cookie Secure when served over HTTPS (5d7297d)
  • auth: password reset, email verification, and email change (b732f56)
  • auth: rate limit forgot-password without revealing accounts (9cbda8e)
  • auth: require a Second factor for a Workspace with a grace period (32d4e78), closes #190
  • auth: reset another User's Second factor (Owner/Admin and operator command) (7a71da0), closes #192
  • auth: revoke sessions on password change, reset, email change and sign-out-everywhere (7ebf7ad)
  • auth: self-service account pages + profile email management (4713e61)
  • auth: throttle login per account with exponential delay (6291441)
  • auth: two-step login with TOTP or Recovery code (49976b2)
  • automations: sync workflow builder theme with Mantine color scheme (1deee46)
  • config: fail fast on weak production JWT secrets and make examples safe (7fcf520)
  • contacts: emit PII-free contact.erased Event and webhook on Erasure (eb06f3f)
  • contacts: erase a Contact by id (delete is Erasure, ADR 0021) (8783bbb)
  • contacts: erase by email and by visitor_id (1d97f28)
  • contacts: stop in-flight work and clear internal queues on erasure (119f7a4)
  • contacts: subject-access export of one Contact (32c3d2f)
  • db: bound Postgres pools, export pool stats, explicit river retention (816d5c8)
  • deploy: add Helm chart with migrate hook and check:helm (2a3b753)
  • dev: one Postgres for all checkouts, started by an idempotent db:up (d2f295f)
  • dev: per-worktree dev stack ports and origin (2961828)
  • dev: shared Postgres profile and per-checkout scratch database names (6d55b8c)
  • dev: worktrees:gc sweeps databases and daemon state of deleted worktrees (7ee8a95)
  • edit Integration send limits and show effective limit and usage (dc079a3)
  • ee: advanced retention prunes the audit log (47fe2c0)
  • ee: align audit diff keys with the explicit entries (from/to, changed marker) (d6c351e)
  • ee: audit access and configuration entities (e0cb2d9)
  • ee: audit capture in the scoped client, Tag first (a3e448f)
  • ee: audit content, audience and Contact changes (47341f3)
  • ee: audit explicit actions (invitation, login, password change, suspension) (cc474c0)
  • ee: audit log (spec #110) (65b0ae7)
  • ee: audit log CSV export and /api read with audit:read scope (0f80ff6)
  • ee: audit log filters, diff view and change-history links (dacef11)
  • ee: audit log retention setting, /api filters, audited export, safer snapshots (926c63d)
  • ee: audit log skeleton, a role change is recorded and listed (23db54c)
  • ee: audit retention control and audit UI tests (ab582a1)
  • ee: forward audit entries to Webhook endpoints (76cef23)
  • events: delete analytical Events past EVENTS_RETENTION_DAYS (427de7c)
  • events: prune the domain-event outbox below the slowest consumer (68e4d50)
  • export: typed contact export document; river API for test queue access (66a8fec)
  • expose Integration effective send limit, source and 24h usage ([8183b7e](https://github.com/...
Read more