Updates
Platform Updates
Public-facing release notes for meaningful changes across Furries PH operational systems.
First created Last updated
Release Notes
Finance Tailwind CSS Fidelity Pass
Repositories: partners.furries.ph, docs.furries.ph
Status: Preview; local visual, interaction, and SPA validation passed
What’s Changed
- Finance Management now uses the workspace Tailwind CSS v4 pipeline for route shells, compact action rows, filters, KPI grids, split workspaces, responsive detail rails, centered dialogs, and shared breakpoint density.
- Typography and spacing were tightened against approved Design 2 at both the 1120 × 912 working viewport and the approved desktop comparison size. Semantic badge colors and the standard partner dashboard palette remain unchanged.
- Persistent SPA navigation now shows exactly one Finance navigation panel. The root dashboard navigation can no longer remain visible beside the Finance panel after switching routes.
- Finance now uses the same nested sidebar heading and active-route treatment as Asset Management. Standard Finance creation dialogs retain a shell-level fallback, so modal actions remain available after a refresh or SPA route swap.
- Runtime-created table rows, audit details, and stateful dialog content retain narrowly scoped semantic selectors where static utility classes cannot safely represent server-provided markup.
- The approved overview hierarchy is now present in the live partner scope: five compact financial signals, an eight-column PHP/USD event ledger, selected-event cash/outflow/budget/audit detail, and a narrow accountability rail.
- Local development sign-in now identifies the dashboard audience explicitly and can recover a stale configured development password through a server-side, localhost-only session flow. Production authentication behavior is unchanged.
Validation
- Astro diagnostics, the clean 150-page static build, Finance route/modal inventory, Finance accessibility checks, the Tailwind contract, the API type check, and the 124-route SPA inventory pass.
- Authenticated in-app-browser validation covers all 14 Finance routes with one visible primary heading, one visible Finance sidebar, approved-canvas source/render comparison, and a centered outflow dialog.
- A refreshed signed-in Transactions check confirmed the active Finance sidebar and centered Record manual entry dialog with no browser-console errors.
- Fresh real-API captures and the approved-source comparison are retained in
certification/finance/real-api/andcertification/finance/comparisons/overview-approved-vs-real-api-final.png.
AMS Tailwind CSS Visual System
Repositories: partners.furries.ph, docs.furries.ph
Status: Preview; local visual and interaction validation passed
What’s Changed
- The Asset Management System now uses the workspace Tailwind CSS v4 pipeline for shared route headers, KPI grids, register toolbars, responsive workspaces, scanner chrome, and modal anatomy.
- Typography and spacing were tightened against approved Design 1 while preserving owned/loaned registers, accountable workflows, QR/NFC scanning, and persistent-SPA behavior.
- The nested AMS sidebar now keeps exactly one route active during SPA navigation, and governed
?action=addmodal state is removed when an operator cancels the dialog. - The universal QR, barcode, manual, and NFC resolver now keeps one compact method pane visible at a time. The Overview scene also remounts and refreshes correctly after operators leave and return through the SPA shell.
- Runtime-created register rows and dialog state retain narrowly scoped component selectors where static utility classes cannot safely express the behavior.
Validation
- Tailwind framework contracts, Astro diagnostics, the 150-page static build, and the 124-route SPA inventory pass.
- Authenticated in-app-browser validation used the localhost-only
partners-apidevelopment session and covered all 10 AMS routes, loaded Overview data, single-active nested navigation, SPA route changes, add-action cleanup, the owned-asset and nested category dialogs, the Logistics Hub task dialog, and the universal scanner. - Fresh Overview, Logistics Hub, owned-asset, category-master, hub-task, and scanner captures were visually checked against the approved AMS Design 1 gallery.
Unpublished Event Feedback Link Guard
Repositories: rego.furries.ph, docs.furries.ph
Status: Implemented and locally validated
What’s Changed
- Event pages now show the Event feedback block and
Give feedbackbutton only after that event’s feedback form has been published. - Draft-only and not-yet-published feedback forms remain private to organizers and no longer expose an attendee link that opens an unavailable form.
Impact
Attendees only see feedback actions they can use. Event organizers do not need to change existing drafts; publishing the form makes the event-page action appear automatically.
Validation
- Astro diagnostics pass with zero errors, and the production build completes successfully.
- Rendered browser QA confirms the block is absent for an unpublished form, appears for a published form, and opens the correct attendee feedback route.
