Current version v0.28.0

Changelog

A concise history of user-visible Loop changes.

Back to Loop

v0.28.0

Added

  • Added Team View selection mode with bulk assignee and due-date updates.

Changed

None.

Fixed

  • Team View selection highlighting now clears immediately when a tile is deselected and uses a softer elevated treatment.
  • The bulk due-date control now opens a visible calendar field reliably.

Security

  • Bulk updates validate edit permissions and Private Space assignment visibility for every selected action before making changes.

Technical

  • Bulk changes are transactional and create a separate audit entry for each action whose value changes.

v0.27.0

Added

  • Added a Team View filter to show only actions followed by the connected user.

Changed

None.

Fixed

None.

Security

  • The followed-actions filter is applied server-side in addition to existing action visibility and Private Space restrictions.

Technical

  • Saved Team View filters and filtered return URLs now preserve the followed-actions criterion.

v0.26.1

Added

None.

Changed

  • Improved Team View filtering performance and responsiveness without changing filter behavior.

Fixed

None.

Security

  • Team View visibility, edit rights, follow rights and Private Space restrictions continue to use the existing server-side permission rules.

Technical

  • Team View now uses reusable server-side query construction, compact tile data, batched permission decoration and development-only load timing instrumentation.

v0.26.0

Added

  • Added Team View Private Space filtering, overdue filtering and a compact filtered-actions summary.

Changed

None.

Fixed

None.

Security

  • Team View Private Space filter options, action results and summary counts are scoped server-side to spaces and actions visible to the connected user.

Technical

  • Saved Team View filters now preserve the Private Space criterion through the existing filter serialization.

v0.25.2

Added

None.

Changed

  • Improved action tile visual density, rounded priority strip alignment and due-date spacing for localized labels.

Fixed

None.

Security

None.

Technical

None.

v0.25.1

Added

None.

Changed

None.

Fixed

  • Strengthened action permission checks, Private Space reassignment validation and security regression tests.

Security

  • Action finish now uses centralized edit permissions, and reassignment verifies that the selected assignee can view attached Private Spaces.

Technical

  • Added Node test-runner regression coverage for permission perimeters and rich-text/XSS sanitization, and runs it in CI.

v0.25.0

Added

  • Improved action detail comments, followers, closing behavior and rich description editing.

Changed

  • Action detail Back and close controls now return to the previous browser context when available.
  • Description audit records now state only that the description changed.

Fixed

  • Restored reliable rich-description color and indentation persistence, and clarified description audit wording.

Security

  • Comment edits are author-only; follower additions validate organization and Private Space visibility before creating a relation or notification.
  • Rich description formatting remains constrained by the sanitizer allowlist.

Technical

  • Added follower-added Home news events and safe rich-text font-family sanitization.

v0.24.0

Added

  • Improved Home agenda with current-day highlight and month navigation.

Changed

  • Home agenda now keeps the displayed month in the URL and reloads due counts for the selected month.
  • Clicking the Home agenda month label opens a lightweight month selector.
  • Home agenda month changes preserve the user scroll position on the calendar and localize month and weekday display order.

Fixed

None.

Security

  • Home agenda counts continue to use the existing assigned-action visibility and Private Space restrictions.

Technical

  • Documented Home agenda calendar guardrails and Definition of Done checks.

v0.23.0

Added

  • Added quick due-date rescheduling directly from action tiles.

Changed

None.

Fixed

None.

Security

  • Quick tile rescheduling uses the existing action due-date update permission checks and audit path.

Technical

  • Documented quick action tile control guardrails and reused the existing due-date update server action.

v0.22.1

Added

  • Added heading and title-size controls to rich action descriptions.

Changed

None.

Fixed

  • Fixed rich description encoding so punctuation, special characters and accented characters display as readable text instead of visible HTML entities.

Security

  • Legacy encoded rich descriptions are decoded only before passing through the existing sanitizer; unsafe tags, event handlers and dangerous links remain blocked.

Technical

  • Rich descriptions continue to be stored as sanitized HTML in Action.description with safe heading tags and predefined font-size values.

v0.22.0

Added

  • Added password change from My Profile.

