July 2026
Everything that reached production in July 2026. See every commit from this month on GitHub
The releases announced at the time:
- Team accounts, roles & staff tools — Invite teammates with roles, and manage everything from a multi-tenant org.
- Self-serve add-ons & a new billing portal — Add capacity and features to your plan yourself, and manage billing in one place.
- Richer writing: media picker & paste-to-format — Insert images from your media library and paste formatted text straight into posts.
- The Aglyn REST API is here — Read and write your site content programmatically with a versioned REST API and scoped API keys.
- Sell in person with Point of Sale — Ring up in-person sales against the same catalog and inventory as your online store.
- Extend your site from the plugin marketplace — Browse, install, and configure plugins that add blocks and capabilities.
- Interactions: no-code element behavior — Add open, toggle, hover, and dismiss behavior to any element — no code required.
- Contextual help, everywhere you work — A new documentation hub plus unobtrusive help tips woven through the console.
- Gift cards, discounts & product reviews — Run promotions, sell gift cards, and collect verified customer reviews.
- Design emails and send campaigns — A drag-and-drop email designer and audience campaigns, built into your site.
- Digital products & subscriptions — Sell downloads, gated content, and recurring plans alongside physical goods.
- Blogging upgrades: categories, SEO controls & RSS — Organize posts by category, fine-tune search snippets, and syndicate with RSS.
New
- Console: preview the current besigner state in a new tab
- Console: open the live production screen from the besigner app bar
- Sites: serve tenant sites on vercel preview deployment urls
- Shared data types: add plain-json host theme document types
- Platform: add host theme field to the host document schema
- Themes: convert host theme documents into mui theme options
- Themes: add host theme provider and google fonts url builder
- Aglyn node renderer: render host-configured themes in the site theme hook
- Sites: apply host themes with light and dark schemes on published sites
- Besigner core: add canvas color scheme flag to the interface controller
- Besigner feature designer: preview screens under the host theme
- Console: supply the host theme and fonts to the besigner canvas
- Console: add host theme editor with live preview
- Platform: promote shared layout documents from concept types
- Sites: add layout and layout version hooks
- Plugins ui mui: add layout slot content outlet component
- Platform: compose layout slots with screen nodes
- Site data: add layout and layout version admin converters
- Sites: render screens composed with their published layout
- Besigner core: track the host view type being edited on the canvas
- Besigner feature designer: gate layout-only components by view type
- Plugins ui mui: export bundle constants from the package index
- Console: add layout management and besigner editing routes
- Besigner feature designer: render bound layout chrome around screen content
- Console: bind screens to shared layouts in the besigner
- Besigner feature designer: show a placement marker for the layout slot
- Besigner core: explain rejected drops with the violated lineal rule
- Besigner feature designer: warn when placement rules reject an action
- Besigner: export the artboard scheme preview toggle from the designer surface
- Console: add the artboard light/dark scheme toggle to the besigner app bar
- Platform: add screen route slug normalization and routing-map lookup utils
- Console: publish screens with a slug registered in the host routing map
- Platform: compose hierarchical screen route paths with cycle guards and descendant collection
- Console: parent screen selector with cascading routing-map rewrites on slug and parent change
- Platform: add buildScreenRouteEntries cascade util and sibling order field
- Console: drag-and-drop screen hierarchy editing in the screens list
- Platform: resolve id-based screen hrefs from the routing map via ScreenLinkContext
- Plugins: add muiScreenLink component linking screens by id, resolved at render time
- Besigner: resolve screen-select attribute fields from the host screens list
- Console: provide screen-link routing context on all render surfaces
- Plugins: expose a Text attribute field on text-capable components
- Console: besigner app-bar document switcher with current-screen indicator
- Besigner: double-click inline text editing on the canvas
- Console: host-switcher dropdown in the primary app bar
- Console: screen and layout versioning with app-bar version dropdown
- Platform: reusable component model — instance nodes and render-time graft util
- reusable component promote, insert, and demote flows
- Platform: tenant plan and entitlement model with checkEntitlement/checkQuota
- Console: billing page, entitlement gates, and stripe scaffolding
- Cloud functions: staff authz — scoped firestore rules and staff-claim script
- Console: move the version dropdown to the app bar's right side near the user menu
- Console: host display name in breadcrumbs + polished host-switcher menu
- Console: screen switcher v2 — main app bar placement with paginated dropdown
- Billing: align tiers, add pricing model, wire feature gates
- Console: billing usage meters for every quota and redesigned plan cards
- Versioning: named versions, delete, and scheduled publishing
- Besigner: basic rich text editing for opt-in canvas elements
- Besigner: multi-selection across hierarchy and canvas (AGL-5..AGL-12)
- Console: media library with storage quotas and an Image element
- SEO: screen SEO editor, tenant meta emission, sitemap.xml and robots.txt (SEO Toolkit)
- Forms: lead-capture form components, submit api, and console inbox
- Console: starter template gallery instantiating published screens
- Console: custom domain self-service wizard with DNS verification (Custom Domain project)
- Content: collections with console manager, tenant blog pages, and RSS
- Analytics: pageview beacon, daily counters, and dashboard traffic panel
- Console: rename and delete reusable components from the host dashboard
- Billing: one-command stripe bootstrap script and go-live runbook
- Console: staff tenant management with audited plan/entitlement overrides
- Operations: one-command managed-platform bootstrap and provisioning docs
- Blocks: section and block library v1
- Protection: per-screen passwords and a custom not-found screen
- Search: tenant site search page, content matcher, and search box
- Console: ai copy assist in the besigner via env-gated claude route
- Console: community marketplace v1 — profiles, publish api, browse and install
- Console: authenticated media upload api and locked storage rules
- Console: marketplace monetization — paid listings, stripe connect, ledger
- Console: usage metering rollup and cost-plus-30% estimate
- Commerce: starter selling — products, product block, checkout, orders
- Console: site-size and bandwidth meters, host creation, chrome fixes
- Console: typed host variables with {{name}} prop bindings
- Console: no-code function builder with safe evaluator
- Sites: function bindings in text props via {{fn:name(args)}}
- Plugins: interactive function widget and drawer card polish
- Console: quota warning banner at 80/100% on the host dashboard
- Console: marketplace browse search, category filter, and sort
- Console: builder plan gating — variable/function/workflow/dataset caps
- Console: workflow builder with pure step runner
- Console: manage quick menu in the app bar
- Console: insert-binding picker and in-editor function builder
- Billing: seat limits and paid seat addons per tier
- Console: manage screens without the besigner on the detail page
- Console: move theme editor under setup tabs
- Console: card layout and proper icons for media, content, inbox
- Console: per-version scheduling and scrollable raw json on screen detail
- SEO: screen-level seo editor and richer tenant head emission
- Console: user activity log across host changes
- Console: host and tenant user managers with seat enforcement (AGL-107/108)
- Billing: team and host-member seat meters in usage list
- Console: enforce tenant manager permissions across apis and surfaces
- Console: datasets v1 with table editor and plan caps
- Sites: repeatable components over datasets
- Console: custom domain tab on setup and stacked-card spacing (AGL-122/121)
- Console: skeleton loading and onboarding empty state for screens table
- Console: role-based permissions with per-member overrides
- Console: media organization with folders, tags, metadata, search
- Content: rich blog entries with images, preview, and scheduling
- Besigner: browse-media action for image elements
- Console: inbox mail reader dialog
- Content: entry-template screens with {{entry.*}} bindings
- Sites: site membership with sign-in/up and members-only screens
- Console: monthly usage email summary via env-gated Resend
- Console: marketplace listing previews, detail pages, publisher profiles
- Console: site-wide usage-cap banner with upgrade link
- Console: host name collision and generated-domain guards
- Platform: workflows page + host event triggers
- Platform: meter event-triggered workflow runs per tier
- Platform: media manager video + PDF uploads with tiered caps, Video component
- Console: media favicon picker, sorting, and type/date/size filters
- Platform: designable 404/401/403/503 error screens + maintenance mode
- Console: dedicated Data page + paid extra-dataset addons
- Platform: custom team roles with unique permission sets
- Platform: analytics insights (referrers, devices, ranges) + Google Analytics ID
- Sites: og/twitter media completeness + JSON-LD for blogs, site, breadcrumbs
- Platform: forms write submissions into a bound dataset
- Platform: workflows composable inside functions and variables
- Plugins ui mui: Button gains AppLink-based screen/external link mode
- Platform: icon picker attributes for Button + standalone Icon component
- Platform: bookings v1 - services, availability, booking API, console page
- Platform: email campaigns v1 - audiences, tiered send caps, unsubscribe
- Platform: actions builder - event to action automation, Pro+ metered
- Platform: outbound + inbound webhooks, Business tier
- Console: whole-site export/backup + restore, Pro+
- Platform: AI assist for blog entries + any canvas text prop
- Console: staff overview - metrics, tenant feed, purchases, usage; tenant search
- Platform: multilingual v1 - locale variants, hreflang, language switcher
- Platform: booking widget canvas element + reminder emails
- Console: site templates - save host as template, community browse/install
- Console: support tickets + subscriber community forum
- Tooling: seed-demo-host script with fixtures for every recent feature
- Platform: Event Calendar paid add-on - events manager, public API, Event List
- Console: signed-URL uploads for large video up to 200MB
- Platform: site search over dataset records + editor repeat badge
- Platform: Stripe payments for paid bookings with slot holds
- Platform: redirect model, shared validation, paid entitlements + plan-card catch-up
- Sites: enforce redirect rules in route resolution with sampled hit counts
- Console: redirect manager page with CRUD, validation, paid gating
- Console: redirect hit metrics + chain-loop and screen-collision checks
- Platform: screenAnalytics entitlement flag, Pro+
- Sites: attribute pageviews to screenId with referrer/device dims
- Console: per-screen traffic panel on the screen view page, Pro-gated
- Console: surface screen analytics in plan cards + host-card teaser
- Platform: media folder hierarchy model + legacy string migration
- Console: media folder rail with drag-and-drop organization
- Console: asset metadata capture, detail drawer, bulk edit
- Console: query-side media filters with cursor pagination
- Platform: CDN media delivery with hashed URLs and WebP variants
- Console: per-asset usage — references scan + delivery counters
- Platform: gate CDN media delivery as a paid-tier feature
- Platform: runtime dataset models from the dod.ts blueprint
- Console: dataset model builder — schema dialog + typed fields
- Console: typed dataset document editor
- Platform: dataset relations — reference fields + many-to-many
- Platform: dataset query layer for editor and screen bindings
- Platform: dataset round-tripping — CSV/JSON import/export + validated host import
- Platform: commerce v2 — receipts, inventory, coupon codes
- Console: orders filters + CSV export
- Besigner: WYSIWYG binding resolution + bound-content markers
- Besigner: multi-drag moves the whole selection
- Platform: AI Generate Section — constrained subtree into the canvas
- Platform: plugin manifest + sandbox bridge protocol libs
- Console: plugin publish + install pipeline with version pinning
- Plugins: sandboxed PluginFrame host runtime + origin loader
- Platform: plugin registry integration + install/upgrade UX
- Platform: id-based binding tokens with legacy name fallback
- Besigner: picker-first bindings — id tokens, search, friendly display
- Console: where-used scan with rename/delete safety for bindings
- Console: asset rename, replace-file, and image transforms
- Platform: migrate legacy binding tokens to id form + normalize on import
- Plugins: installed plugins as named besigner drawer entries
- Plugins: host-mediated network bridge for plugins
- Plugins: per-plugin configuration via a settings field
- Platform: site-wide announcement bar with marketingOverlays gate
- Platform: promotional popup with triggers, capping, scheduling