EPS Designed UI and Persistent SPA Certification
Repositories: partners.furries.ph, docs.furries.ph
Status: Preview; local visual, interaction, and resilience certification passed
What’s Changed
- The EPS portfolio, overview, My Work, Schedule, Requirements, Departments, Meetings, Files, Notifications, Risks, Gates & Handoff, Event Configuration, and Settings surfaces are registered in the persistent dashboard SPA shell.
- Seamless sidebar navigation now remounts the correct EPS scene and every route’s designed primary dialog without replacing the dashboard document.
- Visual QA confirms the full route and modal atlas, including New Department, membership/RACI/capacity, requirement approvals, meeting notes/minutes, Sanity-only evidence, notification destinations, controls, gate decisions, EMS changes, and project settings.
Validation
- The 144-page static build and Astro diagnostics pass with zero errors.
- EPS contracts and representative-volume resilience certificates pass, including 10,000 work items, 20,000 requirements, 50,000 activity records, reminder replay, and atomic 500-row import identity.
- The browser certificate passes all 13 planning routes, twelve persistent-SPA route transitions, each event-scoped primary dialog after SPA remount, all representative secondary workflows, and desktop/mobile Department states with zero runtime errors.
Next Step
Controlled migration application, secret provisioning, deployment, and hosted non-production canary evidence remain operator-owned rollout actions.
AMS Design Fidelity and SPA Hydration Certification
Repositories: partners.furries.ph, docs.furries.ph
Status: Historical Preview evidence; superseded by the corrective AMS update above
What’s Changed
- Owned and loaned asset registers now include the designed KPI strip and operational attention queue; checkout, transit, audit, maintenance, and logistics routes include their designed exception rail.
- Settings now preserves the approved three-part desktop hierarchy—master-data tabs, register, and attention queue—without collapsing workflow actions into the narrow navigation column.
- Import, exception filtering, Settings tabs, and governed configuration export are functional in direct loads and persistent-SPA navigation.
- SPA scene hydration now updates the added KPI and attention layers after route transitions instead of leaving loading placeholders behind.
Validation
- The 144-page static build and Astro diagnostics pass with zero errors.
- AMS database, no-oversell concurrency, recovery, policy, and SPA route-list certificates pass.
- The then-current authenticated browser smoke certificate passed 56 checks across ten routes and captured 75 route, modal, scanner, and responsive states. A later board-by-board corrective audit found material density and workflow-depth gaps; use the newer 58-check/77-capture manifest only as current fixture regression evidence, not visual release sign-off.
EPS Authorization and Volume Certification
Repositories: partners.furries.ph, partners-api, rego.furries.ph, docs.furries.ph
Status: Preview; local implementation and certification complete, controlled hosted rollout pending
What’s Changed
- EPS now requires explicit project membership or partner/platform administration, then applies role capabilities, department scope, parent-resource access, and confidential/restricted classification checks throughout workspace reads and mutations.
- Calendar exports, meetings, requirements, risks, gates, notifications, audit, handoffs, canonical EMS proposals, and protected file downloads expose only the data granted to the current Planning role. Protected files also enforce configured role and department policies before authenticated proxy download; raw Sanity URLs remain prohibited.
- Representative resilience certification now covers 10,000 work items, 20,000 requirements, 50,000 activity records, 300 participants, and 20 departments. Rego diagnostics, build, canonical EPS publication boundaries, and desktop/mobile Event Shop browser flows also pass.
- EPS publishes a machine-readable OpenAPI 3.1 description using JSON Schema 2020-12, and dependency-date application, baseline creation, and stage-gate decisions now commit through atomic database functions.
Next Step
Operators do not need to change local planning data. The remaining release work is controlled migration application, Worker secret provisioning, deployment, and hosted linked-event/upload/notification/publication canary evidence.
Finance Management Design 2 Workspace
Repositories: partners.furries.ph, partners-api, docs.furries.ph
Status: Preview; locally certified and ready for hosted canary review
What’s Changed
- All 14 partner Finance Management routes now use the approved dense operational layout with AMS-style nested navigation, compact KPI strips, portfolio and workflow tables, event-aware filters, detail rails, audit context, and predictable centered dialogs.
- The Finance overview now follows the approved five-metric, cross-event ledger, selected-event cash bridge, latest-outflow, commitment-health, and audit-activity hierarchy. Duplicate page headings and unresolved runtime icon placeholders were removed.
- Finance tables and detail panels now respond to the available dashboard shell width, preventing clipped columns and document-level horizontal overflow on narrower desktop windows while retaining dense desktop layouts.
- Partner-wide and event-specific outflows expose accountable checkout, maker-checker state, evidence and notification context, while payables, receivables, expenses, budgets, close, reconciliation, automation, integrations, and settings share one consistent workspace language.
