[{"data":1,"prerenderedAt":762},["ShallowReactive",2],{"$f164ai2dk0xojf":3,"mdc-qgn2v2-key":15},{"release":4,"newer":10,"older":12,"page":14},{"tag":5,"name":5,"publishedAt":6,"url":7,"prerelease":8,"markdown":9},"v1.0.16","2026-06-29T03:59:19Z","https:\u002F\u002Fgithub.com\u002Fanhourtec\u002FBookYourPTO-SaaS\u002Freleases\u002Ftag\u002Fv1.0.16",false,"### Document E-Signatures, a Reworked Time-Tracking Suite, a Redesigned Profile, and a Big Security Pass\r\n\r\nThis is a large release. The headline is **document e-signatures** — you can now route a document (or a finalized timesheet) for a dated, audit-trailed signature without leaving the app. Around it, the **time-tracking suite** was substantially reworked (period timesheets that finalize into a signable PDF, configurable approval routing, a guided setup wizard, multi-day manual entry, and a live Team Status board), the **profile page** was rebuilt in a tabbed, HR-suite-style layout, **documents and onboarding documents** got a design refresh, and we closed **every open dependency advisory (25 → 0)** alongside a round of CSP and SSRF hardening.\r\n\r\n### New Features\r\n\r\n- **Document e-signatures** — Documents can be sent for signature with field placement, sequential or parallel multi-signer ordering, per-signer due dates, a SHA-256 content hash, a multi-signer completion certificate, and a full audit trail, all stored encrypted. Signers are notified in-app and by email at each step. The signing UI deliberately avoids ESIGN-Act \u002F \"legally binding\" language.\r\n\r\n- **Period timesheets that finalize into a signable document** — Time entries now roll up into a **period timesheet** (weekly \u002F biweekly \u002F semi-monthly \u002F monthly) with an `OPEN → SUBMITTED → APPROVED → FINALIZED → SIGNED` lifecycle. When a manager finalizes a period, the system generates a complete, branded timesheet PDF (daily breakdown, regular\u002Fovertime\u002Fbreak\u002Fleave\u002Fholiday totals, pay snapshot) and routes it into `\u002Fdocuments` for a dated e-signature, reusing the same signing pipeline. Finalizing also advances the payroll lockdown window.\r\n\r\n- **Configurable timesheet approval routing** — A new **Approval routing** setting decides who signs a finalized timesheet: **No signature** (finalize straight to payroll), **Single approver** (one chosen person signs every sheet), or **Department head** (routes to the employee's department head, escalating to a chosen approver for heads\u002Fadmins). Routing is paired with a separate \"who signs\" order (employee, approver, or employee-then-approver) and a per-signer signing window.\r\n\r\n- **Time Clock setup wizard** — Admins and executives get a guided, three-step setup on `\u002Ftime-tracking` (opened from a \"Time clock setup\" button): the **payroll cycle** (week start, cycle, period anchor), **location tracking** (capture clock-in\u002Fout location, or off), and **what time is tracked against** (nothing, projects, or projects and tasks — wired to the real Projects\u002FTasks system). It writes straight to the existing settings.\r\n\r\n- **Multi-day and break-aware manual time entry** — The Add\u002FEdit time-entry panel now supports an unpaid **break** (subtracted from the worked total) and a **Multiple days** mode that stamps one time-of-day across a weekday-filtered date range — one entry per employee per selected day, instead of adding days one at a time.\r\n\r\n- **Team Status board** — A manager-only board (`\u002Ftime-tracking\u002Fteam`) showing who is on shift right now: a live \"who's working\" list, a full-width GPS map with a marker per clocked-in user (using their real profile photo), clock-in address and elapsed time, plus an \"Everyone\" roster with today's hours.\r\n\r\n- **Redesigned profile page** — The profile was rebuilt as a tabbed, HR-suite-style layout (Personal, Job, Time Off, Documents, Performance, and more) for a far richer, more navigable employee record.\r\n\r\n- **Onboarding documents** — New hires can be assigned documents to read and sign as part of onboarding, tracked to completion.\r\n\r\n- **Per-diem provided meals** — Individual per-diem meals (breakfast, lunch, dinner) can be marked as provided rather than reimbursed, each with its own source (third party, company card, or a colleague), and the provided meal's value is deducted from that day's per-diem. Providers are managed per-meal in expense settings, and the per-diem grid lets a bookkeeper set the provider per meal per day.