Updates
Platform Updates
Public-facing release notes for meaningful changes across Furries PH operational systems.
First created Last updated
Release Notes
EPS Complete Local Certification Gate
Repositories: partners.furries.ph, partners-api, docs.furries.ph
Status: Preview; local source and fixture certification complete, with database and hosted release gates still open
What’s Changed
- Added one repeatable EPS local certification command covering dashboard diagnostics and production build, EPS contract and resilience checks, Partner API type checking and domain certificates, and the full Playwright workflow suite.
- The resulting manifest records the suite outcomes and hashes of the captured visual evidence. The browser lane now uses its own local port so it cannot attach to an unrelated dashboard session.
Impact
- Event Planning changes now have a single local release-readiness check that verifies guided, human-oriented workflows across the dashboard and Partner API.
Validation
- All 14 local suites passed: dashboard diagnostics/build, EPS contract/resilience, API type and eight domain certificates, and the Playwright browser workflow suite.
Next Step
- Run the disposable Supabase/Worker lane and hosted authenticated evidence before production release. Docker or Podman is required for the local database lane and was not available on this workstation.
EPS Scoped Identity Presentation
Repositories: partners.furries.ph, docs.furries.ph
Status: Preview; locally implemented and certified, with deployment and external release gates still open
What’s Changed
- EPS now presents planning-member and canonical-event context with readable scoped labels in agenda, note, control, requirement, Settings, and event-configuration views.
- Internal record identifiers remain inside authorized system commands and are no longer used as normal operator-facing labels.
Impact
- Operators can understand ownership and event context without being asked to interpret internal identifiers.
Validation
- Dashboard diagnostics completed with zero errors and zero warnings.
- The complete EPS Playwright certificate passed after the presentation changes.
Next Step
- Complete identity search/display projections and real role-matrix validation before production release.
EPS Authoritative Risk Score Projection
Repositories: partners.furries.ph, partners-api, docs.furries.ph
Status: Preview; locally implemented and certified, with deployment and external release gates still open
What’s Changed
- EPS now receives the current risk score and scoring-policy identifier from the Partner API instead of calculating the score in the dashboard.
- The Risks register and planning overview display the published score, keeping the browser aligned with the policy used to assess event risk.
Impact
- Operators see a consistent risk priority across planning surfaces, and future policy changes can be introduced through the authorized server boundary.
Validation
- Dashboard diagnostics completed with zero errors and zero warnings.
- Partner API type checking passed.
- The complete EPS Playwright certificate passed with refreshed Risks route evidence.
Next Step
- Add persisted policy-version history and validate the projection against the applied database before production release.
EPS Reminder Destination Input Parity
Repositories: partners.furries.ph, docs.furries.ph
Status: Preview; locally implemented and certified, with deployment and external release gates still open
What’s Changed
- The EPS workspace overview now creates reminder destinations through individual delivery-type choices instead of a comma-separated policy field.
- Assignment, approaching-deadline, overdue-work, and meeting reminders are selected directly. EPS sends the corresponding bounded command internally, without requiring JSON or an internal identifier.
Impact
- Event operators receive the same clear, guided reminder-destination workflow from the overview and the dedicated Notifications area.
Validation
- Dashboard diagnostics completed with zero errors and zero warnings.
- The complete EPS Playwright certificate passed, including the overview destination HTTP 201 command assertion and desktop visual capture.
Next Step
- Verify provider delivery and durable readback in the applied database and hosted environment before production release.
Finance Design 2 Exact-Canvas Fidelity Pass
Repositories: partners.furries.ph, docs.furries.ph
Status: Preview; local implementation and visual certification complete, external release gates remain open
What’s Changed
- Finance Management was rechecked against all 14 approved Design 2 route boards and four modal boards at their exact 1487 × 1058 canvas.
- Desktop pages now follow the approved compact heading, filter, KPI, dense register, and contextual-detail layout more closely. Payables, Receivables, Budgets, and Close also include their route-specific aging, planning, and continuity summaries.
- Transactions, Outflows, Audit, and operational routes now preserve the approved page-spanning detail rails while keeping the primary ledger as the dominant work area.
- The Add Integration dialog now opens centered and bounded like the approved modal family instead of appearing at the top-left.