Changed

None.

Fixed

None.

Security

  • Profile password change requires the current password, updates only the connected user, uses the existing scrypt password helper and is disabled during impersonation.

Technical

  • Successful profile password changes clear mustChangePassword without changing profile fields or the admin password reset flow.

v0.21.4

Added

None.

Changed

None.

Fixed

  • Fixed missing profile password-change translation keys after localization merge resolution.

Security

None.

Technical

None.

v0.21.3

Added

None.

Changed

  • Improved localization coverage across application screens, buttons and labels.

Fixed

  • Replaced remaining hard-coded UI text in action detail, rich description editing, Private Spaces and structure administration controls with English/French translation keys.

Security

None.

Technical

  • Documented systematic localization guardrails in CODEX and project Definition of Done materials.

v0.21.2

Added

None.

Changed

  • Pasted images in rich action descriptions can now fit the documented lightweight inline image limit.
  • Private Spaces moved to the left action detail column between due date and followers.
  • The action detail tag selector is more compact with search/create above the tag list and a small + create button.

Fixed

  • Fixed rich description saves failing when pasted inline images exceeded the previous plain-text description limit.

Security

None.

Technical

None.

v0.21.1

Added

None.

Changed

  • Rich action descriptions now preserve font size and text color formatting in read-only display.
  • URLs typed in rich descriptions are automatically rendered as safe clickable links without using a separate link button.

Fixed

None.

Security

  • Description URL auto-linking uses the existing sanitization allowlist and only creates safe http:// and https:// links.

Technical

None.

v0.21.0

Added

  • Action detail now uses a 3-column desktop layout with a compact title block and a rich description editor opened from a pencil button.

Changed

  • Updated action detail layout and added rich description editing.
  • Comments now render safe http:// and https:// URLs as clickable links.

Fixed

None.

Security

  • Rich descriptions are sanitized before storage and rendering; comment text remains escaped and only safe web URLs are linkified.

Technical

  • Rich descriptions are stored as sanitized HTML in the existing Action.description field, preserving existing plain text descriptions without a migration.

v0.20.1

Added

None.

Changed

  • Updated Workstream sub-action visibility for assignees.
  • Standalone Workstream sub-action tiles now display a small explanatory label and action detail identifies the parent Workstream.

Fixed

None.

Security

  • Workstream sub-action standalone visibility continues to respect normal action permissions and Private Space restrictions.

Technical

  • Adjusted My Actions and Team View action list queries to include eligible assigned sub-actions without duplicating or detaching records.
  • Documented Workstream sub-action visibility guardrails and Definition of Done checks.

v0.20.0

Added

  • Private Spaces let authenticated users create restricted visibility compartments for sensitive actions.
  • Actions can be attached to Private Spaces from quick action capture using [ autocomplete and from the action detail page.
  • The Administration area now includes a Private Spaces page with owned and shared sections.

Changed

None.

Fixed

None.

Security

  • Private Space action visibility is enforced server-side across My Actions, Team View, Home, filters, tags, agenda counts, news and direct action detail routes.
  • Private Space membership is organization-scoped and dynamically includes linked team and entity members.

Technical

  • Added PrivateSpace, PrivateSpaceUser, PrivateSpaceTeam, PrivateSpaceEntity and ActionPrivateSpace Prisma models and migration.
  • Documented Private Space guardrails, permissions, data model and definition of done.

v0.19.0

Added

  • Team View now includes a Today due-date filter, live title/description search, and a visible tag filter with top tag suggestions.
  • Teams, Entities and Assignees filters now use compact multi-select dropdowns.

Changed

  • The duplicate current-month due-date option was removed and saved filters using the old this-month value are mapped to Current month.
  • The left menu no longer displays the disabled Workstreams/Chantiers entry.

Fixed

None.

Security

  • Team View text, tag, due-date, team, entity and assignee filters remain enforced server-side after the existing visibility scope is applied.

Technical

  • Documented Team View filter guardrails and visibility-scoped tag suggestion behavior.

v0.18.3

Added

None.

Changed

None.

Fixed

  • Fixed overdue action highlighting regression in My Actions.

Security

None.