\r\n\r\n- **Guided workspace setup checklist** — New organizations get a dismissible \"Finish setting up your workspace\" card on the dashboard, visible to administrators and executives only, that tracks four quick settings: timezone & business days, public-holiday location, leave types, and expenses & per-diem. Each step's status is auto-detected from real configuration. Crucially, settings we pre-fill at sign-up (timezone, a starter set of leave types, default expense rates) are surfaced as **\"pre-filled — review\"** with a one-click **Looks good** confirmation rather than silently shown as complete, so the values we guessed actually get verified before they count as done. The progress bar reflects only confirmed steps. The first-run welcome dialog and the product tour are now sequenced so they never appear at the same time — the profile dialog comes first, then the tour on the next dashboard load.\r\n\r\n### Improvements\r\n\r\n- **Documents design refresh** — The documents experience was reorganized (Inbox \u002F Sent \u002F Action Required style surfacing) so it's clearer what needs your signature versus what you've sent.\r\n\r\n- **Row actions consolidated into an ellipsis menu** — Timesheet finalization rows now use a compact ellipsis action menu (Submit \u002F Approve \u002F Reject \u002F Finalize & send \u002F Finalize only \u002F View document) instead of a row of buttons, which also reads cleanly on mobile.\r\n\r\n- **Finalize actions follow the auto-send setting** — When the org has \"Automatically send finalized timesheets for signature\" enabled, finalizing is a single **Finalize & send** action (it always routes for signature). With auto-send off, both **Finalize & send** and **Finalize only** are offered so a manager can choose per timesheet, and the two are genuinely distinct — \"Finalize only\" never sends. With no signature configured, a single **Finalize for payroll**.\r\n\r\n- **Finalized timesheets file into a Timesheets folder** — A signed\u002Ffinalized timesheet PDF now appears in a dedicated **Timesheets** folder under `\u002Fdocuments` (it was previously only findable via search), and the folder shows a live count. The category is system-managed, so it isn't offered as a manual upload option.\r\n\r\n- **Geofencing available on Pro and above** — Plan limits were updated so geofencing is included from Pro upward.\r\n\r\n- **Faster, reliable approvals counts** — The pending-approvals badge cache is now busted immediately on approve\u002Freject, and `\u002Fapi\u002Fapprovals\u002Fcounts` is scoped to the caller's approval rights.\r\n\r\n- **Referral tracking** — Referral attribution now captures the `?via=` parameter and persists it via cookie fallback.\r\n\r\n- **Per-diem bookkeeper summary** — The per-diem display was rebuilt as a per-day summary that reads cleanly for bookkeepers, showing each day's meals, their provided\u002Fexcluded status, and the amount actually paid.\r\n\r\n- **Redesigned travel route entry** — The travel and mileage route entry was redesigned to resemble a turn-by-turn directions view, with address autocomplete that falls back to a plain text input when autocomplete isn't available.\r\n\r\n- **View Audit Trail from any folder** — Administrators, executives, and department heads get a \"View Audit Trail\" row action on every document folder, opening the document with its History expanded. Previously the trail was only reachable from the Sent view.\r\n\r\n- **Compact document audit trail** — The History timeline is now a fixed-height scroll area and collapses repeated views by the same person into a single counted row, so a heavily-opened document no longer stretches the detail page.\r\n\r\n- **Upload defaults to signing** — The document upload entry points open the send-for-signature flow by default; filing to a folder stays available via the mode toggle or a `?mode=store` link.\r\n\r\n- **Per-recipient field placement** — The signing-field placer no longer forces signature\u002Finitials parity across signers; it only requires that each recipient has at least one field, and it previews the burned-in \"Signed by\" label and timestamp around placed signature and initials boxes.\r\n\r\n- **Themed sidebar counts** — The sidebar count badges (Approvals, Action Required, and others) now use the primary color instead of amber.\r\n\r\n- **Currency-neutral expense settings** — The expense per-diem and rate fields now offer a full list of world currencies (up from four) and render the selected currency's symbol live across every input and the per-diem section heading. Region-specific guidance copy was removed so the defaults read neutrally for any organization, wherever it operates.\r\n\r\n### Responsive layout\r\n\r\n- **Tables no longer overlap their headers on small screens** — Wide data tables (approvals, expenses, timesheets, documents, projects, security logs, and more) compressed their fixed columns on narrow viewports until the header labels overlapped. They now keep a minimum width and scroll horizontally instead, with non-wrapping headers; desktop is unchanged.\r\n\r\n- **Create\u002FEdit Shift opens as a side drawer** — Scheduling a shift now opens a right-side push drawer (matching the time-entry panel) that sits beside the page and collapses the sidebar, rather than a centered modal over the content.