[{"data":1,"prerenderedAt":322},["ShallowReactive",2],{"$f3reh12imzorzk":3,"mdc--148q0n-key":15},{"release":4,"newer":10,"older":12,"page":14},{"tag":5,"name":5,"publishedAt":6,"url":7,"prerelease":8,"markdown":9},"v1.0.20","2026-08-26T19:12:49Z","https:\u002F\u002Fgithub.com\u002Fanhourtec\u002FBookYourPTO-SaaS\u002Freleases\u002Ftag\u002Fv1.0.20",false,"### Data import and migration from 48 HR platforms, plus a security and stability pass\r\n\r\nThis release adds **Data Import & Migration**, a guided way to bring an existing HR system's\r\npeople, departments, and time-off history into BookYourPTO. It ships with built-in column\r\nmappings for 48 platforms, direct API connections for four of them, and a preview step that\r\nwrites nothing to the database until it is approved. Alongside it: the framework and its\r\ndependencies were moved onto patched releases, and three regressions that came with that\r\nupgrade were found and fixed before release.\r\n\r\n### Data Import & Migration\r\n\r\n- **A four-step wizard** — Upload a file, confirm how its columns map onto BookYourPTO\r\n  fields, review a preview of exactly what will be created, then import. The wizard is at\r\n  **Settings → Data Import** and is available to administrators and executives.\r\n\r\n- **Nothing is written until you approve it** — The preview validates the first 100 rows\r\n  and shows what each one would create, so problems with the mapping surface before anything\r\n  reaches the database. Rows that cannot be imported are reported with the reason and\r\n  skipped, so a single malformed date does not fail the whole file.\r\n\r\n- **Imports can be rolled back for 72 hours** — A completed import can be reversed from its\r\n  detail page within three days, which matters when a mapping turns out to have been wrong on\r\n  the second look rather than the first.\r\n\r\n- **48 platforms recognized automatically** — Built-in templates cover 63 column layouts\r\n  across 48 platforms. The uploaded file's headers are matched against them, so in most\r\n  cases the mapping is already filled in when the step opens. Any column can still be\r\n  remapped by hand, and unmatched columns are skipped rather than guessed at.\r\n\r\n- **Employees, leave history, and departments** — Each is imported separately, so a\r\n  migration can be done in stages: people first, then their historical time off. Leave rows\r\n  are matched back to employees by email within the organization.\r\n\r\n- **CSV and Excel** — Both `.csv` and Excel workbooks (`.xlsx`, `.xls`) are accepted, since\r\n  most HR systems export one or the other and few offer a choice. Files can be up to 25MB\r\n  and 10,000 rows; larger migrations can be split across several imports.\r\n\r\n- **Sample files** — A sample CSV for each of the three data types can be downloaded from\r\n  the import page, for teams building a file by hand rather than exporting one.\r\n\r\n- **Save your own column mappings** — An organization can save a custom mapping as a\r\n  reusable template. Custom templates take priority over the built-in ones, which covers\r\n  systems that export a bespoke report layout.\r\n\r\n- **Canadian coverage** — 12 of the supported platforms are Canada-first: Collage HR,\r\n  Employment Hero (formerly Humi), Folks HR, Payworks, Rise People, Wagepoint, Payment\r\n  Evolution, Avanti Software, Nethris, PurelyHR, Wave Payroll, and Knit People. Folks HR serves\r\n  Quebec employers and exports in the account language, so its templates recognize both\r\n  English and French column headers rather than requiring every column to be remapped by\r\n  hand.\r\n\r\n### Direct platform connections\r\n\r\n- **Import without exporting a file** — BambooHR, Timetastic, Employment Hero (formerly\r\n  Humi), and Zoho People can be connected directly. Once connected, employees and leave\r\n  history are pulled straight from the account and can be re-imported at any time without\r\n  producing a new export.\r\n\r\n- **BambooHR, Timetastic, and Employment Hero** connect with an API key. BambooHR also\r\n  needs the account subdomain.\r\n\r\n- **Zoho People** connects by signing in to Zoho, so no key needs to be copied between\r\n  systems. The connection uses the Canadian Zoho region.\r\n\r\n- **Connections are tested before they are saved** — Credentials are verified against the\r\n  provider when the connection is created, so a mistyped key is reported immediately rather\r\n  than at the first import.