Technical

  • Shared the start-of-today overdue helper between My Actions and Team View overdue filtering.

v0.18.2

Added

  • Added an Overdue section to My Actions for open assigned actions whose due date is strictly before today.

Changed

  • My Actions now shows overdue actions above Just created, active/open actions and finished actions without duplicating them in active actions.

Fixed

None.

Security

None.

Technical

  • Documented My Actions overdue rules and Definition of Done expectations.

v0.18.1

Added

None.

Changed

None.

Fixed

  • Fixed Users Management role assignment and edit persistence for MANAGER users with entity/team attachments.

Security

  • Entity attachment no longer grants SUPERMANAGER scope unless SUPERMANAGER is explicitly selected and permitted server-side.

Technical

  • User account updates now reconcile organization, entity and team assignments in a single transaction.

v0.18.0

Added

  • Authenticated users now have a My Profile page to update their own first name, last name, login and language.

Changed

None.

Fixed

None.

Security

  • Profile updates derive the edited user from the authenticated session, reject impersonation edits and cannot modify roles, rights, memberships or active status.

Technical

  • Added server-side profile validation, login uniqueness handling, localized navigation and documentation guardrails.

v0.17.1

Added

None.

Changed

  • User identifiers are now labeled and handled as login values instead of email addresses across authentication and Users Management.

Fixed

  • User creation, update, lookup and sign-in no longer require email-format validation.

Security

  • Existing identifier values are preserved by renaming the database column from email to login, so existing users can keep signing in with the same string.

Technical

  • Updated Prisma User.login, login normalization, bootstrap admin configuration and documentation guardrails.

v0.17.0

Added

  • Home now provides an operational dashboard with followed action news, an assigned open actions priority donut chart, and a monthly agenda.
  • Team View supports exact due-date filtering from agenda day clicks.

Changed

  • Home agenda counts now focus on actions assigned to the connected user, and priority donut segments link to Team View priority filters.

Fixed

None.

Security

  • Home news, seen updates and purge are scoped to the connected user; agenda date filters reuse Team View server-side visibility.

Technical

  • Added FollowedActionNews for followed action closure and due-date change events.

v0.16.2

Added

None.

Changed

None.

Fixed

  • Fixed Users Management team options for SUPERMANAGER users whose SUPERMANAGER scope comes from Entity membership.

Security

  • Server-side user management permissions now resolve the organization for Entity memberships before computing SUPERMANAGER team scope.

Technical

None.

v0.16.1

Added

None.

Changed

None.

Fixed

  • Fixed SUPERMANAGER team visibility in Users Management user creation.

Security

  • Server-side user creation validation now matches the SUPERMANAGER entity perimeter and organization fallback for team assignment.

Technical

None.

v0.16.0

Added

  • Team View now includes an Overdue due-date filter for actions whose due date is strictly before today.

Changed

  • Saved Team View filters can persist and replay the overdue due-date criteria, with results recomputed dynamically each time the view opens.
  • Team View now hides finished actions by default and offers a filter checkbox to show them again.

Fixed

None.

Security

  • The overdue filter is applied server-side after existing Team View visibility rules and combines with other filters without changing action permissions.

Technical

  • Documented the Team View overdue definition and Definition of Done expectations.

v0.15.0

Added

  • Loop now has an English/French localization foundation with lightweight dictionaries and a per-user language selector in the authenticated topbar.

Changed

  • Visible interface text is normalized to English as the default baseline before translation switching.
  • Localization coverage now includes main pages, action tiles, Team View, changelog and administration page content.

Fixed

None.

Security

  • Language updates are authenticated, limited to supported language codes and scoped to the connected user only.

Technical

  • Added User.language with a safe default-English migration for existing users.

v0.14.0

Added

  • Topbar quick action capture now recognizes due-date tokens, priority tokens and a permission-scoped @ assignee autocomplete.
  • My Actions now includes a Just created section for quick-captured open actions until their detail page is opened.

Changed

  • Quick-created action titles now remove parsed date, priority and selected assignee tokens before saving.

Fixed

None.

Security

  • Quick action assignment is validated server-side and cannot use users outside the connected user's assignment perimeter.

