Release history
What changed, and when.
Desktop, Server and Evidence-Public keep independent patch histories after their shared 3.9.0 release boundary. Filter the timeline to follow the component you use.
Serverv3.9.18
- Showed task time and location once in their dedicated sections instead of repeating them in operational details
- Rendered structured allocation names with their ordered people while suppressing capability requirements and incomplete legacy capability fallbacks
- Displayed non-location links with the published field name and exact clickable URL, while retaining multiline notes and other bounded operational values
- Kept root Operations user filters and name searches on the Users view instead of navigating back to Events
Serverv3.9.17
- Preserved the exact signed Caddy and PostgreSQL image digests for migration-free blue/green releases even when release-workflow changes require conservative component testing
- Required an explicitly selected, signed and ancestral active predecessor when a skipped release must be bypassed
- Included the unified authenticated task visibility, structured allocation details and revised offline-governance boundary introduced in v3.9.16
Serverv3.9.16
- Gave every authenticated account in an event the same bounded task fields and ordered allocation names while retaining role-based editing and cross-event isolation
- Rendered allocation categories consistently in phone cards, calendar blocks, tooltips and task details, with labelled multiline operational fields
- Rejected assigning one person to more than one allocation category on the same task, including partial Server edits
- Versioned the broader optional offline schedule disclosure and cache so existing opt-ins are not silently expanded
- Added a manifest-gated blue/green activation path for migration-free Server upgrades
Serverv3.9.14
- Kept Schedule, People, Updates and More in one persistent phone navigation bar for event managers, without duplicating those destinations in the header
- Added a dedicated More page for account security, appearance, notifications, offline controls, privacy information and other less frequent actions
- Kept participant and editor phone navigation focused on Schedule, My schedule, Programme and More, with deterministic calendar views
- Limited the optional offline schedule to the compact phone layout and kept existing copies subject to their original expiry and removal boundaries
- Projected audience teams into the bounded offline shape of name and optional short name, preventing numeric category metadata from breaking the download
Serverv3.9.13
- Made the phone schedule a compact, app-like view that opens linked organisers on their own assignments while retaining the complete event schedule
- Added My schedule to phone navigation when the account is linked to a participant identity
- Contained the phone layout to the device viewport so navigation and schedule controls no longer overflow into unused space
- Changed the offline disclosure into a compact dismissible notice with management available from More
Serverv3.9.12
- Recorded first-activation processing consent through the signed evidence ledger using only pseudonymous references and exact policy and statement digests
- Kept passkey creation, consent, account activation, evidence, and activation-link consumption in one atomic transaction
- Showed the Server's safe structured error message when passkey registration fails instead of reducing every failure to Registration failed
- Treated the short wait between peer-copy acceptance and the witness's next healthy observation as resumable commissioning state
- Kept automatic failover disabled after readiness validation so the controller can enable it deliberately after acceptance testing
Serverv3.9.11
- Serialised commissioning and scheduled recovery snapshots through one host-local execution lease so a timer catch-up cannot interrupt final validation
- Made a scheduled snapshot defer cleanly while setup owns the lease and made setup report a retryable wait while a snapshot is active
- Kept scheduled snapshots compatible with the restricted NoNewPrivileges service by reusing the validated runtime Compose command without sudo or permission repair
- Made approved transient-file cleanup safe under concurrency while continuing to reject symlinks, substituted paths and unsafe ownership or modes
- Made a completed validation checkpoint resumable without redeploying the application or repeating the first HA copy
Serverv3.9.10
- Kept the replication worker inside its restricted service identity while validating the existing runtime contract without privileged repair
- Captured application state from the running database and Backend while retaining permission, evidence and root-bootstrap safety checks
