Updates
Platform Updates
Public-facing release notes for meaningful changes across Furries PH operational systems.
First created Last updated
Release Notes
Partner Finance Hub Foundation
Repositories: partners.furries.ph, partners-api, docs.furries.ph
Status: Ready for deployment review; migrations required
What’s Changed
- A new partner-wide Finance hub consolidates posted accounting activity from every event while preserving each event reference and drill-down scope.
- Finance now uses an AMS-style nested management workspace with dedicated Overview, Transactions, Outflows, Reconciliation, Events, Audit trail, Automation, Settings, Payables, Receivables, Expenses & advances, Budgets & forecasts, Close & assurance, and Integrations pages, plus focused creation and action dialogs with responsive layouts.
- The hub distinguishes available cash, money in, money out, pending outflows, unreconciled differences, event coverage, cash accounts, and complete journal lines instead of presenting one ambiguous total.
- Authorized operators can post partner-wide or event-specific income, expenses, and cash transfers through a balanced-entry form; server-side account, currency, event, and open-period checks prevent malformed postings.
- Authorized reviewers can download a bounded UTF-8 journal export using the same optional event scope as the dashboard; every export records its actor, cutoff, scope, and row counts in the audit trail.
- Partner-wide entries can be allocated across owned events with exact reconciliation and immutable version history; posted mistakes are corrected with balanced linked reversals rather than edited in place.
- Reconciliation now follows a preview-first statement workflow with row validation, source digests, a different signed-in reviewer for commit, immutable committed rows, per-account coverage, and audited soft close, hard close, and reopen controls.
- Outflow requests bind the signed-in requester and authoritative server time, require independent approval, use optimistic version checks, and produce immutable action receipts and audit events.
- Finance decisions now acquire a short renewable checkout for the signed-in team member; competing users are locked out, the lease is rechecked inside the same transaction as the decision, and the activity trail shows acquisition, action, and release times.
- Payables, receivables, procurement, expenses, cash advances, budgets, forecasts, close checklists, and audit findings use a common event-aware subledger with maker-checker transitions, immutable final states, and accountable checkout.
- Cash boxes and drawers record signed-in opening custody, movements, count-based handover independently acknowledged by both parties, closing variance, and separate supervisor review.
- Evidence metadata is content-addressed with SHA-256, retention and legal-hold state, immutable history, and purpose-bound access records.
- Versioned ISO 20022 statement, UBL 2.3 document, XBRL GL, and SAF-T-style adapters preserve canonical IDs, event scope, currency, source drill-down, and original provenance; integration health and continuity reconciliation controls appear in the hub.
- Partner defaults and event-specific inherit, override, or disabled routing can send inflow and outflow updates to verified Telegram topics and Discord channels or threads.
- Finance administrators can define default payment accounts once for the partner. They are copied to every current and future event checkout; editing an inherited event account creates a local override so later partner changes do not erase event-specific setup.
- All Finance dialogs now use a centered responsive presentation. The settings workflow explains inheritance, availability, limits, account identifiers, and the signed-in audit trail without requiring operators to repeat setup event by event.
- Telegram and Discord disbursement buttons accept only one active linked dashboard identity with current finance authority; provider identity, names, group roles, and forwarded payloads do not grant permission.
- Notification delivery uses a transactional outbox, bounded retries, quarantine state, one-time opaque actions, and scheduled processing so a provider failure cannot alter or duplicate a ledger transition.
Deployment Order
- Apply the Finance migrations from
partners.furries.phin timestamp order, including20260813230000_partner_finance_default_payment_accounts.sqland20260813231000_partner_finance_security_hardening.sql. Apply only the pending forward migrations reported by the dry run. - Configure the Discord interaction public key and existing bot/webhook secrets, then deploy
partners-api. - Deploy
partners.furries.phand verify finance access for one non-production partner. - Configure test partner and event destinations, confirm the non-financial verification messages, then exercise request, approval, disbursement, and inflow posting paths.
Validation
- The disposable database certification passes the finance invariants across service-only finance tables, covering balanced posting and reversal, immutable journals/imports/allocations/evidence, tenant isolation, idempotency, maker-checker, accountable checkout, custody handover, close/reopen, control bootstrap, continuity reconciliation, outbox commit, version conflicts, and receipts.
- The local audit also passes an independent exact-money oracle, seeded mutation detection, 40,000 property cases, deterministic 16-actor contention, a 1,000,000-line performance fixture, logical restore/reconciliation, route/API inventory, and static dialog accessibility checks.
