[{"data":1,"prerenderedAt":318},["ShallowReactive",2],{"$f20aoeidp81qne":3,"mdc--1sgkcp-key":15},{"release":4,"newer":10,"older":12,"page":14},{"tag":5,"name":5,"publishedAt":6,"url":7,"prerelease":8,"markdown":9},"v1.0.13","2026-05-20T01:58:43Z","https:\u002F\u002Fgithub.com\u002Fanhourtec\u002FBookYourPTO-SaaS\u002Freleases\u002Ftag\u002Fv1.0.13",false,"This release rounds out the onboarding-documents workflow that started in v1.0.12, finishes the profile-page redesign that began in v1.0.9, ships a number of authentication and security fixes (TOTP, refresh tokens, dependency CVEs, Redis), and polishes the document signing UX top-to-bottom.\r\n\r\n### New Features\r\n\r\n- **Per-employee onboarding document copies, finished end-to-end** — The per-recipient document generation introduced in v1.0.12 is now fully wired across the onboarding lifecycle. Every new hire gets their own copy of every required onboarding doc, with their own audit trail, their own signature, and their own signing certificate. Existing organisations have been backfilled.\r\n\r\n- **Read-only acknowledgment paths cleaned up** — The \"I have read this\" footer button and the implicit-on-view acknowledgment from v1.0.12 are now stable across both onboarding and offboarding flows. Edge cases where a read-only doc would only surface after signing a sibling document have been closed.\r\n\r\n- **Stable behaviour after rapid back-to-back deletes** — Deleting two documents in quick succession could leave a stale row visible on the documents page for a moment before the second delete caught up. The list now reconciles deletes the moment each response returns, so rapid keyboard- or mouse-driven cleanup feels predictable instead of \"did that one save?\".\r\n\r\n- **Onboarding-doc workflow refinements** — Several smaller flow fixes shipped on top of the v1.0.12 foundation: the per-user generation runs in more places that previously only generated on profile-tab visits, the sidebar Action Required badge stays in sync after every acknowledgment, and template-scoped documents flow through to instance-scoped per-user copies in every path that creates a task.\r\n\r\n- **Profile page redesign shipped** — The profile redesign that started in v1.0.9 is now the only profile experience: sidebar vitals on the left, tabbed sections on the right, inline edit per section. Multiple iteration rounds finalised the layout, inline-edit interactions, completeness indicator, and the per-tab navigation chrome.\r\n\r\n- **All section editors land inline** — The legacy modal-based edit flow is fully retired. Each section (basic info, social links, address, contact, emergency contact, employment, leave allowance, holidays, education, languages, certifications, visa, assets, compensation, bonuses, job history, employment status, notes, termination) opens its own inline editor with a sticky save \u002F cancel footer.\r\n\r\n- **Faster paint on large profiles** — Build configuration was tuned to give Node a 6 GB heap during production builds so the redesign compiles cleanly under load. End users will notice quicker first-paint on the heaviest profile pages.\r\n\r\n- **Continued time-tracking improvements** — The time-tracking module received another wave of refinements building on v1.0.10's expansion: list-view interactions, schedule auto-generation behaviour, edit-flow safety nets, and a handful of cross-cutting bug fixes across the timesheet, schedule, and approvals surfaces.\r\n\r\n- **Geofencing now included in Pro and above** — Geofencing (allowed clock-in locations, circle \u002F polygon shapes, the compliance dashboard, audit trail — all introduced in v1.0.10) is now part of the Pro plan and above instead of being Business \u002F Enterprise only. Existing Pro customers gain access without any billing change.\r\n\r\n- **Approval counts scoped to the caller's rights** — `\u002Fapi\u002Fapprovals\u002Fcounts` (the endpoint that powers the badges on the approvals dashboard) now scopes its numbers to whatever each viewer is actually allowed to act on. Department heads see the count of items in their own queue rather than the org-wide total.\r\n\r\n- **Pending-approvals badge updates immediately after approve \u002F reject** — Approving or rejecting any leave, expense, or time entry now busts the cached approvals count so the sidebar and overview badges drop in real time instead of waiting on the next poll.\r\n\r\n- **Cleaner copy throughout the signing flow** — Multiple iterations on the document signing pages refined the copy, the recipient picker, the field placement UX, and the post-signing confirmation. The Sign mode upload page is faster and more obvious to use end-to-end.\r\n\r\n- **No more \"legally binding\" \u002F ESIGN Act claims in the UI** — Removed copy that asserted the in-app signature was ESIGN-Act-compliant or legally binding. The signature flow still records full audit context (IP, user-agent, timestamp, signing certificate) for evidentiary purposes, but the product no longer makes legal claims it isn't qualified to make. Customers who need full e-signature legal force are still expected to use a dedicated provider.