- Platform: contacts CRM v1 — unified ingestion from forms, members, orders, bookings
- Console: contacts page — list, profile drawer, tags/notes, CSV export
- Console: contact segments as campaign audiences
- Console: tenant suspension — staff toggle, 503 sites, owner banner
- Console: staff audit log viewer
- Console: full entitlement override editor for staff
- Console: users admin — staff-claim and disable management + gated listing
- Besigner: bindings v2 polish — inspector summary, deep links, publish-time migration
- Platform: popup v2 — email capture, overlay metrics, media picker
- Console: per-tenant usage drill-down + anomaly flags for staff
- Platform: retire the legacy name-token fallback
- Console: per-contact deletion for right-to-erasure requests
- Console: read-only tenant detail view for staff support
- Documentation: Docusaurus docs site — Material theme, console colors, recent features (AGL-208) (#261)
- Console: staff RBAC, audit export, guarded GDPR erasure
- Sites: add FirebaseServicesProvider + hooks replacing reactfire
- Forms: add MUI-native data-driven-forms component mapper
- Platform: add release-flag registry and rollout evaluation utils
- Sites: expose Firebase Remote Config in FirebaseServicesProvider
- Console: gate unreleased features behind release flags
- Console: staff feature-flags manager backed by Remote Config
- Cloud functions: seed release-flag Remote Config template + staff docs
- Platform: organization data model, slug policy and role math
- Console: org creation, slug reservation and org-owned hosts
- Console: org membership and invite APIs
- Cloud functions: Firestore rules v2 for org-scoped tenancy
- Tooling: one-shot tenants-to-orgs backfill script
- Console: org workspace context and switcher behind release flag
- Console: org-scoped host creation and workspace-subdomain middleware
- Console: billing mirrors to orgs and entitlements resolve from the org doc
- Console: per-org usage attribution rollups
- Console: organizations are permanent, not release-flagged
- Console: org membership UI — members card, invites, org creation
- Console: invite emails via Resend
- Console: per-site access editor for org members
- Tooling: org-aware GDPR erasure (AGL-232/238)
- Sites: datasets and contacts move to org scope server-side
- Console: data surfaces read org-scoped datasets and contacts
- Tooling: host-to-org data migration for datasets and contacts
- Console: org media library shared across the org's sites
- Console: org-tier plugin installs
- Console: org media in the besigner media picker
- Console: org plugin install UI — share, upgrade, uninstall
- Console: Stripe metering re-keyed to organizations
- Console: entitlements resolve from the org doc only
- Tooling: post-soak cleanup script for migrated legacy data
- Console: cross-subdomain sessions for workspace hopping
- Console: swap the org and host switchers
- Console: organization area without host context
- Tooling: read-only Firestore inventory script
- Console: modifiable workspace URLs with redirecting tombstones
- Console: billing, team, community and support join the org section
- Tenancy: orgs are the only billing/suspension source
- Console: org roles replace the manager-seat permission system
- Console: staff Organizations section replaces Tenants
- Console: org ownership transfer + settled design questions
- Console: scheduled audit archival + erasure-hold reminders
- Console: org media library at full parity + real Storage folder paths
- Console: folder edits move real Storage objects (org DAM work)
- Console: screen View buttons + workspace-scoped host routes
- Console: organization activity log on the Team page
- Console: org-level Data page — datasets managed and surfaced at org scope
- Billing: org-metered data usage — org-keyed dataset quotas, storage overage pricing
- Console: dashboard reorg — Logic/Products/Components pages, paginated Activity in Setup
- Marketing site: marketing hub — multiple scheduled/targeted announcement bars & popups
- Organizations: granular permissions, custom roles, host-scoped access guards
- Console: in-app notifications — model, emitters, app-bar dropdown, feed page
- Data bindings: id-based references for functions/workflows/datasets/webhooks + picker previews
- Automations: site-event triggers + client/server action steps with page runtime
- Marketing site: email lists + list audiences, and A/B experiments core
- Admin: staff user detail, org billing history, impersonation
- Console: subscription page v2 + org plugin installs inventory
- Experiments: screen/section variant serving, email A/B sends, besigner Interactions panel
- Experiments: lift + z-test confidence in results, one-running-per-screen guard
- Automations: run log, test runs, once-per-visitor triggers
- Notifications: per-category preferences, pref-aware fan-out, mark-all-read
- Email: Resend event ingestion — opens/clicks stats + experiment conversions
- Billing: cancel/resume, annual prices, proration preview + in-place plan switch
- Console: overlay ordering, staff exact-email lookup, effective-permissions viewer
- Marketing site: per-overlay engagement stats + bar impressions
- Email: campaign scheduling + per-recipient merge tags
- Experiments: auto-winner promotion + end dates
- Automations: session caps + cooldown windows
- Billing: Stripe billing portal, dunning banner, usage-threshold alerts (wave v5)
- Staff: broadcast announcements, org staff notes, activity filters (wave v5)
- Workflows: run history with status + duration (wave v6)
- Data: unique-key upsert on dataset import (wave v6)
- Commerce: in-app order notifications for host managers (wave v6)
- Logic: reference-integrity audit for automations/workflows/variables (wave v7)
- Besigner: Interactions panel v2 — toggle + remove in place (wave v7)
- Analytics: mirror overlay + experiment events into the site's GA (wave v8)
- Marketing site: at-a-glance channel rollup on the Marketing hub (wave v8)
- Tooling: local authenticated e2e — org-model seeder + Playwright harness
- Commerce: catalog model v1 — products, variants, categories, smart collections
- Billing: commerce entitlement matrix + Squarespace/Shopify-parity pricing
- Plugins: feature-plugin pattern — UI bundle + console extension contracts
- Console: products hub v1 — searchable catalog table + full product editor
- Console: categories, tags & collections manager with live smart-rule preview
- Commerce: inventory v1 — variant stock, oversell policy, low-stock alerts
- Commerce: orders model v1 — snapshots, status machine, totals, timeline
- Commerce: merchant Connect onboarding + plan-based platform fees
- Commerce: catalog CSV import/export in the Shopify dialect
- Commerce: taxes v1 — manual region rates + Stripe Tax option
- Commerce: shipping zones & rates — flat, free-over, tiered, pickup
- Console: orders console — detail dialog, refunds, draft orders
- Commerce: multi-location inventory buckets + transfers
- Commerce: dropship supplier routing with signed webhooks + tracking callback
- Plugins: commerce UI feature-plugin scaffold, registered beside mui
- Storefront: product grid block + public catalog API
- Storefront: product detail block + /products/{slug} template routes
- Storefront: server-backed cart, mini-cart drawer, multi-line checkout
- Storefront: customer account block on the site-member rails
- Console: store settings card — PDP template, checkout prefs, receipts
- Storefront: checkout v2 — email-first capture, recoverable checkouts, receipts
- Storefront: wishlists — guest localStorage, member merge, PDP heart
- Storefront: collection template routes + faceted grid filters
- Storefront: commerce SEO — product JSON-LD, sitemap URLs, merchant feed
- Storefront: newsletter opt-in with consent timestamps
- Console: shop starter templates for physical and digital stores
- Digital: secure downloads with limits + automatic update re-delivery
- Digital: storefront subscriptions with self-service portal
- Digital: members gate block + server-enforced entitlement API
- Digital: members-only video with short-TTL streams + resume
- Digital: license key pools with auto-assignment on purchase
- Digital: member updates feed for entitled subscribers
- Reservations: resources & availability model — seasons, deposits, windows
- Reservations: storefront widget — live quote, deposit checkout
- Console: reservations console — resources CRUD, check-in/out, walk-ins
- Console: pos register — cash, QR card, and room-folio sales
- Console: channel-split orders + folio-aware check-out
- Commerce: discounts engine v2 — codes + automatic promotions
- Commerce: abandoned checkout recovery emails
- Commerce: verified-buyer reviews with moderation + replies
- Commerce: related products — manual picks, co-purchase mining
- Commerce: back-in-stock alerts + GA4 ecommerce events
- Console: commerce analytics dashboard
- Contacts: purchase RFM rollups on order upserts
- Commerce: gift cards — issuance on purchase, checkout redemption
- Billing: advanced plan — $299 annual, zero fees, top quotas
- Billing: v2 stripe prices with grandfathering
- Www: pricing page driven from the plan tables
- Billing: pos register add-on price at $89/mo
- Releases: commerce v2 rollout flag + what's-new changelog
- Plugins: extract events calendar into a standalone plugin pair
- Automations: toggleClass action step for node-id targets
- Besigner: fluent interaction builder — no more workflows detour
- Besigner: custom HTML block — sanitized by default, sandboxed embeds
- Besigner: styling v3 — breakpoint-scoped sx, css builder, box stylers, classes (AGL-332..335)
- Besigner: section + theme-mode components, icon picker fix + perf (AGL-336/337/340)
- Besigner: subtree JSON editor, screen-picker links, media browse everywhere (AGL-338/339/341)
- Besigner: rename-safe entity references — id pickers + audit coverage (AGL-343/344/345)
- Email: besigner email designer — plugin, render pipeline, campaign templates (AGL-346..349)
- Console: users & analytics sections, glance widgets, manage tabs (AGL-350..353)
- Console: tabbed hub pages + redirect matcher v2 (AGL-354..356/375)
- Org: logo + contacts, member detail page, profiles, billing polish (AGL-363..367)
- Admin: impersonate org owners, direct org/user editing, list polish (AGL-357..361)
- Demo: full-feature sample data seed for demos
- Admin/org: staff user assignment depth + core plugins at org level (AGL-378/379)
- Console: host-setup vertical nav tabs + per-host member access editing (AGL-382/388)
- Console: track changes made to a member on their detail page
- Analytics: top-line insights — avg/day, week-over-week, top device
- Console: tab the host inbox like host setup — submissions / members / campaigns
- Console: tab the org community page like host setup
- Console: tab the org settings page like host setup — general/profile/ownership
- Console: media-browser field for logos and avatars
- Admin: staff host detail page with usage + subdomain edit (AGL-392/390)
- Admin: entitlement usage column + staff ownership transfer (AGL-391/390)
- Plugins: console consumes ConsoleExtension registry for dynamic nav + pages
- Email: relocate email console into the plugin + dedicated Emails page
- Besigner: show only email-safe components when editing an email document
- Commerce: register the Products nav via the plugin ConsoleExtension
- Commerce: relocate the Products console into the plugin via a media-picker context
- Email: vertical HubTabs on the Emails page (Campaigns / Designs / Audiences)
- Bookings: extract booking into its own plugin with console separation
- Redirects: extract the redirects console into its own plugin
- Data: extract the datasets console into its own plugin
- Logic: extract the logic console into its own plugin
- Workflows: extract the workflows console into its own plugin
- Marketing site: extract the marketing console into its own plugin
- Community: extract the community console into its own plugin
- Inbox: extract the inbox console into its own plugin
- Contacts: extract the contacts CRM console into its own plugin
- Plugins: plugin API extension registry + dispatcher; events/list reference
- Plugins: migrate email/marketing/workflows/bookings tenant APIs into their plugins
- Commerce: migrate the storefront tenant APIs into the commerce plugin
- Commerce: migrate membership-gated storefront APIs + the membership util into the plugin
- Commerce: migrate membership account/logout/wishlist APIs into the plugin
- Runtime: promote the host-event actions runtime into @aglyn/tenant-runtime
- Bookings: migrate the booking-create API into the plugin
- Events: migrate the site-event dispatch API into the plugin
- Commerce: migrate the membership sign-in/sign-up APIs into the plugin
- Commerce: migrate the members-only content API + promote the screen-composition pipeline
- Console: add the console plugin-API dispatcher + promote resolveOrgPermissions
- Bookings: migrate the reminder-emails console API into the plugin
- Marketing site: migrate the campaign send + scheduler console APIs into the plugin
- Commerce: migrate the merchant/staff + scheduler console APIs into the plugin
- Community: migrate the marketplace publish/install console APIs into the plugin
- Sites: App Router foundation — root layout, per-host theme, emotion SSR
- Sites: migrate site search to a Server Component; fix _sites private-folder routing
- Sites: migrate the catch-all site render to App Router
- Console: App Router foundation — root layout + provider stack + emotion SSR
- Console: App Router (app) shell + migrate the uniform authenticated pages (AGL-401/402)
- Console: migrate auth, hosts, and dynamic admin/org pages to App Router
