Changelog

Product updates — shipped features from the TraXmark team.

  1. 2026-08-19 · 3a8acf112c2b

    feat(contact-matrix): CONTACT & EMAIL MATRIX — single source of truth tożsamości (support/privacy/billing/security/unsubscribe/noreply/postmaster/bounce @traxmark.com / @mg.traxmark.com)

  2. 2026-08-19 · 22ecd352f6f6

    feat(features+help): /features ×6 generowany z FEATURE_CATALOG (packages/shared/src/catalog — maszynowy single source of truth: id/key/area/status, publicFeatures/postMpfBacklog, 4 testy spójności)

  3. 2026-08-19 · dac3bb9ee8ba

    feat(api-v1): TASK 1 — OpenAPI 3.1 generowany z single source of truth (zasoby+scopes z apiKeys/apiAuth, RFC7807 ProblemDetail schema, securityScheme trax_ apiKey) + publiczna strona /[locale]/docs/api (SSG ×6, snippets …

  4. 2026-08-19 · fa4a75c882d0

    feat(esign-flow): E-sign signer flow domknięcie pętli — kolejność signerów (signer N podpisuje dopiero po wszystkich o niższym order → 409 waiting_for_prior_signers), podpis po rewokacji/anulowaniu → 403 envelope_revoked…

  5. 2026-08-19 · 8ae1da8dd415

    feat(api-v1-http): API v1 HTTP layer — RFC7807 Problem Detail (type/status/i18nKey/correlation_id w x-correlation-id), katalog kodów błędów (401/403/404/409/429), anty-enumeracja ujednolicone 404

  6. 2026-08-19 · 44f32ff14a39

    feat(scale): SCALE-READY 1M — EventBus DIRECT/QUEUE (env switch bez refaktoryzacji: DIRECT dev synchroniczny write, QUEUE prod push do kolejki bez zapisu PG w Edge <10ms), chunkEvents 1000 rows/txn, TTL cache (token 1h, …

  7. 2026-08-19 · 2456ec2e2a33

    feat(smartask+roi+approvals): Smart Ask Suggested Action Card — logika wyłącznie server-side (karta tylko gdy suggestAskMoment=true, brak contributions→brak karty, XSS przez contributions sanityzowany, dismiss cooldown 2…

  8. 2026-08-18 · a5a9cd4cafb0

    feat(fala3-integrations): 3C Booking — blok type=booking (Calendly/Cal.com embed z prefill email + UTM), booking_clicked event w evidence graph, entitlement booking_block=Starter+

  9. 2026-08-18 · 6be507773a24

    feat(idp): AI IDP — extractDocumentFields (regułowa ekstrakcja numeru faktury/kwot EUR-USD-PLN/dat/stron/key terms z confidence per pole), sanitizeExtractedText UNTRUSTED_DOCUMENT (script/injection/javascript neutralizow…

  10. 2026-08-18 · 102f6b57facc

    feat(hardening): HARDENING PATCH 10 luk — PAYMENTS: kwota wyłącznie z payment_requests (amount/currency tampering → odrzucone), anty-double-charge (1 aktywny intent per request), refund flow (deal refunded + audit + revo…

  11. 2026-08-18 · caf383f3b4bb

    feat(deal-engine): Block Composer + Content Library + Approval Workflow — migracja 0020 (content_blocks 6 typów z wersjonowaniem, proposals z ordered block_ids, approvals z komentarzem

  12. 2026-08-18 · ca592ce4ae2c

    feat(payments): Payments in Documents (Pay Now) — migracja 0019 payment_requests (amount NUMERIC(12,2), currency eur/usd, status pending/paid/failed/refunded, stripe_payment_link_id, RLS tenant isolation)

  13. 2026-08-18 · 0479bd734ef5

    feat(dsar): DSAR automation (GDPR Art. 15/17) — validateExportIsolation (wykrywa dane innego tenanta/usera w eksporcie: message_foreign_tenant/document_foreign_tenant/profile mismatch), buildExportManifest (profile/messa…

  14. 2026-08-18 · 2ee5323d1528

    feat(load-testing): skrypty k6 — pixel_burst.js (1000 req/s, threshold p95<200ms, weryfikacja anty-enumeracji 200 GIF) + dashboard_heavy.js (100 concurrent users, p95<500ms, ramp 0→100→0) + docs/ops/LOAD_TEST_RESULTS.md …

