Skip to content

platform: v0.21.0

Choose a tag to compare

@github-actions github-actions released this 11 Jul 16:48
3a7e2e1

0.21.0 (2026-07-11)

Features

  • add bulk student performance report sending functionality via new API route and UI components (4e3e52e)
  • add Cambridge Dictionary scraper API and integrate into vocabulary section (30078ec)
  • add difficulty (24eafbd)
  • add quiz deadline editing functionality with persistent state and API support (c17a286)
  • add quiz deadline functionality to modules and update database schema and types (8748efe)
  • add quiz mode to vocabulary practice with multiple-choice questions (db8fe9e)
  • add student report email service and corresponding API route for performance tracking (22ab655)
  • add text-to-speech API endpoint and integrate speech synthesis into vocabulary learning components (4f452e7)
  • add vocabulary tab to course modules with dynamic UI injection and API endpoint (8f3ba0e)
  • apps: make launcher cards clickable (b9cd9bd)
  • auth: add email auth recovery override (0debe1c)
  • auth: support external profile scopes (531a0ff)
  • auth: support workspace session external apps (0ca4909)
  • backend: add bun check:backend one-shot CI-parity gate (24ec329)
  • backend: migrate additional api routes to rust (932e1ef)
  • backend: migrate cron whitelist domain writes + cron-jobs read to Rust (d44f765)
  • backend: migrate GET of 13 more API routes to Rust (batch 5) (00b0079)
  • backend: migrate GET of 2 final wallet-interest API routes to Rust (batch 7) (4d79a59)
  • backend: migrate GET of 22 more API routes to Rust (batch 3) (779720e)
  • backend: migrate GET of 48 more API routes to Rust (batch 6) (e639411)
  • backend: migrate GET of 50 more API routes to Rust (f0ec58d)
  • backend: migrate GET of 50 more API routes to Rust (batch 2) (6c147a2)
  • backend: migrate GET of 50 more API routes to Rust (batch 4) (687ac51)
  • backend: migrate GET of whiteboards detail + cron whitelist domains to Rust (cc5d31f)
  • backend: migrate managed-cron whitelist POST + cron-job DELETE to Rust (63a8453)
  • calendar: migrate calendar module from web to dedicated calendar app (678b949)
  • calendar: port hours + colors settings into the calendar app (fe7fa76)
  • cli: add task search (b8ec86f)
  • cms: add Richfield external-project adapter (fde0143)
  • cms: add Richfield external-project adapter (#4924) (b16a5e8)
  • contacts: add internal-api contacts base-url seam + web dual-run flag (fc9f0f8)
  • contacts: add workspace dashboard shell + users/CRM navigation (c0d0317)
  • contacts: migrate feedbacks, tutoring, guest-leads to apps/contacts (47bafeb)
  • contacts: migrate reports + groups and complete the users cutover (2ee89cd)
  • contacts: migrate users [userId]/follow-up; fix owned-route matcher (765b87a)
  • contacts: migrate users approvals module, extracting shared parts to packages (e66ae32)
  • contacts: migrate users attendance; add satellite-safe workspace-user link helper (8f53453)
  • contacts: migrate users group-tags module (bcc61e4)
  • contacts: migrate users topic-announcements module (01e19ab)
  • contacts: migrate users/database UI into apps/contacts (d3aa461)
  • contacts: migrate users/structure (org chart) to apps/contacts (93f2cb5)
  • contacts: move user-management settings into apps/contacts dialog (b6a3efe)
  • contacts: redirect non-migrated workspace routes to apps/web (f5a6518)
  • contacts: scaffold contacts.tuturuuu.com satellite shell + monorepo registration (7e335fc)
  • cron: add managed cron operations (24012e6)
  • docker: auto-enable cloudflared from CF_TUNNEL_TOKEN (80231b6)
  • edu: add quiz management flow & dashboard improvements (#4933) (9dafc17)
  • edu: add vocabulary journey (#4946) (06535d2)
  • education: extract shared education libs into @tuturuuu/education-core and ready learn/teach for API hosting (dd77db3)
  • external-apps: add managed scheduler cron integration (431ed1b)
  • external-apps: add scoped drive attachments (a03d577)
  • external-apps: add workspace member management (c5f6d2c)
