Skip to content

Yuva 0.0.1

Choose a tag to compare

@github-actions github-actions released this 07 Oct 21:34
· 68 commits to main since this release

Yuva — one inbox for every product you run

One home for every product's conversations.
E-mail, live chat and in-app messages in one open-source inbox that you host yourself.

Website · Install guide · Upgrading · Changelog · Security

Warning

Pre-alpha. Yuva is young: the API and database schema can still change between
releases. Try it, read it, tell us what breaks — but keep real customer data out of it for now.

Get Yuva 0.0.1

docker pull ghcr.io/productdevbook/yuva:0.0.1
Piece How to get it
Server and team panel ghcr.io/productdevbook/yuva:0.0.1 for linux/amd64 and linux/arm64 — one binary, Postgres is all it needs
Web widget served by your own Yuva at /yuva.js, embed <yuva-chat> (guide)
iOS Swift Package https://github.com/productdevbook/yuva, version 0.0.1 (guide)
Android the sdk/kotlin module at tag v0.0.1 (guide)
Go helpers go get github.com/productdevbook/yuva/sdk/go@v0.0.1 — identity tokens and webhook verification
API contract openapi/openapi.yaml

What's in this release

The first public release. Pre-alpha: do not put real customer data in it yet.

Added

  • Server: one Go binary with Postgres, applying its own migrations on start; River jobs in the
    same process; attachments and raw e-mails on local disk or S3-compatible storage; /healthz,
    /readyz and Prometheus metrics. Docker image for linux/amd64 and linux/arm64.
  • Workspaces and members: owners, admins and agents with per-inbox access; sign-in with
    e-mailed codes and passkeys; invites; workspace API keys; usage counters.
  • Inboxes, contacts and conversations: per-inbox branding, language, time zone, business hours
    and live or async mode; messages, notes, attachments, assignment, status, priority, labels,
    canned replies, events and the /v1 REST API for all of them, described in
    openapi/openapi.yaml.
  • Agent panel: conversation list with filters and search, thread view, composer, contact
    sidebar, settings, realtime updates over WebSocket, English and Turkish; installable as a PWA.
  • E-mail channel: signed /ingress/email fed by a Cloudflare Email Worker (edge/, with a
    fallback address when the server is unreachable) or by any MTA through yuva ingest-email;
    threading, quote stripping, HTML sanitizing, attachments and raw message storage; outbound SMTP
    per channel with thread headers; loop protection; bounce and complaint handling, including
    Amazon SES notifications.
  • Catch-all e-mail channels: *@example.com receives every address of a domain that no other
    channel has, and replies go out from the address the contact wrote to.
  • Volume without bounces: a sender opens at most 20 new conversations per channel per hour;
    further mail joins their latest conversation. Only senders above YUVA_EMAIL_SENDER_HOURLY_CAP
    are refused.
  • Web widget: the <yuva-chat> web component for live chat and embedded threads, on the
    /client/v1 API with contact sessions, anonymous visitors, identity tokens signed by the host
    backend, allowed origins, presence, typing, read receipts and e-mail continuity for unread
    replies.
  • Mobile SDKs: sdk/swift (YuvaKit) and sdk/kotlin with a client, conversation list, thread,
    composer and feedback form.
  • Feedback and webhooks: feedback conversations with metadata, posting by API key, Standard
    Webhooks delivery with retries and a delivery log, contact deletion by external id.
  • sdk/go: identity token signing and webhook verification for host backends.
  • Member notifications: Web Push with per-member preferences and e-mail fallback.
  • Retention: an optional per-workspace period after which closed conversations and raw e-mails
    are deleted.
  • Operator commands: yuva bootstrap, migrate, api-key, inbox, channel, vapid-keys.

Security

  • Hardening of sign-in, sessions, client sessions and identity tokens, inbound mail and outbound
    connections, attachment handling, rate limiting behind proxies, and the panel's security
    headers. Report vulnerabilities as described in SECURITY.md.

Before you upgrade

Back up the database (and attachment storage) first. Migrations run when the new server starts,
and until 1.0 they have no way back. The steps are in the
operations guide.

Thank you

Yuva is AGPL-3.0 at its core and MIT for everything you embed in your own apps, so it can stay
open and keep going. Issues, ideas and pull requests are welcome — see
CONTRIBUTING.md.
Found a vulnerability? Please report it privately as described in
SECURITY.md.

First release. Every commit is in https://github.com/productdevbook/yuva/commits/v0.0.1