Technical

  • Added Action.justCreatedAt with a safe nullable migration and server-side clearing without audit-log noise.

v0.13.1

Added

None.

Changed

  • Team View now shows Organization-wide actions to every member of the Organization while keeping ADMIN visibility across all Organizations.
  • Action detail and Team View tiles now separate view access from edit controls, so visible actions stay read-only when the connected user lacks edit permission.

Fixed

  • Follow and unfollow now use action visibility instead of edit permission, allowing users to follow visible non-assigned actions in their Organization for themselves only.

Security

  • Server-side permission helpers now distinguish Team View visibility, action edit scope and follow permission instead of reusing edit permission as a proxy.
  • Team View filter options and action results are scoped to the connected user's Organizations, with action Organization inferred from assignee membership when no action organization field exists.

Technical

None.

v0.13.0

Added

  • Actions now support free-form tags from the action detail page, with compact tag pills on details and action tiles.
  • Administration now includes a Tags page for MANAGER+ users showing tags used inside their visibility perimeter, with SUPERMANAGER+ tag deletion.

Changed

None.

Fixed

None.

Security

  • Tag suggestions and tag administration are scoped server-side to actions visible to the connected user.

Technical

  • Added Tag and ActionTag data models with normalized unique tag names, cascade cleanup of action tag associations, and administration deletion that removes tag links without otherwise changing actions.

v0.12.0

Added

  • Users Management now shows a confirmation modal before destructive user deletion, including the number of related actions that will be removed.

Changed

  • Confirmed user deletion now removes the user plus actions they created or were assigned to, while preserving unrelated actions.

Fixed

None.

Security

  • User deletion impact preview and deletion are permission-checked server-side and prevent users from deleting their own account or users outside their perimeter.

Technical

  • User deletion now runs in a transaction that cleans related action children, sessions, memberships, saved filters, followers and remaining user references.

v0.11.0

Added

  • Users can now follow visible actions assigned to someone else with a discreet eye toggle on action tiles.
  • Action detail now shows a read-only list of users following the action.

Changed

None.

Fixed

None.

Security

  • Follow and unfollow always use the connected user from the server-side session and cannot be managed on behalf of another user.

Technical

  • Added the ActionFollower data model with unique action/user records and cascade deletion through a safe additive Prisma migration.

v0.10.1

Added

None.

Changed

  • Team View filters can now be collapsed, and saved Team View links open with the filter area collapsed so results stay prominent.

Fixed

None.

Security

None.

Technical

None.

v0.10.0

Added

  • Team View page with perimeter-scoped action filters, user-specific saved views, and saved filter links in the left menu.
  • Returning from an action opened through Team View now restores the filtered Team View URL.

Changed

None.

Fixed

None.

Security

  • Team View action results, filter options and saved filter mutations are scoped server-side to the connected user's authorized perimeter.

Technical

  • Added the SavedTeamViewFilter data model and safe additive Prisma migration for private saved Team View criteria.

v0.9.5

Added

None.

Changed

  • Users Management now groups users by organization, then entity, then team, with entity-level users shown before teams inside each entity.

Fixed

None.

Security

None.

Technical

None.

v0.9.4

Added

None.

Changed

  • Users Management now displays entity-scoped SUPERMANAGER users with their effective SUPERMANAGER badge instead of showing only their STANDARD organization membership.

Fixed

  • Editing a SUPERMANAGER onto an entity no longer makes the tile appear as a STANDARD user after validation.

Security

None.

Technical

None.

v0.9.3

Added

  • User creation and edit forms now include entity scope selection so SUPERMANAGER users can be attached to an entity without requiring a team.

Changed

  • SUPERMANAGER user creation and edit validation now accepts entity assignment as a valid scope in addition to team assignment.

Fixed

None.

Security

None.

Technical

None.

v0.9.2

Added

  • Administration tiles now expose compact action bubbles to edit, deactivate or delete organizations, entities, teams and users.

Changed

  • Edit fields now stay hidden until the edit bubble is clicked, keeping Teams Management and Users Management in tile mode by default.

Fixed

None.

