Anmelden

Changelog

Current version: v0.7.7 (df8397e)

All notable changes to app-platform are documented here.

The format follows Keep a Changelog, and this project uses Semantic Versioning.

[0.7.7] - 2026-07-30

Fixed

  • Showroom Workbench tables now keep component identities, release status,

migration details, and actions readable without horizontal scrolling at supported desktop widths.

  • Contract preview selectors are visibly labelled, and technical and evidence

values wrap instead of being clipped.

[0.7.6] - 2026-07-30

Fixed

  • Staging deployments now keep the SigNoz MCP observability sidecar stable and

report container OOM/restart evidence when its liveness gate fails.

[0.7.5] - 2026-07-30

Fixed

  • Showroom headings and current-status badges now remain readable in both themes.
  • Workbench filters are visibly labelled and catalog rows expose their complete values and actions.
  • Anonymous Workbench visits now reach the centralized sign-in page instead of a blank response.

[0.7.4] - 2026-07-30

Added

  • The internal platform API now provides the dormant, append-only activation

ledger for the GitHub control plane. It separates deployment and runtime identities, enforces approved candidate and rollback sequencing, and permits recovery only after completed rollback proof. No organization-wide GitHub routing or production activation is enabled.

[0.7.3] - 2026-07-30

Fixed

  • Golden Sample replay now validates the rendered component while the Validate tab is open.

[0.7.2] - 2026-07-29

Fixed

  • The Showroom now focuses its navigation on Discover, Contract, and Migrations.
  • Reviewers can open each preview from the navigation and use its Radzen-based

review actions directly.

  • Signed Golden Sample links continue to open the exact approved preview.

[0.7.1] - 2026-07-29

Fixed

  • Workbench review-link manifests now use stable camel-case field names.

[0.7.0] - 2026-07-29

Added

  • Added three staging/development-only compiled Design Workbench draft previews

for Discover, Contract, and Migrations. Every visible draft element is composed from Radzen Blazor components.

  • Added private, time-boxed reviewer links tied to a specific draft and

deployment. Draft previews remain disabled by default, unavailable in production, and cannot create review access from the Workbench UI.

[0.6.31] - 2026-07-24

Fixed

  • Staging deployments now validate GitHub workflow access through the supported

read-only integration.

[0.6.30] - 2026-07-24

Fixed

  • The theme toggle in the shell header now announces its action in German

("Zum hellen Modus wechseln" / "Zum dunklen Modus wechseln") when the platform is used in German, instead of always announcing in English.

  • The DE/EN language-switch buttons in the shell header now expose a clear,

localized accessible name ("Deutsch" / "English") to screen readers and other assistive technology.

[0.6.29] - 2026-07-24

Changed

  • The pattern catalog's trait-control reference card now links to the live

interactive dot and box control exhibit instead of describing it as a planned placeholder.

[0.6.28] - 2026-07-24

Fixed

  • The staging GitHub integration now declares its approved read-only

repository-content and issue-metadata permissions, allowing the control plane to validate the least-privilege deployment boundary.

[0.6.27] - 2026-07-24

Fixed

  • The staging GitHub integration now starts with its approved repository and

permission boundaries and loads its control-plane credential from the dedicated security scope, restoring authorized agent reads while preserving fail-closed behavior.

[0.6.26] - 2026-07-23

Fixed

  • Loading placeholders now show the full set of shimmering lines they were meant

to, instead of a single line, so a screen that is still fetching content gives an honest impression of how much is on the way. This affects the app catalog and app details pages, My Apps, plan management, the interactive tour page, the app switcher, the admin operations and theme screens, the theme editor and deactivation dialogs, and the design showroom.

[0.6.25] - 2026-07-23

Added

  • The agent audit log now shows tool discovery as well as tool calls. When the

platform refreshes the set of observability tools it offers to agents, the log records the upstream address, the environment, and how many tools were found — and records it again when that upstream stops answering or comes back. An entry is written only when the outcome or the tool set actually changes, so the routine one-minute refresh cycle does not bury the calls and denials an operator is looking for.

[0.6.24] - 2026-07-23

Fixed

  • Filtering the MCP audit log by an agent identity now lists that agent's

activity. Governed tool calls and refusals are recorded against the identity that made them, so a filtered view shows the agent's events instead of coming back empty as though nothing had happened, and the agent's display name is still shown alongside each event.