- Every Finance route is registered in the persistent dashboard SPA shell. Rapid route switching now safely cancels stale overview rendering, and Astro/Vite module transforms remain intact during SPA script remounts.
- Linked-project current-history inspection corrected a Finance pgcrypto schema-resolution defect and now verifies required migrations, privileged-function grants, the deployed Finance schema, and a forced-rollback synthetic partner/journal mutation without retaining finance records.
Impact
Finance teams can move between partner-wide books and event detail without page reloads, use the same navigation and control patterns throughout, and inspect more financial context without opening separate pages.
Validation
- Astro diagnostics pass with 0 errors; the 144-page static build passes.
- The complete local Finance certificate passes database/accounting invariants, 29 independent calculations, mutation sensitivity, 16-actor concurrency, one-million-line volume, logical restore, accessibility, 54 API contracts, Telegram/Discord provider contracts, security hardening, and SPA-manifest coverage.
- Current in-app-browser evidence covers all 14 routes and 15 representative modal entry points with no console errors. Approved-source and implementation comparisons are retained in the Finance certification evidence directory.
- A fresh 1120 × 912 visual pass confirms every Finance route stays within the viewport. The outflow modal measured centered to the viewport within the scrollbar offset, and the corrected overview comparison is retained as
overview-approved-vs-implementation-final-v2.png.
AMS Design 1 Complete Workflow Gallery
Repositories: partners.furries.ph, partners-api, docs.furries.ph
Status: Historical Preview milestone; superseded by the corrective AMS program above
What’s Changed
- All ten Asset Management System routes now implement the selected Design 1 visual language with route-specific context, dense operational data, and consistent button-launched dialogs.
- The complete secondary workflow gallery is available for owned and loaned asset lifecycle, custody, checkout return and renewal, transit receipt and exceptions, audit counts and variance review, maintenance and warranty work, logistics-hub controls, finance approvals, master data, policy configuration, and governed imports.
- Add Loaned Asset can now create an external owner and its custody agreement in a nested accountable dialog, then select both new records without losing the parent asset draft.
- Every operational dialog identifies the signed-in operator, records server-time context, supports shared QR/barcode/NFC scanning where identity is required, and provides predictable Cancel, draft, and submit controls.
- AMS import now has a distinct dry-run validation state before controlled commit, preserving blocked rows and review evidence.
- Asset and work-order details loaded authoritative records; lifecycle/custody/exception/maintenance/bulk/finance submissions created actor-locked pending cases, policy changes created immutable drafts, and QR, Code 128, DataMatrix, and NFC carriers used the authenticated identifier API. The pending cases did not themselves apply the represented domain transition; later wording and UI now state that limitation explicitly.
- All AMS navigation remains inside the persistent dashboard SPA shell, including workflow initialization after nested-sidebar transitions.
Impact
Asset, custody, logistics, maintenance, audit, and finance operators can use one consistent Preview workspace instead of learning separate interaction patterns for each route. Owned property and assets held in external custody remain visibly and operationally distinct.
Validation
- Astro diagnostics and the 144-page static build pass.
- The dedicated authenticated browser certificate passes 54 checks across all ten routes and produces 75 route/modal/scanner captures. It opens every primary modal and unique secondary workflow; proves detail reads and accountable case/policy persistence; checks scanner and autocomplete states, nested Cancel/close, console health, route-by-route SPA document preservation, and desktop/mobile overflow.
- Database certification passes 13 ordered AMS migrations and 64 RLS-enabled relations, including idempotent workflow cases and versioned policy drafts; API type-check and certification pass across 90 authenticated routes and 69 database commands. The linked Supabase migration list and non-mutating
--include-alldry run also pass. - Side-by-side Design 1 comparisons were recorded at this milestone. The later corrective audit supersedes that visual sign-off after identifying material route density, specialist-column, governance, and workflow-state gaps.
Event Planning System Preview Workspace
Repositories: partners.furries.ph, partners-api, rego.furries.ph, docs.furries.ph
Status: Preview; ready for migration and deployment review
What’s Changed
- The new Event Planning System (EPS) adds a complete pre-event workspace for schedules, requirements, departments, meetings, controlled files, reminders, risks, readiness gates, event configuration, and project settings.
- Schedule records now share real Gantt, calendar, table, board, workload, and baseline views. Every visual has a keyboard-accessible table and focused edit dialog.
- Schedule now also includes month/week/agenda calendar modes, dependency and critical-path Gantt context, zoom, approved-baseline overlays, hierarchy/WBS, accessible signed-day rescheduling, scenarios, and reusable personal/team saved views.