\r\n\r\n### Security\r\n\r\n- **Framework and dependency updates** — The application framework and its build toolchain\r\n  were moved onto patched releases, closing every advisory raised by automated security\r\n  scanning. These covered remote code execution and cross-user data disclosure in\r\n  server-side rendering, an authentication bypass on mixed-case route paths, a\r\n  cross-site-scripting issue in HTML sanitization, and a development-tools issue that could\r\n  allow command execution on a developer's own machine. Automated scanning reports no\r\n  remaining advisories.\r\n\r\n- **The full test suite and a production build were verified on the new versions**, and the\r\n  three regressions the upgrade introduced were found and fixed rather than shipped. They\r\n  are listed below.\r\n\r\n### Fixes\r\n\r\n- **Authenticated requests could be sent without their credentials** — A framework change\r\n  altered when the shared request helper is bound, with the effect that the authorization\r\n  header stopped being attached. The application would load and then every request to the\r\n  API would be rejected. Requests now resolve the helper at call time, and a regression test\r\n  pins that behavior so a future upgrade fails the build instead of the login.\r\n\r\n- **The production server would not start** — The build stopped emitting part of a required\r\n  runtime dependency, so every page request returned an error while the API kept answering\r\n  normally. That combination would have reported a deployment as healthy. The dependency is\r\n  now bundled directly, with a test that fails if the incomplete form reappears.\r\n\r\n- **Leave records on the edge of a time zone were skipped on import** — The API connectors\r\n  ended their fetch window on the server's UTC day. An organization running ahead of UTC had\r\n  already moved into a day UTC had not reached, so time off booked on their current day fell\r\n  outside the window and was never imported, with the job still reporting success. The\r\n  window now extends past every real time zone offset.\r\n\r\n- **Hours could be imported as days** — The Payworks leave template mapped an hours column\r\n  onto the day-count field, which would have recorded 7.5 hours as 7.5 days. The row would\r\n  have validated and imported cleanly while overstating the employee's usage. The mapping\r\n  was removed and a check now scans every leave template for the same class of mistake.\r\n\r\n- **Platform logos were missing from the templates list** — The built-in templates page\r\n  showed a generic icon for all 63 entries. Logos are now served from a single shared list\r\n  used by every screen that shows them.\r\n\r\n- **Searching the platform picker returned an error** — Typing in the platform search field\r\n  raised an error instead of filtering the list.",{"tag":11,"name":11},"v1.0.21",{"tag":13,"name":13},"v1.0.19",1,{"data":16,"body":17},{},{"type":18,"children":19},"root",[20,29,43,48,175,181,224,230,253,259],{"type":21,"tag":22,"props":23,"children":25},"element","h3",{"id":24},"data-import-and-migration-from-48-hr-platforms-plus-a-security-and-stability-pass",[26],{"type":27,"value":28},"text","Data import and migration from 48 HR platforms, plus a security and stability pass",{"type":21,"tag":30,"props":31,"children":32},"p",{},[33,35,41],{"type":27,"value":34},"This release adds ",{"type":21,"tag":36,"props":37,"children":38},"strong",{},[39],{"type":27,"value":40},"Data Import & Migration",{"type":27,"value":42},", a guided way to bring an existing HR system's\npeople, departments, and time-off history into BookYourPTO. It ships with built-in column\nmappings for 48 platforms, direct API connections for four of them, and a preview step that\nwrites nothing to the database until it is approved. Alongside it: the framework and its\ndependencies were moved onto patched releases, and three regressions that came with that\nupgrade were found and fixed before release.",{"type":21,"tag":22,"props":44,"children":46},{"id":45},"data-import-migration",[47],{"type":27,"value":40},{"type":21,"tag":49,"props":50,"children":51},"ul",{},[52,70,80,90,100,110,145,155,165],{"type":21,"tag":53,"props":54,"children":55},"li",{},[56,61,63,68],{"type":21,"tag":36,"props":57,"children":58},{},[59],{"type":27,"value":60},"A four-step wizard",{"type":27,"value":62}," — Upload a file, confirm how its columns map onto BookYourPTO\nfields, review a preview of exactly what will be created, then import. The wizard is at\n",{"type":21,"tag":36,"props":64,"children":65},{},[66],{"type":27,"value":67},"Settings → Data Import",{"type":27,"value":69}," and is available to administrators and executives.",{"type":21,"tag":53,"props":71,"children":72},{},[73,78],{"type":21,"tag":36,"props":74,"children":75},{},[76],{"type":27,"value":77},"Nothing is written until you approve it",{"type":27,"value":79}," — The preview validates the first 100 rows\nand shows what each one would create, so problems with the mapping surface before anything\nreaches the database. Rows