- Reconciled Node B from the sender's durable accepted-bundle receipt instead of leaving a successfully restored peer in a stale waiting state
- Retired the temporary root-bootstrap value before the first HA copy or scheduled snapshot can run
- Required a real standby-protected verification mutation and the installed scheduled-snapshot service during commissioning qualification
Serverv3.9.9
- Added a structured local commissioning interface that uses the same guarded operations, durable checkpoints and execution lease as the interactive TUI
- Made fresh HA setup reconcile exact deployment, witness, lease and first-copy receipts without repeating work that already succeeded
- Hardened candidate deployment, standalone-to-HA conversion, peer replacement and full-loss recovery around protected evidence, secret and snapshot custody
- Made Cloudflare witness creation and secret activation safely retryable when provider state exists before the local checkpoint is written
- Added bounded test-only interruption hooks and exact development-candidate verification while keeping them unavailable in signed production operation
Serverv3.9.8
- Validated systemd read/write paths by their meaning, including valid optional path prefixes, while still rejecting broader or unsafe service access
- Bound every material commissioning action to its own durable checkpoint and reconciled accepted first-copy receipts without repeating a successful transfer
- Separated first-bundle acceptance, HA service activation, Caddy validation, local origin health and public routing so the TUI reports the action that actually needs attention
- Made initial lease promotion idempotent and required a stable local-health observation before commissioning advances
- Replaced the long first-activation disclosure with a compact controller, purpose and audience summary plus an accessible processing-details view
Serverv3.9.7
- Separated signed application deployment, local origin health, public DNS propagation and public HTTPS routing into distinct commissioning checkpoints
- Used agreement between independent public resolvers instead of treating a stale VPS resolver response as a failed deployment
- Reconciled a healthy exact deployment on resume so an interrupted checkpoint does not rebuild or recreate working services
- Kept normal DNS propagation waits inside the TUI with clear status, automatic retries and stage-specific recovery messages
- Removed interrupted witness-secret temporary files through bounded startup and signal cleanup without exposing their contents
Serverv3.9.6
- Made the runtime permissions used by HA, recovery, evidence, Caddy and PostgreSQL explicit and self-validating
- Required every management-console action to declare and pass its applicable permission profile before and after a change
- Checked the Backend container's real access before committing a standby-protected mutation
- Added bounded HA protection errors and an idempotent root-authorised retry for indeterminate non-privacy operations
Serverv3.9.5
- Accepted canonical UUIDv4 and deterministic UUIDv5 evidence identities in Desktop setup imports without rewriting them
- Validated supplied account email addresses before any setup-import write and preserved them for activation and passkey email delivery
- Kept accounts without an email valid while making their missing delivery address explicit
- Removed the retired governance phone contact so controller and privacy contact details are email-only
Serverv3.9.4
- Started Caddy on a fresh receiving peer even when the shared domain configuration was unchanged
- Kept an already-running Caddy instance in place during ordinary replication when its effective configuration had not changed
- Required PostgreSQL, Backend, and Caddy health before accepting the first replicated bundle
- Kept Node B visibly waiting and automatic failover disabled until the first protected copy was verified
Serverv3.9.3
- Persisted generation-1 Node A ownership before the public backend starts during fresh HA commissioning
- Restored root-passkey registration without weakening normal witness and database writer fencing
- Bound fresh ownership initialization to the exact setup-v2 cluster, node, and generation
- Rejected conflicting or contaminated bootstrap state while keeping exact retries resumable
Serverv3.9.2
- Prepared missing optional Evidence Git token mount files safely before a fresh HA peer starts its backend
- Preserved configured node-local Evidence Git credentials and rejected unsafe substituted paths
- Bound first participant activation to an explicit, published processing statement before passkey registration