\r\n\r\n- **Email logos render correctly in Outlook for Windows** — A long-standing rendering bug caused organisation logos to balloon to the full email width in Outlook for Windows specifically. Logos now render at the intended size across Outlook, Gmail, Apple Mail, and the major email clients.\r\n\r\n- **Leave-submission notifications are scoped to the submitter's department** — When an employee submits a leave request, the approver notification used to fan out to managers across the entire org. It now goes only to the submitter's own department head plus administrators and executives, matching how every other approval queue is scoped. Cross-department managers are no longer pulled into approvals that aren't theirs.\r\n\r\n- **\"Remember me\" now defaults to off** — The login screen's \"Remember me\" checkbox defaults to unchecked. Long-lived sessions are now an explicit opt-in rather than the silent default.\r\n\r\n- **TOTP login fix** — Two-factor login was being rejected by the API interceptor before the verification request could reach the server, because the TOTP-verify endpoint wasn't in the public route list. Users with 2FA enabled can now log in without a transient \"Unauthorised\" error.\r\n\r\n- **Email verification fixes** — `verify-code` and `resend-verification` were treated as public endpoints, which interacted badly with rate-limiting and session continuity for users who'd partially registered. They now flow through the authenticated path, so verification works correctly on first try.\r\n\r\n### Bug Fixes\r\n\r\n- **Training auto-assign computed due dates in the past** — When a training requirement was created with a \"due X days from hire date\" rule, the auto-assign logic could resolve a `dueDate` earlier than today for new hires whose hire date was already past the offset window. The check is now resolved against \"today in the org's timezone\" so brand-new requirements assigned to existing employees get sensible due dates instead of arriving pre-overdue.\r\n\r\n- **PDF receipts wouldn't render in some browsers** — A stricter X-Frame-Options policy (`DENY`) was preventing inline PDF receipt previews from rendering inside the app on Safari and a few Chrome configurations. Relaxed to `SAMEORIGIN` so receipts preview correctly without weakening cross-site protection.\r\n\r\n- **Rapid back-to-back document deletes left a stale row** — See \"Onboarding Documents\" above. Two deletes in quick succession could leave a phantom row visible until the next refresh; the list now reconciles after each response.\r\n\r\n- **Outlook for Windows email logo size** — See \"Document Signing\" above.",{"tag":11,"name":11},"v1.0.14",{"tag":13,"name":13},"v1.0.12",2,{"data":16,"body":17},{},{"type":18,"children":19},"root",[20,28,35,245,251],{"type":21,"tag":22,"props":23,"children":24},"element","p",{},[25],{"type":26,"value":27},"text","This release rounds out the onboarding-documents workflow that started in v1.0.12, finishes the profile-page redesign that began in v1.0.9, ships a number of authentication and security fixes (TOTP, refresh tokens, dependency CVEs, Redis), and polishes the document signing UX top-to-bottom.",{"type":21,"tag":29,"props":30,"children":32},"h3",{"id":31},"new-features",[33],{"type":26,"value":34},"New Features",{"type":21,"tag":36,"props":37,"children":38},"ul",{},[39,51,61,71,81,91,101,111,121,131,150,160,170,180,190,200,210,220],{"type":21,"tag":40,"props":41,"children":42},"li",{},[43,49],{"type":21,"tag":44,"props":45,"children":46},"strong",{},[47],{"type":26,"value":48},"Per-employee onboarding document copies, finished end-to-end",{"type":26,"value":50}," — The per-recipient document generation introduced in v1.0.12 is now fully wired across the onboarding lifecycle. Every new hire gets their own copy of every required onboarding doc, with their own audit trail, their own signature, and their own signing certificate. Existing organisations have been backfilled.",{"type":21,"tag":40,"props":52,"children":53},{},[54,59],{"type":21,"tag":44,"props":55,"children":56},{},[57],{"type":26,"value":58},"Read-only acknowledgment paths cleaned up",{"type":26,"value":60}," — The \"I have read this\" footer button and the implicit-on-view acknowledgment from v1.0.12 are now stable across both onboarding and offboarding flows. Edge cases where a read-only doc would only surface after signing a sibling document have been closed.",{"type":21,"tag":40,"props":62,"children":63},{},[64,69],{"type":21,"tag":44,"props":65,"children":66},{},[67],{"type":26,"value":68},"Stable behaviour after rapid back-to-back deletes",{"type":26,"value":70}," — Deleting two documents in quick succession could leave a stale row visible on the documents page for a moment before the second delete caught up. The list now reconciles deletes the moment each response returns, so rapid keyboard- or mouse-driven cleanup feels predictable instead of \"did that one save?