  15. 2026-08-18 · bad59563b543

    feat(av-cdr): AV/CDR pipeline — scanFileContent (sygnatury z EICAR test string, bytes→latin1 czyste JS edge-ready), decideUpload (threat→BLOCK, clean→watermark proceed), buildAvThreatAlert (alert admina + userMessageKey …

  16. 2026-08-18 · 7307480f738b

    feat(xai-ui): Email Header Analyzer (lead magnet) — publiczny endpoint /api/tools/analyze-headers (parsuje nagłówki → analyzeEmailJourney offline, walidacja rozmiaru, bez logowania) + strona /[locale]/tools/header-analyz…

  17. 2026-08-18 · de83165b7893

    feat(red-team): automated red-team suite tests/red-team/ — privilege_escalation (member→admin/owner odrzucone), prompt_injection (UNTRUSTED_CONTEXT izolacja + filtr wyjścia bez linków zewn.), ssrf_redirect (javascript:/d…

  18. 2026-08-18 · d125ccbb6a6e

    feat(xai): Explainable Evidence Engine (XAI Layer) — bayesowski scorer (prior 0.5 + addytywny model wag: IP residential +0.35/mobile +0.30/datacenter -0.30, UA entropia Shannona ±0.20, timing human >2min +0.25/bot <2s -0…

  19. 2026-08-18 · 277b055274ce

    feat(branding): identyfikacja wizualna TraXmark we wszystkich touchpointach — assety SVG (logo-mark/logo-full/favicon, brand navy/cyan/violet) + site.webmanifest (PWA, theme #0B132B) + metadata icons/manifest/OG w [local…

  20. 2026-08-18 · 1951dc21f150

    feat(crm+ai): CRM Sync Engine (HubSpot/Pipedrive) — least-privilege scopes (contacts read/write, bez full_access/admin), mapowanie pól + walidacja formatu emaila (fix po teście: garbage nie wchodzi do CRM), dedupe case-i…

  21. 2026-08-18 · 2130a3590084

    feat(compliance+esign): Compliance Center + E-Sign model — migracja 0018: user_consents (unique user+doc+version, RLS user-scope, check constraint dokumentów, re-akceptacja nowej wersji), signature_envelopes/signers/sign…

  22. 2026-08-18 · de011052443a

    feat(entitlements): Auditable Entitlements Matrix — single source of truth uprawnień (wymóg #7 raportu): ENTITLEMENTS_PLANS starter/business/enterprise (ceny 9.99/24.99/49.99 + annual 99.9/249.9/499.9

  23. 2026-08-18 · 8cd38ce83d2c

    feat(stealth-v2): Stealth Deliverability — deterministyczny domain pool per para Hash(sender+recipient+date)%pool (ta sama para→ta sama domena, różne pary rotują, case-insensitive)

  24. 2026-08-18 · 8173dd22624a

    feat(MFA): TOTP RFC 6238 — implementacja czysta Web Crypto (HMAC-SHA1 + dynamic truncation), WEKTORY RFC 6238 PASS (T=59/1111111109/1234567890/2000000000), verify z oknem ±1 krok (clock skew) constant-time, generateTotpS…

  25. 2026-08-18 · ad2e4243df68

    feat(admin-app): Admin Command Center scaffold — apps/admin (Next 14, port 3001, dark data-dense, 6 języków): middleware PRZED renderem (sesja → profil SUPER_ADMIN+mfa_enrolled → allowlista ADMIN_ALLOWED_IPS z prefiksami…

  26. 2026-08-18 · 80be56078384

    feat(admin): Admin Command Center logika — impersonate (HMAC token TTL 30min, read_only/full modes, verify constant-time, audit entry actor=ADMIN z metadanymi trybu) + entitlement overrides (walidacja reason >=5 znaków, …

  27. 2026-08-18 · fa091a216e2a

    feat(P2-viewer-ui): Secure Viewer frontend — SecureViewer (streaming stron jako obrazy /api/documents/page z podpisanej sesji, raw PDF nie opuszcza serwera

  28. 2026-08-18 · bfd44a115395

    feat(P2-viewer): warstwa Secure Viewer — migracja 0015 (documents z otp_hash Argon2id PHC, document_grants z token_hash unique+expiry+revoked+require_otp, document_sessions z forensic_session_id, page_view_events z walid…