- Console: migrate the host dashboard pages to App Router
- Console: migrate the [pluginSlug] route + full-screen editor pages
- Sites: emit JSON-LD + hreflang server-side from the App Router route (AGL-143/164)
- Platform: App Router adapter + server JSON/CSRF helpers for API route handlers
- Sites: migrate pages/api to app/api and delete pages/ — 100% App Router
- Console: migrate pages/api to app/api and delete pages/ — 100% App Router
- Sdk: @aglyn/plugins-sdk — the SDK feature plugins build against
- Org: enabledPlugins switchboard + org-settings plugins tab
- Plugins: dynamic org-gated plugin loading via generated manifests
- Plugins: remote realm bundles — signed sha-pinned marketplace plugins load in-app
- Plugins: release flags feed the plugin loader on every surface
- Console: plugins & add-ons hub — unified plugin management page
- Plugins: install/uninstall syncs org enablement + switchboard gates realm loads
- Tooling: plugin scaffolding cli + community realm template
- Plugins: bundle verifier — shared static checks, cli + publish api
- Plugins: dev-only unverified localhost realm loading
- Plugins: per-plugin config framework — schema, storage, generic ui
- Plugins: loader bootstrap phase + host-abi compatibility
- Community: marketplace listing content v2
- Community: listing detail v2 — docs, gallery, badges, changelog
- Console: staff plugin review queue + listing lifecycle
- Plugins: injection-zone catalog + four new console zones
- Plugins: custom field types — plugins extend dataset fields
- Plugins: plugin-declared permissions + scheduled jobs
- Tooling: plugin bundle budgets + loader metrics
- Plugins: marketplace security pass — limits, auditing, rotation
- Brand: aglyn documentation + aglyn besigner wordmarks
- Besigner: publish/unpublish button in the app bar
- Accounts: idle auto-logout after one hour with continue-url resume
- Data: server-enforce dataset/record creation quotas (AGL-473 phase 1)
- Hosts: server-enforce screen/layout creation quotas (AGL-473 phase 2)
- Logic: server-enforce variable/function/workflow creation quotas (AGL-473 phase 3)
- Commerce: server-enforce service/redirect/location/product creation quotas (AGL-473 phase 4)
- Accounts: add console password recovery pages
- Commerce: make posRegisters enforceable with named POS registers
- Billing: alert on workflow/action monthly run caps
- Onboarding: sites zero-state for new users, hidden when invite pending
- Accounts: require verified email before console access for email/password accounts
- Billing: alert on over-limit sites and media storage after downgrade
- Billing: warn about over-limit resources before downgrade/cancel
- Organizations: self-serve org deletion + complete GDPR erasure
- Hosts: self-serve single-site deletion with proper cleanup
- Organizations: automate post-hold org erasure
- Operations: in-repo Vercel cron config for the scheduled routes
- Security: nonce-based script-src CSP, report-only
- Billing: fold purchased add-ons into entitlement resolution
- Billing: add Stripe add-on price catalog + env plumbing
- Billing: self-serve add-ons API - get/preview/set items
- Billing: plan switch re-prices per-plan add-on items
- Console: billing add-ons management card + release flag
- Console: point-of-need add-on upsells
- Billing: invoice PDFs, receipts, dates & paging in billing history
- Besigner: surface sections & blocks as a first-class picker category
- Besigner: add prebuilt nav bar, hero, footer, cta, and more blocks
- Besigner: fill style-panel gaps with sizing, type, border, position groups
- Besigner: regroup element library into forms, media, commerce categories
- Plugins: survey field types for forms
- Commerce: pdp subscription framing + buyer-chosen billing mode
- Billing: accept a test-mode webhook signing secret fallback
- Console: site-member drawer, suspension, purchase records
- Commerce: site-member password recovery flow
- Sites: first-class designed content collections
- Sites: designable signin/signup/recovery screens + auth blocks
- Plugins: id-based form dataset binding with select pickers
- Automations: structured trigger condition (field/op/value) on event actions
- Automations: condition inputs (only run when field matches) in the actions builder
- Plugin UI: form after-submit outcomes — message, redirect, or reveal an element
- Data: field display-name editing and descriptions in dataset schema
- Commerce: catalog ux — grid search, categories, sort, type, paging; pdp preset
- Platform: hover triggers, element show/hide + drawer action steps, ui event bus
- UI components: dropdown menu, mega menu, drawer + menu button elements
- Marketing site: hover triggers + element/drawer steps in the site automations engine
- Besigner: visibility style control + hover interaction triggers
- Console: author hover triggers, element targets + drawer commands in interaction builders
- Build: switch tenant and www production builds to turbopack
- Commerce: price-range filter on catalog API + product grid
- Besigner: AND/OR condition chaining for form automations
- Besigner: pick interaction target by clicking in canvas
- Interactions: ungate basic presentational interactions from actions gate
- Datasets: editable reference ID separate from display name
- Deploys: assert serving deployment was built from production HEAD
- Platform: entry model v2 tokens, filters, related selection, internal md links
- Site runtime: entry v2 fields, related-posts compose, image-free fallback
- Plugin UI: related/share/entry-meta blocks + AppLink markdown links
- Sites: per-entry SEO head, RSS categories, blog sitemap URLs
- Console: entry SEO/category/tags fields, selection toolbar, live preview
- Platform: markdown-lite serializer with lossless round-trip property tests
- Console: WYSIWYG visual editor for markdown-lite blog bodies
- Console: visual-first blog editor — markdown demoted to advanced toggle
- Content: per-collection category taxonomy — stable ids, names resolved at render
- Besigner: browsable data-token picker with insert-at-cursor on attribute fields
- Deploys: verify the docs project too — silent Error builds now flag
- Besigner: token pills in attribute fields and inline text editor
- Interactions: grace delays + Esc/outside-click dismissal on element visibility
- Rendering: resolve scheme-scoped sx against the active theme mode
- Besigner: scope color style edits to the artboard scheme
- Forms: two-stage color picker with theme color references
- Besigner: supply site-theme color tokens to the designer panels
- Besigner: dropdown panel preset with pre-wired hover interactions
- Sites: branded page-navigation loader + host logo support
- Tests: tenant production-mode smoke harness
- Console: media picker in image dialog + HTML paste conversion
- Console: add Documentation link to the account menu
- Console: contextual docs help tooltips on feature pages
- Shared libraries: HelpTip affordance with help slots in cards, form fields, and tables
- Console: contextual docs help across pages, cards, forms, and tables
- Besigner: contextual help on styles, attributes, and editor panels
- Console: generate the docs help registry from apps/docs with typed anchors
- Besigner: help on the Screen Properties and Variables & Functions panels
- Console: contextual help on the screen detail page
- Documentation: click-to-enlarge image zoom
- Documentation: Cursor-style welcome landing with hero + card grids
- API: API key model, mint/verify core, and apiAccess entitlement
- API: v1 request pipeline — auth, errors, rate limiting, pagination
- API: v1 resource endpoints — datasets/records CRUD, sites, contacts, forms
- Console: API keys management card in org settings
- Www: marketing changelog with dated entries + image lightbox
- Sites: paginated collection page sets (/{collection}/page/N)
- Content: changelog on the aglyn-marketing host via content collections
- Console: org-slug path routing + org jump page
- Console: designed 404 on the console chrome
- Console: address hosts by subdomain slug, not doc id
- Console: Vercel-style org & site switcher dropdowns
- Console: show the site's favicon in the site switcher
- Console: logo to org home, jump page in dashboard layout, tier badges
- Console: show full host domain & org workspace URL in switcher rows
- Billing: API request pricing model — quota + metered overage
- Billing: meter API requests per org + bill overage via the Stripe rollup
- Billing: surface API pricing across console, marketing & docs
- Billing: attach shared metered price to subscriptions
- Besigner: order right panel Attributes, Styles, Info + default open
- Console: show a site's favicon on its card in the sites list
- Console: lift the create-org action into the jump page header
- Console: notification sound, desktop notifications and tab badge
- Marketplace: org-owned publisher identity schema
- Marketplace: publisher profile resolver + handle claim
- Marketplace: make publishing org-owned end to end
- Sites: emit Product structured data server-side
- Sites: structured data for collection lists and better Article
- Marketplace: claim publisher handles transactionally
- Marketplace: one discriminator for listing artifact types
- Marketplace: consolidate the community profile onto the org
- Console: redirect cross-org host deep links instead of 404ing
- Console: resolve prefix-less paths on workspace subdomains
- Console: add a Test alerts button for the chime and permission prompt
- Console: ask in-app before raising the native notification prompt
- Templates: model, collection, rules and quota
- Templates: save a page as a template
- Templates: save layouts and components as templates
- Console: make the test alert a permanent feature
- Templates: console page and host nav tab
- Templates: route, nav tab and page coverage
- Templates: use a template — new page, component or layout
- Templates: wire Use into the library, docs and e2e
- Templates: marketplace install lands in the library
- Templates: surface marketplace updates in the library
- Marketplace: publish and install layouts
- Marketplace: scoped sanitizer allowance and route registration
- Templates: layout publish UI and placeholder authoring
- Templates: wire publish action, detection and e2e
- Templates: gallery renders the library alongside starters
- Templates: route both gallery sources through the Use flow
- Marketplace: ratings and comments backend
- Marketplace: reviews rules, frozen aggregates and coverage
- Marketplace: ratings and comments UI
- Marketplace: wire reviews into detail and browse
- Marketplace: reportable listings and staff takedown
- Marketplace: takedown gate, rules and 'plan add-ons' copy
- Marketplace: explicit install targets, and fix dead browse links
- Components: version history, keeping the runtime read cheap
- Components: a besigner of their own
- Components: route, open action and exports
- Templates: a besigner of their own
- Templates: edited-copy badge, edit action, shared placeholder detection
- Besigner: warn and refuse before a document exceeds Firestore's limit
- Besigner: apply the size guard in all four editors
- Besigner: attribute canvas saves to a person
- Co-editing: RTDB rules, coverage and a scoped token broker
- Co-editing: open RTDB for presence, deny-all everywhere else
- Co-editing: show who else is in the document
- Co-editing: wire into the screen editor, add RTDB to the e2e emulators
- Console: seed first-party starters into each site's template library
- Console: components table, Create button and a component detail page
- Console: templates table, Create button and a template detail page
- Console: layout detail page, completing list → detail → besigner
- Console: searchable template picker on screens, layouts and components
- Console: name artifacts before creating them
- Console: component, template and layout detail pages match the screen detail shape
- Console: grouped starter rows act on the whole bundle
- Console: used-by cards on component and layout detail pages
- layouts can render inside other layouts
- Email: route all app email through one sendEmail helper
- Email: add the system email catalog and its Firestore rules
- Console: add the staff System Emails list page
- Email: render designed system templates at send time
- Console: derive the secondary nav tab strip from the route
- Email: edit system email templates in a host-free besigner
- Email: send a test system email to a chosen recipient
- Email: list Stripe-delivered billing emails in the system emails UI
- Email: add welcome, member-added, and erasure-confirmation emails
- Console: reference of the emails a site sends, under Setup
- Email: host-scoped email catalog + resolver for per-site templates
- Console: site owners can design their site's emails in the besigner
- Bookings: send booking emails through the site-designed template
- Commerce: send back-in-stock & abandoned-cart via the site template
- Email: acknowledge a GDPR erasure request to the owner at request time
- Commerce: wire the billing-webhook order emails to site templates
- Console: reset a site email back to its default from the Emails tab
- Marketplace: show honest plugin install state on browse & detail
- Marketplace: org-scope destination at /[orgSlug]/marketplace
- Marketplace: install targeting — All sites vs Selected sites
- Marketplace: Browse + Installed tabs at org scope
- Marketplace: retire the per-site community tab
- Marketplace: org-level Publish tab with a source-site picker
- Marketplace: publish dataset schemas and email templates
- Marketplace: show install state for dataset schemas and email templates
- Marketplace: let publishers fix a listing's name and description