Impact
Finance operators receive a denser, more consistent desktop workspace that mirrors the approved management boards while retaining existing accounting controls, guided workflows, and responsive behavior.
Validation
- Exact-canvas browser evidence passed all 14 routes with one Finance navigation, one route heading, and no document-level horizontal overflow.
- The 144-page static build, Astro diagnostics, Tailwind contract, Finance route/modal inventory, accessibility checks, and complete local Finance accounting/API certificate passed.
Next Step
- Complete hosted authentication, provider sandbox, native restore, additional-browser, authenticated multi-role mutation, and independent-review gates before production release.
EPS Human-Oriented Tabletop Exercise Workflow
Repositories: partners.furries.ph, partners-api, docs.furries.ph
Status: Preview; locally implemented and certified, with deployment and external release gates still open
What’s Changed
- Event operators can now run a tabletop exercise from the EPS Risks workspace using named participant and observer choices, a scenario, timed-inject count, date, duration, and corrective-action preference.
- EPS creates the structured participant, observation, and timed-inject records internally. The workflow never asks an operator to enter JSON or internal IDs.
- The Partner API validates the resulting bounded exercise command before it is stored.
Impact
- Planning teams can document readiness exercises through a readable guided workflow and retain the resulting exercise record for operational follow-up.
Validation
- Dashboard diagnostics completed with zero errors and zero warnings.
- Partner API type checking passed.
- The complete EPS Playwright certificate passed, including the new tabletop-exercise HTTP 201 command assertion and desktop visual capture.
Next Step
- Run the same workflow against the applied database and hosted integration before production release.
Finance Design 2 Corrective Implementation Preview
Repositories: partners.furries.ph, partners-api, docs.furries.ph
Status: Preview; locally implemented and certified, with deployment and external release gates still open
What’s Changed
- All 14 Finance routes now have local approved-design route states, filters, detail views, and guided workflows. The browser evidence inventory covers Transactions, Outflows, Reconciliation, Events, Audit, Payables, Receivables, Expenses, Budgets, Close, Custody, Automation, Integrations, and Settings.
- Event Finance no longer divides a partner-wide balance in the browser to invent event figures. The Partner API now returns authoritative event-and-currency snapshots for inflow, outflow, book net, available cash, pending outflows, exceptions, reconciliation coverage, source, cutoff, and freshness.
- Finance administrators can create and maintain cash accounts through a guided Settings dialog. The API rechecks account-management capability, ledger ownership, and currency and prevents ledger, currency, or opening-balance changes once postings exist.
- Custody operators now enter denomination counts in guided peso rows with a calculated total. Raw denomination JSON is no longer part of the operator workflow.
- Reconciliation commit now requires the operator to review the evidence-package summary before the statement is sealed. A browser-entered evidence URL is no longer accepted as accounting proof.
- When recording a disbursement, operators now select an evidence file instead of entering an external URL. The dashboard sends the selected file through the Worker to the restricted journal-evidence vault after the authoritative posting succeeds.
- The local browser workflow now proves the checkout sequence end-to-end in a disposable fixture: lease acquisition, authoritative transition, lease release, and evidence-file upload. The row then presents its disbursed state and audit-trace action.
- Automation exposes a filterable routing matrix, job/detail views, test and run controls, and health metrics. Integrations distinguishes bank, accounting, and interchange connections and exposes health, sync, mapping, and guided connection states.
Impact
Finance operators can exercise the approved local workflows with clearer accounting ownership and fewer unsafe free-form inputs. Event totals now come from the server contract, cash-account changes carry posting safeguards, and custody totals are derived from explicit denominations. This is not yet a production-release declaration.
Upgrade Notes
No production operator action is authorized from this Preview entry. Complete the additive migration/RLS/query-plan review, Worker and dashboard deployment, authenticated real-stack canary, provider sandbox checks, mobile evidence, native restore, documentation walkthrough, and independent finance/security review before release approval. Preserve Sanity as the only uploaded-evidence store and expose only opaque artifact or authorized proxy references to clients.
Validation
- The dashboard static build completes for 144 pages. Finance inventory, accessibility, browser-evidence, resilience, calculation, mutation, deterministic contention, million-row volume, and logical-recovery certificates pass locally.
