Skip to content
You are reading the unreleased documentation. No version is released yet, and these pages describe code that is not in a release.

Changelog

The first release of the engine as a product. Title this section with the version package.json carries before running npm run release; the script requires the first section of this file to be that version, so it refuses to tag while this heading stands.

  • Runtime client config: store identity, brand palette, locale pair, money and domains live in StoreSetting and are served on GET /v1/store/config. The storefront renders its tokens, locale routing and money formats from it at SSR; the admin renders its editors, money inputs and shell identity from it. No client branch, no build per client.
  • The install stepper: ./setup.sh (Linux, macOS) and ./setup.ps1 (Windows, local profile) run tools/setup, which asks for every store-specific value once, verifies storage, mail, bot protection and the optional search-engine integrations live, renders the compose stack, the nginx vhosts and the timers from deploy/templates/, builds the images on the box, installs the schema, the seeds and the owner account, issues TLS and probes the result. Profiles: engine, storefront, both, local.
  • An offline Ed25519-signed license verified at setup and at boot, with an admin banner and a grace period on expiry.
  • Admin light mode, a semantic token layer, settings screens for identity, brand (with a palette preview and contrast report), localization, money, domains and the license.
  • A brandless tree, guarded by verify:no-client-refs on every push, and scenario fixtures (gulf-rtl, maghreb-ltr, demo) every locale, money and e2e matrix runs against.
  • Deploy templates with no client value, an operator manual at deploy/README.md, a generic GitHub Actions pipeline with an install smoke job, secret scanning, and npm run release.
  • Phase 20, Notifications + Global search: shipped NotificationTemplate + NotificationLog Prisma models, /v1/admin/notifications/{templates,log,log/:id/resend} CRUD, /v1/admin/search cross-entity fan-out, 3 notification admin screens, a Cmd+K global search overlay replacing the nav-only palette, and a /search full-page results route. 15 new api unit tests (958 total), 30 new admin tests (484 total).

    Phase 21, Quality gates: tightened admin bundle budgets (900 kB initial error ceiling, 80 kB main-bundle guard), whitelisted sanitize-html CJS, shipped lighthouserc.json + GitHub Actions workflow running lint + test + budget + Lighthouse on every admin PR. Local LHCI known-broken on Windows+Node 22; documented as CI-only.

    Phase 22, Docs + handoff: README rewritten to cover the full Nx monorepo; docs/deployment.md §13 added for admin static-host + SPA fallback + CSP + cookie scoping; /dev/design-system demo extended with every primitive shipped after Phase 3 (Icon, KPI card, Sparkline, Tab strip, Translatable input, Rich text editor, Dropzone).

    Sentry wiring: env-var-driven init on both apps, inert without a DSN. captureException called from HttpExceptionFilter on unmapped Prisma/unknown errors and from GlobalErrorHandler on uncaught + 5xx ApiError. PII scrubbed in beforeSend.

    Changesets tooling: wired @changesets/cli for CHANGELOG generation.