- Department workflows include creation, effective membership, RACI, and capacity designs; meeting workflows include externally hosted calls, ordered agendas, versioned minutes, decisions, and canonical follow-up actions.
- Department/role requirement templates assign idempotent user obligations to current and later joiners. Their due-date reminders are created in the same transaction, so a successful assignment cannot be left without its notification schedule. Requirements support draft/final versions and withdrawal before review; governed records support watchers, comments, mentions, and reactions.
- Requirement and risk ownership is selected from named planning members, rather than by entering internal person identifiers. EPS does not ask operators to enter raw JSON for these workflows.
- Handoff preparation now selects named signatories and creates the actual accountable package command, preserving the selected baseline, cutoff, links, signatories, and operator reason.
- Handoff creation is replay-safe and all-or-nothing: the package, manifest, audit record, and command receipt are committed together.
- Readiness gates now record Go, Modify, Postpone, or Cancel decisions through named approval-participant choices and plain-language exceptions/rationale. The gate decision, state transition, audit entry, and replay receipt commit together, so operators never need to enter raw JSON or internal person identifiers.
- Gate review no longer shows an unused reviewer-assignment text field; the named approval-participant picker appears at the decision that records those approvals.
- Event Configuration proposals now start with a readable EMS record picker and named field changes, rather than internal record IDs or JSON patches. Proposed updates remain governed and are not attendee-visible until authorized application.
- File access and retention controls now use named planning roles and departments, plus retention and legal-hold choices, rather than typed policy lists. Changes remain audited and enforce the existing controlled-download boundary.
- File uploads now send their selected classification and retention period as a governed multipart command. Operators choose the file and readable controls; they are not asked to paste an EPS record ID or structured data.
- The Files register now shows actual version lineage and retention/hold status, with selected-file details for version history, encryption, checksum, and scan state. Storage locations remain hidden behind the authenticated download boundary.
- Reminder, gate-decision, and handoff registers now show human-readable planning-member labels instead of internal person identifiers.
- Notification destinations now save through a validated controlled command using readable delivery addresses/channels, subscriptions, quiet hours, and a write-only secret boundary. Invalid email routes and unsupported policy values are rejected before save.
- Project Settings now saves lifecycle, calendar/template choices, access roles, retention, and an operator reason through a versioned EPS command. Operators select readable records and roles instead of entering settings JSON or internal IDs.
- Meeting recurrence now uses readable repeat choices and an end date rather than a raw calendar-rule string. EPS derives the standards-compatible calendar value internally while preserving selected participants and reminders.
- Department ownership and reminder-policy choices now use readable scoped pickers. EPS continues to keep operational IDs and structured command data out of operator-facing forms.
- Meeting workflows include classified shared/confidential/facilitator notes plus draft/published/locked agenda revisions and pre-read deadlines. Published minutes remain immutable.
- Every route-specific primary, secondary, filter, comment/mention, RSVP, review, history, retention, handoff, and audit/export dialog is implemented in the shared desktop dialog/mobile sheet system. The New Department dialog opens blank and includes identity, charter, accountable lead, capacity model, and effective date.
- Email, Discord bot/webhook, and Telegram bot destinations use encrypted write-only secrets with test, rotation, revocation, routing, and durable delivery-history controls.
- Ordinary task, requirement, and meeting writes materialize bounded idempotent reminders; edits reschedule them, completion cancels them, personal subscriptions/channels/snooze/quiet hours are enforced, and terminal provider failures can follow configured escalation routes.
- Daily and weekly preferences now create real aggregated digest buckets rather than individual messages. The calendar export dialog offers iCalendar and JSCalendar; recurring meetings retain stable UIDs, sequences, and cancellation state.
- Requirement review now supports sequential and parallel approval stages, reviewer quorum, and submitter/reviewer segregation. Governed detail panels render threaded replies, reactions, and watcher controls.
- Settings now includes a fully designed preview-first bulk-import dialog for work, requirements, meetings, and risks. It validates up to 500 records, binds apply to the exact preview digest, commits one batch atomically, and preserves idempotent receipts.
- New schedule dependencies deterministically move affected successor dates through working-week, holiday, blackout, and working-day exception rules and audit the affected item set.
- Every upload uses Sanity through the authenticated Worker. Confidential or restricted bytes are encrypted before upload, Postgres keeps only metadata and opaque asset IDs, and no Sanity API/CDN URL is returned to clients.
