[{"data":1,"prerenderedAt":153},["ShallowReactive",2],{"$f22y9o3uskvqx1":3,"mdc--63cljj-key":15},{"release":4,"newer":10,"older":12,"page":14},{"tag":5,"name":5,"publishedAt":6,"url":7,"prerelease":8,"markdown":9},"v1.0.18","2026-07-15T05:29:23Z","https:\u002F\u002Fgithub.com\u002Fanhourtec\u002FBookYourPTO-SaaS\u002Freleases\u002Ftag\u002Fv1.0.18",false,"### Privacy hardening for leave, safer sign-in, and expense workflow polish\r\n\r\nThis release closes a set of leave-privacy gaps so a leave marked **Private** stays\r\nprivate everywhere it is surfaced — the dashboard, the calendar, the iCal feed, digest\r\nemails, and the mobile app — and tightens who can act on a cancellation request. It also\r\nhardens the sign-in forms and brings a batch of expense-workflow improvements on the web.\r\n\r\n### Privacy & Security\r\n\r\n- **Private leave stays private, end to end** — A private leave type no longer leaks its\r\n  purpose to people who shouldn't see it. Every free-text field on a leave (the reason,\r\n  notes, approver comments, and rejection \u002F cancellation reasons) is now hidden from\r\n  anyone who isn't the leave's owner, an admin\u002Fexecutive, or the owner's department head.\r\n  Previously a colleague in another department could read a private leave's cancellation\r\n  reason from the details view.\r\n\r\n- **Consistent redaction across every surface** — The same rule is now applied wherever\r\n  leaves are shown to others: the dashboard, the per-user calendar, the subscribable iCal\r\n  calendar feed, and the scheduled digest emails. A department head subscribing to a\r\n  direct-reports iCal feed no longer receives the real type name or reason of a private\r\n  leave belonging to someone outside their department.\r\n\r\n- **Cancellation review limited to the right approvers** — Approve \u002F Decline actions on a\r\n  leave cancellation are now shown only to the people actually authorized to review that\r\n  request (the owner's department head, or an admin\u002Fexecutive), on both web and mobile.\r\n\r\n- **Safer authentication forms** — The login, registration, and SSO sign-in forms now\r\n  submit explicitly over POST, and the UI library was updated to a version that guarantees\r\n  the same, so credentials can never be placed in a URL if a form is submitted before the\r\n  page finishes loading.\r\n\r\n### Expenses\r\n\r\n- **Download all receipts as a single ZIP** — Export every receipt on an expense report in\r\n  one archive instead of saving them one at a time.\r\n\r\n- **All Claims filter** — The expenses list gains an \"All Claims\" filter so you can see\r\n  every claim in one place.\r\n\r\n- **Clearer receipt uploads** — Upload prompts now list every supported receipt format, and\r\n  the claim header carries a hover help note explaining the workflow.\r\n\r\n- **Verify scanned figures** — After a receipt scan, a reminder now prompts you to confirm\r\n  the extracted amounts before submitting.\r\n\r\n- **Cleaner per-diem view** — The per-diem Actions column is hidden once a report is no\r\n  longer editable, removing controls that would not do anything.\r\n",{"tag":11,"name":11},"v1.0.19",{"tag":13,"name":13},"v1.0.17",1,{"data":16,"body":17},{},{"type":18,"children":19},"root",[20,29,43,49,94,100],{"type":21,"tag":22,"props":23,"children":25},"element","h3",{"id":24},"privacy-hardening-for-leave-safer-sign-in-and-expense-workflow-polish",[26],{"type":27,"value":28},"text","Privacy hardening for leave, safer sign-in, and expense workflow polish",{"type":21,"tag":30,"props":31,"children":32},"p",{},[33,35,41],{"type":27,"value":34},"This release closes a set of leave-privacy gaps so a leave marked ",{"type":21,"tag":36,"props":37,"children":38},"strong",{},[39],{"type":27,"value":40},"Private",{"type":27,"value":42}," stays\nprivate everywhere it is surfaced — the dashboard, the calendar, the iCal feed, digest\nemails, and the mobile app — and tightens who can act on a cancellation request. It also\nhardens the sign-in forms and brings a