\".",{"type":21,"tag":40,"props":72,"children":73},{},[74,79],{"type":21,"tag":44,"props":75,"children":76},{},[77],{"type":26,"value":78},"Onboarding-doc workflow refinements",{"type":26,"value":80}," — Several smaller flow fixes shipped on top of the v1.0.12 foundation: the per-user generation runs in more places that previously only generated on profile-tab visits, the sidebar Action Required badge stays in sync after every acknowledgment, and template-scoped documents flow through to instance-scoped per-user copies in every path that creates a task.",{"type":21,"tag":40,"props":82,"children":83},{},[84,89],{"type":21,"tag":44,"props":85,"children":86},{},[87],{"type":26,"value":88},"Profile page redesign shipped",{"type":26,"value":90}," — The profile redesign that started in v1.0.9 is now the only profile experience: sidebar vitals on the left, tabbed sections on the right, inline edit per section. Multiple iteration rounds finalised the layout, inline-edit interactions, completeness indicator, and the per-tab navigation chrome.",{"type":21,"tag":40,"props":92,"children":93},{},[94,99],{"type":21,"tag":44,"props":95,"children":96},{},[97],{"type":26,"value":98},"All section editors land inline",{"type":26,"value":100}," — The legacy modal-based edit flow is fully retired. Each section (basic info, social links, address, contact, emergency contact, employment, leave allowance, holidays, education, languages, certifications, visa, assets, compensation, bonuses, job history, employment status, notes, termination) opens its own inline editor with a sticky save \u002F cancel footer.",{"type":21,"tag":40,"props":102,"children":103},{},[104,109],{"type":21,"tag":44,"props":105,"children":106},{},[107],{"type":26,"value":108},"Faster paint on large profiles",{"type":26,"value":110}," — Build configuration was tuned to give Node a 6 GB heap during production builds so the redesign compiles cleanly under load. End users will notice quicker first-paint on the heaviest profile pages.",{"type":21,"tag":40,"props":112,"children":113},{},[114,119],{"type":21,"tag":44,"props":115,"children":116},{},[117],{"type":26,"value":118},"Continued time-tracking improvements",{"type":26,"value":120}," — The time-tracking module received another wave of refinements building on v1.0.10's expansion: list-view interactions, schedule auto-generation behaviour, edit-flow safety nets, and a handful of cross-cutting bug fixes across the timesheet, schedule, and approvals surfaces.",{"type":21,"tag":40,"props":122,"children":123},{},[124,129],{"type":21,"tag":44,"props":125,"children":126},{},[127],{"type":26,"value":128},"Geofencing now included in Pro and above",{"type":26,"value":130}," — Geofencing (allowed clock-in locations, circle \u002F polygon shapes, the compliance dashboard, audit trail — all introduced in v1.0.10) is now part of the Pro plan and above instead of being Business \u002F Enterprise only. Existing Pro customers gain access without any billing change.",{"type":21,"tag":40,"props":132,"children":133},{},[134,139,141,148],{"type":21,"tag":44,"props":135,"children":136},{},[137],{"type":26,"value":138},"Approval counts scoped to the caller's rights",{"type":26,"value":140}," — ",{"type":21,"tag":142,"props":143,"children":145},"code",{"className":144},[],[146],{"type":26,"value":147},"\u002Fapi\u002Fapprovals\u002Fcounts",{"type":26,"value":149}," (the endpoint that powers the badges on the approvals dashboard) now scopes its numbers to whatever each viewer is actually allowed to act on. Department heads see the count of items in their own queue rather than the org-wide total.",{"type":21,"tag":40,"props":151,"children":152},{},[153,158],{"type":21,"tag":44,"props":154,"children":155},{},[156],{"type":26,"value":157},"Pending-approvals badge updates immediately after approve \u002F reject",{"type":26,"value":159}," — Approving or rejecting any leave, expense, or time entry now busts the cached approvals count so the sidebar and overview badges drop in real time instead of waiting on the next poll.",{"type":21,"tag":40,"props":161,"children":162},{},[163,168],{"type":21,"tag":44,"props":164,"children":165},{},[166],{"type":26,"value":167},"Cleaner copy throughout the signing flow",{"type":26,"value":169}," — Multiple iterations on the document signing pages refined the copy, the recipient picker, the field placement UX, and the post-signing confirmation. The Sign mode upload page is faster and more obvious to use end-to-end.",{"type":21,"tag":40,"props":171,"children":172},{},[173,178],{"type":21,"tag":44,"props":174,"children":175},{},[176],{"type":26,"value":177},"No more \"legally binding\" \u002F ESIGN Act claims in the UI",{"type":26,"value":179}," — Removed copy that asserted the in-app signature was ESIGN-Act-compliant or legally binding. The signature flow still records full audit context (IP, user-agent, timestamp, signing certificate) for evidentiary purposes, but the product no longer makes legal claims it