  29. 2026-08-18 · b41ee6729a50

    feat(P2-documents): Secure Content wg wymogów DocSend-killer — watermark (email+IP+timestamp+Confidential, opacity 0.15, rotate -45°, siatka kafelków, forensic session ID, polityka anti-screenshot z uczciwym ograniczenie…

  30. 2026-08-18 · 79de66163f33

    feat(seo/geo): struktura marketingowa — llms.txt + ai.txt (standard 2026 dla botów AI), robots.txt (AI crawlers allowlista), sitemap.xml (6 języków × 5 ścieżek), marketingMetadata (hreflang alternates + OG/Twitter + cano…

  31. 2026-08-18 · ec3c2a5ae1d3

    feat(omni-channel+shield): Slack Block Kit Hot Lead Alert + Teams MessageCard (themeColor brand, OpenUri) + Web Push payload (przycinanie, bez treści wrażliwych)

  32. 2026-08-18 · 5b1e6ef88f49

    feat(org): Organization Management — seats (usage z pending invitations = race-safe, canAddSeat), validateInviteMember (limity+role+email), acceptInvitation z ponownym sprawdzeniem seatów, validateProfilePatch BIAŁA LIST…

  33. 2026-08-18 · 0a7331d82f43

    feat(compliance+delivery): audit hash-chain (genesis 0, canonicalJson, create/build/verify — tamper treści/prev-link/metadata wykrywane, non-repudiation dla Enterprise

  34. 2026-08-18 · f03999fb0188

    feat(intelligence): Evidence Engine v2 — anti-bot/AI detection z explainability: klasyfikacja priorytetowa AI_CRAWLER 0.95 (26 botów 2026: GPTBot/ClaudeBot/Perplexity/Google-Extended/link-preview) > SECURITY_SCAN 0.90 (I…

  35. 2026-08-18 · f2b65e0c8154

    feat(P2-1/2/3): dokumenty — grant token HMAC (expiry/revoked/OTP-required flow), watermark config (email+timestamp+Confidential, opacity 0.15, rotate -45°, uczciwie: nie DRM), aktywny czas widzenia (cap 15s/przedział, tł…

  36. 2026-08-18 · 8c06911087bd

    feat(P1-9): Deliverability Guardian — pre-send checks: bounce/complaint rate progi (2/5%, 0.1/0.3%), list hygiene (>10% suppressed block), volume spike (3x warn), content analysis (spam words, image/text ratio, link dens…

  37. 2026-08-18 · 32dffc65aa7d

    feat(P1-8): zespoły — invite token HMAC+expiry 7dni (lowercase email, tamper/expired/invalid), validateRoleChange (canManageRole + zakaz nadawania równej/wyższej + owner tylko przez transfer), validateOwnershipTransfer (…

  38. 2026-08-18 · 81a027cbb6ff

    feat(P1-7): szablony — wersjonowanie append-only (historia chroniona, monotoniczne wersje, limit 100), walidacja merge-variabli/subject 988/unbalanced, requiredVariables, scope individual/team/organization + uprawnienia …

  39. 2026-08-18 · 1bdeecc75fa7

    feat(P1-6): unsubscribe RFC 8058 — token HMAC-SHA256 (base64url payload + podpis, expiry 90 dni), weryfikacja constant-time (tamper/zły sekret/expired/invalid format), List-Unsubscribe (mailto + https) + List-Unsubscribe…

  40. 2026-08-18 · adb16f5a136a

    feat(P1-5): bounce + suppression — klasyfikacja SMTP 5xx hard/4xx soft (550 unknown, 552 storage, 421 try-later, 451 greylisting), spam/complaint → global suppression

  41. 2026-08-18 · 3f3c00f4ee94

    feat(P1-4): harmonogram — localMinutesOfDay przez Intl (timezone-aware), quiet hours dzienne+i przez północ, adjustForQuietHours (przesunięcie poza okno, bezpiecznik 48h), optimalSendHour (modalna godzina otwarć, fallbac…

  42. 2026-08-18 · 1aab02a5ae28

    feat(P1-3): kampanie porcjowane — state machine draft→validating→scheduled→running→paused→completed/cancelled (terminalne chronione, cancel z każdej aktywnej fazy)

  43. 2026-08-18 · 732348bfcfd8

    feat(P1-2): mail merge engine — {{var}}, {{var|fallback}}, dot notation, {{#if}}/{{#unless}} zagnieżdżone (inside-out regex), escape HTML wartości (anty-XSS, bez eval), extractVariables + validateTemplate (100KB/50 zmien…