- Uploaded bytes enter a durable scan queue. A scheduled authenticated Worker decrypts only server-side for the trusted HTTPS scanner, quarantines detections, retries failures, and withholds downloads until a clean result.
- Linked EPS and Event Management workspaces share the same canonical event, tiers, inclusions, add-ons, tier relationships, and Event Shop records. Planning proposals remain private until authorized application.
- The canonical linked view also projects Dealers Den packages, programme forms, volunteer departments/positions, and redacted payment-setup references without copying them into EPS.
Impact
Event directors and department teams can coordinate convention readiness in one pre-event system without duplicating EMS, Rego, Finance, or AMS records. EPS remains visibly labelled Preview while security and canonical-data boundaries remain mandatory.
Deployment Order
- Review and apply the pending EPS migrations in timestamp order. The current dry-run requires explicit
--include-allbecause local EPS and Finance migrations precede the remote migration tip. - Deploy
partners-api; configure the existing Sanity and notification secrets plusPLANNING_ARTIFACT_ENCRYPTION_KEY,PLANNING_NOTIFICATION_ENCRYPTION_KEY,PLANNING_MALWARE_SCAN_URL, andPLANNING_MALWARE_SCAN_TOKEN; then deploypartners.furries.ph. - Enable EPS for a non-production partner, verify one linked EMS event, and test encrypted upload/download plus Email, Discord, and Telegram destinations.
- Confirm that pending planning proposals remain absent from attendee-facing Rego until applied.
Validation
- Dashboard Astro diagnostics and static build pass; Worker TypeScript passes.
- EPS contracts certify the auth boundary, canonical EMS link and scoped forms, attendee isolation, notifications/digests, staged approvals, meetings/RSVPs/threaded comments, iCalendar/JSCalendar, immutable records, malware scan queue, and Sanity-only media policy.
- Browser evidence covers all ten routes and their primary/secondary/filter/comment/RSVP/bulk-import modals, plus the complete New Department dialog at desktop and 390px. Resilience evidence processes 10,000 work items, a 500-row import identity, and three reminder replays without duplicate logical sends. The production migration dry-run made no remote changes and reported the required migration-history reconciliation step.
AMS Certified Reference Policy
Repositories: partners.furries.ph, docs.furries.ph
Status: Ready for deployment review
What’s Changed
- AMS Finance now includes a readable and downloadable management-policy reference with all twelve economic decisions populated.
- The package includes owned-asset, third-party loaned-asset, and maintenance work-order examples plus an open JSON Schema and SHA-256 certification receipt.
- Safety controls identify the package as sample-only, omit an effective date, and prohibit production activation. Teams must clone, adapt, and independently approve a real policy with different proposer and approver identities.
- Fixed AMS tables and operation modals after navigation inside the persistent dashboard shell. Overview, registers, checkouts, transit, audits, maintenance, Logistics Hub, Finance, and Settings now initialize consistently after either a direct load or nested-sidebar navigation.
- AMS is now visibly labelled
Previewin its Workspace entry, AMS sidebar, and every AMS page header while operators evaluate the module. - AMS documentation now uses the same staged structure as Event Management: Foundations, Basics, Surfaces, Best Practices, Lifecycles, and Reference. Each of the ten AMS Workspace routes now has operator-facing guidance, with separate role, data, route, standards, and readiness references.
- AMS register suggestions now remain clear of adjacent fields, stack above surrounding form content, expose their autocomplete state, and dismiss consistently with Escape or focus changes. QR/barcode/NFC label generation also falls back safely to the canonical resolver when an identifier response is incomplete.
- Asset creation now includes in-context
New categoryandNew modelactions. Each opens a focused nested master-record dialog, records the signed-in operator through the existing AMS catalog API, and automatically selects the newly created record without losing the asset draft. - All ten AMS routes continue through the persistent dashboard SPA shell. The transient
?action=adddeep-link state no longer follows sidebar navigation, and Cancel/close controls work after direct loads and SPA transitions.
Impact
Asset and finance operators have a practical starting point instead of an empty policy packet, while auditors retain a clear boundary between certified software behavior and professional accounting decisions.
Validation
pnpm workspace-assets:certify:policy, dashboard diagnostics/build, and documentation diagnostics/build pass.- The 20-check AMS browser certificate covers direct loads, all ten primary route dialogs, nested category/model master-record dialogs on direct and SPA navigation, scanner and identity-label dialogs, mobile overflow, autocomplete spacing, the Finance reference-policy dialog, Add Asset query cleanup, and a real Overview → Checkouts SPA transition followed by opening and cancelling the checkout modal.