- The browser manifest covers 14 routes, 18 modal controls, five critical workflows, and six sanitized desktop screenshots. Fourteen dialog families and eight accessibility contracts pass.
- The API complete local certificate passes interchange checks, 40,000 property cases, 14 provider-contract cases, 15 operational-state cases, 24 security-hardening contracts, deterministic contention, million-row volume, logical recovery, and TypeScript validation.
- The dashboard Astro check has zero errors and warnings (with pre-existing repository hints only); Finance sources introduce no diagnostics.
- A Playwright fixture capture now verifies the Outflows accountable-disbursement dialog at 390px width as well as desktop. It shows the cash account, settlement reference, decision note, selected-file evidence control, and deliberate scrollable mobile layout. Real-stack mobile coverage remains a release gate.
AMS Corrective Evidence and Register Query Foundation
Repositories: partners.furries.ph, partners-api, docs.furries.ph
Status: Preview corrective work in progress; six database migrations and Worker configuration require controlled deployment
What’s Changed
- AMS evidence no longer uses Supabase Storage or returns signed provider URLs. Authenticated multipart uploads pass through the Partner API to Sanity; private and restricted bytes are encrypted before upload, queued for malware/MIME review, and unavailable until the scan is clean.
- Evidence metadata now records checksum, classification, encryption, scan state, retention, legal hold, version/supersession, and access history. Authorized downloads use an opaque Partner API content path; Sanity API/CDN locators remain internal.
- Owned and Loaned registers now use stable compound cursor pages with server-side search, category, location, lifecycle, condition, quality, and availability filters. Page size, opaque cursor, and filter state are restored from the URL.
- Personal saved views are partner/user/surface scoped, normalized for duplicate names, and versioned on update. Register export uses the authorized, schema-versioned AMS snapshot instead of serializing visible browser rows.
- Overview location, category, and condition filters are populated and functional. Asset rows show resolved master-data names, available book values, and a direct action into the correct owned/loaned register.
- The Playwright harness now waits for dashboard hydration, isolates its development port per process, and accepts query-bearing SPA URLs, so screenshots no longer capture the global loading mask or fail on correct URL state.
- Pending workflow requests now have a capability-filtered reviewer queue. A different authorized user can approve or reject with optimistic version control, idempotency, recent MFA/passkey step-up, versioned history, and a durable application receipt.
- Approved lifecycle disposition, external-owner return, overdue escalation, transit resolution, inspection/calibration, warranty claim, and bounded bulk move/status workflows apply atomically. Untyped finance-review proposals fail closed without completing the case.
- Private workflow drafts are now stored server-side by authenticated user, partner, route, and workflow. Drafts are versioned, size-bounded, expire within 30 days, restore into the form, and can be discarded without submitting or mutating an operational record.
- Finance proposals now select an authorized owned asset, active accounting book, open period, and active policy. A different
finance_approveuser can approve the typed debit/credit proposal; approval atomically posts the append-only value entry and returns a durable receipt. Rejection and idempotent replay remain state-safe. - Identity, custody, depreciation, and permissions policies now use typed versioned documents. Authors submit a draft for a different authorized reviewer to approve or reject; approval atomically activates one version, supersedes the previous active policy, and returns a durable activation receipt.
- Add Owned Asset and Add Loaned Asset now save, restore, and discard actor-scoped server drafts. Restored entity references are checked against the caller’s current authorized catalogue, location, party, and agreement choices before they can be submitted.
- Checkouts, Transit shipments, Audits, and Maintenance work orders now use bounded server pages with exact totals and stable timestamp-plus-ID cursors. Search, status, page size, page number, and opaque cursor state remain in the URL; Previous and Next read authoritative pages instead of slicing a capped browser snapshot.
- Audit reviewers, checkout custodians, and Hub assignees now come from an active-partner, capability-filtered user endpoint. The dashboard shows names, roles, and eligibility while retaining immutable user IDs internally; the signed-in audit maker is not offered as their own independent reviewer.
- Finance Book, Basis, Currency, and As-of controls now query the authoritative rollforward, remain in URL state, preserve selections through refresh, and clear together. Gross cost, accumulated depreciation, impairment, and carrying amount use the filtered rows and explicitly show currency and as-of context.