isn't qualified to make. Customers who need full e-signature legal force are still expected to use a dedicated provider.",{"type":21,"tag":40,"props":181,"children":182},{},[183,188],{"type":21,"tag":44,"props":184,"children":185},{},[186],{"type":26,"value":187},"Email logos render correctly in Outlook for Windows",{"type":26,"value":189}," — A long-standing rendering bug caused organisation logos to balloon to the full email width in Outlook for Windows specifically. Logos now render at the intended size across Outlook, Gmail, Apple Mail, and the major email clients.",{"type":21,"tag":40,"props":191,"children":192},{},[193,198],{"type":21,"tag":44,"props":194,"children":195},{},[196],{"type":26,"value":197},"Leave-submission notifications are scoped to the submitter's department",{"type":26,"value":199}," — When an employee submits a leave request, the approver notification used to fan out to managers across the entire org. It now goes only to the submitter's own department head plus administrators and executives, matching how every other approval queue is scoped. Cross-department managers are no longer pulled into approvals that aren't theirs.",{"type":21,"tag":40,"props":201,"children":202},{},[203,208],{"type":21,"tag":44,"props":204,"children":205},{},[206],{"type":26,"value":207},"\"Remember me\" now defaults to off",{"type":26,"value":209}," — The login screen's \"Remember me\" checkbox defaults to unchecked. Long-lived sessions are now an explicit opt-in rather than the silent default.",{"type":21,"tag":40,"props":211,"children":212},{},[213,218],{"type":21,"tag":44,"props":214,"children":215},{},[216],{"type":26,"value":217},"TOTP login fix",{"type":26,"value":219}," — Two-factor login was being rejected by the API interceptor before the verification request could reach the server, because the TOTP-verify endpoint wasn't in the public route list. Users with 2FA enabled can now log in without a transient \"Unauthorised\" error.",{"type":21,"tag":40,"props":221,"children":222},{},[223,228,229,235,237,243],{"type":21,"tag":44,"props":224,"children":225},{},[226],{"type":26,"value":227},"Email verification fixes",{"type":26,"value":140},{"type":21,"tag":142,"props":230,"children":232},{"className":231},[],[233],{"type":26,"value":234},"verify-code",{"type":26,"value":236}," and ",{"type":21,"tag":142,"props":238,"children":240},{"className":239},[],[241],{"type":26,"value":242},"resend-verification",{"type":26,"value":244}," were treated as public endpoints, which interacted badly with rate-limiting and session continuity for users who'd partially registered. They now flow through the authenticated path, so verification works correctly on first try.",{"type":21,"tag":29,"props":246,"children":248},{"id":247},"bug-fixes",[249],{"type":26,"value":250},"Bug Fixes",{"type":21,"tag":36,"props":252,"children":253},{},[254,272,298,308],{"type":21,"tag":40,"props":255,"children":256},{},[257,262,264,270],{"type":21,"tag":44,"props":258,"children":259},{},[260],{"type":26,"value":261},"Training auto-assign computed due dates in the past",{"type":26,"value":263}," — When a training requirement was created with a \"due X days from hire date\" rule, the auto-assign logic could resolve a ",{"type":21,"tag":142,"props":265,"children":267},{"className":266},[],[268],{"type":26,"value":269},"dueDate",{"type":26,"value":271}," earlier than today for new hires whose hire date was already past the offset window. The check is now resolved against \"today in the org's timezone\" so brand-new requirements assigned to existing employees get sensible due dates instead of arriving pre-overdue.",{"type":21,"tag":40,"props":273,"children":274},{},[275,280,282,288,290,296],{"type":21,"tag":44,"props":276,"children":277},{},[278],{"type":26,"value":279},"PDF receipts wouldn't render in some browsers",{"type":26,"value":281}," — A stricter X-Frame-Options policy (",{"type":21,"tag":142,"props":283,"children":285},{"className":284},[],[286],{"type":26,"value":287},"DENY",{"type":26,"value":289},") was preventing inline PDF receipt previews from rendering inside the app on Safari and a few Chrome configurations. Relaxed to ",{"type":21,"tag":142,"props":291,"children":293},{"className":292},[],[294],{"type":26,"value":295},"SAMEORIGIN",{"type":26,"value":297}," so receipts preview correctly without weakening cross-site protection.",{"type":21,"tag":40,"props":299,"children":300},{},[301,306],{"type":21,"tag":44,"props":302,"children":303},{},[304],{"type":26,"value":305},"Rapid back-to-back document deletes left a stale row",{"type":26,"value":307}," — See \"Onboarding Documents\" above. Two deletes in quick succession could leave a phantom row visible until the next refresh; the list now reconciles after each response.",{"type":21,"tag":40,"props":309,"children":310},{},[311,316],{"type":21,"tag":44,"props":312,"children":313},{},[314],{"type":26,"value":315},"Outlook for Windows email logo size",{"type":26,"value":317}," — See \"Document Signing\" above.",1790889964909]