  • external-apps: support invitation decisions (982cfb3)
  • finance: extract shared finance route-auth + storage libs into @tuturuuu/finance-core (79140d2)
  • finance: move workspace-finance API routes from apps/web to apps/finance (bafd61e)
  • finance: port the full finance settings into the finance app (8c20ffd)
  • finance: ready apps/finance to host finance API routes (37c0150)
  • finance: support prepaid subscription invoice ranges (fa0f338)
  • hive: migrate hive module from web to apps/hive (incl. APIs) (689085a)
  • implement AI-powered feedback generation for quiz submissions and integrate into the teach interface (0f5c7cf)
  • implement image search API and integrate related image suggestions into vocabulary section (50b4926)
  • implement module quiz submission tracking and management interface (fa4842e)
  • implement pronunciation practice mode with audio recording and analysis API integration (248bf3d)
  • implement quiz score visibility toggle and manual review status for learners (300909c)
  • implement student performance tracking and update workspace data schemas (9235679)
  • implement teach dashboard statistics API and UI component (7357463)
  • implement vocabulary management system for course lessons with database support (a11daf0)
  • implement vocabulary word autocompletion using Cambridge Dictionary API integration (2470e8b)
  • imrpove matching question UI (d085214)
  • infrastructure: add abuse protection controls (0e09692)
  • infrastructure: add friendly rate-limit review (ecb5660)
  • infrastructure: add rate-limit appeals (f1e50e9)
  • infrastructure: add satellite shell parity (d2fcaf3)
  • internal-api: add pay app base-URL seam (0d1eb1d)
  • inventory: add product stock history (b27571e)
  • inventory: add revenue share and category bundles (20b2e1e)
  • inventory: add Square Terminal checkout (0a3bd76)
  • inventory: collapse advanced settings in the integration panels (8e0967c)
  • inventory: de-crowd the Polar hub with tabs (9ada335)
  • inventory: finish moving inventory API routes to apps/inventory; delete tanstack-web inventory dashboard (740db08)
  • inventory: make the storefront section builder an accordion (c9d8012)
  • inventory: move inventory API routes into apps/inventory (071a72c)
  • inventory: redirect web inventory dashboard to apps/inventory (243a7b0)
  • inventory: revamp the setup page reference-data layout (598b640)
  • inventory: store Square credentials per workspace (e606f23)
  • inventory: tab the bundle create form (58721a5)
  • inventory: tab the costing profile dialog (7180a20)
  • inventory: tab the storefront create form (1f11960)
  • inventory: tab the storefront listing editor (856ff61)
  • inventory: use shared Tabs for the commerce panel (bf2d48b)
  • inventory: use skeleton loading state in OperatorDataList (86b1d4e)
  • learn: move tulearn + guest course API routes from apps/web to apps/learn (ee1aa7b)
  • mail: add advanced mailbox APIs and shadow ingestion (2543fc5)
  • mail: add catch-all delivery and revamp client (8d4cb12)
  • mail: add Cloudflare-native mail foundation (7c755b7)
  • mail: focus mailbox shell (4c2604d)
  • mail: refine composer and reading experience (926a28c)
  • mind: migrate mind module from web to apps/mind (incl. APIs) (bdc5f71)
  • pay: complete payment ownership migration (e79e421)
  • pay: dual-run billing behind NEXT_PUBLIC_ENABLE_PAY_APP rollout flag (3266ec2)
  • pay: host the billing surface on pay; redirect web /billing (5162706)
  • pay: move payment + billing API routes into apps/pay (8a932e9)
  • pay: scaffold apps/pay satellite (pay.tuturuuu.com, port 7826) (3d6e45c)
  • posts: add queue diagnostics and observability (744dcc9)
  • posts: audit log + revert for group-post completion checks (b38de09)
  • posts: reset / uncheck-all / history UI for group-post checks (bb2ecdc)
  • satellite: add sidebar apps launcher (b2f6fcd)
  • satellite: improve apps launcher picker (a3e92cb)
  • satellite: open settings on Cmd/Ctrl+, in satellite apps (841f425)
  • sdk: add external project operator commands (729ab49)