Security

  • Delete actions are guarded server-side and refuse destructive deletion when records still have related data or history, directing administrators to deactivate instead.

Technical

None.

v0.9.1

Added

  • Teams Management can now edit or deactivate organizations, entities and teams, including changing a team's entity attachment or moving it directly under its organization.
  • Users Management can now edit user profile fields and deactivate user accounts without deleting their actions or history.

Changed

None.

Fixed

None.

Security

  • Edit and deactivation actions for structures and users are permission-checked server-side and preserve existing data by using deactivation instead of destructive deletion.

Technical

None.

v0.9.0

Added

  • Entity layer between organizations and teams, with teams still allowed directly under an organization when no entity is needed.
  • Dedicated Teams Management screen for organizations, entities and teams.
  • Users Management now focuses on users, rights and organization/entity/team assignments.

Changed

  • Administration navigation now separates Teams Management and Users Management.
  • SUPERMANAGER scope is entity-based for structure, user and action visibility while DIRECTOR remains organization-scoped.

Fixed

None.

Security

  • Server-side administration and action visibility helpers now account for entity perimeters and avoid exposing users or teams outside the actor scope.

Technical

  • Added Entity and EntityMembership Prisma models plus nullable Team.entityId with a safe additive migration that leaves existing teams directly attached to their organizations.

v0.8.0

Added

  • Workstreams let a root action contain sub-actions while staying within the lightweight action tracker model.
  • Root actions can be grouped by drag and drop after confirmation, and classic actions can be transformed into empty workstreams from the detail page.
  • Expanded workstream tiles and workstream detail pages display compact sub-action tiles that can be opened and completed.
  • Workstream detail pages include a simple + form to create sub-actions assigned to the parent workstream assignee.

Changed

  • Normal action lists now show only root actions so sub-actions appear only through their parent workstream or direct detail page.

Fixed

None.

Security

  • Grouping, transforming, sub-action creation and direct sub-action deletion restrictions are enforced server-side.

Technical

  • Added Action self-relation fields parentActionId, parentAction and subActions plus isWorkstream with a safe additive Prisma migration.
  • Permanent workstream deletion explicitly deletes comments and audit logs for the parent and all direct sub-actions in a transaction.

v0.7.3

Added

None.

Changed

  • Improved action detail priority styling with a subtle priority color on the title and assignee summary block.
  • Changed action detail description editing to save on blur or with a Save Description button instead of saving while typing.

Fixed

None.

Security

None.

Technical

None.

v0.7.2

Added

None.

Changed

  • Archived action tiles in Administration now open the action detail page when clicked.
  • Archived action tiles now show priority with the same colored dot and left liseret visual language as action tiles instead of P1/P2/P3 labels.

Fixed

None.

Security

None.

Technical

None.

v0.7.1

Added

None.

Changed

  • Made the finished action delete/archive control more visible while keeping it limited to finished action tiles.

Fixed

None.

Security

None.

Technical

None.

v0.7.0

Added

  • Finished actions can be reopened from the Finished section and returned to active actions.
  • Finished action tiles now include a discreet delete/archive control.
  • SUPERMANAGER, DIRECTOR and ADMIN users can access Administration > Archived Actions to view, restore or permanently delete archived actions in their authorized perimeter.

Changed

  • STANDARD and MANAGER delete requests on finished actions now archive the action instead of permanently deleting it.
  • Normal My Actions views now exclude archived actions from both open and finished sections.

Fixed

None.

Security

  • Permanent deletion is restricted server-side to SUPERMANAGER+ users and removes the action together with comments and audit logs without leaving a deletion audit trail.

Technical

  • Added nullable action archive metadata fields and a safe additive Prisma migration.
  • Permanent action deletion runs in a database transaction and explicitly removes action comments and audit logs before deleting the action record.

v0.6.2

Added

  • Mobile topbar menu button that opens a left-side navigation drawer on small screens.

Changed

  • Desktop and mobile navigation now share the same menu data and permission visibility rules.
  • Documentation now records responsive navigation requirements for mobile access.

Fixed

None.

Security

None.

Technical

None.

v0.6.1

Added

None.