- Security: durable rate limiting for public tenant endpoints
- Console: add activity-feed presenter for friendly labels + deep links
- Console: render activity entries as friendly deep links
- Console: record resource name on besigner saves
- Media library: polish DAM grid cards with overflow menu
- Media library: render folders as grid items, folders-first
- Media library: drag-and-drop reorg onto folder grid cards
- Media library: drag-and-drop file upload into the DAM
- Media library: custom metadata on assets, backed by Storage customMetadata
- Tooling: committed blog cover generator using the Aglyn logo
- Tooling: per-post color variations for blog covers
- Media library: surface Replace file in the DAM card overflow menu
- Tooling: faint white dot-grid texture on blog covers
- Media library: stable mediaId-keyed CDN URL that survives replace + moves
- Console: surface published dates for screens and content entries
- Search: stamp nameLower on screen/host name writes
- Media library: carry file extension in the stable CDN path
- Search: add hosts name-search composite indexes
- Sites: useSwitcherCollection — recent window + name-prefix search
- Console: hide Staff console menu item from non-staff
- Console: 404 non-staff on the staff console instead of leaking the grant script
- Console: on-demand "Used on" list with deep links in the DAM drawer
- Console: staff support-ticket queue & triage in the staff console
- Support: notify staff when a ticket is opened or a customer replies
- Console: show email + provider on the profile, sync display name, fix Google-only accounts
- Console: polish org-member & staff invite UX
- Organizations: per-user hostMemberships projection maintained beside memberRoles
- Organizations: close hostMemberships projection gaps — erase + rename fan-out
- Organizations: hostMemberships backfill + indexes; drop unused host nameLower
- Console: site switcher + subdomain routing via hostMemberships projection
- Console: redesign the user menu (Vercel-style) + Manage Account naming
- Console: Manage Account — move Account & Profile into tabs, unify naming
- Console: connect/disconnect sign-in providers on Manage Account
- Marketplace: prominent artifact-type label on listings
- Marketplace: listing preview image picks from the DAM
- Marketplace: listing editor reachable from Your Listings
- Marketplace: gate ratings on verified email + installed; comments open
- Marketplace: install is deliberate — grid is view-only, detail confirms targets
- Console: polish Manage Account — branded Google sign-in, password non-removable, nicer profile
- Console: redesign the notifications menu Vercel-style
- Marketplace: full-page listing editor with WYSIWYG body + wider detail
- Marketplace: publisher storefront + links to it
- Marketplace: self-service plugin upload from the Publish tab
- Marketplace: unified version timeline, review avatars, screenshot lightbox
- Console: always show the org-list pagination control
- Plugins: deploy the plugin origin — plugins.aglyn.com
- Plugins: per-manifest CSP on the sandbox loader
- Marketplace: track activeInstalls alongside installCount
- Marketplace: offer uninstall from the listing detail
- Examples: Promo Countdown — a real self-contained community plugin
- Admin: grant/revoke realm trust for listed plugins
- Plugins: sandbox loader frame-ancestors for custom-domain sites
- Billing: advertise unlimited member accounts on every plan
- Billing: contact audience bands with metered overage, not silent drops
- Console: contact band visibility — meter, overage estimate, missed alert
- Billing: show the declining platform-fee ladder on plan cards
- Www: advertise unlimited members and contact bands on the pricing page
- Self-hosting: opt-in standalone output + Docker images for console and tenant
- Self-hosting: docker-compose + self-host env template
- Console: shared password-admin primitives — policy, reset mail, change notice
- Console: staff can send a password reset or set a password directly
- Console: org admins reset a teammate's password, and set it only when safe
- Commerce: admin password help for site members, with session revocation
- Console: link the owner and every member on staff org detail to their user page
- Console: rate-limit admin-initiated password reset mail
- Console: require Terms/Privacy consent on sign-up, notice on sign-in
- Marketplace: capture README + license in the plugin upload dialog
- Console: reap orphaned plugin artifacts with a Firestore join
- Admin: wire the plugin takedown buttons
- Admin: add a per-listing plugin review endpoint and route
- Admin: add the plugin review detail page
- Admin: rebuild the plugin review index for scanning
- Admin: gate plugin listing on a recorded staff review checklist
- Admin: say what listed, verified and realm trust actually mean
- Marketplace: move plugin review onto the version
- Console: keep tables and code blocks when pasting a README
- Console: swap the listings row's Image action for View
- Admin: toggle a plugin README between rendered and source
- Console: insert and edit code blocks and tables in the editor
- Console: one markdown toolbar, built from MUI toggle buttons
- Admin: frame the README and link the stored bundle object
- Admin: expose the artifacts bucket to the review page
- Marketplace: choose private when uploading a plugin bundle
- Marketplace: let a private plugin go public without re-review
- Admin: flag private submissions in the plugin review queue
- Marketplace: address publisher storefronts by handle, not org id
- Marketplace: lead the listing sidebar with the install card
- Marketplace: make an org-scope install an editable set of sites
- Console: give a plugin installation its own page
- Console: resolve first-party plugins on the installation page
- Console: split Plugins out of Marketplace into its own section
- Marketplace: record provenance and a base snapshot on every install
- Marketplace: say when an update is available, everywhere installed things appear
- Marketplace: update plugins per site, with the changelog up front
- Marketplace: update a copied artifact by diff, never by overwrite
- Marketplace: count installs per version, not just per listing
- Data: the visibleTo scope token, one model for datasets and media
- Accounts: denormalize a member's scope tokens for the rules to intersect
- Admin: backfill visibleTo and scopeTokens before anything enforces them
- Besigner: pick the plugin from a list instead of typing its id
- Console: choose who a media asset is shared with, and scope the picker
- Data: choose which sites a dataset is shared with
- Media library: folder scope cascade, and picked assets get a site-qualified URL
- Organizations: default new datasets and media to the site that created them
- Media library: private DAM assets, reachable only by a signed URL
- Media library: wire the private switch to the console, not just the API
- Media library: sharing for a selection and for a folder's subtree
- Console: tell the user when the SESSION is what stopped working
- Build checks: fail the build when a loading-aware hook's value is taken without its flag
- Marketplace: a publisher attests to their own bundle before it reaches the queue
- Examples: a second worked plugin example, published to exercise the attestation
- Marketplace: the repository a publisher attests to is one they were asked for
- Marketplace: a publishing org accepts terms once, and again when they change
- Marketplace: publishing a plugin is a page, not a dialog
- Marketplace: the publish form's README gets the editor the listing already had
- Marketplace: shipping a new version is a path, not something to infer
- Marketplace: a publisher can see what review is doing with their version
- Marketplace: installing your own unreviewed version says so
- Marketplace: a reviewer can stop rejected bytes that are still running
- Marketplace: the plugin verifier parses the bundle instead of matching text
- Marketplace: the verifier says what it checked, not only what it found
- Marketplace: sweep stored verifier verdicts instead of waiting for a reviewer
- Marketplace: an example plugin that declares a network origin
- Billing: add Scale & Agency tiers, soften digital fee ladder, fix MRR add-ons
- Billing: add whiteLabel entitlement + org branding profile (white-label phase 1)
- Billing: white-label console chrome, brand settings, and branded email (phase 2-3)
- Billing: alert on bandwidth & published-site-size usage (metering enforcement)
- Billing: net-of-processor-fee revenue helpers
- Billing: staff coupons, per-org discounts, and a net-margin guardrail
- Billing: provision enterprise custom pricing from the staff UI
- Accounts: ssoEnabled entitlement + OrgSsoConfig data model
- Accounts: enterprise SSO sign-in, tenant-aware session, JIT mapping
- Accounts: use a popup for desktop SSO, redirect on mobile
- Accounts: dedicated /sso page; /signin links to it
- Billing: show "Enterprise" plan badge for custom-priced orgs
- Billing: show Enterprise + custom price on the Billing page
- Billing: comped-enterprise flag + Billing page polish
- Billing: make enterprise a real OrgPlan, not a display label
- Team: notify org admins when an invite is created and accepted
- Team: label every roster row as manager or site collaborator
- Accounts: refuse social linking on SSO-governed accounts
- Accounts: strip non-IdP sign-in methods when an org enforces SSO
- Team: member avatars everywhere, and the roster remembers a photo
- Billing: checkout collects a billing address, phone and tax id
- Account: one address type, and a phone stored in one format
- Billing: one cost model for the guardrail and the staff views
- Billing: in-page checkout for the console, dark behind a flag
- Accounts: sign up into a ready workspace, on the plan you picked
- Organizations: a workspace's subdomain is attached when the org is
- Billing: the org's address is structured, and reaches Stripe on edit
- Erase: a person's account can finally be deleted
Fixed
- Dependencies: add missing @testing-library/dom peer dependency
- Test: allow jest to transform ESM-only lodash-es, flat, nanoid, react-color
- Test: register @babel/plugin-transform-private-methods for class private methods
- Besigner json editor: use jsdom test environment for component rendering test
- Build: bump TS target from es2016 to es2022 for native private class methods
- Test: register private-methods babel plugin with loose mode matching class-properties
- Core data app: convert AglynAppController private fields from # syntax to TS private
- Core data app: convert AglynBaseModel private fields from # syntax to TS private
- Core data app: convert AglynDependencyManager mixin private members from # syntax
- Core data app: convert AglynExtension private fields from # syntax to TS private
- Core data app: convert AglynExtensionsController private members from # syntax
- Core data app: convert AglynContextsController private members from # syntax
- Core data app: convert AglynCanvasController private method from # syntax
- Core data app: convert AglynCommandsController private fields from # syntax
- Core data app: convert AglynComponentsController private field from # syntax
- Besigner data app: convert controller private members from # syntax to TS private
- Shared util logger: convert Logger private fields from # syntax to TS private
- Test: expand transformIgnorePatterns to cover full react-markdown ESM dependency tree
- Shared util logger: replace dead scaffold placeholder test with real Logger smoke test
- Shared util errors: fix toThrow assertion to pass function ref and expect correct error class
- Test: use jsdom testEnvironment for component-rendering jest configs
- UI components: pass required single child element to Menu in render test
- Aglyn plugin mui: replace bogus component render test with plugin registration test
- UI components: wrap SandboxFrame test in ThemeProvider and pass required child
- Platform: remove broken transformIgnorePatterns override with rootDor typo
- Platform: sync canvas-manager test fixtures with actual normalize/denormalize output shape
- Core util app: correct plugins field name in lineal relationship test fixtures
- Core feature renderer: wrap ElementComponentsContextProvider test in real AglynAppProvider
- Aglyn besigner: use commonjs module interop for jest instead of production ESM swcrc
- Aglyn besigner: replace dead scaffold test with real dnd singleton smoke test
- Test: add react-dnd ecosystem to transformIgnorePatterns ESM allowlist
- Aglyn besigner ui: initialize real besigner app and pass required node prop in tests
- Aglyn besigner ui: wrap remaining component tests with real besigner app and theme
- UI components: type implicit-any params across timer/observer/DOM hooks
- UI components: type implicit-any params across components and HOC
- UI components: type zoomable-panning-component and declare warning module
- UI components: fix module resolution errors under bundler
- UI components: guard against usePathname returning null in AppLink active-state check
- Test: mock static image imports so next/image renders under jest
- Apps tenant: pass required data and nodes props to CatchAllPage in render test
- Shared ui jsx forms: remove stale .d.ts stubs shadowing real source files
- Shared util timestamp: document intentional duplicate enum values in TimeExchange
- Core data app: rename local module variable to avoid shadowing CJS module global
- Shared util tools: use relative imports instead of self-referencing package alias
- Core data foundation: use relative imports instead of self-referencing package alias
- Shared data mdi: use relative imports instead of self-referencing package alias