- Worker TypeScript, dashboard Astro diagnostics/build, standards interchange, and desktop/mobile visual evidence pass locally. The complete gate intentionally remains pending until hosted migration/canary, authenticated Telegram and Discord provider tests, native backup/restore, cross-browser state coverage, and independent review are supplied.
- In-app-browser checks opened all 17 tested Finance modal entry points, saved a partner-default payment account through the real form, and navigated all 14 Finance routes while retaining the persistent dashboard SPA shell. Centering assertions cover all 12 Finance dialog types.
Event-Specific Feedback Forms
Repositories: partners.furries.ph, partners-api, rego.furries.ph, docs.furries.ph
Status: Ready for migration and deployment
What’s Changed
- Every event can now maintain a draft and explicitly publish a versioned feedback form based on the previous CebuFurs seven-category experience.
- Attendees get a responsive
/:eventSlug/feedbackflow with anonymous-by-default answers, optional consented follow-up contact, safety guidance, draft recovery, review, and receipts. - Authorized operators can filter, review, annotate, triage, explicitly hand off, archive, and export event-scoped responses.
- The dashboard feedback-form setup screen now replaces its loading state with a focused, actionable error when event context, authentication, the API, or feedback storage is unavailable.
- Feedback categories now start collapsed, support card-level drag ordering, and use the same draggable collapsed question/section editor as Rego Config, Activities, and Human Resources.
- Published form versions and response schemas remain immutable; browser database roles have no direct feedback-table access.
Deployment Order
- Apply
20260812172006_event_feedback_system.sqlfrompartners.furries.ph. - Deploy
partners-api. - Deploy
rego.furries.ph, thenpartners.furries.ph. - Verify a draft, preview, publication, anonymous submission, receipt, triage update, note, and filtered CSV in a non-production event before enabling a live form.
Validation
- Worker TypeScript, both Astro applications, documentation checks, production builds, migration listing/dry-run, and desktop/mobile browser evidence are required release gates.
Asset Management System Foundation
Repositories: partners.furries.ph, partners-api, docs.furries.ph
Status: In development
What’s Changed
- A new standalone Asset Management System (AMS) separates Owned Assets from Loaned Assets held in FPH care.
- The first dashboard workspaces cover registers, checkouts, transit, audits, maintenance, finance, and settings through EMS-style nested navigation.
- The certified foundation records server-derived actors, immutable movements, QR/Code 128/Web NFC carriers, partial returns, reservations/transfers, audit and maintenance lifecycle, bulk container transit/exceptions, RLS isolation, and maker-checker economic entries.
- Deterministic economics now cover currency, component replacement, prospective estimate changes, full depreciation schedules, NRV, impairment, inventory costing, TCO sensitivity, disposal, hard close, and external journal receipt reconciliation.
- Mature hub controls now include assigned work, quality holds, dock state transitions, automatic min/max replenishment tasks, and RTO/RPO continuity exercises.
- Audit closeout now documents blind counts, independent recounts, immutable variance posting, audit packs, and recovery; finance teams also have a formal policy-approval record for the remaining accountable sign-off.
- Every AMS route now follows the Overview visual language with contextual metrics, searchable registers, and consistent button-launched operation dialogs. Known assets, locations, parties, catalogue entries, and agreements autocomplete with identifying detail; a shared camera QR/barcode, Web NFC, and manual resolver replaces prompt-based scanning.
- EPCIS ObjectEvent/AggregationEvent fixtures pass GS1’s official 2.0.1 JSON Schema, every mapped CBV term resolves in the normative ontology, and sensitive exports/configuration require recent MFA/passkey step-up.
Impact
Partner teams can review the organization-scoped property model without coupling it to events, reports, or Pawsports. Migration/deployment and production-scale/recovery acceptance remain separate release gates.
Validation
- Database invariants pass across 62 RLS-enabled AMS relations and 12 ordered migrations, including transit recovery, hub orchestration, economics, CSV imports, private evidence, alerts, EPCIS mapping, and transactional webhook outbox. Disposable resilience certification also passes a 500-scan burst, 1,002-asset snapshot, no-oversell contention, concurrent idempotency, and zero-loss checkpoint restore.
- The Worker certifies 87 authenticated route contracts and 67 server-side commands, the official GS1 schema/ontology gate, recent-AAL2 controls, and TypeScript.
- Dashboard and documentation Astro checks pass with zero errors; the repeatable AMS browser certificate passes 14 checks across all ten route/modal surfaces, rich autocomplete, deep links, scanner state, console health, and 390 px overflow.