Changed

  • Renamed the administration impersonation menu and page label to English for consistency with the rest of the application.

Fixed

None.

Security

None.

Technical

None.

v0.6.0

Added

  • ADMIN-only Impersonation page to connect as an active non-admin user for support and validation.
  • Topbar impersonation indicator with Back to admin action that restores the original admin session.

Changed

  • Administration navigation now includes Impersonation only for ADMIN users.

Fixed

None.

Security

  • Impersonation is protected server-side, excludes inactive users and ADMIN targets, and keeps the session cookie opaque and HTTP-only.
  • Impersonation START and STOP events are recorded in a dedicated audit log.

Technical

  • Added server-side session impersonation metadata and the ImpersonationAuditLog database model with a safe additive migration.

v0.5.0

Added

  • Action detail page available from My Actions tiles.
  • Editable action title, description, assignee, due date and priority fields on the action detail page.
  • Append-only action comments with author and timestamp displayed chronologically.
  • On-demand action audit trail showing who changed each field, when, and the old and new values.

Changed

  • Action tiles now open the detail page when clicking the tile body while preserving completion and priority controls.
  • Action detail field edits now save automatically without Save buttons and show a small saved notification.

Fixed

None.

Security

  • Action detail, field editing, comments and audit trail access are checked server-side with existing action scope helpers.
  • Assignee reassignment is limited to active users from the connected user's current organization.

Technical

  • Added Action.description plus ActionComment and ActionAuditLog database models with a safe additive migration.
  • Title, assignee, priority and finish mutations now write audit entries only when values actually change.
  • Assignee audit entries now store person names instead of user IDs.

v0.4.0

Added

  • Membership-based organization roles so one user can belong to several organizations with different roles.
  • Multi-team memberships so one user can belong to several teams.
  • User Management forms to add existing users to organizations or teams without creating duplicate accounts.
  • A discreet topbar role badge that shows the connected user's highest effective role with centralized role colors.

Changed

  • Administration permissions now compute scope from organization and team memberships while retaining legacy user organization/team fields for migration safety.
  • User Management now displays organization members and team members from membership data.

Fixed

None.

Security

  • Existing controlled password generation remains one-time only and hashed at rest.
  • Server-side perimeter checks now validate organization memberships and team memberships for existing-user assignment flows.

Technical

  • Added OrganizationMembership and TeamMembership models plus a migration from existing User.organizationId and User.teamId values.
  • Added centralized role helpers for ranking, labels and badge styling, plus reusable action-scope helpers.

v0.3.0

Added

  • Controlled User Management page for organizations, teams, users and team administration responsibilities.
  • Organization and team tenancy model with role hierarchy: Standard, Manager, Supermanager, Director and Admin.
  • Secure temporary password generation for controlled user creation and password reset, shown only once.
  • Environment-protected bootstrap script to create the first Admin account when no Admin exists.

Changed

  • Public self-registration is disabled and account creation is now handled only by authorized users.
  • The sidebar now shows Administration and User Management only to Manager-level users and above.
  • Legacy roles are mapped to the new role hierarchy during migration.

Fixed

None.

Security

  • Administration mutations now enforce server-side role and perimeter checks.
  • Temporary passwords are hashed before storage and existing passwords cannot be displayed from the database.

Technical

  • Added Prisma models for Organization, Team and TeamAdministrator plus a safe migration for existing users.

v0.2.0

Added

  • Public MVP information pages for About, Privacy, Terms and Legal.
  • Internal legal and deployment documentation for MVP positioning, IP intent and licensing paths.

Changed

  • Clarified that Loop is an early-stage MVP for limited evaluation only.
  • Clarified separate internal/on-premise and future SaaS tracks.

Fixed

None.

Security

None.

Technical

  • Updated project guardrails for intellectual property, deployment and contribution documentation.

v0.1.0

Added

  • Initial Loop application shell.
  • Authentication foundation.
  • Quick action creation.
  • My Actions compact tile view.
  • Finished actions section.
  • Discreet application version indicator with changelog access.

Changed

  • Added project documentation and Codex guardrails for changelog updates.

Fixed

None.

Security

None.

Technical

None.

v0.28.0