- UI components: remove trivially-inferred type annotations in ZoomablePanningComponent
- Aglyn besigner ui: remove inferrable type annotation and replace {} type with object
- Shared ui snackstack: replace {} type with object in allClasses record types
- UI components: remove stale eslint-disable comment for unregistered rule
- Shared ui snackstack: remove stale eslint-disable comments for unregistered rule
- UI components: document and suppress intentional exhaustive-deps in useEffectPostMount
- UI components: wrap handleChangePosition in useCallback to satisfy exhaustive-deps
- UI components: correctly position exhaustive-deps suppression for rest-param args
- UI components: add value to useNodeProperty effect deps to close stale-closure gap
- UI components: document why start is excluded from useTimeoutDelay mount effect deps
- Aglyn besigner ui: restructure MobX action wrapper to satisfy exhaustive-deps analysis
- Core data foundation: move LinealDirectiveFlag/ComponentsLinealOrder to correct layer
- Platform: correct framework tag from scope:framework to aglyn:framework
- Core data admin: move workspace document types to core-data-foundation
- Shared data regex: add missing scope:data tag
- Besigner ui color picker: retag as shared UI lib
- Aglyn besigner ui: tag untagged form-fields and svg-icons libs
- Themes: remove dead types-proxy declaration
- Shared util tools: use relative import for _isUndT in object-remap
- Apps: alias next-api-middleware use() to avoid rules-of-hooks false positive
- Apps: stop linting Next.js generated files and root config require
- Www: resolve lint errors across pages, views, and lib helpers
- Console: exempt besigner-ui from the lazy-load static-import check
- Besigner ui: resolve 19 latent type errors across editor libs
- UI components: satisfy strict compiler flags used by dependent libs
- Build: tag the last two untagged libs
- Plugins ui mui: align build with the repo's rollup pipeline
- Plugins ui mui: drop unused load/destroy rest params in legacy plugin
- Console: clear all remaining type errors
- Platform: make canvas save-state tracking reliable so save disables when current
- Besigner feature designer: re-sync overlay rect on node reorder
- Platform: emit fully nested children from nestedNodes raw json
- Platform: make raw-json edits undoable via a history-aware applyNodes
- Sites: resolve production 404s from uncompressed screen nodes
- Console: make the Live button environment-aware and let production reflect saves
- Workspace: stop nx from replaying environment-baked next builds across environments
- Console: make the host theme editor reachable from navigation
- Besigner feature designer: back the layout chrome canvas with the app instance
- Console: compose the bound layout into screen previews
- Platform: keep chrome placed inside the layout slot above screen content
- Besigner feature designer: render in-slot chrome before the editable canvas
- Platform: pin composed layout roots to the canonical canvas root id
- Besigner feature designer: pin the chrome canvas root to the canonical id
- Console: seed screen and layout roots with the canonical canvas root id
- Besigner feature designer: stop selection overlays from growing the page scroll
- Besigner feature designer: keep selection overlays under the designer chrome
- Themes: tolerate themes without custom palette colors
- Console: pad theme editor cards to match the host setup page
- Besigner feature designer: render selection overlays inside the viewport stacking context
- Console: style screen previews with the host theme
- Platform: trust node map keys when loading persisted canvases
- Besigner feature designer: tolerate selecting parentless nodes in the overlay
- Besigner feature designer: make hierarchy reparenting drops reliable
- Platform: add a canvas reset for ending editing sessions
- Console: reset the canvas when leaving a besigner session
- Besigner feature designer: dismiss the node context menu when actions launch dialogs
- Console: resolve screen preview color scheme from system dark mode like the live site
- Besigner: carry body-level baseline into the shadow-rooted canvas so dark scheme text renders
- Platform: default the composed layout root to a renderable div when the stored root has none
- Sites: re-render the site page once the canvas fills instead of relying on parent renders
- Sites: ignore generated .next output in eslint
- Console: use x-data-grid v9 valueFormatter signature so path and date columns render
- Sites: fill the canvas during render so SSR emits the full node tree
- Shared libraries: render shadow-dom text as light DOM until the shadow root attaches
- Console: let the layout grow past 100vh so the sticky toolbar stays pinned
- Console: keep the source element intact when saving as a reusable component
- Console: disable theme save buttons when the draft matches the saved theme
- Console: besigner fills the window as a fixed, non-scrolling editor shell
- Sites: carry tenant host to seo routes via header and dedupe description meta
- Security: scope hosts rules to admins and block scriptable link hrefs
- Console: add billing and community profile links to the account menu
- Sites: remove stale versionRes reference that 404ed every page
- Console: pin view-all-screens to the bottom of the screen switcher
- Console: labeled schedule button in versions dialog
- Console: close actions fragment in layouts besigner page
- Platform: strict-build type errors that broke vercel deploys
- Console: team members act in the owner tenant, not their own
- Cloud functions: restore users/{uid} firestore access lost in the AGL-42 hardening
- Platform: clear residual strict-tsc errors across console/tenant
- Platform: duplication-proof runtime singletons via globalThis
- Platform: custom-domain cname resolution + attachment backfill
- Shared libraries: lazy-load the MDI icon catalog instead of the 2022 disabled stub
- Platform: always offer domain re-attach + guard fbserver build init
- Cloud functions: suspension blocks tenant writes at the rules level
- Console: sign-in-time Firestore permission-denied crash (AGL-216) (#267)
- Console: reactfire cache sweep batch 1 - safe hooks + host cards (AGL-218) (#268)
- Console: reactfire cache sweep batch 2 - host cards part 2 (AGL-219) (#269)
- Console: reactfire cache sweep batch 4 - commerce/community/media/templates (AGL-221) (#270)
- Console: reactfire cache sweep batch 3 - Besigner/screens/layouts (AGL-220) (#271)
- Console: reactfire cache sweep batch 5 - admin/manage/contacts/inbox/content (AGL-222) (#272)
- Sites: reactfire cache bug in shared useDoc helper (AGL-223) (#273)
- Console: retry one-shot media reads on sign-in-time permission race (AGL-224) (#274)
- Platform: pin jwks-rsa v3 to unbreak Vercel runtime ERR_REQUIRE_ESM 500s
- Shared libraries: adapt to change-case v5 renamed and removed exports
- Rest api: adapt to cookie v2 API and switch tsconfig to bundler resolution
- Themes: use js-cookie v3 default export
- Www: migrate FieldSet to react-window v2 List API
- Platform: drop mobx-state-tree v5 union type-arg workaround for v7
- Tooling: backfill re-sync path also writes memberRoles projections
- Documentation: sequence-diagram labels and arrows were white-on-white in light mode
- Documentation: sequence-diagram lifelines were black-on-black in dark mode
- Documentation: dark-mode palette was silently overridden by Infima defaults
- Tooling: backfill never re-parents wired hosts or creates phantom-owned orgs
- Console: workspace domain is aglyn.io with app.aglyn.io as the apex
- Console: phantom host ids bounce to the sites list
- Console: outlined switcher buttons with carets
- Console: ICON_VARIANT icons need .path — they are wrapper objects
- Forms: type-clean the data-driven-forms v4 surface (AGL-225/226)
- Console: scope site lists to the selected workspace org
- Documentation: disable git-backed last-updated stamps on Vercel builds
- Console: workspace sign-out propagation + subdomain org switching
- Platform: export ICON_VARIANT_ORGANIZATION for the org switcher
- Billing: subscription verification — effective-plan resolution closes free-plan leaks
- Console: make authenticated emulator sessions actually work
- Console: mui v7 slotProps + typing sweep across commerce components
- Billing: advanced plan labels and tagline on the plan cards
- Console: view links, switcher ellipsis, staff button, mui rename (AGL-342/362/373/374)
- Console: community page card spacing + org media card framing
- Besigner: entity dataset picker reads org-scoped datasets
- Console: keep hub tab panels mounted so content stays in the DOM
- Console: themed dashboard glance buttons + card-frame staff org page (AGL-384/385)
- Console: nav release-flag defaults to shipped state so Events shows
- Entitlements: type checkQuota's quota param against resolved keys
- Console: resolve App Router runtime render regressions in the migrated console
- UI components: drop Pages-only _app/_document from the barrel
- Server: App-Router-safe plugin server graph + build-time admin init guards
- Tests: fall back across chrome flavors on macos
- UI components: temporary navigation drawer exits toward its anchor edge
- Documentation: last-updated stamps survive the nx build cache
- Data: stamp updatedAt on every shared-hook firestore write
- Besigner: element edit json uses the shared raw json editor
- Accounts: honor the continue url after sign-in
- UI components: icon picker cells, navigation overlay, oauth popup wedge
- Ts: typescript 7 source compatibility for theme vars and app-router pages
- Mdi: satisfy module-boundaries and no-assign-module lint rules
- Accounts: google oauth via redirect flow on mobile with same-origin auth helpers
- Accounts: re-mint absent session cookies instead of signing users out
- Accounts: funnel oauth through single auth.<domain> host to avoid per-org redirect URIs
- Accounts: exempt auth.<domain> host and /__/* from workspace middleware
- Sites: resolve empty catch-all slug to root path so home screens serve (#289)
- Brand: make even-odd fill-rule explicit on logo SVGs; drop legacy icon assets
- Accounts: mint shared cookie on redirect sign-in return, not validate
- Accounts: delegate workspace-subdomain sign-in to auth.aglyn.io
- Accounts: mint shared cookie before cross-origin return to fix workspace sign-in loop
- Accounts: harden delegated-return mint, log session-route errors, add escape hatch
- Accounts: workspace return signs in from the shared cookie directly, with retry
- Accounts: delegate mobile sign-in on app.aglyn.io to the auth host
- Billing: close free-tier and plan-tier entitlement leaks (AGL-469/470/471) (#302)
- Besigner: server-enforce reusable-components entitlement
- Data: cap dataset model payload size (AGL-473 phase 1 follow-up)
- Accounts: hold loading splash during post-sign-in redirect window
- Impersonation: use named-app auth instance so owner impersonation completes
- Accounts: exempt staff impersonation from the email-verify gate
- Www: clear pre-existing type errors and add apps/www to the typecheck gate
- Commerce: server-enforce contentGating at the paywall runtime
- Commerce: enforce posRegisters cap at sale time to close downgrade orphan
- Organizations: use a reliable org name in the delete-confirm gate
- Cloud functions: deny public storage reads; add storage-rules deploy script
- Dependencies: remediate Dependabot alerts across the three lockfiles
- Sites: remove unauthenticated /api/user user-DB dump
- Cloud functions: deny-all Realtime Database rules
- Cloud functions: block editors from rewriting host identity keys
- Cloud functions: freeze Stripe payout fields on profiles writes
- Console: fail closed on missing staffRole instead of defaulting super
- Platform: escape JSON-LD to stop </script> XSS breakout
- UI components: sanitize Typography html prop at render
- Cloud functions: keep enabledPlugins out of client-writable org update
- Cloud functions: hide host webhook secrets + order PII from viewers
- Cloud functions: make host install pins create/update API-only
- Cloud functions: pin server-managed communityListings fields on owner update
- Billing: reject stale Stripe webhook signatures (5-min window)
- Billing: make Stripe webhook idempotent via event-id claim
- Commerce: mark storefront member cookie Secure in production
- Marketing site: sanitize showHtml automation before innerHTML
- Redirects: reject ReDoS-prone host redirect regexes
- Runtime: fail closed on org-permission errors for a targeted org/host
- Platform: fail closed when loading realm plugins without a trust key
- Www: replace real-looking CSRF_SECRET in example env with placeholder
- use constant-time comparison for cron/plugin-jobs secrets
- Billing: gate checkout on billing.manage
- Console: require auth on domains/verify DNS endpoint
- Commerce: sign download/supplier tokens with a dedicated secret
- Commerce: expire digital-download tokens after 90 days
- Sites: rate-limit analytics/collect
- gate dev realm loader on an explicit flag, not NODE_ENV alone
- Sites: block plugin fetch to private/internal addresses
- Http: default CORS to deny; never pair credentials with wildcard
- Security: harden CSP; drop dead X-Frame-Options
- Console: reuse single idToken in domain wizard
- Sites: pin plugin-fetch to the validated IP (DNS-rebind)
- Commerce: gate webhook fulfilment on order-newly-created
- Billing: webhook multi-item plan detection + add-on sync
- Billing: make the monthly/annual toggle actually do something
- Billing: repair setup-stripe webhook creation
- Billing: make add-on confirm clickable + honest proration
- Sites: resolve datasets by displayName in name bindings
