17 KiB
17 KiB
Changelog
All notable changes to probod (the server, including the bundled @probo/console, @probo/trust, and @probo/ui frontends) will be documented in this file.
Unreleased
[0.193.1] - 2026-05-26
Security
- Fix open redirect bypass in safe redirect
[0.193.0] - 2026-05-26
Added
- Add measure ↔ third-party many-to-many link with tabs on both detail pages
- Add self-referential third-party relations with a
first_levelfilter on the third-party list - Track source on detected storage trackers (localStorage, sessionStorage, indexedDB, cacheStorage)
- Promote tracker pattern source on detection and trigger a draft banner version when adopting uncategorised patterns
Changed
- Allow initial minor publishing of documents
- Mark page-world extension writes (MV3 main world, userscripts with
@grant none) with the newEXTENSIONcookie source - Surface the measure state as a header badge and remove the measure detail right-hand drawer
Fixed
- Fix timing attack on signin
- Reject separator-only glob templates (e.g.
__*) in tracker pattern analysis
[0.192.0] - 2026-05-25
Changed
- Enforce IAM authorization on all console resolvers — every data-bearing field now goes through the policy engine and produces an audit log entry; adds
ActionCommonThirdPartyGet,ActionCommonThirdPartyList, andActionElectronicSignatureGetactions wired into Viewer and Auditor policies
Fixed
- Fix signature count mismatch between the document version badge and the signatures tab — both now filter by
activeContract: trueandstate: ACTIVE, so deactivated signers and ended-contract signers are consistently excluded - Fix MCP server resolvers after the signature filter and authorization changes
[0.191.0] - 2026-05-22
Added
- Add a tracker pattern detail page in the console with a properties section and a list of detected tracker resources
Fixed
- Strip empty ProseMirror text nodes from third-party list documents (and migrate existing
document_versions.contentto drop them) so Tiptap renders them instead of erroring with "Empty text nodes are not allowed" - Tailor signature certificate email copy for document approvals — store the per-signature email subject on creation so the certificate worker uses "Your approved