that cannot be imported are reported with the reason and\nskipped, so a single malformed date does not fail the whole file.",{"type":21,"tag":53,"props":81,"children":82},{},[83,88],{"type":21,"tag":36,"props":84,"children":85},{},[86],{"type":27,"value":87},"Imports can be rolled back for 72 hours",{"type":27,"value":89}," — A completed import can be reversed from its\ndetail page within three days, which matters when a mapping turns out to have been wrong on\nthe second look rather than the first.",{"type":21,"tag":53,"props":91,"children":92},{},[93,98],{"type":21,"tag":36,"props":94,"children":95},{},[96],{"type":27,"value":97},"48 platforms recognized automatically",{"type":27,"value":99}," — Built-in templates cover 63 column layouts\nacross 48 platforms. The uploaded file's headers are matched against them, so in most\ncases the mapping is already filled in when the step opens. Any column can still be\nremapped by hand, and unmatched columns are skipped rather than guessed at.",{"type":21,"tag":53,"props":101,"children":102},{},[103,108],{"type":21,"tag":36,"props":104,"children":105},{},[106],{"type":27,"value":107},"Employees, leave history, and departments",{"type":27,"value":109}," — Each is imported separately, so a\nmigration can be done in stages: people first, then their historical time off. Leave rows\nare matched back to employees by email within the organization.",{"type":21,"tag":53,"props":111,"children":112},{},[113,118,120,127,129,135,137,143],{"type":21,"tag":36,"props":114,"children":115},{},[116],{"type":27,"value":117},"CSV and Excel",{"type":27,"value":119}," — Both ",{"type":21,"tag":121,"props":122,"children":124},"code",{"className":123},[],[125],{"type":27,"value":126},".csv",{"type":27,"value":128}," and Excel workbooks (",{"type":21,"tag":121,"props":130,"children":132},{"className":131},[],[133],{"type":27,"value":134},".xlsx",{"type":27,"value":136},", ",{"type":21,"tag":121,"props":138,"children":140},{"className":139},[],[141],{"type":27,"value":142},".xls",{"type":27,"value":144},") are accepted, since\nmost HR systems export one or the other and few offer a choice. Files can be up to 25MB\nand 10,000 rows; larger migrations can be split across several imports.",{"type":21,"tag":53,"props":146,"children":147},{},[148,153],{"type":21,"tag":36,"props":149,"children":150},{},[151],{"type":27,"value":152},"Sample files",{"type":27,"value":154}," — A sample CSV for each of the three data types can be downloaded from\nthe import page, for teams building a file by hand rather than exporting one.",{"type":21,"tag":53,"props":156,"children":157},{},[158,163],{"type":21,"tag":36,"props":159,"children":160},{},[161],{"type":27,"value":162},"Save your own column mappings",{"type":27,"value":164}," — An organization can save a custom mapping as a\nreusable template. Custom templates take priority over the built-in ones, which covers\nsystems that export a bespoke report layout.",{"type":21,"tag":53,"props":166,"children":167},{},[168,173],{"type":21,"tag":36,"props":169,"children":170},{},[171],{"type":27,"value":172},"Canadian coverage",{"type":27,"value":174}," — 12 of the supported platforms are Canada-first: Collage HR,\nEmployment Hero (formerly Humi), Folks HR, Payworks, Rise People, Wagepoint, Payment\nEvolution, Avanti Software, Nethris, PurelyHR, Wave Payroll, and Knit People. Folks HR serves\nQuebec employers and exports in the account language, so its templates recognize both\nEnglish and French column headers rather than requiring every column to be remapped by\nhand.",{"type":21,"tag":22,"props":176,"children":178},{"id":177},"direct-platform-connections",[179],{"type":27,"value":180},"Direct platform connections",{"type":21,"tag":49,"props":182,"children":183},{},[184,194,204,214],{"type":21,"tag":53,"props":185,"children":186},{},[187,192],{"type":21,"tag":36,"props":188,"children":189},{},[190],{"type":27,"value":191},"Import without exporting a file",{"type":27,"value":193}," — BambooHR, Timetastic, Employment Hero (formerly\nHumi), and Zoho People can be connected directly. Once connected, employees and leave\nhistory are pulled straight from the account and can be re-imported at any time without\nproducing a new export.",{"type":21,"tag":53,"props":195,"children":196},{},[197,202],{"type":21,"tag":36,"props":198,"children":199},{},[200],{"type":27,"value":201},"BambooHR, Timetastic, and Employment Hero",{"type":27,"value":203}," connect with an API key. BambooHR also\nneeds the account subdomain.",{"type":21,"tag":53,"props":205,"children":206},{},[207,212],{"type":21,"tag":36,"props":208,"children":209},{},[210],{"type":27,"value":211},"Zoho People",{"type":27,"value":213}," connects by signing in to Zoho, so no key needs to be copied