\r\n\r\n- **Sidebar no longer flickers on resize** — Crossing the desktop\u002Fmobile breakpoint used to briefly animate the sidebar into a broken-looking state; layout transitions are now suppressed while the window is actively resizing.\r\n\r\n### Security\r\n\r\n- **All dependency advisories closed (25 → 0)** — A sweep of dependency vulnerabilities brought the dependency audit to zero, including switching the PDF rendering library to its legacy build, hardening the PDF worker CSP, and patching an HTTP-client SSRF advisory.\r\n\r\n- **CSP and framing hardening** — The web analytics script was added to the CSP `script-src`\u002F`connect-src`; `X-Frame-Options` was relaxed to `SAMEORIGIN` so in-app PDF receipts render; the PDF worker runs under a tightened policy.\r\n\r\n- **Tighter notification and approval scoping** — Leave-submission notifications are scoped to the submitter's department, and approval counts to the caller's rights, so neither leaks cross-team activity.\r\n\r\n- **Safer defaults** — \"Remember me\" now defaults to off at login.\r\n\r\n- **Administrators can view security logs** — Audit-log, sign-in-log, and leave-transaction views (and their exports) are now open to administrators as well as executives, all strictly org-scoped.\r\n\r\n- **Sequential signing visibility** — In sequential signing, a later signer whose turn hadn't come could view and list the document (including its fields and stored signature data) before the earlier signer signed. Not-yet-their-turn assignments are now excluded from every document read path; administrators, owners, and uploaders are unaffected.\r\n\r\n- **No signing on another user's behalf** — Administrators can open any assignment for monitoring, but the signing page presented the full fill-and-sign UI for it. Non-assignees are now redirected to the read-only document view; the sign endpoint already rejected the submission server-side.\r\n\r\n### Bug Fixes\r\n\r\n- **Role changes apply immediately** — Promotions, demotions, and deactivations now take effect on the user's next request instead of waiting up to the access-token lifetime, and a role change no longer forces a disruptive re-login.\r\n\r\n- **Timesheet PDF period dates** — The period header on the generated timesheet renders the calendar boundaries in UTC so a \"May 18 – May 31\" period never shifts a day for a reader in another timezone.\r\n\r\n- **Timesheet signature\u002Fdate alignment** — On the generated timesheet, the signature image and date were landing below the Signature\u002FDate lines because the signing fields were placed at a fixed position while the lines move with the number of entries. The fields are now positioned to the actual drawn lines (and on the correct page for multi-page timesheets). Applies to timesheets finalized after this release.\r\n\r\n- **Schedule week-clear fix** — Clearing a published week referenced a non-existent model and threw at runtime; it now uses the correct schedule-publication record with timezone-aware week matching.\r\n\r\n- **Training auto-assignment timing** — Corrected a comparison in the training auto-assign scheduler that mis-evaluated due windows.\r\n\r\n- **Off-by-one expense dates** — The expense detail and overview views rendered some calendar-day fields a day early in timezones west of UTC; they now read the stored UTC day correctly.\r\n\r\n- **Initials-only signers couldn't sign** — A signer asked only to initial (with no signature field) submitted an empty signature and was rejected with a 400; the signing flow now uses the initials image as the signature.\r\n\r\n- **Right-panel space released on navigation** — Leaving a page with an open right-side push drawer (for example a schedule or timesheet entry) without closing it left the reserved content-shell width behind; it is now released when the page unmounts.",{"tag":11,"name":11},"v1.0.17",{"tag":13,"name":13},"v1.0.15",1,{"data":16,"body":17},{},{"type":18,"children":19},"root",[20,29,71,77,299,305,523,529,562,568,673,679],{"type":21,"tag":22,"props":23,"children":25},"element","h3",{"id":24},"document-e-signatures-a-reworked-time-tracking-suite-a-redesigned-profile-and-a-big-security-pass",[26],{"type":27,"value":28},"text","Document E-Signatures, a Reworked Time-Tracking Suite, a Redesigned Profile, and a Big Security Pass",{"type":21,"tag":30,"props":31,"children":32},"p",{},[33,35,41,43,48,50,55,57,62,64,69],{"type":27,"value":34},"This is a large release. The headline is ",{"type":21,"tag":36,"props":37,"children":38},"strong",{},[39],{"type":27,"value":40},"document e-signatures",{"type":27,"value":42}," — you can now route a document (or a finalized timesheet) for a dated, audit-trailed signature without leaving the app. Around it, the ",{"type":21,"tag":36,"props":44,"children":45},{},[46],{"type":27,"value":47},"time-tracking suite",{"type":27,"value":49}," was