- Logistics Hub tasks, dock appointments, quality holds, replenishment rules, and continuity runs now use authoritative bounded registers with stable timestamp-plus-ID cursor paging, exact totals, record-appropriate filters, named linked data, and URL-restorable page/filter/
hubViewstate. Exact Hub summaries keep KPIs, flow cells, and attention signals consistent with the full registers rather than the visible page. - Controlled movement, quantity, return, receipt, exception, audit, maintenance, warranty, and Hub-assignment workflows now select named authorized locations, parties, agreements, users, and live scoped Hub tasks instead of asking operators to type raw IDs. Bulk assignment supports multiple named tasks, row actions preselect the exact task, and drafts preserve the complete selection. Submitted records retain immutable IDs, unavailable authorization data blocks the choice, and reviewer/approver choices exclude the signed-in actor.
- Hub assignment is one all-or-nothing database command rather than parallel browser requests. Certification proves rollback when one selected task is invalid, successful assignment at the 100-task limit, and rejection of a 101-task request; every accepted task receives its own actor-attributed history event.
- Migration
20260814005001_workspace_asset_bulk_hub_assignment.sqlis locally certified and is the only item reported by the linked-project publish dry-run. The dry-run made no remote change; deployment and hosted readback remain part of the normal reviewed release. - Settings location, Category/Model, party, and agreement registers now use exact authoritative totals, bounded server search/status filters, stable cursor paging, page-size controls, and URL-restorable navigation. New master record creates governed categories, models, locations, external owners, and custody agreements with only the applicable relationship fields shown.
Impact
Asset operators gain reliable register paging/filter restoration, a protected evidence boundary, private expiring workflow and asset-intake drafts, and independent request-review-application paths. Operational, finance, and policy submissions remain pending until a different authorized reviewer acts; approvals apply atomically with durable receipts.
Upgrade Notes
Apply migrations 20260813234500_workspace_asset_sanity_evidence.sql, 20260813235500_workspace_asset_saved_views.sql, 20260814001001_workspace_asset_workflow_decisions.sql, 20260814002001_workspace_asset_workflow_drafts.sql, 20260814003001_workspace_asset_finance_workflow.sql, and 20260814004001_workspace_asset_policy_lifecycle.sql in controlled order. Configure the Worker evidence encryption key and malware scanner endpoint/token before enabling uploads. Do not deploy this Preview slice as a final AMS release until the remaining route/control depth, role/accessibility/conflict/scale tests, visual parity work, and hosted canaries pass.
Validation
- Astro diagnostics pass with zero errors.
- The API certificate passes 115 required route contracts and 80 database commands; TypeScript, EPCIS mapping, encrypted evidence round trip, internal image upload, provider-locator guard, no-upstream-URL checks, authoritative audit/work-order/transit/Hub-task/Hub-companion/Hub-summary/Settings contracts, governed policy lifecycle/capability reads, authorized user choices, scoped workflow drafts, typed finance, atomic workflow decisions, atomic Hub assignment, and exact OpenAPI inventory parity pass.
/api/assets/openapi.jsondeclares OpenAPI 3.1/JSON Schema 2020-12 and covers all 126 mounted AMS operations, including shared command registrations; remaining route-specific mutation schemas are not yet final. - The disposable database certificate passes 19 ordered AMS migrations, 72 RLS-enabled tables, all supported typed workflow branches, actor-scoped expiring drafts, typed finance maker-checker posting/replay, typed policy submit/approve/reject/replay, rejection history, and append-only value-entry behavior.
- Production-static Playwright certification passes 77 functional checks across all ten AMS routes and records 104 route, modal, scanner, query-control, specialist/Hub-task/Hub-companion/Settings server-paging, authoritative Hub-summary, accessible dialog/tab, governed master creation, authorized named-entity/task/reviewer, qualified-finance-filter, draft restoration, policy submission/activation, finance proposal/reviewer receipt, governed-settings, specialist-register, and responsive captures with clean console health. It verifies zero axe WCAG A/AA violations, visible control names, form labels, duplicate IDs, tab selection/arrow-key behavior, dialog focus containment/restoration, a named/focusable Settings record region, compliant muted/orange text contrast, and mobile overflow. These are fixture smoke/regression results, not manual screen-reader, real-stack role, final visual, or hosted sign-off.
