Applied-model is the read-time source of truth for feature availability
Closes the "stale DB leaks a disabled feature" gap by gating every surface that touches OrgFeature / ServiceType through the applied security model. - ********...
Wire applied-model enforcement across every controller
Every non-role setting on the applied security model is now enforced at the exact controller boundary it governs, and the scalar settings round-trip cleanly thr...
Enforce system-role assignment and auto-admin for team-member owners
MemberSecurityController now enforces the three assignment invariants defined in the brainstorm spec: - saveMemberSecurity: before persisting the caller's requ...
Master-model + applied-model endpoints and template-aware org seeding
Adds the controllers that surface the new branch-type security flow: - /api/security/master-model (GET/PUT) manages the current org's master model; only writ...
Supplement session rights with all known rights for grant-all roles
Add SSE endpoint for real-time email verification + improve welcome email logging
Add resetCode to password reset email, add emailVerifyByCode endpoint, send WELCOME_MEMBER after email verification
Pass human-readable expiry time to email verification template
Add humanizeMinutes() helper that formats minutes as days/hours/minutes (e.g. "1 day" for 1440 min). Pass as {{expiryText}} to match updated canonical template ...
Add code-based email verification path to /verify-email endpoint
The endpoint now handles both token (link click) and userId+code (manual 6-digit entry). Token path unchanged; code path hashes the supplied code and matches ag...
Add register-photo endpoint for unauthenticated post-registration avatar upload
POST **************** accepts userId + file/fileSm/fileMd/fileLg without a session. Guards: user must be unverified and have no avatar yet, preventing abuse aga...
Add GET /api/security/geoip/me for client IP country lookup
Reads real client IP from X-Forwarded-For / X-Real-IP headers, does a GeoLite2 lookup, and returns { country_code, country_name }. Used by kamo-register's count...
Implement SP4 email verification and registration wiring
- Delete legacy email/VerificationEmail.java (hardcoded SMTP stub) - Add **************** (mirrors recovery package pattern) - Add **************** — token gene...
Add AccountSettingsController + Service for phone + security questions (SP3)
Allows logged-in users to set/verify phone and configure 3 security questions. Routes to /api/account/* (session-authenticated via KSESSION_DATA).
Add BulkTextSmsClient + EmailTemplateServiceClient + PasswordRecoveryController (SP3)
Full password recovery flow: email-link, SMS OTP, security questions, seed phrase. Routes to /api/recover/* (unauthenticated). Uses SP1 email pipeline + VOIPSer...
Wire EmailTemplateSeedClient into ****************
Thin RestTemplate client that POSTs to EmailService's **************** after an org + owner TeamMember are persisted. Retries twice with backoff; failure throws...
Add public known-aliases endpoint for kamo-nowww build-time bake-in
Add analytics → analytics text replacement in changelog sanitization
Redact tokens ≥32 chars in changelog sanitization
Any word (run of non-whitespace) that is 32 characters or longer is replaced with **************** before titles and descriptions are sent to the translation se...
Generate TXT verification token on domain create, check in verify-dns
- createDomain: generate 32-char UUID token and store via setVerificationToken - verifyDns: check _kamo-verify TXT record for kamo-site-verification=<token> - T...
Update required aliases — add app, capcha, docs, sign; remove legacy
Add /setup/dns backend — one-domain enforcement, SSL probe, new aliases
- Enforce one custom domain per org in POST /api/security/domains - Add capcha, docs, sign to standard aliases; remove legacy aliases - Update verify-dns to tra...
Move changelog word replacement to backend before translation
Text replacements (Docs→Docs, Meet→Meet, etc.) and secret name redaction (K8s secret names→***) were previously applied client-side in ChangelogClient.tsx, mean...
Aggiungi una traduzione asincrona per i piani di changelog e abbonamento, aggiungi le API pubbliche locali-consapevoli
Aggiungi TranslateService alla lista dei progetti pubblici changelog
Aggiungere la gestione dell'assunzione di piombo e ricevere i controller pubblici
Aggiunge due controller per il sistema automatizzato di assunzione di piombo: - LeadIntakeController: autenticato CRUD per endpoint di aspirazione, campo mappat...
Membri StoreType in Redis sessione al login
Aggiunge CASE WHEN e.id non è NULL THEN 'TEAM MEMBER' ELSE 'MEMBER' END a il login query SQL e passa il risultato attraverso creareSession in Redis, così fronte...
Generazione di miniature sincrona per pagina durante il caricamento del modello con progresso granulare WS
- Aggiungi dipendenza PDFBox da pom.xml - Dopo aver memorizzato PDF convertito, rendere tutte le pagine tramite PDFRenderer e caricare ciascuna come {id} thumb ...
Aggiungi GET Non e' vero. endpoint per servire le miniature PNG per pagina
Aggiungi /api/changelog/public/stats endpoint per conteggi aggregati per tipo e progetto
Aggiungere la convalida segreta webhook per changelog endpoint
Difesa-in-profondità: convalida *** intestazione sul lato SecurityService oltre alla validazione del gateway APIService.
Aggiungi il livello di accesso dei membri e gli endpoint dello stato del proprietario
Aggiungi GET e PATCH. endpoints per la lettura e l'aggiornamento dei livelli di accesso con l'applicazione completa del permesso. Creazione di organizzazione di...
Aggiungere fasi di avanzamento di conversione granulare con 8 aggiornamenti WebSocket distinti
Stage: download (0-15%) → preparazione (15-20%) → conversione (20-65%) → verifica (65-75%) → memorizzazione (75-90%) → finalizzazione (90-100%) → completa
Conversione PDF sincrona per gli upload di modelli di firma elettronica
Gli upload dei modelli ora convertono direttamente tramite ConversionService durante il richiesta di upload. Pubblica eventi di progresso NATS per WebSocket in ...
Add e-signature template API endpoints
- POST **************** — upload template with scope control - POST **************** — list templates by context and status - PATCH **************** — update te...
Sostituire Google re***** con la verifica Capcha ***
Rimuovere Re***Service e tutta la configurazione di Google re***. Aggiungi CapchaVerificationService che verifica *** payload via servizio kamo-capcha /api /ver...
Migliorare POST / clienti per accettare informazioni di contatto e utente di ricerca via e-mail
Crea account ora accetta e-mail, contactName, telefono, accettaMarketing, taxExempt. Se l'e-mail è fornita e corrisponde a un utente esistente, automaticamente ...
Aggiungi 18 endpoint dettagli account per la gestione del cliente di commercio
Nuovi endpoint su AccountController sotto /api/security/account/: - CRUD cliente: GET/POST/PUT/DELETE /customers, GET /customers/{uid} - Dati associati: GET /cu...
Aggiungi 111 punti vendita al dettaglio a CommerceMarketController
Tutti gli endpoint sotto /{marketId}/retail/... namespace cover: - Categorie, marche, attributi (con valori), immagini, varianti, tag, recensioni - Clienti, ind...
Expand CommerceMarketController with nested market-centric endpoints
Replace flat POS endpoints with market-scoped REST hierarchy: - Products, inventory, vendor categories under /{marketId}/products, /inventory, /vendor-categorie...
Come quello che vedi la spedizione?
Ognuno di questi aggiornamenti atterra automaticamente nello spazio di lavoro. Inizia gratis e guardalo crescere settimana dopo settimana.