substantially reworked (period timesheets that finalize into a signable PDF, configurable approval routing, a guided setup wizard, multi-day manual entry, and a live Team Status board), the ",{"type":21,"tag":36,"props":51,"children":52},{},[53],{"type":27,"value":54},"profile page",{"type":27,"value":56}," was rebuilt in a tabbed, HR-suite-style layout, ",{"type":21,"tag":36,"props":58,"children":59},{},[60],{"type":27,"value":61},"documents and onboarding documents",{"type":27,"value":63}," got a design refresh, and we closed ",{"type":21,"tag":36,"props":65,"children":66},{},[67],{"type":27,"value":68},"every open dependency advisory (25 → 0)",{"type":27,"value":70}," alongside a round of CSP and SSRF hardening.",{"type":21,"tag":22,"props":72,"children":74},{"id":73},"new-features",[75],{"type":27,"value":76},"New Features",{"type":21,"tag":78,"props":79,"children":80},"ul",{},[81,92,126,164,203,227,245,255,265,275],{"type":21,"tag":82,"props":83,"children":84},"li",{},[85,90],{"type":21,"tag":36,"props":86,"children":87},{},[88],{"type":27,"value":89},"Document e-signatures",{"type":27,"value":91}," — Documents can be sent for signature with field placement, sequential or parallel multi-signer ordering, per-signer due dates, a SHA-256 content hash, a multi-signer completion certificate, and a full audit trail, all stored encrypted. Signers are notified in-app and by email at each step. The signing UI deliberately avoids ESIGN-Act \u002F \"legally binding\" language.",{"type":21,"tag":82,"props":93,"children":94},{},[95,100,102,107,109,116,118,124],{"type":21,"tag":36,"props":96,"children":97},{},[98],{"type":27,"value":99},"Period timesheets that finalize into a signable document",{"type":27,"value":101}," — Time entries now roll up into a ",{"type":21,"tag":36,"props":103,"children":104},{},[105],{"type":27,"value":106},"period timesheet",{"type":27,"value":108}," (weekly \u002F biweekly \u002F semi-monthly \u002F monthly) with an ",{"type":21,"tag":110,"props":111,"children":113},"code",{"className":112},[],[114],{"type":27,"value":115},"OPEN → SUBMITTED → APPROVED → FINALIZED → SIGNED",{"type":27,"value":117}," lifecycle. When a manager finalizes a period, the system generates a complete, branded timesheet PDF (daily breakdown, regular\u002Fovertime\u002Fbreak\u002Fleave\u002Fholiday totals, pay snapshot) and routes it into ",{"type":21,"tag":110,"props":119,"children":121},{"className":120},[],[122],{"type":27,"value":123},"\u002Fdocuments",{"type":27,"value":125}," for a dated e-signature, reusing the same signing pipeline. Finalizing also advances the payroll lockdown window.",{"type":21,"tag":82,"props":127,"children":128},{},[129,134,136,141,143,148,150,155,157,162],{"type":21,"tag":36,"props":130,"children":131},{},[132],{"type":27,"value":133},"Configurable timesheet approval routing",{"type":27,"value":135}," — A new ",{"type":21,"tag":36,"props":137,"children":138},{},[139],{"type":27,"value":140},"Approval routing",{"type":27,"value":142}," setting decides who signs a finalized timesheet: ",{"type":21,"tag":36,"props":144,"children":145},{},[146],{"type":27,"value":147},"No signature",{"type":27,"value":149}," (finalize straight to payroll), ",{"type":21,"tag":36,"props":151,"children":152},{},[153],{"type":27,"value":154},"Single approver",{"type":27,"value":156}," (one chosen person signs every sheet), or ",{"type":21,"tag":36,"props":158,"children":159},{},[160],{"type":27,"value":161},"Department head",{"type":27,"value":163}," (routes to the employee's department head, escalating to a chosen approver for heads\u002Fadmins). Routing is paired with a separate \"who signs\" order (employee, approver, or employee-then-approver) and a per-signer signing window.",{"type":21,"tag":82,"props":165,"children":166},{},[167,172,174,180,182,187,189,194,196,201],{"type":21,"tag":36,"props":168,"children":169},{},[170],{"type":27,"value":171},"Time Clock setup wizard",{"type":27,"value":173}," — Admins and executives get a guided, three-step setup on ",{"type":21,"tag":110,"props":175,"children":177},{"className":176},[],[178],{"type":27,"value":179},"\u002Ftime-tracking",{"type":27,"value":181}," (opened from a \"Time clock setup\" button): the ",{"type":21,"tag":36,"props":183,"children":184},{},[185],{"type":27,"value":186},"payroll cycle",{"type":27,"value":188}," (week start, cycle, period anchor), ",{"type":21,"tag":36,"props":190,"children":191},{},[192],{"type":27,"value":193},"location tracking",{"type":27,"value":195}," (capture clock-in\u002Fout location, or off), and ",{"type":21,"tag":36,"props":197,"children":198},{},[199],{"type":27,"value":200},"what time is tracked against",{"type":27,"value":202}," (nothing, projects, or projects and tasks — wired to the real Projects\u002FTasks system). It writes straight to the existing