Event Management Moved to `/ems`
Repositories: partners.furries.ph, docs.furries.ph
Status: Ready for deployment
What’s Changed
- The dashboard event list is now the EMS landing page at
/ems. - Event creation and all event-management pages now use
/ems/...paths. - The old
/regooverview and/rego/regoscross-event list were removed. - EMS now uses the dashboard root navigation directly instead of an extra one-item Events panel; authenticated event-management pages link back to EMS.
Impact
Partner teams now enter event operations through one EMS route hierarchy. Saved links to the former Rego dashboard paths must be updated.
Validation
- Dashboard route manifests, navigation targets, certification route lists, source documentation, and operator documentation were updated to the
/emshierarchy.
Clearer Rego Navigation
Repository: partners.furries.ph
Status: Ready for deployment
What’s Changed
- Rego’s Overview navigation item now activates only on the Overview screen. Events, registrations, and event-management pages show one clear current destination.
Impact
Partner teams can tell where they are in Rego navigation without two entries appearing selected.
Validation
- Authenticated local browser QA confirms Events is the only active Rego root item and has the sole
aria-current="page"value.
SMS Blasts App and Website Reliability
Repositories: partners.furries.ph, fph-lan-ems
Status: Ready for deployment
What’s Changed
- The Android wrapper now publishes its complete SMS gateway bridge contract, including capability checks, service control, job submission, and delivery-event draining.
- SMS Blasts can request required Android permissions in place and direct denied permissions to app settings.
- Normal website browsers retain the same campaign composer and can queue through a verified online Android app without exposing native-only controls.
Impact
Partners can start and operate SMS Blasts from the Android app, while desktop website operators can compose, queue, monitor, and retry campaigns routed through that linked app.
Validation
- SMS dashboard certification, rendered website/app smoke tests, EMS LAN diagnostics/build, Android debug build, and Android SMS gateway certification pass. The dashboard-wide diagnostic currently retains unrelated Asset Register typing errors outside SMS Blasts.
Clearer Sign-in Errors
Repositories: partners.furries.ph, rego.furries.ph
Status: Ready for deployment
What’s Changed
- Failed password, passwordless, passkey, recovery, and invite attempts now keep their specific validation message instead of incorrectly saying that a session expired before sign-in.
- Genuine expired authenticated sessions still sign out safely and return people to the sign-in page.
Impact
Attendees and dashboard operators receive actionable sign-in feedback and can distinguish an invalid credential from a session that actually expired.
Validation
- Dashboard sign-in was exercised against a simulated HTTP 401 credential failure; the UI displayed “Invalid login credentials.”
- Dashboard Astro diagnostics and Regosite production build pass.
Clearer Pawsport Reassignment and Form Building
Repository: partners.furries.ph
Status: Ready for deployment
What’s Changed
- Pawsport reassignment now separates the current holder, replacement attendee, required audit reason, and final confirmation into a clearer review flow.
- Registration and activity form-builder elements use simpler flat rows and dividers instead of nested card and pill treatments.
- Collapsed activity cards keep the activity title visible, including unsaved title edits.
Impact
Pawsport administrators can verify exactly which account is changing before confirmation, while event operators can scan and edit long activity forms with less visual clutter.
Validation
- Desktop and 390px mobile browser checks pass with no horizontal dialog overflow or console errors.
- Pawsport and dashboard-interaction certifications pass, and Astro diagnostics report zero errors.
More Informative Event Cards
Repository: rego.furries.ph
Status: Ready for deployment
What’s Changed
- Event cards now show the organizer logo and name, a concise event summary, venue, event dates, registration end date/time, pricing, and registration availability.
Impact
Attendees can compare upcoming events from the event index before opening an individual event page.
Consistent Dashboard Ordering and Disclosures
Repository: partners.furries.ph
Status: Ready for deployment
What’s Changed
- Activity forms and Pawsport sticker definitions now use the same double-grip drag ordering as registration inclusions instead of Up/Down arrows.
- Shared question and section editors now use the same labelled chevron expand/collapse control as HR departments.
- Pawsport reassignment confirmations use the browser top layer so the confirmation remains above the reassignment dialog.
Impact
Event operators get one predictable ordering and disclosure language across configuration screens, and reassignment confirmation is no longer obscured by its parent dialog.
Validation
- Dashboard interaction, Pawsport, Event Shop, and forecasting certification pass.
- Astro diagnostics report zero errors and the production build generates 107 pages.