- Console: attach inserted besigner elements to the selected target
- Console: only explicit sign-outs retire the shared session
- Console: derive staff override feature flags from the plan model
- Data: human display names for dataset columns via slug ids
- Themes: map shared-data-types to source, drop dead operators path
- Besigner: reconcile committed conflict markers in the props form
- Commerce: enforce member suspension on all cookie-authenticated endpoints
- UI components: type the menu shell over BoxProps so tenant/console tsconfigs stay clean
- Build: disable workerThreads, enable webpack memory optimizations
- Deploys: add production alias verifier/repair script
- Console: guard collection rows + repair Add product dialog
- Deploys: alias verifier uses explicit project names, not directory links
- Sites: merge node-level sx with props.sx in node renderer
- Besigner: debounce attribute inputs to stop URL-field render crash
- Besigner: persist element interactions to actions so they fire live
- Besigner: collapse nav menus on canvas unless subtree selected
- Runtime: match interaction ids across layout namespace prefix
- Besigner: insert leaf selection as sibling, not nested child
- Besigner: place leaf-targeted drops as siblings, not nested children
- Rendering: honor selfClosing flag so void elements never receive children
- Besigner: pin canvas styles to the artboard device width
- Besigner: register COLOR_PICKER + skip unknown editors in the attributes form
- Organizations: renamed-away slugs are reclaimable, not reserved forever
- Documentation: drop pending-capture image embeds that fail the Docusaurus build
- Plugins email: compose node sx over block defaults so styles edits apply
- Console: stop offering besigner interactions for email documents
- Plugins email: split divider border shorthand so palette tokens resolve
- Besigner: keep classNamePrefix off the DOM and make styles accordions controlled
- Besigner: carry preset interaction templates through registration
- Console: clear scoped firestore hook data on dep change
- Besigner: collapse aglyn-hidden panels on the canvas unless selected within
- Besigner: scale theme typography to the device-preview breakpoint
- Sites: accept ReactNode children on the app loading layout
- Sites: suspense-wrap the navigation loader's route listener
- Console: stop the index smoke spec's infinite render loop
- Console: stop stale sign-out tombstone logging you out on refresh
- Console: kill org-switch bounce & cross-org logout
- Console: don't double the chrome on the in-app 404
- Documentation: match navbar to the console app bar; fix toggle & mobile-menu colors
- Documentation: use the dark-word logo on the now-light navbar in light mode
- Console: honor confirm() cancel path in org cards
- Documentation: make the click-to-enlarge affordance on images explicit
- Besigner: stack the styles panel accordions like the elements panel
- Console: make the host subdomain server-owned
- Console: pair the org switcher glyph with its background
- Console: repair links left behind by the org-slug migration
- Plugins: show the device-default glyph on the theme switcher
- Console: show the billing tier, not the role, on free orgs
- Console: keep the active nav tab in view on load and navigation
- Security rules: make the listing review verdict server-owned
- Commerce: escape the aggregate-rating JSON-LD like every other site
- Sites: render product detail on the server, keeping ISR
- Console: read the GA id from its real field path on the staff page
- Sites: make tenant Google Analytics actually render
- Marketplace: compare listing ownership to the org, not the uid
- Console: resolve notification host links across orgs
- Console: one resolution for plugin console links
- Console: adopt the shared route resolver in three plugins
- Besigner: stop silently overwriting a concurrent editor
- Besigner: wire the concurrent-edit guard into the screen editor
- Besigner: guard the layout editor against concurrent edits
- Components: say what publishing actually does
- Besigner: component and template editors rendered nothing (AGL-680/681)
- Besigner: wire the canvas-root adapter and label the open action (AGL-680/681)
- Co-editing: make failures visible, stop local dev writing to prod RTDB
- Co-editing: developer-visible warnings and emulator wiring
- Co-editing: stop the effect loop that re-minted tokens
- Tests: seed the org membership mirror so both editors can open the screen
- Commerce: sign stream tokens with TOKEN_SIGNING_SECRET
- UI components: allow muiButton in the nav-menu preset guard
- Test: stop nx leaking the root .env into the jest env
- Dependencies: resolve dependabot axios and brace-expansion advisories
- Dependencies: resolve remaining dependabot advisories across all three manifests
- Sites: server-render product grids, closing the /products SEO hole
- Besigner: give reusable components a version switcher
- Community: move the listing preview-image route into the plugin
- SEO: nest aggregateRating, emit sku, add per-entry blog author
- Commerce: walk the denormalized node map, not a tree
- Console: only copy a starter in when it is used or edited
- Console: give a newly created component or template a canvas root
- Console: match components and templates to the screens/layouts design (AGL-693/694)
- Console: make "Not now" on the notification prompt actually hold
- UI components: nest the DataTable header rules so they actually apply
- Console: listing and detail-page polish across the four artifact types
- Console: dates render again on the artifact lists, and trim the lead column
- Console: empty-value dashes, content Created column, clickable entry rows
- Console: move screens row delete and save-as-template into an overflow menu
- Console: picker dialog app bars use the shared surface color
- Console: artifact detail pages show a not-found state for an unknown id
- Console: bundle Use pre-checks the real screen count
- Tests: seed the /survey route the tenant prod smoke gates on
- Console: loading overlay holds until navigation completes
- Accounts: confirm session-wide idleness before global sign-out
- Team: stop invite happy-path showing a false 'no account' warning
- Domains: point workspace domain and hardcoded hosts at aglyn.com
- Domains: verify custom domains against the target the wizard shows
- UI components: annotate LinkNavigationReporter return type to restore typecheck
- Build: fail the build on unresolved imports instead of warning
- Domains: make custom-domain connect and disconnect server-authoritative
- Console: declare nativeButton on the eight Buttons that render AppLink
- Console: stop the site switcher flashing on every navigation
- Console: mount the secondary app bar once in the (app) layout
- Console: hold the hoisted nav bar to routes it can address
- Console: gate the three admin pages that render without a staff check
- Plugins: stop losing the first dependent of every plugin dependency
- Email: seed a system email's first version from its default body
- Email: render designed system emails against the besigner root id
- Plugins: surface a bundle stuck WAITING instead of an empty drawer
- Email: say system email images are pasted URLs, not a media browse
- Email: send the erasure-hold staff alert through the designed template
- Email: send the monthly usage summary through the designed template
- Plugins: drive the Installed-plugins card from the first-party registry
- Plugins: keep marketplace installs from clobbering bundle toggles in enabledPlugins
- Marketplace: show org-owned listings in 'Your listings'
- Marketplace: publish the virtual root-collection wrapper
- CI: pin console cron BASE_URL to app.aglyn.com, drop stale CONSOLE_BASE_URL var
- Marketplace: harden published node props against DOM-spread payloads
- Console: restore the red help-coverage guards
- CI: restore the CONSOLE_BASE_URL override for forks
- Test: let three shared-ui suites actually run their tests
- Security: stop logging the CSRF_SECRET value at startup
- Security: make CSRF fail closed when unconfigured
- Billing: degrade add-ons get to no-subscription when Stripe lookup fails
- Accounts: a silent session restore must not re-mint the shared cookie
- Dependencies: close dependabot alerts — next, react-router, postcss, brace-expansion
- Console: sync host setup tab into the ?tab= URL param
- Forms: route legacy InputProps into slotProps.input
- Dependencies: close 2 high dependabot alerts in apps/docs
- Documentation: org-scoped URLs in screenshot harness + refresh all shots
- Console: confirm empty host lists against the backend, held
- Console: retry, not a false 404, when host resolution fails
- Besigner: run interactions in draft Preview so hover menus work
- point repository references at aglyn/aglyn (retire old aglyn/core repo)
- Marketing site: import action predicates from the context-free subpath
- Besigner: drop the nav-menu editor panel under the trigger, not inline
- Media library: CDN sends Content-Disposition filename for downloads
- Media library: references scan includes content-collection entries
- Media library: absolute Copy URL, same-origin Edit-image load, entry-aware copy (AGL-831/832/833)
- Console: surface pending org invites on the jump page
- Console: scope the staff-menu guard to MainLayout
- Database: exempt large never-queried node/snapshot fields from indexing
- Marketplace: payouts gate on acting org + retire "Community" copy
- Besigner: drop redundant unwired SEO fields from Screen Properties
- Marketplace: reachable detail page + accurate install-target copy
- Console: stop valid hosts intermittently 404ing — server-confirm the empty
- Console: return the user photo in staff user-detail
- Console: stable, paginated org list in the staff console
- Console: staff org list via Admin SDK API so ALL orgs show
- Plugins: resolve bundled load.html across builder roots
- Plugins: serve /load as an .mjs function (no package.json = CJS default)
- Console: don't 404 an org slug on a cache-served membership miss
- Console: don't render a failed org-doc read as the Free plan
- Console: site switcher built literal /<orgSlug?>/ links off the subdomain slug
- Console: stale host-resolution 'ready' 404'd a site picked from the switcher
- Console: server-confirm a cache-served missing org doc
- Console: blank screen on boot — root NoSsr rendered no fallback
- Console: plugin gate blanked the whole window on every org change
- API: honor the v1 contract — envelope on failure, real scopes, field errors
- Console: route every link through AppLink so navigation stays client-side
- Console: base the staff MRR estimate on live subscriptions, not plan fields
- Console: unbreak the two console specs that were red on main
- Console: keep the help tips as plain anchors — AppLink breaks MUI Tooltip
- Brand: restore the knockout circle in the logo head on the social cards
- Besigner: open an empty reusable component on a canvas root
- Documentation: keep the notification prompt out of the console screenshots
- Documentation: address console guide shots by org slug, not host subdomain
- Besigner: guarantee a canvas root for every editor
- Documentation: make the member sign-up walk actually run
- Shared libraries: forward refs from every AppLink variant
- Console: declare nativeButton=false where nav buttons resolve to anchors
- Console: keep the console mounted across an org switch
- Console: stop reporting Stripe failures as an empty billing account
- Marketplace: make staff takedown actually kill the plugin
- Console: cascade dataset deletes to their records
- Email: cascade email-list deletes to their members
- Commerce: cascade collection deletes to their entries
- Plugins: make three confirm-gated deletes actually run
- Commerce: drop the dynamic aglyn import that reddened console lint
- Console: hide the staff admin tab strip from non-staff
- Console: reconcile the staff claim against a forced token refresh
- Console: tell content and catalog collections apart
- Console: stamp the collection kind on site import
- Console: refuse a collection slug that is already taken
- Marketplace: add delist/unverify and enforce review state on install
- Admin: keep the bundle-source link when no plugin origin is set
- Console: claim collection slugs transactionally
- Platform: parse and render markdown code blocks and tables
- Sites: render code blocks and tables in entry bodies
- Console: make the edit-listing dialog scrollable
- Marketplace: keep private listings out of browse, for the owner too
- Marketplace: make "Selected sites" a checkbox list, not a multi-select
- Marketplace: give a missing listing a real empty state
- Marketplace: name the listing in its hero and breadcrumb
- Marketplace: fix browse card layout and show the Verified badge
- Marketplace: weight the Verified badge and regroup install scope
- Marketplace: count a per-site install as having installed it
- Console: list site-pinned installs in the Plugins index
- Console: clearer wayfinding across Plugins and Marketplace
- Console: read the installation page's param by its segment name
- Security: scope site collaborators out of org-wide reads
- Marketplace: let a version with no content change be taken
- Marketplace: let the palette's own blocks be published
- Marketplace: a refused install offers the review it tells you to read
- Besigner: stop telling authors an installed plugin isn't installed
- Besigner: publish installed plugins to every editor, and react to changes
- Security: a site can no longer read or write another site's dataset
- Infrastructure: declare the rateLimits TTL policy that already exists in the project