settings.",{"type":21,"tag":82,"props":204,"children":205},{},[206,211,213,218,220,225],{"type":21,"tag":36,"props":207,"children":208},{},[209],{"type":27,"value":210},"Multi-day and break-aware manual time entry",{"type":27,"value":212}," — The Add\u002FEdit time-entry panel now supports an unpaid ",{"type":21,"tag":36,"props":214,"children":215},{},[216],{"type":27,"value":217},"break",{"type":27,"value":219}," (subtracted from the worked total) and a ",{"type":21,"tag":36,"props":221,"children":222},{},[223],{"type":27,"value":224},"Multiple days",{"type":27,"value":226}," mode that stamps one time-of-day across a weekday-filtered date range — one entry per employee per selected day, instead of adding days one at a time.",{"type":21,"tag":82,"props":228,"children":229},{},[230,235,237,243],{"type":21,"tag":36,"props":231,"children":232},{},[233],{"type":27,"value":234},"Team Status board",{"type":27,"value":236}," — A manager-only board (",{"type":21,"tag":110,"props":238,"children":240},{"className":239},[],[241],{"type":27,"value":242},"\u002Ftime-tracking\u002Fteam",{"type":27,"value":244},") showing who is on shift right now: a live \"who's working\" list, a full-width GPS map with a marker per clocked-in user (using their real profile photo), clock-in address and elapsed time, plus an \"Everyone\" roster with today's hours.",{"type":21,"tag":82,"props":246,"children":247},{},[248,253],{"type":21,"tag":36,"props":249,"children":250},{},[251],{"type":27,"value":252},"Redesigned profile page",{"type":27,"value":254}," — The profile was rebuilt as a tabbed, HR-suite-style layout (Personal, Job, Time Off, Documents, Performance, and more) for a far richer, more navigable employee record.",{"type":21,"tag":82,"props":256,"children":257},{},[258,263],{"type":21,"tag":36,"props":259,"children":260},{},[261],{"type":27,"value":262},"Onboarding documents",{"type":27,"value":264}," — New hires can be assigned documents to read and sign as part of onboarding, tracked to completion.",{"type":21,"tag":82,"props":266,"children":267},{},[268,273],{"type":21,"tag":36,"props":269,"children":270},{},[271],{"type":27,"value":272},"Per-diem provided meals",{"type":27,"value":274}," — Individual per-diem meals (breakfast, lunch, dinner) can be marked as provided rather than reimbursed, each with its own source (third party, company card, or a colleague), and the provided meal's value is deducted from that day's per-diem. Providers are managed per-meal in expense settings, and the per-diem grid lets a bookkeeper set the provider per meal per day.",{"type":21,"tag":82,"props":276,"children":277},{},[278,283,285,290,292,297],{"type":21,"tag":36,"props":279,"children":280},{},[281],{"type":27,"value":282},"Guided workspace setup checklist",{"type":27,"value":284}," — New organizations get a dismissible \"Finish setting up your workspace\" card on the dashboard, visible to administrators and executives only, that tracks four quick settings: timezone & business days, public-holiday location, leave types, and expenses & per-diem. Each step's status is auto-detected from real configuration. Crucially, settings we pre-fill at sign-up (timezone, a starter set of leave types, default expense rates) are surfaced as ",{"type":21,"tag":36,"props":286,"children":287},{},[288],{"type":27,"value":289},"\"pre-filled — review\"",{"type":27,"value":291}," with a one-click ",{"type":21,"tag":36,"props":293,"children":294},{},[295],{"type":27,"value":296},"Looks good",{"type":27,"value":298}," confirmation rather than silently shown as complete, so the values we guessed actually get verified before they count as done. The progress bar reflects only confirmed steps. The first-run welcome dialog and the product tour are now sequenced so they never appear at the same time — the profile dialog comes first, then the tour on the next dashboard load.",{"type":21,"tag":22,"props":300,"children":302},{"id":301},"improvements",[303],{"type":27,"value":304},"Improvements",{"type":21,"tag":78,"props":306,"children":307},{},[308,318,328,365,389,399,417,435,445,455,465,475,493,503,513],{"type":21,"tag":82,"props":309,"children":310},{},[311,316],{"type":21,"tag":36,"props":312,"children":313},{},[314],{"type":27,"value":315},"Documents design refresh",{"type":27,"value":317}," — The documents experience was reorganized (Inbox \u002F Sent \u002F Action Required style surfacing) so it's clearer what needs your signature versus what you've sent.",{"type":21,"tag":82,"props":319,"children":320},{},[321,326],{"type":21,"tag":36,"props":322,"children":323},{},[324],{"type":27,"value":325},"Row actions consolidated into an ellipsis menu",{"type":27,"value":327}," — Timesheet finalization rows now use a compact ellipsis action menu (Submit \u002F Approve \u002F Reject \u002F Finalize & send \u002F Finalize only \u002F View document) instead of a row of buttons, which also reads cleanly on