[0.6.23] - 2026-07-23

Fixed

  • Alerts across the admin and showroom pages now display their severity colour

and icon — error alerts appear red with an error icon, warnings amber, information blue, and success green — instead of a neutral grey box with a generic icon.

[0.6.22] - 2026-07-21

Security

  • Updated a bundled .NET cryptography component to a patched release, addressing

a high-severity denial-of-service advisory (CVE-2026-50648). No configuration or migration steps are required.

[0.6.21] - 2026-07-17

Fixed

  • Restored the packaged light and dark theme colours on the offline theme path,

so apps show the same palette and keep button labels readable when the theme service cannot be reached.

[0.6.20] - 2026-07-14

Fixed

  • Kept Showroom state and viewport controls readable across dark-mode validation

views.

[0.6.19] - 2026-07-14

Fixed

  • Kept the Showroom ThemeCssProvider exhibit readable in dark mode across its

explanatory text and packaged theme samples.

[0.6.18] - 2026-07-14

Fixed

  • Switched the Showroom ThemeToggle exhibit and shell action to the canonical

AppPlatform.Theming implementation so dark-mode accessibility evidence covers the same component used by the platform shell.

[0.6.17] - 2026-07-13

Fixed

  • Kept the Showroom appearance switch readable inside review previews.

[0.6.16] - 2026-07-13

Fixed

  • Kept Showroom design sample rows readable in dark mode while preserving the

packaged theme examples.

[0.6.15] - 2026-07-13

Fixed

  • Improved contrast in Showroom theme examples when dark samples appear inside

a light page.

[0.6.14] - 2026-07-13

Fixed

  • Made Identity Administration user search and detail navigation work through

durable browser requests so operators are not left with an empty grid when the live circuit reconnects during staging validation.

[0.6.13] - 2026-07-13

Fixed

  • Restored the identity administration user-detail action workspace so operators

can see the guarded account, role, two-factor, credential, and session actions.

  • Made the staging validation open the searched account row instead of a stale

visible result after filtering.

[0.6.12] - 2026-07-13

Fixed

  • Made the authenticated account menu use native browser disclosure behavior so

the Identity Administration entry remains reachable from staging home even if Blazor Server interactivity is delayed after sign-in.

[0.6.11] - 2026-07-13

Security

  • Hardened MCP gateway authentication so invalid agent credentials are rejected

before any tool names or policy states are returned.

  • Preserved denied-credential response status semantics while keeping MCP tool

discovery fail-closed.

[0.6.10] - 2026-07-13

Fixed

  • Improved the Identity Administration account-menu flow for authorized

operators so the console launch remains stable after sign-in.

  • Kept identity administration hidden from ordinary authenticated users while

preserving the authorized operator entry.

[0.6.9] - 2026-07-13

Fixed

  • Improved Operations dashboard route stability so quick navigation no longer

exposes a runtime error state during operator validation.

[0.6.8] - 2026-07-13

Fixed

  • Made staging admin seeding fail loudly if the well-known admin cannot be

backfilled with IdentityAdmin, so a green seed run now proves the account can reach the canonical Identity Administration console.

  • Added post-deploy browser proof for the identity-admin console from staging

home navigation, covering the account-menu entry, user search/detail, audit, posture, and non-admin nav absence.

  • Improved Showroom theme previews so dark-mode examples remain readable.

[0.6.7] - 2026-07-13

Changed

  • Rehomed operator user management under the Identity Administration console so

user search and account-management review live in the dedicated identity operations workspace.

  • Retired the old broad-admin user-management API surface with deprecated

responses so identity user management follows the narrower identity-admin access model.

Fixed

  • Added a real access-denied state for unauthorized identity administration

navigation instead of presenting a missing-page experience.

[0.6.6] - 2026-07-13

Added

  • Added a staging-only internal endpoint that clears out the disposable test

accounts left behind by the hourly staging health check, so the identity store, user counts, and admin console stay free of automation clutter.

Fixed

  • Fixed the unbounded build-up of throwaway sign-up test accounts on staging by

removing them automatically after each health-check run and clearing the existing backlog. Production is never affected.

[0.6.5] - 2026-07-13

Security

  • Hardened staging sign-in by retiring the older shared symmetric signing

method, so staging now relies solely on stronger asymmetric signing. No user-facing change; production is unaffected and keeps its current signing.