  44. 2026-08-18 · 1b0d266ea3af

    feat(P1-1): CRM + kontakty — engagement score (wagi reply 10/click 5/open 2/proxy 0.5/bounce -5/unsub -3, decay λ=0.05/dzień, sigmoid 0-100)

  45. 2026-08-18 · d8dde62cf026

    feat(P0-9): powiadomienia + abuse + rate limiting — engine 10 triggerów (reply/document_signed critical → unsubscribe info, kanały per reguła), quiet hours z oknem przez północ, cooldown, dedupe

  46. 2026-08-18 · 1527b5181acf

    feat(P0-8/B): dashboard MVP — layout z auth guardem (redirect /login) + sidebar i18n

  47. 2026-08-18 · 46bad142dbdf

    feat(P0-8/A): dashboard KPI engine (computeKpis z mianownikiem provider_accepted, null zamiast fałszywego 0%, confidenceClass progi 0.3/0.7, formatRate

  48. 2026-08-18 · b37095904896

    feat(P0-7): rozszerzenie MV3 — integracja composer Gmail (toolbar toggle i18n, intercept Send z prepare i podmianą HTML, fail-safe bez utraty szkicu), popup + options, build esbuild (IIFE content/ESM worker), 10 testów (…

  49. 2026-08-18 · d4d4e848b278

    feat(P0-7/prepare): track/prepare — prepareTrackedHtml (inject piksela + przepisywanie linków, skipUrl anty-podwójne-zawijanie, idempotentność), generateTrackingToken 128bit, API route /api/track/prepare (walidacja, mapa…

  50. 2026-08-18 · 25ed4fceee3e

    feat(P0-5): link redirector — Edge Function 302 (nie 301, no-store), cel wyłącznie z mapy w bazie (token bez celu), walidacja https-only + blokada javascript:/data:/file:/vbscript:/blob:, wygaśnięcie/brak celu → neutraln…

  51. 2026-08-18 · 9e38d53bf0e4

    feat(P0-4): piksel trackingu — Edge Function (identyczny GIF zawsze: anty-enumeracja, lookup sha256(token), suppression opt-out, dedupe 5min, klasyfikacja inline, idempotentny insert open_events+classified_events, rate l…

  52. 2026-08-18 · 5e3eddf54d64

    feat(P0-6): Evidence Engine v1 — klasyfikator proxy/bot/człowiek (priorytety: skanery 0.95 → Apple MPP 0.90 → Google proxy 0.85 → prefetch 0.80 → datacenter 0.70 → human 0.60-0.90 → unknown 0.30), ip-ranges, ua-parser, s…

  53. 2026-08-18 · 7b83bff56841

    feat(P0-3): auth Supabase SSR + OAuth PKCE — client/server Supabase, middleware sesja+i18n, login (magic link + Google/Microsoft) 6 języków, auth/callback, logout

  54. 2026-08-18 · 31097f81c015

    feat(P0-10/billing): migracja 0013 — plans/volume_discounts/subscriptions/entitlements/billing_events/usage_records/invoices/trial_qualifications + RLS

  55. 2026-08-18 · 59d6267222b2

    feat(i18n/Fork7): next-intl routing /[locale] (en/pl/de/fr/es/it, prefix always, EN default), messages 6 języków, Intl formattery w packages/shared (formatCurrency/Date/Number + 14 testów), extension _locales 6 języków +…

  56. 2026-08-18 · e1b724934f60

    feat(i18n): migracja 0012 — profiles.locale + tenants.default_locale, CHECK 6 języków (en/pl/de/fr/es/it), 5 testów

  57. 2026-08-18 · 5088d64b2271

    feat(P0-2/Fork5): RLS na 16 tabelach (19 polityk), current_tenant_ids(), handle_new_user bootstrap, WORM audit_events

  58. 2026-08-18 · 41ecf1815c09

    feat(P0-2/Fork4): migracje 0001-0008 — 16 tabel (tenants..audit_events), 45 indeksów, constrainty/FK/CHECK, verified na PG 15.17

  59. 2026-08-18 · c862e749f8c8

    feat(P0-1/Fork1+3): monorepo Turborepo — Next.js 14 (App Router), extension MV3 (TS), packages/shared (EngagementStatus, testy vitest 6/6), packages/ui, TS strict