- Recorded the exact consent statement and governance digest atomically with account activation
- Kept additional-passkey and credential-reset flows unchanged and retained Delete my data after activation
Serverv3.9.1
- Replaced circular blank-database startup with a bounded one-shot schema bootstrap
- Made fresh root and evidence genesis resumable while refusing populated deployments
- Kept HA replication and snapshot services dormant until the first guarded peer copy succeeds
- Kept Node A in the pairing view and continued commissioning automatically after Node B joins
Desktopv3.9.0
- Added local light A4 portrait PDF publishing with readable schedule details
- Event-scoped processor enrolment and automatic signed Desktop evidence
- Fixed Public Schedule and authenticated Masterplan audience rules
- Calmer permitted-data guidance and operational field categories
- Current campaign fixes, dependency updates and packaging hardening
Serverv3.9.0
- Three-step root commissioning, controller trust and governance publication
- Deletion-scoped snapshot resolution and complete portable evidence verification
- Hybrid HA replication barriers, qualified two-way failover and recovery hardening
- Action-first controller-transparent email and calmer role-specific administration
Evidencev3.9.0
- Published the portable complete-chain verifier for exported evidence ZIPs
- Published local-only processor- and controller-key tools with no private-key upload
- Documented offline verification, evidence boundaries and repository ingestion rules
- Tagged the Evidence-Public verification baseline alongside the App and Server release
Desktopv3.8.1
- Corrected separation between the Desktop manifest signing key and public release signing identity
- Republished the verified Desktop package metadata without changing the supported data format
Desktopv3.8.0
- Added signed runtime integrity verification, deletion evidence and protected-data boundaries
- Added the separate one-time legacy conversion operator tool without runtime compatibility
- Hardened cross-platform packaging, encrypted custody and release verification
Serverv3.8.0
- First signed Public Server release with immutable container images, manifest, SBOMs and signatures
- Added the guarded management TUI and qualified standalone installation path
- Established Public documentation, support and vulnerability-reporting contracts
Desktopv3.7.0
- Added direct schedule editing after optimisation
- Repaired copied-task identity, timing and assignment behaviour
- Improved final-review and publication-state feedback
Serverv3.7.0
- Added the governance, retention, deletion and signed-evidence foundation
- Separated authenticated Masterplan data from deliberately public schedule data
- Added protected snapshot and operational audit foundations
Desktopv3.6.0
- Expanded solver diagnostics, bottleneck explanations and reproducible run metadata
- Improved flow-check feedback before long optimisation runs
Serverv3.6.0
- Introduced the symmetric two-node HA foundation, writer fencing and peer replication
- Added load-balancer readiness, witness authority and guarded failover operations
Desktopv3.5.0
- Added General Schedule publishing for deliberately public fields
- Added selected-day publishing while retaining explicit publication boundaries
Serverv3.5.0
- Rectified deployment, update and rollback workflows around immutable release inputs
- Improved host prerequisites, secret-file custody and operator health diagnostics
Serverv3.4.0
- Improved event and account administration while preserving role boundaries
- Refined public schedule presentation and operational security controls
Desktopv3.4.0
- Added the concept of working day, which allows to seggregate optimisations by sleeping and not by midnight
- Added the ability to copy and paste selected tasks in the CMI-view
- Added human-readable timestamps for optimisation, publish, manual edits, and pending changes
- Added OS secure credential storage for sensitive secrets
- Desktop updates now preserve the local database and encryption key
- Added visible startup integrity-check progress before backend/frontend startup
- Added crash/error diagnostics with log-dump support where appropriate
- Self-hosted fonts to avoid external font loading/CSP problems in packaged builds
- UI-overhaul to make the interface calmer
- Several bugfixes
Desktopv3.3.0
- Added presentation module for optimised schedule
- Modified the task template creation process to be more intuitive
- The standard for the publish target is now none instead of both
- Capabilities are now sorted (secondary) by machine_name and not display_name
- Upgraded JS dependencies: next to 16.2.6, postcss to patched 8.5.14, electron to 42.0.1, electron-builder to 26.8.1.