Fixed

  • Improved Showroom ThemeToggle preview contrast in dark mode so the design

system review surface remains readable.

[0.6.4] - 2026-07-12

Fixed

  • Improved Operations dashboard stability so live evidence rows no longer disrupt

the operator page during staging validation.

[0.6.3] - 2026-07-12

Added

  • Added operations workspaces for reviewing MCP administration activity,

operational audit history, approval queues, policies, endpoint inventory, identity oversight, and dashboard health.

  • Added scoped agent access management improvements for controlled service

access.

  • Added staging routing for MCP operations flows so approved reviews can

exercise the same deployed candidate that may later be promoted.

Changed

  • Improved Operations navigation so authorized users see coherent operations

surfaces and unauthorized users receive a clearer forbidden-state experience.

  • Improved public changelog rendering so release notes display as structured

release text instead of raw markdown.

  • Improved staging signing and operations hardening at an operator-visible

outcome level.

Fixed

  • Improved Admin Users localization, mobile layout, action visibility, and

expired-session handling.

[0.6.2] - 2026-07-06

Added

  • Added identity administration screens for authorized operators to find users,

review account status, and manage common account actions.

  • Added account recovery and session-management foundations for safer unlock,

lost-authenticator recovery, and device/session review flows.

  • Added stronger visual quality checks that help catch missing icons, clipped

text, overlapping content, and contrast problems before release.

Changed

  • Improved release visibility so the displayed app version comes from SemVer

release metadata with commit information.

  • Improved staging review and design-system workflows for operators.

Fixed

  • Fixed an invisible theme toggle icon so users can see and use the light/dark

mode control reliably.

  • Fixed small-screen branding layout so long product names wrap instead of

overflowing.

  • Improved theme-toggle contrast in light mode.

Security

  • Improved protection for external sign-in changes so stale sessions cannot

silently change how an account signs in.

  • Strengthened administrator account-management safeguards and audit visibility.
  • Improved account recovery, session revocation, audit retention, and

personal-data minimization safeguards.

  • Strengthened multi-factor enforcement and recent-authentication checks for

sensitive account actions.

  • Improved protection for long-lived sign-in sessions.

[0.6.1] - 2026-07-02

Added

  • Added operator-facing automation health information for scheduled platform

and runner monitoring.

  • Added staging design-review previews for pipeline health monitoring screens.

Fixed

  • Improved sign-in reliability when the same account signs in from more than

one place at nearly the same time.

  • Improved second-factor and recovery-code sign-in reliability during

concurrent account activity.

[0.6.0] - 2026-07-01

Added

  • Added runner and automation health monitoring, including trends, source

freshness, findings, alerts, and recommendations for operators.

  • Added product version ownership, public changelog pages, and footer links to

release notes.

  • Added shared design-system controls for character traits, box tracks, and

health tracks so connected apps can use consistent interactive controls.

  • Added gothic styling variables for character-sheet controls used by WoDVTT.
  • Added staging review previews for Agent Email Proxy product screens.
  • Added health and capacity visibility that helps operators spot pressure on

deployed services.

Changed

  • Improved deployed version labels so users see a product version with commit

context instead of placeholder build values.

  • Improved reliability of operations metrics collection and storage reporting.
  • Updated Agent Email Proxy design previews based on product review feedback.
  • Updated the design-system showroom to display the real shared character-sheet

controls instead of local demonstrations.

Fixed

  • Fixed WoDVTT sign-in sessions expiring too soon after session renewal.
  • Replaced placeholder support and notification email addresses with reachable

product addresses.

  • Fixed passkey setup and sign-in in deployed environments.

Security

  • Improved protection for service-to-service access at the public edge.
  • Replaced shared service credentials with independently managed consumer

access so one integration can be changed without affecting others.

[0.5.0] - 2026-06-25

Added

  • Established 0.5.0 as the first app-platform SemVer baseline for deployed

services.

Ein unerwarteter Fehler ist aufgetreten. Seite neu laden 🗙

Verbindung unterbrochen. Wir stellen die Seite wieder her...

Die Seite konnte nicht automatisch verbunden werden. Seite neu laden

Diese Sitzung ist abgelaufen. Seite neu laden