# Changelog

All notable changes to MONOLITH are documented in this file.

Format follows [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).
Versions follow [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

---

## [Unreleased]

---

## [1.2.0] - 2026-06-29

### Security — Scale & Hardening Release

- **Paddle webhook signature now strictly required** — bypass path removed; all webhook calls without a valid signature are rejected with 401.
- **Login brute-force protection** — accounts are rate-limited to 10 login attempts per minute per IP; excess attempts return 429.
- **Email-to-username Pro escalation vulnerability patched** — users could previously escalate to Pro tier by supplying a Pro-registered email during login; this path is now closed.
- **Magic link URL hardcoded** — the base URL for magic links is now a static environment variable; the `Origin` header is no longer trusted to construct callback URLs (prevents open redirect abuse).
- **RSS proxy restricted to 70-domain allowlist** — the proxy only fetches from pre-approved news organization domains; arbitrary URLs are rejected (prevents SSRF attacks).
- **Email endpoint now requires authentication** — unauthenticated callers can no longer trigger outbound email sends.

### Performance

- **Rate limiter uses in-memory L1 cache** — eliminates ~80% of KV writes for rate limit tracking by maintaining a short-lived in-memory counter before persisting to KV.
- **Session cache (30-second TTL)** — session validation results are cached in memory per isolate, eliminating the double KV read that previously occurred on every authenticated request.
- **`seedAccounts()` early exit for warm isolates** — account seeding now checks a module-level flag and skips re-seeding if the isolate has already initialized, removing redundant KV writes on every request in warm state.

### Added

- **IP ban system** — god-tier admins can ban IP addresses via the System Monitor dashboard; banned IPs receive 403 on all requests.
- **Subscription cancellation endpoint** — users can now cancel their Pro subscription via the API; cancellation is proxied to Paddle and takes effect at the end of the billing period.
- **Data export endpoint (GDPR Article 20)** — authenticated users can request a full export of their personal data in JSON format.
- **Post-signup email nurture drip** — new Pro subscribers receive automated emails at Day 1 (welcome + getting started), Day 3 (tips), and Day 7 (feature highlights).
- **Affiliate/referral tracking** — referral codes can be attached to signup URLs; conversions are tracked and attributed in the CRM dashboard.
- **CRM dashboard in System Monitor** — god-tier admins can view subscriber counts, trial conversions, churn metrics, and referral attribution.
- **PostHog analytics** — product analytics integration for tracking feature usage and funnel events (privacy-respecting, no PII in events).
- **PWA manifest and installability** — MONOLITH can now be installed as a Progressive Web App on desktop and mobile via `manifest.json`.

### SEO & Discoverability

- **`llms.txt`** — machine-readable summary of MONOLITH for AI crawlers and LLM context windows.
- **`robots.txt`** — explicit crawl permissions for search engines.
- **Structured data** — JSON-LD schema markup added for improved search engine rich results.
- **AI discoverability** — OpenGraph and meta tags updated for improved sharing and AI-assisted discovery.

---

## [1.1.0] - 2026-06-28

### Added — Guardian System

- **Guardian health monitoring** — automated health check runs every 30 minutes via Cloudflare Worker cron trigger; checks API availability, AI model responsiveness, and KV health.
- **AI consultation** — Guardian invokes GPT-4o and Claude every 30 minutes to audit the platform for security issues, legal risks, and performance degradation; findings are written to KV and trigger GitHub Actions auto-fix.
- **Morning briefing emails (8am UTC)** — subscribers receive a curated morning news briefing email generated by AI from overnight headlines.
- **Evening health report (8pm UTC)** — founders receive a full system health report each evening summarizing the day's performance, AI consultations, and any issues flagged.

### Fixed

- **`guardian:hist` now uses single rolling key** — guardian history was previously written to 48 unique KV keys per day (one per 30-min interval); now uses a single rolling JSON array key, reducing KV storage bloat and simplifying reads.
- **`seedAccounts` was running on every request** — account seeding ran unconditionally on every incoming request, causing unnecessary KV reads and writes; moved to an initialization guard that fires once per cold start.

---

## [1.0.0] - 2026-06-01

### Launch

- **Live news feed** — real-time aggregation from 70+ official RSS sources across major global news organizations.
- **AI chat** — conversational news analysis powered by Claude Fable 5, GPT-4o, Google Gemini, and Meta Llama 3.3 (model selected by tier).
- **Live global map** — geographic news visualization with real-time story pins.
- **Live TV** — 40+ embedded official YouTube channels from international broadcasters.
- **Real-time market data** — live stock indices, individual equities, and cryptocurrency prices.
- **Trust graph and bias scoring** — per-source reliability and political bias indicators for all 70+ RSS sources.
- **Multi-language translation** — AI-powered translation for international news content.
- **Text-to-speech** — ElevenLabs voice synthesis for articles and AI responses.
- **Pro tier with Paddle billing** — subscription management, payment processing, VAT handling via Paddle (Merchant of Record); monthly ($9.99) and annual ($95.88) plans.
- **Magic link login for Pro users** — passwordless email-based authentication for Pro subscribers.

---

[Unreleased]: https://github.com/parsahejazian-ctrl/-monolith/compare/v1.2.0...HEAD
[1.2.0]: https://github.com/parsahejazian-ctrl/-monolith/compare/v1.1.0...v1.2.0
[1.1.0]: https://github.com/parsahejazian-ctrl/-monolith/compare/v1.0.0...v1.1.0
[1.0.0]: https://github.com/parsahejazian-ctrl/-monolith/releases/tag/v1.0.0