  • settings: expose settings permission availability (abf7e1e)
  • settings: flatten infrastructure dialog entries (082a2d7)
  • settings: lazy load dialog entries (c5c64bb)
  • settings: lazy load searchable settings availability (78091c0)
  • settings: manage internal project bindings (5347be6)
  • settings: open settings dialog from sidebar (f3d223f)
  • tanstack: add local deploy runbook and build validation (12ebaf5)
  • tasks: add board header loading skeleton (73f1242)
  • tasks: add quick-create targeting and edge autoscroll (f03e932)
  • tasks: add task templates (8d0700a)
  • tasks: allow archiving document tasks (0c51941)
  • tasks: consolidate task settings (982e0b9)
  • tasks: consolidate tasks entry and sidebar controls (56e80eb)
  • tasks: stabilize shared board realtime collaboration (6028caf)
  • teach: move education CRUD, user-group modules, valsea, and AI routes to apps/teach (6062756)
  • teach: move teach instructor API routes from apps/web to apps/teach (fb2cd39)
  • teach: move the education dashboard to apps/teach and retire the web + tanstack copies (5c80135)
  • tools: add apps/tools public tools app, remove apps/qr (204aae8)
  • track: serve the time-tracking API from apps/track (2e1562c)
  • web: add external app scope approval (ae465ae)
  • web: add managed workspace cron service (453763e)
  • web: migrate settings dialog panels (e2c0726)
  • web: return external app user profiles (1eff6a6)

Bug Fixes

  • apps: opt authed pages and GET routes into request-time rendering under cacheComponents (9496ec3)
  • auth: allow CLI refresh without Redis (dee98c1)
  • auth: allow CLI refresh without Redis (c10e334)
  • auth: allow managed oauth subdomain returns (b4b5229)
  • auth: allow recovery proxy access (0f216ca)
  • auth: expose auth rate-limit diagnostics (da8eaba)
  • auth: infer workspace session scope (1365e70)
  • auth: preserve managed oauth callbacks (d72823b)
  • auth: return invitation sessions after accepted replay (acebda9)
  • auth: share account preference cookies (8c1848a)
  • auth: show hard IP block support details (d26684b)
  • auth: store invitation action replays in database (d86b1db)
  • auth: trust managed Tuturuuu return hosts (ffefed4)
  • auth: use public recovery redirects (8ef2184)
  • backend: restore Rust CI (34e7c6a)
  • build checks (cc5a21e)
  • build checks (67205c2)
  • build: restore repo check (4def830)
  • calendar: document + surface the e2ee master key requirement (28d9db8)
  • calendar: use GitHub-owned Vercel deploys (946a8a5)
  • ci: align docker setup workflow test (bc4fd61)
  • ci: allow duplicated aws smithy clients (c29829e)
  • ci: build E2E support images in native mode (bc2a2aa)
  • ci: cap Rust backend cargo parallelism (0c8a018)
  • ci: correct tools vercel project secret (7479691)
  • ci: drop stale infrastructure web E2E (dc91e2d)
  • ci: finish storage-core workspace integration (ba786af)
  • ci: keep cache components enabled in production (75e6e2b)
  • ci: normalize aws presign types (860e209)
  • ci: normalize web aws presign types (de0520e)
  • ci: recover unresponsive Docker watcher (28b39e2)
  • ci: reduce MarkItDown Docker build disk use (f83aa17)
  • ci: resolve biome format + empty-package test failures on main (e1520a0)
  • ci: restore repository validation parity (db6afe4)
  • ci: restore tanstack docker checks (191c2e8)
  • ci: select Buildx for E2E caching (63bf5d4)
  • ci: skip tanstack vercel deploy without project secret (0cc5e60)
  • ci: stabilize Docker E2E readiness (2227af4)
  • ci: stabilize flaky unit-test timeouts under repo-wide Turbo runs (832bd2c)
  • ci: stabilize PR merge gates (bfa893a)
  • ci: stabilize tanstack dual-stack healthcheck (b5a095e)
  • cli: preserve markdown tables in task descriptions (9faf8ba)
  • cli: route finance and calendar APIs to app hosts (aa5c932)
  • cms: harden richfield external submissions (1c1fb47)
  • contacts: add missing shared i18n namespaces; move contacts into the checked apps (0971c8f)
  • contacts: backfill shared-shell translation keys and close the scan gap (90b4672)