mobile.",{"type":21,"tag":82,"props":329,"children":330},{},[331,336,338,343,345,349,351,356,358,363],{"type":21,"tag":36,"props":332,"children":333},{},[334],{"type":27,"value":335},"Finalize actions follow the auto-send setting",{"type":27,"value":337}," — When the org has \"Automatically send finalized timesheets for signature\" enabled, finalizing is a single ",{"type":21,"tag":36,"props":339,"children":340},{},[341],{"type":27,"value":342},"Finalize & send",{"type":27,"value":344}," action (it always routes for signature). With auto-send off, both ",{"type":21,"tag":36,"props":346,"children":347},{},[348],{"type":27,"value":342},{"type":27,"value":350}," and ",{"type":21,"tag":36,"props":352,"children":353},{},[354],{"type":27,"value":355},"Finalize only",{"type":27,"value":357}," are offered so a manager can choose per timesheet, and the two are genuinely distinct — \"Finalize only\" never sends. With no signature configured, a single ",{"type":21,"tag":36,"props":359,"children":360},{},[361],{"type":27,"value":362},"Finalize for payroll",{"type":27,"value":364},".",{"type":21,"tag":82,"props":366,"children":367},{},[368,373,375,380,382,387],{"type":21,"tag":36,"props":369,"children":370},{},[371],{"type":27,"value":372},"Finalized timesheets file into a Timesheets folder",{"type":27,"value":374}," — A signed\u002Ffinalized timesheet PDF now appears in a dedicated ",{"type":21,"tag":36,"props":376,"children":377},{},[378],{"type":27,"value":379},"Timesheets",{"type":27,"value":381}," folder under ",{"type":21,"tag":110,"props":383,"children":385},{"className":384},[],[386],{"type":27,"value":123},{"type":27,"value":388}," (it was previously only findable via search), and the folder shows a live count. The category is system-managed, so it isn't offered as a manual upload option.",{"type":21,"tag":82,"props":390,"children":391},{},[392,397],{"type":21,"tag":36,"props":393,"children":394},{},[395],{"type":27,"value":396},"Geofencing available on Pro and above",{"type":27,"value":398}," — Plan limits were updated so geofencing is included from Pro upward.",{"type":21,"tag":82,"props":400,"children":401},{},[402,407,409,415],{"type":21,"tag":36,"props":403,"children":404},{},[405],{"type":27,"value":406},"Faster, reliable approvals counts",{"type":27,"value":408}," — The pending-approvals badge cache is now busted immediately on approve\u002Freject, and ",{"type":21,"tag":110,"props":410,"children":412},{"className":411},[],[413],{"type":27,"value":414},"\u002Fapi\u002Fapprovals\u002Fcounts",{"type":27,"value":416}," is scoped to the caller's approval rights.",{"type":21,"tag":82,"props":418,"children":419},{},[420,425,427,433],{"type":21,"tag":36,"props":421,"children":422},{},[423],{"type":27,"value":424},"Referral tracking",{"type":27,"value":426}," — Referral attribution now captures the ",{"type":21,"tag":110,"props":428,"children":430},{"className":429},[],[431],{"type":27,"value":432},"?via=",{"type":27,"value":434}," parameter and persists it via cookie fallback.",{"type":21,"tag":82,"props":436,"children":437},{},[438,443],{"type":21,"tag":36,"props":439,"children":440},{},[441],{"type":27,"value":442},"Per-diem bookkeeper summary",{"type":27,"value":444}," — The per-diem display was rebuilt as a per-day summary that reads cleanly for bookkeepers, showing each day's meals, their provided\u002Fexcluded status, and the amount actually paid.",{"type":21,"tag":82,"props":446,"children":447},{},[448,453],{"type":21,"tag":36,"props":449,"children":450},{},[451],{"type":27,"value":452},"Redesigned travel route entry",{"type":27,"value":454}," — The travel and mileage route entry was redesigned to resemble a turn-by-turn directions view, with address autocomplete that falls back to a plain text input when autocomplete isn't available.",{"type":21,"tag":82,"props":456,"children":457},{},[458,463],{"type":21,"tag":36,"props":459,"children":460},{},[461],{"type":27,"value":462},"View Audit Trail from any folder",{"type":27,"value":464}," — Administrators, executives, and department heads get a \"View Audit Trail\" row action on every document folder, opening the document with its History expanded. Previously the trail was only reachable from the Sent view.",{"type":21,"tag":82,"props":466,"children":467},{},[468,473],{"type":21,"tag":36,"props":469,"children":470},{},[471],{"type":27,"value":472},"Compact document audit trail",{"type":27,"value":474}," — The History timeline is now a fixed-height scroll area and collapses repeated views by the same person into a single counted row, so a heavily-opened document no longer stretches the detail page.",{"type":21,"tag":82,"props":476,"children":477},{},[478,483,485,491],{"type":21,"tag":36,"props":479,"children":480},{},[481],{"type":27,"value":482},"Upload defaults to signing",{"type":27,"value":484}," — The document upload entry points open the send-for-signature flow by default; filing to a folder stays available via the mode toggle or a ",{"type":21,"tag":110,"props":486,"children":488},{"className":487},[],[489],{"type":27,"value":490},"?mode=store",{"type":27,"value":492}," link.",{"type":21,"tag":82,"props":494,"children":495},{},[496,501],{"type":21,"tag":36,"props":497,"children":498},{},[499],{"type":27,"value":500},"Per-recipient field placement",{"type":27,"value":502}," — The signing-field placer no longer forces signature\u002Finitials parity across signers; it only requires that each recipient has at least one field, and it previews the burned-in \"Signed by\" label and timestamp around placed signature and initials boxes.",{"type":21,"tag":82,"props":504,"children":505},{},[506,511],{"type":21,"tag":36,"props":507,"children":508},{},[509],{"type":27,"value":510},"Themed sidebar counts",{"type":27,"value":512}," — The sidebar count badges (Approvals, Action Required, and others) now use the primary color instead of amber.",{"type":21,"tag":82,"props":514,"children":515},{},[516,521],{"type":21,"tag":36,"props":517,"children":518},{},[519],{"type":27,"value":520},"Currency-neutral expense settings",{"type":27,"value":522}," — The expense per-diem and rate fields now offer a full list of world currencies (up from four) and render the selected currency's symbol live across every input and the per-diem section heading. Region-specific guidance copy was removed so the defaults read neutrally for any organization, wherever it operates.",{"type":21,"tag":22,"props":524,"children":526},{"id":525},"responsive-layout",[527],{"type":27,"value":528},"Responsive layout",{"type":21,"tag":78,"props":530,"children":531},{},[532,542,552],{"type":21,"tag":82,"props":533,"children":534},{},[535,540],{"type":21,"tag":36,"props":536,"children":537},{},[538],{"type":27,"value":539},"Tables no longer overlap their headers on small screens",{"type":27,"value":541}," — Wide data tables (approvals, expenses, timesheets, documents, projects, security logs, and more) compressed their fixed columns on narrow viewports until the header labels overlapped. They now keep a minimum width and scroll horizontally instead, with non-wrapping headers; desktop is unchanged.",{"type":21,"tag":82,"props":543,"children":544},{},[545,550],{"type":21,"tag":36,"props":546,"children":547},{},[548],{"type":27,"value":549},"Create\u002FEdit Shift opens as a side drawer",{"type":27,"value":551}," — Scheduling a shift now opens a right-side push drawer (matching the time-entry panel) that sits beside the page and collapses the sidebar, rather than a centered modal over the content.",{"type":21,"tag":82,"props":553,"children":554},{},[555,560],{"type":21,"tag":36,"props":556,"children":557},{},[558],{"type":27,"value":559},"Sidebar no longer flickers on resize",{"type":27,"value":561}," — Crossing the desktop\u002Fmobile breakpoint used to briefly animate the sidebar into a broken-looking state; layout transitions are now suppressed while the window is actively resizing.",{"type":21,"tag":22,"props":563,"children":565},{"id":564},"security",[566],{"type":27,"value":567},"Security",{"type":21,"tag":78,"props":569,"children":570},{},[571,581,623,633,643,653,663],{"type":21,"tag":82,"props":572,"children":573},{},[574,579],{"type":21,"tag":36,"props":575,"children":576},{},[577],{"type":27,"value":578},"All dependency advisories closed (25 → 0)",{"type":27,"value":580}," — A sweep of dependency vulnerabilities brought the dependency audit to zero, including switching the PDF rendering library to its legacy build, hardening the PDF worker CSP, and patching an HTTP-client SSRF advisory.",{"type":21,"tag":82,"props":582,"children":583},{},[584,589,591,597,599,605,607,613,615,621],{"type":21,"tag":36,"props":585,"children":586},{},[587],{"type":27,"value":588},"CSP and framing hardening",{"type":27,"value":590}," — The web analytics script was added to the CSP ",{"type":21,"tag":110,"props":592,"children":594},{"className":593},[],[595],{"type":27,"value":596},"script-src",{"type":27,"value":598},"\u002F",{"type":21,"tag":110,"props":600,"children":602},{"className":601},[],[603],{"type":27,"value":604},"connect-src",{"type":27,"value":606},"; ",{"type":21,"tag":110,"props":608,"children":610},{"className":609},[],[611],{"type":27,"value":612},"X-Frame-Options",{"type":27,"value":614}," was relaxed to ",{"type":21,"tag":110,"props":616,"children":618},{"className":617},[],[619],{"type":27,"value":620},"SAMEORIGIN",{"type":27,"value":622}," so in-app PDF receipts render; the PDF worker runs under a tightened policy.",{"type":21,"tag":82,"props":624,"children":625},{},[626,631],{"type":21,"tag":36,"props":627,"children":628},{},[629],{"type":27,"value":630},"Tighter notification and approval scoping",{"type":27,"value":632}," — Leave-submission notifications are scoped to the submitter's department, and approval counts to the caller's rights, so neither leaks cross-team