- Security: scope contacts and segments to the site reading them
- Security: the media CDN stops serving restricted org assets to anyone
- Security: the media APIs stop leaking assets and the client roster
- Security: rules scope datasets, records, media and folders per site
- Console: scope the media library's queries so the rules don't reject them
- Console: scope the datasets query so the rules don't reject it
- Console: the PWA manifest is linked again and its icons resolve
- Console: the installed app icon uses the real brand plate, not a gray fallback
- Data: stamp visibleTo on every new dataset, and confirm before narrowing
- Media library: the org media upload route also stamps visibleTo
- Console: the app icon uses the light solid brand variant
- Console: scope the last four dataset queries, and badge restricted assets
- Data: a reference must resolve everywhere its collection does
- Console: give every console route its own tab title
- Security: the missing-field escape hatch let scoped members list everything
- Console: restore the original title separator and brand affix
- Console: keep the brand on tab titles below a titled layout
- Security: a site collaborator could erase datasets they cannot read
- Media library: the scoped media grid had NO composite index in production
- Media library: a failed load is not an empty library
- Console: say so when a permission denial is NOT the sign-in race
- Commerce: a plan still loading is not the free plan
- Data: the host Data banner still promised every site sees every dataset
- Security rules: host datasets were a quota-free second address for org data
- Console: find the payment method where Stripe actually keeps it
- Community: the browse surfaces sent an unfiltered dataset list every mount
- Console: the quota banner asked for org totals a collaborator may not have
- API: the erase route still accepted org resources under the host scope
- Console: the site switcher shows a site's favicon, not always the glyph
- Console: the site icon reads BOTH favicon shapes, which the switcher needed
- Console: a site collaborator's console is their site, not the org
- Console: a site collaborator's quota banner keeps the warning, loses the button
- Console: a plugin surface's help tooltip points at its own docs, not the marketplace
- Marketplace: the review card said nothing installs, over a live install
- Markdown: a # heading in a pasted README is a heading, not literal text
- Marketplace: the stopped-version alert agrees with itself at one site
- Marketplace: a muted Marketplace category no longer mutes the verifier alert
- Marketplace: a verifier check row says its state, not only draws it
- Marketplace: a rejected publish shows why instead of crashing the card
- Marketplace: a call through an alias is the call it stands for
- Marketplace: test the sandbox CSP that ships, delete the one that did not
- Marketplace: a URL held in a constant is read, not shrugged at
- Marketplace: a data: URL no longer takes the whole verifier down
- Billing: custom enterprise price is MRR truth, not the plan default
- Organizations: dedup pending invites — one per email, no seat double-count
- Notifications: default the arrival chime on; resume suspended audio (AGL)
- White label: activate only when a brand is configured, not by entitlement
- Billing: site collaborators no longer consume manager seats
- Staff: the staff console stops claiming a personal-workspace context
- Console: staff chrome goes home, and the site Owner row shows the owner
- Team: member avatars render a photo instead of always an initial
- Accounts: reach SSO users from every admin surface
- Console: only a URL that names a workspace lets the chrome claim one
- Accounts: seed the personal profile doc on every account path
- Billing: rate discount DEPTH, not just whether $2 of infra is covered
- Console: the site Users table pages, and its rows go somewhere
- Team: one column per question — role and its custom layer are one cell
- Team: a member's face comes from the org doc, not the site roster
- Team: the site Users column is "Site access", not a second kind of Role
- Security: the host gate was the one copy of the constant that opted out
- Besigner: the theme's webfont never loaded in the canvas or preview
- Marketplace: say why Verify is disabled, at the button
- Marketplace: split Verified into a publisher claim and a per-version one
- Cron: give the scheduled routes a duration, not Vercel's 10s default
- Cron: the usage sweep resumes, and a skipped org goes red
- Billing: the Stripe address sync never ran — void promise on serverless
Performance
- Build: raise nx parallel from 1 to 3 so library builds stop serializing
- Build: stop Next app builds from rebuilding 41 unused libraries
- Build: move the last 22 libraries off the deprecated Rollup executor
- Marketplace: lazy-mount inactive hub tabs so only the active panel settles
- Tooling: render blog covers at 1x + optimize PNG
- Admin: store the plugin verifier verdict instead of re-running it
- Cron: the usage rollup waits once per org, not six times
Changed
- UI components: move CardDisplay and DataTable out of console app
- Shared util fbclient: absorb www's aglyn-deprecated module
- Www: fold verifyIdToken into firebase helpers, drop dead fetch-data module
- Site data: relocate core-data-admin under libs/tenant
- Platform: unify duplicated framework symbols
- Platform: absorb core-data-foundation, core-data-app, core-util-app
- Aglyn node renderer: absorb core-feature-renderer, retire libs/core
- Shared util fbserver: single firebase-admin initializer
- Shared util fbclient: single browser Firebase app bootstrap
- Plugins ui mui: absorb aglyn-plugin-mui as the single MUI plugin lib
- Runtime: drop dead controller-registry writes, manager registry is canonical
- Besigner ui: drop vestigial controller context providers from root
- Besigner data app: stand alone, off the controller framework
- Platform: delete the RxJS controller framework
- Shared ui color picker: move color picker into the shared ui scope
- Shared ui json editor: move json editor into the shared ui scope
- Besigner feature designer: move designer ui under libs/besigner and absorb its panels
- Besigner: merge aglyn-besigner and besigner-data-app into @aglyn/besigner
- Platform: clarify module boundaries and naming
- Besigner core: converge dnd and hover/selection state on the mobx managers
- Platform: fold the root constants module into foundation
- Besigner core: drop the orphaned interface-controller surface
- Besigner core: encapsulate focus state behind accessors
- Console: reuse shared buildScreenRouteEntries in the besigner publishing flow
- Platform: add-ons rename + manifest-based plugin bundle registry
- Platform: migrate firebase-admin to modular API behind compatibility facade
- Console: swap reactfire imports to @aglyn/tenant-feature-instance
- Console: retire the Account page, move theme toggle into the app bar
- Plugins: move plugins out of ui/ and rename to @aglyn/plugins-*
- Sites: share useFirestoreCollection + useHostOrgId from tenant-feature-instance
- Plugins: shared plugin-page plumbing — page props, permissions, barrels
- Platform: add @aglyn/aglyn/server entry so Server Components avoid client contexts
- Sites: drop the _sites namespace — rewrite to /[host] at the app root
- Sites: remove Pages Router _app/_document — App Router owns the shell
- Console: remove Pages Router _app/_document — App Router owns the shell
- Plugins: make plugin /server graphs App-Router-safe (context-free)
- Commerce: move the commerce domain model out of core into plugins-commerce
- Plugins: move marketing/email/redirects/bookings domain models out of core
- Plugins: move community/reference-audit/dataset-io models + console usage-metering out of core
- Platform: dissolve @aglyn/plugins-sdk into the core plugin-manager
- Plugins: move plugin-owned console routes into their plugins (AGL-418a)
- Plugins: billing-webhook hook registry — plugins absorb their Stripe sections (AGL-418b)
- Plugins: tenant site-page hooks — redirects/commerce/marketing leave the loader (AGL-418c)
- Plugins: marketing site runtime — overlays/experiments/automations leave the tenant app (AGL-419a)
- Plugins: console surfaces leave the app + boundary rule enforced
- Naming: org/workspace/tenant/host convention — glossary + legacy alias clarity
- Naming: drop workspace.types.ts (renamed to platform.types.ts in AGL-443)
- Naming: remove the tenant-as-org alias — Tenant identifiers are Org
- Naming: retire persisted tenant spellings pre-launch
- Naming: sweep remaining legacy naming leftovers
- updated tenant favicon
- UI components: drive nav menu open/close via interactions, drop openOn
- UI components: menu button toggles drawer via bus default, drop binding attr
- Besigner: consolidate styles panel into immediate-apply groups
- Console: route outbound console links through buildRoute
- Besigner: extract the shared editing core out of all four routes
- Email: move the email renderer out of the plugin into shared
- Console: drop the dead nav props from every call site
- Canvas: harden the node-append sites against the AGL-759 ||= trap
- Console: converge the remaining admin pages onto StaffOnly
- Plugins: drop duplicate PluginSdk alias for one Aglyn import
- Marketplace: cut render churn behind the AGL-785 publish update-depth loop
- Console: fold plugin switchboard + config into Marketplace › Installed
- Console: fold seller area into Marketplace › Publish, retire /community
- Console: collapse org nav to one Marketplace tab, de-dupe cross-links
- Console: give each seller section its own Marketplace tab
- Community: drop the redundant first-party list from the Installed card
- Media library: consolidate media pickers onto one shared DAM
- Besigner: adopt shared switcher design language + fix pagination flash
- Besigner: serve screens via useSwitcherCollection search
- Marketplace: Listings-tab edit dialog reuses the WYSIWYG editor
- Billing: collaborator-seat copy — 'members per host' was never end users
- Security: finish deleting the CSRF module — it had no callers
- Console: shared confirmed-doc listen for the tombstone contract
- Platform: stop inferring a collection's kind from its shape
- Marketplace: one View action per listing row, the rest in a menu
- Console: put marketplace installs above the plugin switchboard
- Marketplace: extract the site-set control from the listing page
- Console: rename the installation segment to [pluginRef]
- Data: delete the host-scoped data fallback production proved dead
- Console: delete the page-title mechanism the App Router never read
- fix five defects a review pass found in the scoped-sharing work
- one home for "what may this member see" (review follow-ups)
Documentation
- Besigner: operate & extend guides — workflows, roles, membership, plugin publish (AGL-211) (#263)
- domains, redirects, protection & multilingual guides (AGL-212) (#264)
- deepen Besigner, datasets, templates, AI, theme & search into task pages (AGL-213) (#265)
- add themed diagrams & SVG mockups across the docs (AGL-215) (#266)
- add real console screenshots to 8 pages (AGL-217) (#275)
- multi-tenant organizations & Firestore v2 design proposal
- record org implementation status and early-access workspace docs
- record second-pass org implementation status (AGL-237/238)
- architecture pages with Mermaid diagrams for flags and multi-tenancy (AGL-231/236)
- record resource-scoping decisions for org-shared data
- Documentation: customer terminology sweep — host→site, tenant→organization
- architecture docs reflect the AGL-238 tenant retirement
- v2/v3 polish coverage — billing flows, email engagement, automation runs, permissions viewer
- v4–v8 polish wave coverage — engagement stats, scheduling, auto-winner, frequency caps, run history, upsert, portal, staff tools
- populated console screenshots via the emulator e2e stack (AGL-217 unblocked)
- Commerce: overview rewrite for the ecommerce core wave (AGL-279..289)
- Commerce: pos hardware setup, failure modes, reservations guide
- Besigner: interactions cookbook + custom HTML safety model
- responsive styling, designed emails, redirects v2, whats-new wave
- Plugins: plugin relocation + email console/Emails page + besigner email filter
- Plugins: commerce fully relocated + media-picker context escape hatch
- Plugins: bookings extraction + tenant prop on ConsolePluginPageProps
- Plugins: redirects as the console-only plugin reference
- Plugins: data as the console-only, dual-surfaced plugin reference
- Plugins: logic plugin + its shared where-used tooling
- Plugins: workflows plugin + plugin-to-plugin dependency note
- Plugins: marketing plugin + useMediaPicker consumer note
- Plugins: community plugin + multi-page/permissions notes
- Plugins: inbox plugin composing commerce + email tabs
- Plugins: contacts CRM plugin
- Plugins: document the server-half API-route registry + dispatcher
- Plugins: document the shared @aglyn/tenant-runtime server lib
- Plugins: document the console dispatcher + body-parsing exceptions
- Plugins: App Router plugin dispatcher + aglyn:addons-only tagging (AGL-408/409)
- Plugins: both apps' API dispatchers on the App Router + build-time eval gotcha
- Plugins: dynamic loading, slots, runtimes, and hook registries
- Plugins: strapi competitive gap analysis + v2 roadmap
- Plugins: plugin-manager api reference
- Plugins: reference guides — zones, manifests, trust, envs, extension points
- Plugins: walkthrough guides — first plugin, surfaces, apis, realm
- Plugins: publisher handbook
- Plugins: worked-examples gallery + narrated realm demo
- Glossary: comprehensive term reference with anchor nav
