Major version because the team-coordination architecture is rebuilt
end-to-end: the old GitHub coord-repo, members.json/team.json
clone-and-push dance, and `gh` Issues join-request flow are gone;
desktop clients now enroll with a 6-character PIN into a self-hosted
Node + SQLite server (see `server/`) and read team / member / project
state over HTTP.
Audit fixes folded into this release:
P0 — correctness
- gitHubOrg vs githubOrg casing mismatch between server and desktop
silently dropped the team's GitHub org from the welcome screen.
Aligned server (DB column, routes, admin UI) to the desktop's
`gitHubOrg`.
- useTeam now distinguishes loading (`snapshot === null` during the
brief IPC prime window) from `enrolled === false`; App.tsx defers
role-tier commit until loading clears so already-enrolled users
no longer flicker into the standalone-admin UI on cold boot.
- Stale UI strings: `TeamProjects.tsx` and `README.md` referenced the
coord repo as the source of truth — replaced with team-server
wording.
P1 — cleanup
- apiBusy.ts FRIENDLY_LABELS lost the six dead coord-* keys and
gained team-enroll / -refresh / -sign-out entries.
- framecad:// deep-link parser drops the `team` action (silently
no-op'd before; now correctly rejects unknown actions).
- DeepLinkPayload type narrowed to action: 'join' so the type
system enforces the contract.
- CLAUDE.md architecture section now covers /server/ and the new
desktop modules (teamServer.ts, useTeam.ts, TeamEnroll.tsx).
- docs/DEVELOPMENT.md source map updated; Settings-page section
reframed around team-server roles.
P2 — robustness
- teamSignOut now best-effort DELETE /api/me/device before clearing
local state, so a sign-out cleans up the server-side device row
+ audit-logs the revoke (new endpoint in server/src/routes/client.ts).
- 401 on /api/me clears every snapshot field (team, members,
projects, lastSyncAt) plus the on-disk cache, so the welcome
screen flips cleanly back to the enroll card.
- config.ts:getTeamServerSettings validates the persisted shape;
malformed JSON no longer crashes the main process.
CI — `.github/workflows/build-installer.yml` gets a `server-image`
job that builds the multi-arch (linux/amd64 + linux/arm64) Docker
image and pushes to ghcr.io/<owner>/framecad-server, tagged with
both the version and `latest`. Pulls via `docker compose up` for
self-hosters.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>