  • contacts: drop force-dynamic segment config incompatible with cacheComponents (db263e1)
  • contacts: fall back to first workspace, not the root workspace (937d8d0)
  • contacts: opt authed pages into request-time rendering with connection() (df7288c)
  • contacts: provide nuqs adapter (17f4ac4)
  • contacts: redirect app entry to the default workspace (244e852)
  • contacts: resolve workspace + permissions from the app session (55cffe4)
  • contacts: stop catch-all routes from shadowing the /api → web proxy (852a79b)
  • cron: recover stale docker runner (33cbe47)
  • database: harden richfield submission status rpc (47df367)
  • database: reference private.user_group_posts in post-check-logs FK (15ec4bf)
  • database: refine richfield status migration (6e78a9d)
  • database: refresh quiz feedback migration timestamp (cc48f0c)
  • database: refresh vocabulary migration timestamp (ced09e5)
  • db: preserve RLS policy semantics (30519a9)
  • db: refresh RLS migration timestamp (fad865f)
  • devboxes: gate heartbeat and split v1 dispatch (34c7a49)
  • docker: auto-recover buildkit transport failures (e519ad3)
  • docker: avoid remote builder for native runner (a29b9a9)
  • docker: bootstrap idle watcher runtime (f8b9e69)
  • docker: budget buildkit resource fallback (2504a2d)
  • docker: cap web build turbo concurrency (7817ce1)
  • docker: capture compose recovery output (650cebf)
  • docker: escalate buildkit memory recovery (103b85a)
  • docker: keep native support builds local (2171a6b)
  • docker: normalize watcher host workspace path (30f129d)
  • docker: prefer buildkit memory rescue on oom (05f237e)
  • docker: promote stale buildkit fallback state (f09a810)
  • docker: recover cloudflared tunnel serving (10d4774)
  • docker: recover down compose services in watcher (3bb771c)
  • docker: recover fresh watcher git locks (5a34ff1)
  • docker: recover linked worktree git locks (8f6781a)
  • docker: recover stale cron runner dependencies (6b68edf)
  • docker: resolve buildkit compose auto caps (3243092)
  • docker: resolve watcher incident emails (b0888f8)
  • docker: retry lower buildkit profiles (bdbfb11)
  • docker: retry serial build profile before shrinking memory (504c0d7)
  • docker: retry stale compose dependencies (dcc1fab)
  • docker: retry stale support dependencies (966c869)
  • docker: skip stale no-build recovery (b1c1369)
  • docker: skip support builds in native recovery (48bfb43)
  • docker: stabilize native blue-green deploy (f41fbed)
  • docker: start cloudflared from watcher startup (9d596ae)
  • docker: support watcher linked worktrees (d4319f9)
  • docker: tolerate stale proxy config directory (3e32074)
  • e2e: dismiss personal workspace notice in task board test (5df8f08)
  • e2e: prune migrated routes from the tanstack auth-gate list (92e2862)
  • e2e: skip satellite-owned web tests (04c58aa)
  • edu: address follow-up review feedback (f183d8f)
  • edu: address follow-up vocabulary review (c21565f)
  • edu: address quiz review feedback (ec77bd8)
  • edu: address vocabulary review comments (815699a)
  • edu: count zero-quiz modules complete (5ea3b08)
  • edu: enforce quiz review invariants (992f84e)
  • edu: harden vocabulary api checks (1819c15)
  • edu: polish review follow-ups (8309bc0)
  • edu: prefer canonical quiz answer index (4feb158)
  • edu: resolve vocabulary journey review feedback (46e4180)
  • edu: satisfy vocabulary ci checks (61b011e)
  • edu: stabilize quiz response option mapping (58e8915)
  • email: use server-native HTML sanitizer (e16fbd8)
  • external-apps: add managed cron diagnostics (e65cd6b)
  • external-apps: allow signed asset uploads (0d83b3b)
  • external-apps: approve managed scheduler domains independently (a1a47b0)
  • external-apps: refresh app scopes for external login (4e48030)
  • finance: add default wallet settings copy (3ba8a1b)
  • finance: apply invoice defaults and i18n coverage (a5a7a26)
  • finance: apply invoice defaults and i18n coverage (97fabad)
  • finance: stabilize subscription invoice checkout (742c163)