- Ia: nested category architecture for the docs site
- Images: real annotated screenshots for every area
- Images: screenshots on every feature page
- Tests: tenant smoke table covers the seeded published /home screen
- Billing: add downgrade / cancel / delete data-lifecycle page
- Security: add responsible-disclosure policy
- Commerce: document TOKEN_SIGNING_SECRET in tenant example env
- Environment: add example env files for root/console/docs; flesh out tenant
- Billing: self-serve add-ons page + whats-new
- Documentation: screenshot-driven walkthroughs for surveys, datasets, commerce, members
- Forms: after-submit outcomes section + conditional automation docs
- Documentation: menus & navigation guide + interactions/visibility updates
- Besigner: document new-element placement relative to selection
- Besigner: expand drag-and-drop reference with drop zones and leaf rules
- Besigner: mega-menu walkthrough + interactions plan tiering
- Content: entry model v2 fields, blog blocks, tokens, editor toolbar
- Content: visual editor tabs, toolbar behavior, and shortcuts in blog guide
- Documentation: document styles-panel consolidation and email-designer limits
- Documentation: scheme-scoped colors and the theme-reference picker
- Documentation: mega-menu walkthrough screenshots via the capture harness
- replace stale 'how-tos coming' notices with links to the shipped guides
- rewrite Site Search pages from ground truth; fix incorrect 'Paid' claim
- API reference area at /api with its own nav tab and sidebar
- Learn section with guided learning paths + nav tab
- Help section (FAQ, troubleshooting, billing, contact) + nav tab
- Console: explain the one-shot notification permission prompt
- Operations: document TOKEN_SIGNING_SECRET provisioning and rotation
- Operations: scope the shared-secret rule to a deployment tier
- Operations: correct the token-signing runbook — it is already provisioned
- Operations: recreating a shared env var drops its project links
- Email: add Resend + aglyn.com sending-domain setup runbook
- Build: audit the console's 41-library dependency graph
- Domains: publish aglyn.com as the API base URL and workspace host
- Plugins: note the tab strip is route-derived and mounted once
- Marketplace: document the org-level marketplace IA
- Console: make production builds smoke-testable locally
- Operations: record live TTL policy and why the SA cannot set one
- real screenshots of the org marketplace
- sync guides to the consolidated Marketplace IA
- Media library: document DAM v2 — folders-in-grid, drag-and-drop, picker, custom metadata
- Media library: refresh media page screenshot for DAM v2
- refresh README with cover image, product screenshots, and accurate monorepo overview
- correct console.aglyn.com references to app.aglyn.com
- Switchers: keep host/org switchers client-filtered by design
- add GitHub social preview card (1280x640)
- link the hosted docs site (docs.aglyn.com) in the README
- Media library: describe the on-demand "Used on" audit
- Database: track gcloud/console-only Firestore config (AGL-866/870/871/872)
- Database: mark TTL, backups, delete-protection applied (AGL-870/871/872)
- Marketplace: document the shipped v2 publisher flow (AGL-868/869)
- what's-new entry for scalable audience pricing (AGL-888..892)
- document the Manage Account area and correct the console chrome
- document support tickets, the forum, and the staff triage queue
- API: rebuild the REST API reference from the real v1 surface
- Plugins: document the sandbox security model and close marketplace v2 gaps
- Plugins: explain the installs vs active counts on listings
- stable media URLs, Preview vs canvas, and the real per-screen SEO fields
- Self-hosting: self-hosting runbook, readme section, docs-site page
- Security: document CSRF_SECRET and track the AGL-792 rotation
- switcher-search backfill, orgs-collection rule caveat, Setup deep links
- admin password reset and manual set across the three account surfaces
- capture the admin password controls on all three surfaces
- Billing: note pre-release pricing is provisional on the billing overview
- Billing: add the missing Advanced row and list all five tiers
- Console: document the local artifacts bucket for plugin review
- Readme: replace oversized cover with banner-ratio brand image
- Readme: add repo social-preview image (1280x640)
- Console: record the re-auth threshold as reviewed, not merely chosen
- Sites: scopedToHost still claimed the host fallback exists
- Support: a site collaborator asks whoever invited them
- Events: the events calendar gets a docs page, so its help tooltip is its own
- Markdown: the source hint mentions the # heading it now accepts
- Marketplace: nothing still says the verifier matches source text
- Organizations: the workspace-domain env is already set, and how to read it back
Behind the scenes
- Tsconfig: remove dead path mappings and duplicate exports
- Shared libraries: remove unreachable shared-util-fbserver lib
- Www: remove dead profile-data fetch helper
- Revert "chore(www): remove dead profile-data fetch helper"
- Shared ui snackstack: drop obsolete ts-ignore in merge util
- Platform: remove superseded core-ui-renderer lib
- Platform: remove superseded core-feature-singleton lib
- Platform: inline mitt, remove shared-util-emitter lib
- Shared libraries: remove unused besigner-feature-canvas-designer lib
- Besigner ui: delete unconsumed controller-store hooks
- Aglyn node renderer: remove dead controller-runtime react bindings
- Platform: prune foundation and app-utils to the surviving surface
- regenerate project graph snapshot for the besigner reorganization
- Platform: delete dead managers and unused api surface
- refresh project graph snapshot
- Workspace: run nx without the disabled nx cloud org and drop cloud-only fix-ci steps
- Workspace: add the tenant dev server to the preview launch config
- Workspace: serve the console preview in dev mode
- Build checks: guard against module-graph duplication regressions
- Platform: repair actions spec nesting broken in AGL-149 merge
- disable Nx Cloud so builds don't hard-fail on the cache (infra)
- Dependencies: bump node-fetch from 2.6.6 to 2.6.7 in /cloud/functions (#13)
- Dependencies: bump minimist from 1.2.5 to 1.2.6 in /cloud/functions (#18)
- Dependencies: bump protobufjs from 6.11.2 to 6.11.3 in /cloud/functions (#26)
- Dependencies: bump jose from 2.0.5 to 2.0.6 in /cloud/functions (#31)
- Dependencies: bump minimatch from 3.0.4 to 3.1.2 in /cloud/functions (#32)
- Dependencies: bump json5 from 1.0.1 to 1.0.2 in /cloud/functions (#37)
- Dependencies: bump @tootallnate/once in /cloud/functions (#56)
- Dependencies: bump all dependencies within semver-safe ranges (#276)
- Dependencies: remove unused packages and bump build/minor versions (#278)
- Dependencies: bump firebase to v12 / firebase-admin to v14, drop reactfire
- Dependencies: bump workspace dependencies across apps and libs
- Build: migrate workspace to nx 23.0.1
- Build checks: convert eslintrc configs to flat config (eslint 9)
- Jest: transform newly ESM-only deps in jest
- Console: stub firebase services in index smoke spec
- Dependencies: bump @data-driven-forms to v4.2.0
- Cloud functions: Firestore rules emulator matrix + host-delete wildcard fix
- Tooling: docs preview launch config with autoPort
- Cloud functions: rules matrix covers org datasets, contacts, media, installs (AGL-235/237)
- Console e2e: real smoke suite replacing the scaffold stub
- Console: trim the Manage quick menu to user-scoped items
- Console: switcher restyle — contained org switcher with Secure badge
- Console: rename Sites back to Hosts across the org UI
- ignore .env files, regenerated next-env types
- Console: customer-facing terminology is Sites everywhere
- Scripts: rules deploy via REST for expired-CLI-auth situations
- Tests: cover the July feature waves — marketing, logic audit, runs, billing, notifications
- Plugins: drop mui event-list source now owned by events-calendar
- Workspace: remove dead apps; core plugins listed; batched registrations (AGL-369..371)
- Tests: assert hub-tab content by DOM attachment + fix marketing expectations
- Build checks: enforce plugin↔core decoupling via nx module boundaries
- Tests: free port 4500 for the tenant + document the tenant smoke pass
- remove unused turbo directory with apps
- Cloud functions: modernize the cloud functions scaffold
- Ts: migrate workspace to typescript 7 native compiler
- fix latent spec type errors surfaced by the ts7 typecheck gate
- Tests: add serve:tenant:emulated script and launch config
- Logic: drop createResourceUid imports made unused by AGL-473 phase 3
- Naming: rename tenant→org local vars/params holding org entity
- Tests: seed a non-staff-owned org to cover the impersonation success path
- Tests: seed an unverified-owner org for the impersonation gate exemption
- Operations: drive console crons via GitHub Actions, not vercel.json
- Cloud functions: default Firebase project to aglyn-main
- harden workflow inputs and bump checkout action
- Vercel: only create deployments for production-branch pushes
- Cloud functions: add REST deploy script for RTDB rules
- Cloud functions: make RTDB rules deploy robust to token auth style
- Cloud functions: prove the new Firestore field guards (AGL-493..508)
- Platform: reword visibility band doc comment to appease tsdoc
- experiment(build): turbopack production build for the console
- Deploys: re-trigger production build for AGL-573 (webhook miss)
- Deploys: re-trigger console production build (dropped webhook, AGL-566)
- Console: coverage guard for contextual help on pages and cards
- Revert "Merge pull request #456 from zgover/feature/agl-614-marketing-changelog"
- allow tools/scripts node invocations in project settings
- Tests: seed org slugs + a second org for the new routing
- Tests: point console smoke shells at the new /[orgSlug] routes
- Tests: membership mirror uses orgName, matching production
- Console: point the notification pre-prompt at AGL-663
- Console: pin the notification pre-prompt gating
- Console: restore the build-output next-env route types
- Templates: e2e for save as template
- drop the duplicate helper left at its pre-move path
- Tests: assert the second presence session actually reaches the editor
- Tooling: add read-only staff claim audit script
- Tooling: add a read-only Stripe Connect profile audit
- UI components: match DataTable column headers to the screens table head
- Console: pin both table header heights to one shared constant
- Vercel: repoint tooling and docs at the renamed Vercel projects
- Console: mock next/navigation in the host page smoke test
- Console: pin down the publish-panel update-depth loop
- Console: scope the publish-panel loop guard honestly
- Operations: script the rateLimits TTL policy, and correct where TTL lives
- Console: drop orgSlug from OrgPublishPanel render
- Husky: drop v10-deprecated hook header + prepare script
- Dependencies: bump safe minors/patches across workspace
- Dependencies: bump nanoid 5 -> 6
- Dependencies: remove 3 vestigial @babel/plugin-proposal-* deps; hold babel 8
- Build: run the nx 23.1.0 migrations skipped by the manual bump
- Brand: remove outdated aglyn-logo raster assets
- Tooling: one-pass blog-cover migration script
- Tooling: self-load env + preserve stable coverImage in cover migration
- Tooling: nameLower backfill migration
- Revert "feat(media): carry file extension in the stable CDN path (AGL-843)"
- Tooling: self-load .env in the firestore-rules deploy script
- Plugins: trigger origin redeploy with static project settings
- Plugins: redeploy origin with pinned no-op build
- Besigner: regenerate docs-help anchors for the new Preview section
- Pricing: drop grandfathering promise; state pre-release pricing is provisional
- prune the Next dev cache at serve time to stop it eating the disk
- worktree spin-up script, with the Next cache prune wired in
- Plugins: stop rebuilding the plugin origin on every monorepo push
- Scheduled jobs: run the plugin-artifact reaper weekly
- Cloud functions: pin the plugin-artifacts bucket lifecycle policy
- Sites: pin the takedown kill switch on the sandbox site path
- Security: cover the collaborator boundary, and close its write half
- Admin: prove the scope backfill against a real emulator, not a mock
- Security: prove the agency scenario end to end, and write the model down
- Security: close the three verification gaps AGL-1047 left open
- Console: stop the silent title-template reset from coming back
- Security rules: assert the org-wide unfiltered list, and say which query was denied
- Console: the staff gate spec was leaking a claim between cases
- Scripts: count what actually lives under the host fallback paths
- Commerce: cover the plan-load window on the other three cards
- Build: regenerate the Next tsconfigs, which had drifted from tsconfig.base
- Console: org.plan is not revenue, and now something enforces it
- Build: fail the build when the generated Next tsconfigs go stale
- Build: actually run the docs-help freshness check
- Build: the revenue guard must not be affected-scoped
- Agent tooling: a /marketplace-publishing command to resume the publisher-flow arc
- Security rules: the publisher agreement freeze is covered, and deployed
- Marketplace: prove the sweep's regression alert is wired, not just correct
- Marketplace: the sweep can be forced from a manual dispatch
- Agent tooling: add the enterprise/SSO continuation command
- Agent tooling: add the payments/profiles continuation command
- Agent tooling: retire the finished arc commands
Share this article
We're building the open web platform. Follow along as we ship — and tell us what you need.