activity.",{"type":21,"tag":82,"props":634,"children":635},{},[636,641],{"type":21,"tag":36,"props":637,"children":638},{},[639],{"type":27,"value":640},"Safer defaults",{"type":27,"value":642}," — \"Remember me\" now defaults to off at login.",{"type":21,"tag":82,"props":644,"children":645},{},[646,651],{"type":21,"tag":36,"props":647,"children":648},{},[649],{"type":27,"value":650},"Administrators can view security logs",{"type":27,"value":652}," — Audit-log, sign-in-log, and leave-transaction views (and their exports) are now open to administrators as well as executives, all strictly org-scoped.",{"type":21,"tag":82,"props":654,"children":655},{},[656,661],{"type":21,"tag":36,"props":657,"children":658},{},[659],{"type":27,"value":660},"Sequential signing visibility",{"type":27,"value":662}," — In sequential signing, a later signer whose turn hadn't come could view and list the document (including its fields and stored signature data) before the earlier signer signed. Not-yet-their-turn assignments are now excluded from every document read path; administrators, owners, and uploaders are unaffected.",{"type":21,"tag":82,"props":664,"children":665},{},[666,671],{"type":21,"tag":36,"props":667,"children":668},{},[669],{"type":27,"value":670},"No signing on another user's behalf",{"type":27,"value":672}," — Administrators can open any assignment for monitoring, but the signing page presented the full fill-and-sign UI for it. Non-assignees are now redirected to the read-only document view; the sign endpoint already rejected the submission server-side.",{"type":21,"tag":22,"props":674,"children":676},{"id":675},"bug-fixes",[677],{"type":27,"value":678},"Bug Fixes",{"type":21,"tag":78,"props":680,"children":681},{},[682,692,702,712,722,732,742,752],{"type":21,"tag":82,"props":683,"children":684},{},[685,690],{"type":21,"tag":36,"props":686,"children":687},{},[688],{"type":27,"value":689},"Role changes apply immediately",{"type":27,"value":691}," — Promotions, demotions, and deactivations now take effect on the user's next request instead of waiting up to the access-token lifetime, and a role change no longer forces a disruptive re-login.",{"type":21,"tag":82,"props":693,"children":694},{},[695,700],{"type":21,"tag":36,"props":696,"children":697},{},[698],{"type":27,"value":699},"Timesheet PDF period dates",{"type":27,"value":701}," — The period header on the generated timesheet renders the calendar boundaries in UTC so a \"May 18 – May 31\" period never shifts a day for a reader in another timezone.",{"type":21,"tag":82,"props":703,"children":704},{},[705,710],{"type":21,"tag":36,"props":706,"children":707},{},[708],{"type":27,"value":709},"Timesheet signature\u002Fdate alignment",{"type":27,"value":711}," — On the generated timesheet, the signature image and date were landing below the Signature\u002FDate lines because the signing fields were placed at a fixed position while the lines move with the number of entries. The fields are now positioned to the actual drawn lines (and on the correct page for multi-page timesheets). Applies to timesheets finalized after this release.",{"type":21,"tag":82,"props":713,"children":714},{},[715,720],{"type":21,"tag":36,"props":716,"children":717},{},[718],{"type":27,"value":719},"Schedule week-clear fix",{"type":27,"value":721}," — Clearing a published week referenced a non-existent model and threw at runtime; it now uses the correct schedule-publication record with timezone-aware week matching.",{"type":21,"tag":82,"props":723,"children":724},{},[725,730],{"type":21,"tag":36,"props":726,"children":727},{},[728],{"type":27,"value":729},"Training auto-assignment timing",{"type":27,"value":731}," — Corrected a comparison in the training auto-assign scheduler that mis-evaluated due windows.",{"type":21,"tag":82,"props":733,"children":734},{},[735,740],{"type":21,"tag":36,"props":736,"children":737},{},[738],{"type":27,"value":739},"Off-by-one expense dates",{"type":27,"value":741}," — The expense detail and overview views rendered some calendar-day fields a day early in timezones west of UTC; they now read the stored UTC day correctly.",{"type":21,"tag":82,"props":743,"children":744},{},[745,750],{"type":21,"tag":36,"props":746,"children":747},{},[748],{"type":27,"value":749},"Initials-only signers couldn't sign",{"type":27,"value":751}," — A signer asked only to initial (with no signature field) submitted an empty signature and was rejected with a 400; the signing flow now uses the initials image as the signature.",{"type":21,"tag":82,"props":753,"children":754},{},[755,760],{"type":21,"tag":36,"props":756,"children":757},{},[758],{"type":27,"value":759},"Right-panel space released on navigation",{"type":27,"value":761}," — Leaving a page with an open right-side push drawer (for example a schedule or timesheet entry) without closing it left the reserved content-shell width behind; it is now released when the page unmounts.",1790889963334]