Dashboard and Regosite Loading Performance
Repositories: partners.furries.ph, rego.furries.ph, docs.furries.ph
Status: Implemented and locally validated; deployment required
What’s Changed
- Shared layout, loader, notice, and dialog startup modules now remain mounted during SPA page switches instead of executing again for every fetched page. Page-specific scripts continue to remount normally.
- The dashboard and regosite keep their SPA scene registries ready with the persistent shell, avoiding a deferred module pause on the first page switch. Diagram rendering, analytics, SPA-contract warmup, and other background account checks remain outside the first useful render where safe.
- Fetched page documents remain available for 10 minutes across up to 48 routes. Same-area dashboard switches also preserve stable sidebar chrome instead of repeating profile and partner-scope hydration.
- Concurrent identical read requests are shared while in flight. The dashboard also reuses its access snapshot briefly during auth boot, avoiding repeated scope lookups.
- The regosite events page now ships a current build-time event snapshot, so event cards can appear immediately while the live events API refreshes in the background.
- Production builds mark bundled Astro modules as exempt from Cloudflare Rocket Loader after bundling, preventing duplicate module downloads without sacrificing Astro/Vite optimization.
Impact
Attendees should see the event list sooner, and dashboard operators should see near-instant page transitions without repeated shell startup work. Navigation and data freshness behavior remain unchanged.
Upgrade Notes
No operator action or database migration is required. Deploy fresh static builds of both sites to publish the performance changes.
Validation
- Astro diagnostics pass with zero errors in both repositories.
- Production builds complete successfully in both repositories.
- Local browser tracing found zero duplicate Astro module requests. The regosite events page reached first content at 116 ms with 18 requests and 105 KB transferred in the local production-artifact preview, with no console errors.
- A dashboard production-artifact trace measured 12 EPS route switches at 17-41 ms (26 ms average). Shared shell modules loaded once while each route’s own script still remounted.
EPS Authenticated Schedule Refresh
Repositories: partners.furries.ph, partners-api, docs.furries.ph
Status: Preview; locally verified, with a database migration pending deployment
What’s Changed
- EPS Schedule now leads directly with its designed Gantt workspace instead of a KPI block, keeping the timeline, filters, views, and planning controls in the first working screen.
- The Planning workspace delivery-history query now scopes notification attempts through their immutable reminder record. This matches the published planning schema and restores authenticated workspace loading without duplicating project fields in the delivery outbox.
- Local dashboard development sign-in accepts the dashboard preview origin, so operators can refresh an EPS route and immediately continue in the authenticated workspace.
- EPS workspace registers now provide keyboard-accessible tabs and row actions, real page-size/previous/next controls, authorized department filters, and URL-restored view state. Draft-capable requirement, meeting, and event-configuration operations now send draft intent separately from their commit action.
- Core planning registers now load through an authorized bounded bootstrap and stable server-cursor pages instead of slicing a capped browser snapshot. Schedule Table, Requirements, Meetings, Risks/Issues/Decisions, and Controls preserve a fixed result cutoff while paging; their search, status, department, kind, and due-date filters run before the API limit.
- The Gantt now reads a bounded authorized schedule window from the Partner API. Critical markers, cycle detection, early/late offsets, total float, and latest approved-baseline variance come from the server projection instead of being inferred independently in the browser.
- Dependency creation now uses a closed versioned command with an idempotency key. A pending database migration makes dependency insertion, affected schedule dates, item/project version increments, audit evidence, and the replay receipt one indivisible transaction.
- Schedule Workload now reads a bounded server projection. Weekly department capacity respects active membership dates and project allocation percentages; assigned effort is reconciled across the visible window, while over-capacity, no-capacity and unestimated work remain explicit.
- Requirement responses now distinguish Save draft from Submit using an optimistic, idempotent command. The response revision, optional evidence link, requirement state/version, audit record and replay receipt commit together, preventing a partially saved response.
- Requirement review now applies the same transaction boundary to active-stage reviewer eligibility, quorum and segregation-of-duties checks, the immutable review decision, submission/requirement state, audit evidence and replay handling.