between\nsystems. The connection uses the Canadian Zoho region.",{"type":21,"tag":53,"props":215,"children":216},{},[217,222],{"type":21,"tag":36,"props":218,"children":219},{},[220],{"type":27,"value":221},"Connections are tested before they are saved",{"type":27,"value":223}," — Credentials are verified against the\nprovider when the connection is created, so a mistyped key is reported immediately rather\nthan at the first import.",{"type":21,"tag":22,"props":225,"children":227},{"id":226},"security",[228],{"type":27,"value":229},"Security",{"type":21,"tag":49,"props":231,"children":232},{},[233,243],{"type":21,"tag":53,"props":234,"children":235},{},[236,241],{"type":21,"tag":36,"props":237,"children":238},{},[239],{"type":27,"value":240},"Framework and dependency updates",{"type":27,"value":242}," — The application framework and its build toolchain\nwere moved onto patched releases, closing every advisory raised by automated security\nscanning. These covered remote code execution and cross-user data disclosure in\nserver-side rendering, an authentication bypass on mixed-case route paths, a\ncross-site-scripting issue in HTML sanitization, and a development-tools issue that could\nallow command execution on a developer's own machine. Automated scanning reports no\nremaining advisories.",{"type":21,"tag":53,"props":244,"children":245},{},[246,251],{"type":21,"tag":36,"props":247,"children":248},{},[249],{"type":27,"value":250},"The full test suite and a production build were verified on the new versions",{"type":27,"value":252},", and the\nthree regressions the upgrade introduced were found and fixed rather than shipped. They\nare listed below.",{"type":21,"tag":22,"props":254,"children":256},{"id":255},"fixes",[257],{"type":27,"value":258},"Fixes",{"type":21,"tag":49,"props":260,"children":261},{},[262,272,282,292,302,312],{"type":21,"tag":53,"props":263,"children":264},{},[265,270],{"type":21,"tag":36,"props":266,"children":267},{},[268],{"type":27,"value":269},"Authenticated requests could be sent without their credentials",{"type":27,"value":271}," — A framework change\naltered when the shared request helper is bound, with the effect that the authorization\nheader stopped being attached. The application would load and then every request to the\nAPI would be rejected. Requests now resolve the helper at call time, and a regression test\npins that behavior so a future upgrade fails the build instead of the login.",{"type":21,"tag":53,"props":273,"children":274},{},[275,280],{"type":21,"tag":36,"props":276,"children":277},{},[278],{"type":27,"value":279},"The production server would not start",{"type":27,"value":281}," — The build stopped emitting part of a required\nruntime dependency, so every page request returned an error while the API kept answering\nnormally. That combination would have reported a deployment as healthy. The dependency is\nnow bundled directly, with a test that fails if the incomplete form reappears.",{"type":21,"tag":53,"props":283,"children":284},{},[285,290],{"type":21,"tag":36,"props":286,"children":287},{},[288],{"type":27,"value":289},"Leave records on the edge of a time zone were skipped on import",{"type":27,"value":291}," — The API connectors\nended their fetch window on the server's UTC day. An organization running ahead of UTC had\nalready moved into a day UTC had not reached, so time off booked on their current day fell\noutside the window and was never imported, with the job still reporting success. The\nwindow now extends past every real time zone offset.",{"type":21,"tag":53,"props":293,"children":294},{},[295,300],{"type":21,"tag":36,"props":296,"children":297},{},[298],{"type":27,"value":299},"Hours could be imported as days",{"type":27,"value":301}," — The Payworks leave template mapped an hours column\nonto the day-count field, which would have recorded 7.5 hours as 7.5 days. The row would\nhave validated and imported cleanly while overstating the employee's usage. The mapping\nwas removed and a check now scans every leave template for the same class of mistake.",{"type":21,"tag":53,"props":303,"children":304},{},[305,310],{"type":21,"tag":36,"props":306,"children":307},{},[308],{"type":27,"value":309},"Platform logos were missing from the templates list",{"type":27,"value":311}," — The built-in templates page\nshowed a generic icon for all 63 entries. Logos are now served from a single shared list\nused by every screen that shows them.",{"type":21,"tag":53,"props":313,"children":314},{},[315,320],{"type":21,"tag":36,"props":316,"children":317},{},[318],{"type":27,"value":319},"Searching the platform picker returned an error",{"type":27,"value":321}," — Typing in the platform search field\nraised an error instead of filtering the list.",1790889963334]