- Hardened OAuth state handling, token exemptions, logging, frontend callback validation, and Electron navigation/IPC/permissions
- Metrics board can now highlight capabilities too
- Added loading screen on app startup
- Fixed various bugs concerning presentation mode and port handling
Serverv3.3.0
- Added the ability to freeze and rename snapshots
- Added more runtime variables to be set by the admin in the security tab
- Added the role issuer that has (non-critical) admin access for one specific event they are associated with
Desktopv3.2.0
- Encrypted Google Calendar token data and event secrets at rest using Fernet-based column encryption
- Added per-session auth token injected via Electron for all backend requests
- Merged optimiser engine into the backend - single service, smaller installer, simpler architecture
- Added 5 MB request body size limit middleware
- Added Content Security Policy headers to the renderer process
- Fixed countless smaller bugs
Serverv3.2.0
- Accessibility & UX upgrades: colour-blind modes, swipe/keyboard calendar navigation, PWA install prompt, and improved admin UI
- Scheduling & publishing improvements: schedule snapshots/rollback + enhanced batch activation tools with previews & QR exports
- Stronger authentication & session security: passkey rate limiting, session fingerprinting/revocation, encrypted data, safer WebAuthn handling
- API & system hardening: rate limiting, input/request validation, Content-Type enforcement, reduced logging exposure, stricter CSP
- Compliance, auditing & ops: audit logs, GDPR tools, secret rotation, Docker secrets, dependency cleanup, and security config controls
Desktopv3.1.0
- Added person_id to setup export for automatic person-user account linking on server import
- Publish target now defaults to 'none' instead of 'both' - users must explicitly choose a target
- Added more extensive toast notifications and solver progress visualisation
- Extended limit for flow-checker to 10 minutes
- Updated font to Source Sans 3
- Enabled ASAR integrity verification (Electron-native tamper protection for application shell)
- Added Ed25519 signed hash manifest with automatic startup integrity check for all bundled binaries
- Added integrity verification UI in About dialogue (Verify button with per-file status)
- Added SHA-256 checksums (checksums.txt) to GitHub Releases for download verification
Serverv3.1.0
- Push notifications - participants are automatically notified when a new schedule is published
- Offline mode - the calendar is cached locally so it can be viewed without an internet connection
- Announcement system - administrators can broadcast messages to all participants via push notification
- QR code activation - administrators can display a scannable QR code instead of sending activation links
- QR codes detect when a link has been used and allow generating a new one on the spot
- My-tasks navigation: floating arrow buttons on task detail modal to navigate between your assigned tasks
- Automatic person-user linking via person_id during server setup import
- Updated font to Source Sans 3
Desktopv3.0.1
- Fixed application icon to use transparent background at 512x512 (required for macOS)
- Fixed 'Failed to fetch' errors by replacing hardcoded startup delay with proper service health-check polling
- Changed all internal URLs from localhost to 127.0.0.1 to avoid IPv6 resolution issues on Windows
- Application now shows a clear error page with diagnostic logs if backend services fail to start
- Fixed missing execute permissions on macOS/Linux for bundled backend and optimiser binaries
- CI build now ensures PyInstaller binaries retain execute permissions before packaging
- Fixed flow-checker ortools dependency missing from the bundled backend executable
- Fixed icon not found error on macOS caused by assets folder missing from packaged app
- Themed icon now persists to user data directory instead of read-only app bundle
Desktopv3.0.0
- New desktop application powered by Electron
- Complete rewrite of the cross-day optimisation engine using OR-Tools CP-SAT solver
- Real-time flow-check diagnostics with bottleneck analysis
- Pre-optimise gate to validate data before running the solver
- Dark mode support across the entire application
- Cross-platform support: Windows, macOS, and Linux
- Bundled backend and optimiser - no Python installation required
Serverv3.0.0
- Multi-user web calendar with passkey (WebAuthn) authentication
- Complete rewrite of the cross-day optimisation engine using OR-Tools CP-SAT solver
- Real-time flow-check diagnostics with bottleneck analysis
- Pre-optimise gate to validate data before running the solver
- Dark mode support across the entire application
- Docker Compose deployment with Caddy reverse proxy and automatic HTTPS