- Approval-flow configuration now replaces undecided sequential or parallel review stages atomically with optimistic conflict protection, replay safety, reviewer/quorum/expiry validation and correlated audit evidence. Operators use ordered stage cards with reviewer choices, quorum, expiry and segregation controls; no raw JSON is entered.
- EPS notification policies now use channel/subscription choices, quiet-hour time inputs, destinations and escalation delay controls. Bulk planning import now accepts a CSV spreadsheet export, previews it, then applies the exact confirmed preview atomically; raw JSON input is prohibited across EPS.
- Notification delivery and artifact scanning now use atomic database claim leases. Expired work can be recovered, stale workers cannot finalize a newer claim, and terminal scan failures enter a dead-letter state for accountable repair.
- Meeting minutes now use a planning-member attendance choice and plain-language notes, then record discussion, decisions, and generated EPS follow-up tasks as one versioned, replay-safe action. If any minute or follow-up task is invalid, nothing from that save is recorded; retrying the same save returns its original result.
- Requirement templates now create their current matching assignments together with the template. A failed setup leaves no partial assignments, while draft templates remain unassigned until activated. Template reviewers are selected by name instead of entering an identifier.
Impact
Planning teams can refresh and review a populated event schedule in the local preview without a missing-project state or an outbox schema error. Delivery records remain scoped to the same project through their reminder relationship.
Upgrade Notes
Apply the pending planning job-lease migration before deploying the updated Partner API workers. This remains Preview; production rollout still requires the normal controlled deployment and canary process.
Validation
- Astro diagnostics pass with zero errors.
- The API type check passes.
- Authenticated in-app-browser QA confirmed a real planning project, 16 representative schedule records, and the refreshed Gantt workspace.
- Playwright confirmed persistent-shell portfolio → overview → schedule navigation, semantic tab behavior, two-page schedule controls, authorized department metadata, and desktop/390px captures. The EPS fixture regression gate also passes ten routes and its designed workflow families.
- Authenticated Playwright confirmed a 10-record first Schedule page and distinct 6-record second page, with an opaque cursor in the URL and exact browser Back/Forward restoration. The API pagination model also reached all 834 authorized rows from a 1,200-row data set exactly once across stable 37-row pages.
- The schedule projection certificate passes its 366-day window boundary, authorization-before-limit, deterministic dependency graph, critical/float, cycle, and baseline-variance cases. Authenticated local readback returned the real 16-record schedule window, and refreshed desktop/390px Gantt evidence contains no runtime errors.
- The dependency transaction certificate passes commit, rollback, replay, digest-conflict, optimistic-conflict, strict-schema and service-role privilege cases. Playwright submitted the populated dependency form with a project version, signed lag and idempotency key and received HTTP 201; the complete EPS route/workflow suite still passes.
- The workload certificate passes bounded-window, authorization-before-limit, allocation-capacity, effort-reconciliation and unestimated-work cases. Desktop and 390px Playwright assertions cover 125% utilization, no capacity and explicit unestimated counts from the server projection.
- The requirement transaction certificate passes commit, evidence-link, rollback, replay, digest-conflict, optimistic-conflict, strict-schema and service-role privilege cases. Playwright submitted the populated declaration form with explicit submit intent, requirement version and idempotency key and received HTTP 201.
- Staged-review certification also passes two-reviewer quorum progression, unauthorized/segregation rollback, stale-version rollback and duplicate-replay protection. Playwright selected a submitted revision, issued the strict review command and received HTTP 201; sequential shared-dialog actions remain usable.
- API type-check and the new worker-lease concurrency certificate pass, covering non-overlap, lease expiry recovery, stale-token rejection, retry timing, and dead-letter exclusion. Applied-database and provider-sandbox evidence remain open.
- The meeting transaction certificate passes commit, full rollback, stale-version rejection, idempotent replay, payload-conflict rejection, published-content validation, audit, and service-role boundary cases. Playwright observed a populated minutes form creating two follow-up tasks with HTTP 201 and captured desktop/390px evidence. The migration is pending the normal controlled deployment; no production database write was attempted.
- The template transaction certificate passes active assignment, draft isolation, rollback, replay, conflict, audit, service-role, and OpenAPI cases. Playwright submitted the populated template form as a strict HTTP 201 command and captured the reviewer-picker dialog. The migration remains pending controlled deployment; no production database write was attempted.