  • i18n: catch conditional translation keys (bb303c5)
  • i18n: catch forwarded translator keys (cd67f48)
  • infrastructure: default docker web to native builds (7d89f00)
  • infrastructure: harden internal dashboard access (81e8f8b)
  • infrastructure: improve cron execution monitoring UX (8abf7b3)
  • infrastructure: land root workspace on internal (b3f63c2)
  • infrastructure: let watcher recover stale cron runner (dadc904)
  • infrastructure: provide intl context in locale layout (39ebbba)
  • infrastructure: recover cron runner via docker control (d1f216d)
  • infrastructure: refresh cron next-run metadata (5307fa0)
  • infrastructure: replace workspace picker with logo link (0e998eb)
  • infrastructure: restore canonical auth host access (9f6715f)
  • infrastructure: show dashboard error details (70de0b7)
  • infrastructure: stop protected locale redirect loop (d8843b5)
  • internal-api: guard cron job search nulls (cdde19f)
  • inventory: align operator UI with design tokens + a11y (1e035e1)
  • inventory: contain operator tables and translations (5fa064e)
  • inventory: give the OperatorDataList loading region a status role (acca059)
  • inventory: grant service access to category bundle components (63c3804)
  • inventory: harden Square Terminal contracts (547ce87)
  • learn: allow blocking dashboard entry (e01b16b)
  • learn: clarify vocabulary practice requirement (44b5000)
  • learn: pin bootstrap api origin (e0326fe)
  • learn: stabilize dashboard dev entry (e6ced1e)
  • mail: add settings translations (da50201)
  • mail: allow signed provider webhooks (adbbb87)
  • mail: localize post email dates (9be736d)
  • mail: pass ingest secret to builds (7d4e317)
  • mail: restore production inbox rendering (e03a782)
  • mail: stabilize layout and managed sender identity (a22205e)
  • mail: use managed SES credentials (9ffb3a1)
  • managed-cron: add admin runner recovery (13c07c6)
  • offline: trace esbuild wasm runtime files (8e3f5fa)
  • offline: trace esbuild-wasm sidecars (203fab6)
  • onboarding: skip pending invite users (c10429f)
  • paragraph question without text box (aac0439)
  • restore apps launcher categories (5c5b571)
  • satellite: allow external command launcher host (527a2e7)
  • satellite: compact apps picker dialog (17853c8)
  • satellite: constrain apps launcher scroll area (5bce7a0)
  • satellite: constrain apps picker layout (7249d1e)
  • satellite: group apps launcher catalog (e1b72dd)
  • satellite: stabilize apps launcher layout (150af1c)
  • satellite: stabilize apps launcher scrolling (5097e89)
  • satellite: use link cards in apps launcher (70ab897)
  • satellite: widen apps launcher grid (90e3106)
  • satellite: widen apps picker dropdown (f95ebcf)
  • security: harden managed cron fetches (1cb22c7)
  • security: keep blue-green native builds opt-in (078cf7b)
  • security: limit auth recovery code attempts (72d454c)
  • security: omit meet publish URL from Rust stream reads (67f549e)
  • security: restrict cron whitelist admin gate (8231bf7)
  • security: scope chat observability app sessions (a2ace0f)
  • security: scope Square webhook checkout sync (7618e01)
  • security: scope task update comment reads (a7553b8)
  • settings: resolve lazy search import for docker build (8a6dc1b)
  • support workspace session external apps (108879d)
  • tanstack: redirect random tool to satellite app (861f0ab)
  • tasks: allow personal board external placements (89a3fa2)
  • tasks: authenticate label association routes (a3350a6)
  • tasks: authorize personal placement targets (e617cee)
  • tasks: compact due date menu summaries (473ca52)
  • tasks: default task boards to kanban (477c12a)
  • tasks: harden satellite task route hydration (9d51a38)
  • tasks: instantiate templates through task route (6a0d96f)
  • tasks: keep personal board moves on workspace route (60e29b0)
  • tasks: keep personal moves off placement API (d8c41d7)
  • tasks: let CLI bearer sessions reach task routes (c8cd910)
  • tasks: let CLI bearer sessions reach task routes (e607186)
  • tasks: log personal task route failures (d2b7f64)