batch of expense-workflow improvements on the web.",{"type":21,"tag":22,"props":44,"children":46},{"id":45},"privacy-security",[47],{"type":27,"value":48},"Privacy & Security",{"type":21,"tag":50,"props":51,"children":52},"ul",{},[53,64,74,84],{"type":21,"tag":54,"props":55,"children":56},"li",{},[57,62],{"type":21,"tag":36,"props":58,"children":59},{},[60],{"type":27,"value":61},"Private leave stays private, end to end",{"type":27,"value":63}," — A private leave type no longer leaks its\npurpose to people who shouldn't see it. Every free-text field on a leave (the reason,\nnotes, approver comments, and rejection \u002F cancellation reasons) is now hidden from\nanyone who isn't the leave's owner, an admin\u002Fexecutive, or the owner's department head.\nPreviously a colleague in another department could read a private leave's cancellation\nreason from the details view.",{"type":21,"tag":54,"props":65,"children":66},{},[67,72],{"type":21,"tag":36,"props":68,"children":69},{},[70],{"type":27,"value":71},"Consistent redaction across every surface",{"type":27,"value":73}," — The same rule is now applied wherever\nleaves are shown to others: the dashboard, the per-user calendar, the subscribable iCal\ncalendar feed, and the scheduled digest emails. A department head subscribing to a\ndirect-reports iCal feed no longer receives the real type name or reason of a private\nleave belonging to someone outside their department.",{"type":21,"tag":54,"props":75,"children":76},{},[77,82],{"type":21,"tag":36,"props":78,"children":79},{},[80],{"type":27,"value":81},"Cancellation review limited to the right approvers",{"type":27,"value":83}," — Approve \u002F Decline actions on a\nleave cancellation are now shown only to the people actually authorized to review that\nrequest (the owner's department head, or an admin\u002Fexecutive), on both web and mobile.",{"type":21,"tag":54,"props":85,"children":86},{},[87,92],{"type":21,"tag":36,"props":88,"children":89},{},[90],{"type":27,"value":91},"Safer authentication forms",{"type":27,"value":93}," — The login, registration, and SSO sign-in forms now\nsubmit explicitly over POST, and the UI library was updated to a version that guarantees\nthe same, so credentials can never be placed in a URL if a form is submitted before the\npage finishes loading.",{"type":21,"tag":22,"props":95,"children":97},{"id":96},"expenses",[98],{"type":27,"value":99},"Expenses",{"type":21,"tag":50,"props":101,"children":102},{},[103,113,123,133,143],{"type":21,"tag":54,"props":104,"children":105},{},[106,111],{"type":21,"tag":36,"props":107,"children":108},{},[109],{"type":27,"value":110},"Download all receipts as a single ZIP",{"type":27,"value":112}," — Export every receipt on an expense report in\none archive instead of saving them one at a time.",{"type":21,"tag":54,"props":114,"children":115},{},[116,121],{"type":21,"tag":36,"props":117,"children":118},{},[119],{"type":27,"value":120},"All Claims filter",{"type":27,"value":122}," — The expenses list gains an \"All Claims\" filter so you can see\nevery claim in one place.",{"type":21,"tag":54,"props":124,"children":125},{},[126,131],{"type":21,"tag":36,"props":127,"children":128},{},[129],{"type":27,"value":130},"Clearer receipt uploads",{"type":27,"value":132}," — Upload prompts now list every supported receipt format, and\nthe claim header carries a hover help note explaining the workflow.",{"type":21,"tag":54,"props":134,"children":135},{},[136,141],{"type":21,"tag":36,"props":137,"children":138},{},[139],{"type":27,"value":140},"Verify scanned figures",{"type":27,"value":142}," — After a receipt scan, a reminder now prompts you to confirm\nthe extracted amounts before submitting.",{"type":21,"tag":54,"props":144,"children":145},{},[146,151],{"type":21,"tag":36,"props":147,"children":148},{},[149],{"type":27,"value":150},"Cleaner per-diem view",{"type":27,"value":152}," — The per-diem Actions column is hidden once a report is no\nlonger editable, removing controls that would not do anything.",1790889963334]