  • tasks: make personal board bootstrap idempotent (25f08ae)
  • tasks: match board name input surface (2552733)
  • tasks: pad board header skeleton (b0c5c0f)
  • tasks: prevent description wipes during yjs hydration (947f38c)
  • tasks: refresh task template placeholders (0c3c309)
  • tasks: relax personal placement target access (20dd211)
  • tasks: repair settings data and i18n (0159488)
  • tasks: resolve personal placement board from list (ed52667)
  • tasks: resolve personal placement board from list (14335af)
  • tasks: resolve personal placement target lists (c98ed29)
  • tasks: restore personal board entrypoint (e707bf5)
  • tasks: restore satellite resource access (ec5e0a8)
  • tasks: restore task dialog app-session requests (69f83cb)
  • tasks: restore tracked task descriptions (f892ae2)
  • tasks: route native personal task moves normally (5bbba3c)
  • tasks: scroll kanban board at drag edges (1053f6c)
  • tasks: serve config APIs from tasks app (6d12722)
  • tasks: simplify empty board setup (2fe8783)
  • tasks: support personal external task moves (83cee1f)
  • tasks: support personal external terminal defaults (50434cb)
  • tasks: tolerate missing task settings row (d835fe1)
  • tasks: tolerate personal count rpc auth gaps (a31044a)
  • tasks: unify board loading skeleton (eaf2b65)
  • tasks: use connection for boards route (15bc262)
  • tasks: use connection without segment config (e3e89e0)
  • teach: fallback OED suggestions from search (f0d2825)
  • teach: resolve package conflict (4d9c3d4)
  • teach: soften dictionary details failures (920210b)
  • teach: soften vocabulary suggestions failures (be1a06c)
  • teach: switch vocabulary lookup to OED (28cb8b9)
  • teach: tolerate empty OED suggestions (7b2468b)
  • track: require app-session auth for APIs (15473ee)
  • ui: preserve personal external task edits (8e537e3)
  • ui: stabilize task property popover handoff (8fb2e62)
  • update launchable app catalog (cb31207)
  • users: preserve attendance history (fd16cee)
  • vocabulary: stabilize CI and OED lookup (0d153a7)
  • web-e2e: keep account settings tests on web route (0e13340)
  • web: accept zero-price fixed free products (6c7f587)
  • web: align e2e login paths with locale routes (d259995)
  • web: align e2e with satellite route ownership (a7833b2)
  • web: align login route with cache components (62f0948)
  • web: allow add-account before onboarding (157fec5)
  • web: allow production tools redirect in e2e (ab7f69d)
  • web: authorize workspace member invites (4adcdc0)
  • web: avoid browser IP blocks from stale auth cookies (b44e9e2)
  • web: fail open without redis (74bfcc7)
  • web: gate devbox agent traffic by env (e900348)
  • web: handle returned oauth exchange errors (87e6ec1)
  • web: keep MFA login verification on page (bdda222)
  • web: keep root redirects on workspace home (6f66f97)
  • web: opt auth pages out of prerendering (edf227c)
  • web: opt auth shells out of prerender (290e7e2)
  • web: opt users routes out of prerender (8c064ee)
  • web: redirect root tasks preference to tasks app (82465b2)
  • web: refresh ai credits e2e session (9393f7e)
  • web: show personal workspace notice as toast (c31afeb)
  • web: skip step-up for scoped app profile writes (b54d913)
  • web: stabilize ai credits e2e indicator (a343c89)
  • web: stabilize navigation icon test (facf753)
  • web: sync guest toggle across guest groups (415fdea)
  • web: unify login loading card (fcac4a8)

Performance Improvements

  • ci: deduplicate Bun caches (5d64570)
  • ci: enable repository-wide remote caching (6250f91)
  • ci: serialize BuildKit cache writers (72bab33)
  • rls: also wrap auth calls nested in EXISTS subqueries (complete the wrap) (967e745)
  • rls: wrap auth calls in (select ...) for per-statement eval (5011630)
  • rls: wrap auth helpers in (select ...) for per-statement evaluation (#4907) (4de00a9)
  • tooling: improve service build caches (1a7a5bf)
  • web: make login shell cache friendly (0fcf4da)
  • web: split legacy api route wrappers (3b1b7f2)
  • web: split legacy v1 api routes (9971e4a)